Audit Open Original ↗
Go Crypto Libraries
Type
Security review
Client
Date
2025-03
Domain
Crypto
Effort
12 wks
Section
Cryptography Reviews
Trail of Bits's security review of Google (Mar 2025) identified 6 issues: 1 low, and 5 informational.
Findings · 6
- 1 Fiat conversion from bytes to field elements is not constant time Informational
- 2 P-256 conditional negation is not constant time in PowerPC assembly Informational
- 3 Custom finalizer may free memory at the start of a C function call using this memory Low
- 4 The CTR-DRBG module presents multiple misuse risks Informational
- 5 PBKDF2 does not enforce output length limitations Informational
- 6 Timing leak in edwards25519 Scalar.SetCanonicalBytes Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related