Skip to content
Discussion options

You must be logged in to vote

Have you read the advisory? It says:

As stated in the security policy side-channel vulnerabilities are outside the scope of the project. Not because we don't want side-channel secure implementation, but because the main goal of the project is to be pure python and implementing side-channel free code in pure python is impossible.

See also previous reports and their discussion on the topic. @tomato42 makes it very clear in a comment in #330:

I don't want people to use this library in production environments...

It's a teaching tool, it's a testing tool, it's absolutely not an production grade implementation.
I maintain it to have support for ECDH and ECDSA in tlsfuzzer, which I need to be…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by neverpanic
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants