Article 25WMD Project Wycheproof

Project Wycheproof

by
ris
from LWN.net on (#25WMD)
Google has announcedthe release of a set of security tests that check cryptographic softwarelibraries for known weaknesses, called Project Wycheproof."Our first set of tests are written in Java, because Java has a common cryptographic interface. This allowed us to test multiple providers with a single test suite. While this interface is somewhat low level, and should not be used directly, we still apply a "defense in depth" argument and expect that the implementations are as robust as possible. For example, we consider weak default values to be a significant security flaw. We are converting as many tests into sets of test vectors to simplify porting the tests to other languages."
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments