Skip to content

bignp256: reject secrets that aren't 32 bytes in hash_secret_to_curve - #1948

Open
FlashWayne wants to merge 1 commit into
RustCrypto:masterfrom
FlashWayne:bignp256-swu-secret-len
Open

FlashWayne wants to merge 1 commit into
RustCrypto:masterfrom
FlashWayne:bignp256-swu-secret-len

Conversation

@FlashWayne

Copy link
Copy Markdown
Contributor

bake-swu (STB 34.101.66-2014, 6.2.3) takes a secret of exactly 2l = 256 bits, which belt-keywrap then wraps into 48 bytes. hash_secret_to_curve accepted any length: the expander copies at most 32 bytes into a zeroed buffer, so longer secrets are silently truncated and shorter ones zero padded. As a result different secrets map to the same point (x and x || anything, or a 31 byte x and x || 00), and an empty secret is accepted too.

It now returns an error unless the secret is 32 bytes. Doesn't touch the step 4 change in #1934.

before: test_secret_length ... panicked at bignp256/tests/swu.rs:32:5
after:  test_secret_length ... ok, test_bake_b4 ... ok

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant