On Friday, July 26, 2019 at 12:56:48 AM UTC-4, Jeffrey Walton wrote: > > Hi Everyone, > > We received a private email concerning an ECDSA timing attack by Ján > Jančár. > > We are tracking the report at > https://github.com/weidai11/cryptopp/issues/869 . >
The leak on the length of the nonce was cleared at https://github.com/weidai11/cryptopp/pull/870/commits/80c59bcdb251 . Next on the hit list are the leaks on Add(), Double() and Multiply(). Jeff -- You received this message because you are subscribed to "Crypto++ Users". More information about Crypto++ and this group is available at http://www.cryptopp.com and http://groups.google.com/forum/#!forum/cryptopp-users. --- You received this message because you are subscribed to the Google Groups "Crypto++ Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/cryptopp-users/d3b9a4a6-80d3-40f7-b08e-15a2cc725da3%40googlegroups.com.
