High-Assurance Cryptography.

5 posts tagged “High-Assurance Cryptography”.

Research

CE Labs' Approach to TLS: A Critical Analysis

An examination of CE Labs' TLS implementations reveals 75% of valid ECDSA signatures rejected, authentication tags silently dropped, no certificate validation, and remote denial-of-service vectors.

11 min read
Research

Even More Bugs in CE Labs' libcrux: ML-DSA

Three findings in libcrux's ML-DSA implementation: a verifier norm check that is dead code due to a wrong constant, a missing bounds check in hint deserialization, and a wrong multiplication specification that renders AVX2 proofs unsound.

12 min read