Please sign in to comment.
Address a timing side channel whereby it is possible to determine some
information about the length of the scalar used in ECDSA operations from a large number (2^32) of signatures. Thanks to Neals Fournaise, Eliane Jaulmes and Jean-Rene Reinhard for reporting this issue. Refer to #4576 for further details. Reviewed-by: Andy Polyakov <firstname.lastname@example.org> Reviewed-by: Matt Caswell <email@example.com> (Merged from #4623)
- Loading branch information...