-
12
pages
-
English
-
Documents
Description
Fortify Software NIST SHA-3 Competition Security Audit Results Joy Forsythe, Security Researcher Douglas Held, Software Security Consultant Abstract The National Institutes of Standards and Technology (“NIST”) is holding a competition to choose a design for the Secure Hash Algorithm version 3 (“SHA-3”). The reference implementations of some of the contestants have bugs in them that could cause crashes, performance problems or security problems if they are used in their current state. Based on our bug reports, some of those bugs have already been fixed. Copyright © 2009 Fortify Software. All rights reserved. 1 Introduction The inspiration for the project was the result of testing of a pre-release version of Fortify SCA against the Skein and MD6 reference implementations. This was prompted by an article introducing the NIST round 1 entries on the 1technology discussion website Slashdot.org . The original idea was to test complex C code that was unlikely to contain defects. We were surprised to discover buffer overflows in the MD6 implementation. We carefully reviewed the automated results and contacted the author, Professor Ron Rivest. The MD6 team to confirmed the findings and they resubmitted a corrected version of the implementation to NIST. Based on this positive outcome, we decided to do a similar review of the remaining SHA-3 submittals. Ultimately two projects, MD6 and Blender, contained buffer ...
-
Publié par
-
Langue
English