Profile

Contact Details

Ribbons

Badges

Christopher Duane


Contributions

1 to 4 of 4 total
Posted By Christopher Duane 06-26-2013 19:36
Found In Egroup: OASIS PKCS 11 TC
\ view thread
Hi Mike, The article you are (I think) referring to is an improvement to the attack, and the mitigation against the improvement is to disallow support for v1.5. If we recommended only to use v2 with OAEP, it would not be enough. That is why the recommendation is to both move to v2 and to disallow v1.5. ...
Posted By Christopher Duane 06-26-2013 14:49
Found In Egroup: OASIS PKCS 11 TC
\ view thread
Hi Oscar, The recommendation to use OAEP (optimal asymmetric encryption padding), as the name implies, is referring to a padding scheme for encryption. Essentially the attack in question is a side channel attack against the padding, and moving to v2 with OAEP itself is not sufficient unless you also ...
Posted By Christopher Duane 06-24-2013 14:13
Found In Egroup: OASIS PKCS 11 TC
\ view thread
Resending proposal without signature enabled for proper archival in the public domain. Apologies about the delay, as I was on vacation. Hi, A concern was raised on the wiki around extraction attacks (more specifically a padded oracle/Bleichenbaucher style attack). In general the protection lies in selection ...
Posted By Christopher Duane 05-31-2013 15:40
Found In Egroup: OASIS PKCS 11 TC
\ view thread
Attachment: smime.p7m Description: S/MIME encrypted message