You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
draft-irtf-cfrg-rsa-guidance contains plenty of guidance for how to implement RSA in constant time correctly. This is an issue tracking what parts of its recommendations we're currently missing.
Note we have a separate issue #626 specifically to track padding defects and the lack of implicit rejection on padding failures.
NOTE: I'd kindly request that people do NOT open PRs that try to vibe code solutions to these problems. We already have people including myself working on these issues and vibe coded PRs clutter the tracker and just generally waste my time.
draft-irtf-cfrg-rsa-guidancecontains plenty of guidance for how to implement RSA in constant time correctly. This is an issue tracking what parts of its recommendations we're currently missing.Note we have a separate issue #626 specifically to track padding defects and the lack of implicit rejection on padding failures.
rem_vartimefor mod reduce (see §6.1, §6.2)kciphertext octets for PKCS#1 v1.5 decryption (see §7.2, addressed in Fix RSA constant-time padding and length checks #710)NOTE: I'd kindly request that people do NOT open PRs that try to vibe code solutions to these problems. We already have people including myself working on these issues and vibe coded PRs clutter the tracker and just generally waste my time.