Audit Open Original ↗
Ren
Type
Security review
Client
—
Date
2020-08
Domain
AppSec
Effort
4 wks
Section
Technology Product Reviews
Trail of Bits's security review of Ren (Aug 2020) identified 6 issues: 1 high, and 5 informational.
Findings · 6
- 1 Index of zero is allowed for secret shares High
- 2 Sanity checks missing for second secret sharing generator Informational
- 3 NewPointFromXY does not verify the point is on the curve Informational
- 4 NegateUnsafe assumes field element representation is normalized Informational
- 5 IsZero and Eq assume leading zeros have been removed Informational
- 6 XY returns the wrong result for the point at infinity Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related