-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
citing Marvin attack? #214
Comments
Hi @armfazh, @chris-wood : What do you think? Our last revision precedes the public disclosure of this vulnerability but I don't know what our options are to address this. |
The only option is errata at this point. That said, doesn't the attack only apply to PKCS#1 v1.5? What would be the reason for citing it in this document? |
Because we are quoting RFC8017: "Although no attacks are known against RSASSA-PKCS#1 v1.5" [RSA-PSS is recommended] |
Oh, hah, I see 🤦 an errata is the best way forward then! |
It's probably worth citing Marvin attack in Section Alternative RSA Encoding Functions
The text was updated successfully, but these errors were encountered: