Re: Security update of nettle

2016-08-09 Thread Niels Möller
reas as valid and defined at the end of the signature functions. Unfortunately, one might get some warnings even after the fix, it probably doesn't make the computation *completely* silent. Regards, /Niels -- Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26. Internet ema

Re: Security update of nettle

2016-08-06 Thread Niels Möller
I suggest something like this: > "Protect against potential timing attacks against exponentiation operations > as described in CVE-2016-6489 RSA code is vulnerable to cache sharing > related attacks." I'd suggest the more general "side-channel attacks" over "

Re: Security update of nettle

2016-08-09 Thread Niels Möller
s, /Niels -- Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26. Internet email is subject to wholesale government surveillance.