Getting apples, bananas or cherries from hash functions !
ID: e7e0f49c-47ef-539e-aab3-db682fc257fe
STIX ID: report--e7e0f49c-47ef-539e-aab3-db682fc257fe
Feed Name: Kudelski Security
This blog post examines insecure approaches for hashing arbitrary inputs into bounded ranges or elliptic-curve groups, showing how naive modular reduction and 'hunt-and-peck' (try-and-increment) schemes introduce biases, enable second-preimage collisions, and may leak information via timing. The authors present proof-of-concept examples, cite real-world findings (Swiss Post e-voting and issues found in Kyber Go), note that fixes were applied, and recommend using standardized, constant-time constructions such as XOF-based generation, hash_to_field, and the IETF hash_to_curve/map_to_group methods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
