Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Tracking issue for constant-time implementation problems

オープン
#711 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
20/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
rust

調査の方向性

Start by reading the linked draft-irtf-cfrg-rsa-guidance sections and reviewing related issues #710, #702, and #626 to identify which recommendations remain unaddressed. This is a broad tracking issue with existing contributors working on it; done means a specific unchecked recommendation is resolved and its checklist entry can be marked complete, with coordination before any contribution.

索引モデルが issue の本文から書いたものです。

説明

security

draft-irtf-cfrg-rsa-guidance contains plenty of guidance for how to implement RSA in constant time correctly. This is an issue tracking what parts of its recommendations we're currently missing.

Note we have a separate issue #626 specifically to track padding defects and the lack of implicit rejection on padding failures.

  1. Make private-result integer-to-octet conversion fixed-width and constant-time (see §6.1, §7.2, partly addressed in #710)
  2. Ignore the first encoded-message octet when depadding OAEP (see §7)
  3. Apply base blinding by default across private-key operations (see §6.1, partly addressed in #702)
  4. Audit and replace CRT reductions using division by secret primes including rem_vartime for mod reduce (see §6.1, §6.2)
  5. Derive private arithmetic buffer widths from the public modulus (§6.2.1)
  6. Add fresh exponent blinding for each private operation (see §6.4)
  7. Add CRT modulus blinding (see §6.5)
  8. Require exactly k ciphertext octets for PKCS#1 v1.5 decryption (see §7.2, addressed in #710)

NOTE: I'd kindly request that people do NOT open PRs that try to vibe code solutions to these problems. We already have people including myself working on these issues and vibe coded PRs clutter the tracker and just generally waste my time.

主要言語
Rust
スター
672
フォーク
193
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

RustCrypto/RSA のほかの issue

RustCrypto/RSA の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。