Tracking issue for constant-time implementation problems
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 20/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- rust
- 領域
- cryptography, security
調査の方向性
Start by reading the linked draft-irtf-cfrg-rsa-guidance sections and reviewing related issues #710, #702, and #626 to identify which recommendations remain unaddressed. This is a broad tracking issue with existing contributors working on it; done means a specific unchecked recommendation is resolved and its checklist entry can be marked complete, with coordination before any contribution.
索引モデルが issue の本文から書いたものです。
説明
draft-irtf-cfrg-rsa-guidance contains plenty of guidance for how to implement RSA in constant time correctly. This is an issue tracking what parts of its recommendations we're currently missing.
Note we have a separate issue #626 specifically to track padding defects and the lack of implicit rejection on padding failures.
- Make private-result integer-to-octet conversion fixed-width and constant-time (see §6.1, §7.2, partly addressed in #710)
- Ignore the first encoded-message octet when depadding OAEP (see §7)
- Apply base blinding by default across private-key operations (see §6.1, partly addressed in #702)
- Audit and replace CRT reductions using division by secret primes including
rem_vartimefor mod reduce (see §6.1, §6.2) - Derive private arithmetic buffer widths from the public modulus (§6.2.1)
- Add fresh exponent blinding for each private operation (see §6.4)
- Add CRT modulus blinding (see §6.5)
- Require exactly
kciphertext octets for PKCS#1 v1.5 decryption (see §7.2, addressed in #710)
NOTE: I'd kindly request that people do NOT open PRs that try to vibe code solutions to these problems. We already have people including myself working on these issues and vibe coded PRs clutter the tracker and just generally waste my time.
- 主要言語
- Rust
- スター
- 672
- フォーク
- 193
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
RustCrypto/RSA のほかの issue
-
Silent salt_len truncation in signature_algorithm_identifier() causes signature verification failures対応中かも @cong-or が 72 日前に担当しました。 オープン
難易度 3/5 半日 初心者へのやさしさ 74/100
RustCrypto/RSA#703 ·
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
RustCrypto/RSA#686 · コメント 4 件 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
RustCrypto/RSA#647 · コメント 10 件 · リアクション 2 件 ·
-
broken rust docsオープン
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
RustCrypto/RSA#641 · リアクション 3 件 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
RustCrypto/RSA#640 ·
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
pact-foundation/pact-cli#154 ·
メンテナーはふだん 3 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
antithesishq/bombadil#361 ·
メンテナーはふだん 1 日以内に返信
-
test(executor_l0): assert execute() TaskOutcome, not only bus events / 断言 execute() 返回的 TaskOutcomeオープンtype:debt
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
skaiy/wild_agentos#425 ·
メンテナーはふだん 1 日以内に返信
-
Default-import note suggests `import * as process` for velt:process, which does not name the builtinオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
bug ticket
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
cratestack/cratestack#1154 ·
メンテナーはふだん 1 日以内に返信