Trail of Bits

Ren

Type

Security review

Client

Date

2020-08

Domain

AppSec

Effort

4 wks

Section

Technology Product Reviews

Trail of Bits's security review of Ren (Aug 2020) identified 6 issues: 1 high, and 5 informational.

Findings · 6

  1. 1 Index of zero is allowed for secret shares High
  2. 2 Sanity checks missing for second secret sharing generator Informational
  3. 3 NewPointFromXY does not verify the point is on the curve Informational
  4. 4 NegateUnsafe assumes field element representation is normalized Informational
  5. 5 IsZero and Eq assume leading zeros have been removed Informational
  6. 6 XY returns the wrong result for the point at infinity Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related