Discussion about this post

User's avatar
Neural Foundry's avatar

Stellar write-up on the RDSEED bug. The PS3 example really drives home how catastrophic nonce reuse is for ECDSA, but the subtler angle about bias slowly leaking bits over many signatures is way scarier imo. Back when I was messing around with crypto implementations, I never fully appreciated how sensititve EC schemes are to RNG quality compared to somthing like RSA. Makes you wonder how many embedded devices are out there with similarly flawed TRNGs nobody's caught yet.

Expand full comment

No posts

Ready for more?