Blog

Do not use AES in a context where timing attacks are possible
Pascal Cuoq on 31 December 2011

Justification There recently was a thread in the Frama-C mailing list on verifying the Rijndael cipher, standardized and better-known as AES. Nowadays, AES is mostly famous for being sensitive to timing attacks. An attacker measuring the time it takes to encrypt known plaintext with an unknown key can deduce the...

Read More

More Christmas rant
Pascal Cuoq on 30 December 2011

In 2011, I got an Xbox 360. It's not what I would have liked but you know what they say about not looking gift consoles in the mouth especially when you get them one solstice early. When in the game shop I saw in the second-hand games bin the game...

Read More

Christmas and social networks
Pascal Cuoq on 30 December 2011

I would use a social network where the discussions are about the near future's zeitgeist. As they are, people just use them to discuss what is happening now (\what are you doing?") which does not have the same usefulness. Case in point: Christmas just came and went; presents given and...

Read More

Overconfidence expected
Pascal Cuoq on 9 December 2011

I was previously complaining about the use of the word \prove" when describing either what Frama-C or another tool does to mean something other than what it means. But it seems we have come to the point over-confidence is actually expected lest readers get confused. In a submitted article one...

Read More