![]() |
|
Message-ID: <99b8ce87-c95b-4679-62ee-6576764f38e9@iki.fi>
Date: Tue, 14 Oct 2025 13:12:18 -0400 (EDT)
From: Billy Brumley <bbb@....fi>
To: oss-security@...ts.openwall.com
Subject: Re: BoringSSL private key loading is not constant
time
> It appears to be the number of trailing zero bytes in an elliptic
> curve secret key. That lets an attacker narrow the search space,
> but that is all.
Thank you, that's accurate from the science perspective.
Yet more importantly, the implementation is not constant time in the
accepted model we've been using since 2004. It seems BoringSSL has their
own definition for that, better suiting their business model --
"alternative facts"
BBB
--
Dr. Billy B. Brumley, D.Sc. (Tech.)
Research Director, ESL Global Cybersecurity Institute (GCI)
Kevin O'Sullivan Endowed Professor, Department of Cybersecurity (CSEC)
Director, Platform Security Laboratory (PLATSEC)
Rochester Institute of Technology
Cybersecurity Hall 70-1770
100 Lomb Memorial Drive
Rochester, NY, 14623-5608, USA
S/MIME public key: https://people.rit.edu/bbbics/bbbics@rit.edu.crt
S/MIME public key: https://people.rit.edu/bbbics/bbb@iki.fi.crt
https://www.rit.edu/directory/bbbics-billy-brumley
https://www.rit.edu/cybersecurity/
Download attachment "smime.p7s" of type "application/pkcs7-signature" (1537 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.