Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <92f8c3a1-b61-52bd-c56e-965891a84530@iki.fi>
Date: Tue, 14 Oct 2025 12:10:23 -0400 (EDT)
From: Billy Brumley <bbb@....fi>
To: oss-security@...ts.openwall.com
Subject: Re: BoringSSL private key loading is not constant
 time

Hey Alex,

> it's not really an attack of note. In this case, as I understand it,
> the only thing that's alleged to be leaked is the length of a key,
> which already wasn't confidential.

Is byte 31 (indexed from zero, bc I'm a computer scientist, not a savage) 
of Jeff's BitCoin private key confidential or not?

The leak reveals if it's all-zero or not, which of course, 1/256 keys are, 
so it affects a significant portion of the Internet. (Maybe not Jeff, but 
I assure you Jeff is significant, and I value him as a human being.)

It's your reputation as a securty profession on the line, so please speak 
up. You chose to have the discussion on oss-security without understanding 
the post, so here we are.

(I'm shocked we're still battling this CVE 15 years later. This was the 
running joke in the talk.)

Let us know,

BBB

-- 
Dr. Billy B. Brumley, D.Sc. (Tech.)
Research Director, ESL Global Cybersecurity Institute (GCI)
Kevin O'Sullivan Endowed Professor, Department of Cybersecurity (CSEC)
Director, Platform Security Laboratory (PLATSEC)
Rochester Institute of Technology
Cybersecurity Hall 70-1770
100 Lomb Memorial Drive
Rochester, NY, 14623-5608, USA
S/MIME public key: https://people.rit.edu/bbbics/bbbics@rit.edu.crt
S/MIME public key: https://people.rit.edu/bbbics/bbb@iki.fi.crt
https://www.rit.edu/directory/bbbics-billy-brumley
https://www.rit.edu/cybersecurity/
Download attachment "smime.p7s" of type "application/pkcs7-signature" (1537 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.