[Cryptography-dev] The ECDH vulnerability

Roland Hedberg roland at catalogix.se
Mon Jul 23 12:06:22 EDT 2018


In https://blogs.adobe.com/security/2017/03/critical-vulnerability-uncovered-in-json-encryption.html
Antonio Sanso discusses a vulnerability when doing Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES).

Can cryptography help me with this ?

Basically, can I use cryptography to check whether public key is on the private key's curve.

— Roland

The higher up you go, the more mistakes you are allowed. Right at the top, if you make enough of them, it's considered to be your style. 
-Fred Astaire, dancer, actor, singer, musician, and choreographer (10 May 1899-1987)



More information about the Cryptography-dev mailing list