Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
Explore a critical security vulnerability in the Go implementation of the P-256 elliptic curve in this 46-minute Black Hat conference talk. Dive into the intricacies of a subtle bug caused by a misplaced carry bit affecting a minuscule percentage of field subtraction operations. Learn how this seemingly insignificant flaw can be exploited to construct a full-scale, practical key recovery attack targeting JSON Web Encryption. Follow along as Filippo Valsorda breaks down the attack methodology, covering topics such as code analysis, Double and Add operations, Scalar Multiplication, Adaptive Attack strategies, Magic Points, and postprocessing techniques. Gain insights into the attack's initiation process and witness a live demonstration of its effectiveness. Conclude with a discussion on new policies and their implications for the crypto community.