Skip to content

Potential side-channels during en-/decoding of private-key #56

Description

@blochberger

There are multiple places where an RSA private-key is encoded or decoded with Base64 using standard Swift library functions. Since these functions do not guarantee constant-time processing of the input, there is a potential side-channel that may leak information about the private-key.

I did not investigate the code thoroughly, but here are the potentially insecure uses I found at first glance:

https://github.com/IBM-Swift/BlueRSA/blob/9435e102af2838aa29c1f52a843ee1886876c379/Sources/CryptorRSA/CryptorRSAKey.swift#L392

https://github.com/IBM-Swift/BlueRSA/blob/9435e102af2838aa29c1f52a843ee1886876c379/Sources/CryptorRSA/CryptorRSAKey.swift#L631

https://github.com/IBM-Swift/BlueRSA/blob/9435e102af2838aa29c1f52a843ee1886876c379/Sources/CryptorRSA/CryptorRSAKey.swift#L676

https://github.com/IBM-Swift/BlueRSA/blob/9435e102af2838aa29c1f52a843ee1886876c379/Sources/CryptorRSA/CryptorRSAKey.swift#L739

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions