[tor-bugs] #18896 [Core Tor/Tor]: Test supposedly constant-time crypto primitives to verify that they are in fact constant-time
Tor Bug Tracker & Wiki
blackhole at torproject.org
Mon Jul 10 17:57:24 UTC 2017
#18896: Test supposedly constant-time crypto primitives to verify that they are in
fact constant-time
-------------------------------------------------+-------------------------
Reporter: nickm | Owner:
Type: enhancement | Status: new
Priority: Medium | Milestone: Tor:
| unspecified
Component: Core Tor/Tor | Version:
Severity: Normal | Resolution:
Keywords: testing crypto constant-time side- | Actual Points:
channel disaster-waiting-to-happen |
Parent ID: | Points: medium
Reviewer: | Sponsor:
| Sponsor3-can
-------------------------------------------------+-------------------------
Comment (by isis):
I [https://github.com/isislovecruft/ctgrind-valgrind revised agl's ctgrind
patch for the latest valgrind]. Next we'd need to make tests which
exercise the crypto code with the secrets poisoned in memory.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18896#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list