Skip to content

redact secret key material from Debug output - #394

Open
EliNaig wants to merge 1 commit into
RustCrypto:masterfrom
EliNaig:fix/ml-kem-redacted-debug
Open

EliNaig wants to merge 1 commit into
RustCrypto:masterfrom
EliNaig:fix/ml-kem-redacted-debug

Conversation

@EliNaig

@EliNaig EliNaig commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

DecapsulationKey and DecryptionKey derived Debug, which could expose secret key material when a key was printed or logged.

This changes DecapsulationKey to show only the public ek, following the approach used in x-wing. DecryptionKey now prints as DecryptionKey { .. }.

No changes to the algorithms or public API. Added a regression test covering ML-KEM-512, ML-KEM-768, and ML-KEM-1024.

`DecapsulationKey` and `DecryptionKey` derived `Debug`, which printed
the secret vector `s_hat`, the seed `d`, and `z`. Only show the public
`ek` for `DecapsulationKey`, matching `x-wing`, and print
`DecryptionKey { .. }` for the inner key.

Adds a test covering ML-KEM-512/768/1024.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant