README.md: add info about Marvin Attack (RUSTSEC-2023-0071) (#391)
References: - https://github.com/RustCrypto/RSA/issues/19 - https://rustsec.org/advisories/RUSTSEC-2023-0071.html - https://people.redhat.com/~hkario/marvin/
This commit is contained in:
parent
ac108c9e9d
commit
5d45065bd8
12
README.md
12
README.md
@ -65,16 +65,19 @@ There will be three phases before `1.0` 🚢 can be released.
|
|||||||
- [ ] Fuzz testing
|
- [ ] Fuzz testing
|
||||||
- [ ] Security Audits
|
- [ ] Security Audits
|
||||||
|
|
||||||
## Security Notes
|
## ⚠️Security Warning
|
||||||
|
|
||||||
This crate has received one [security audit by Include Security][audit], with
|
This crate has received one [security audit by Include Security][audit], with
|
||||||
only one minor finding which has since been addressed.
|
only one minor finding which has since been addressed.
|
||||||
|
|
||||||
See the [open security issues] on our issue tracker for other known problems.
|
See the [open security issues] on our issue tracker for other known problems.
|
||||||
|
|
||||||
Notably the implementation of [modular exponentiation is not constant time],
|
~~Notably the implementation of [modular exponentiation is not constant time],
|
||||||
but timing variability is masked using [random blinding], a commonly used
|
but timing variability is masked using [random blinding], a commonly used
|
||||||
technique.
|
technique.~~ This crate is vulnerable to the [Marvin Attack] which could enable
|
||||||
|
private key recovery by a network attacker (see [RUSTSEC-2023-0071]).
|
||||||
|
|
||||||
|
You can follow our work on mitigating this issue in [#390].
|
||||||
|
|
||||||
## Minimum Supported Rust Version (MSRV)
|
## Minimum Supported Rust Version (MSRV)
|
||||||
|
|
||||||
@ -118,3 +121,6 @@ dual licensed as above, without any additional terms or conditions.
|
|||||||
[open security issues]: https://github.com/RustCrypto/RSA/issues?q=is%3Aissue+is%3Aopen+label%3Asecurity
|
[open security issues]: https://github.com/RustCrypto/RSA/issues?q=is%3Aissue+is%3Aopen+label%3Asecurity
|
||||||
[modular exponentiation is not constant time]: https://github.com/RustCrypto/RSA/issues/19
|
[modular exponentiation is not constant time]: https://github.com/RustCrypto/RSA/issues/19
|
||||||
[random blinding]: https://en.wikipedia.org/wiki/Blinding_(cryptography)
|
[random blinding]: https://en.wikipedia.org/wiki/Blinding_(cryptography)
|
||||||
|
[Marvin Attack]: https://people.redhat.com/~hkario/marvin/
|
||||||
|
[RUSTSEC-2023-0071]: https://rustsec.org/advisories/RUSTSEC-2023-0071.html
|
||||||
|
[#390]: https://github.com/RustCrypto/RSA/issues/390
|
||||||
|
Loading…
x
Reference in New Issue
Block a user