Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question about cryptographic security rules ? #17

Open
prodnet opened this issue Mar 30, 2019 · 1 comment
Open

Question about cryptographic security rules ? #17

prodnet opened this issue Mar 30, 2019 · 1 comment

Comments

@prodnet
Copy link

prodnet commented Mar 30, 2019

Hello,

Your secret sharing codes around meet the cryptographic security rules ?
Some details like : integrity checks and side-channel resistance

Recommandations :

*Be side channel resistant (timing, branch, cache)
*Secure the shared secret with a MAC
*Use the platform (OS) randomness source

**These slip-ups can often fully compromise the security of the scheme.

@Qbicz
Copy link
Owner

Qbicz commented Apr 1, 2019

Hello @prodnet. Thank you for drawing attention to these important aspects. The repo contains algorithms. They achieve the goal of the algorithm as described in every research work they are based on. There were no additional effort to make it resistant to side-channel attacks or to add integrity check.

I added a note, please see c59272d

If you can help make the code secure against attacks, contributions are welcome.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants