Slashdot Mirror


Security Review Summary of NIST SHA-3 Round 1

FormOfActionBanana writes "The security firm Fortify Software has undertaken an automated code review of the NIST SHA-3 round 1 contestants (previously Slashdotted) reference implementations. After a followup audit, the team is now reporting summary results. According to the blog entry, 'This just emphasizes what we already knew about C, even the most careful, security conscious developer messes up memory management.' Of particular interest, Professor Ron Rivest's (the "R" in RSA) MD6 team has already corrected a buffer overflow pointed out by the Fortify review. Bruce Schneier's Skein, also previously Slashdotted, came through defect-free."

6 of 146 comments (clear)

  1. SHA-3 Is Cracked. by Anonymous Coward · · Score: -1, Troll

    Otherwise the NSA wouldn't have let it get this far.

    1. Re:SHA-3 Is Cracked. by gavron · · Score: 1, Troll

      Your null pointer bitch derefernced[sic] herself and crashed, or I'll take out your fucking lights. How would you like that?

  2. What do you call a penis up your ass? ASS-PENIS!! by Anonymous Coward · · Score: -1, Troll

    Most niggers in Africa don't know what SHA-3 is. Therefore, SHA-3 is RACIST!

    nigger nigger nigger

  3. Re:ANSI C by Anonymous Coward · · Score: -1, Troll

    Blame open source, not the language. This is the typical crap that comes out of FOSS projects -- unchecked boundary conditions, buffer overflows, sloppy (or non-existent) error handling. Trust me, even if they coded this stuff in Ada or Perl, they would have fucked it up. Frankly, I'm surprised most of them even compiled without lint warnings.

  4. Re:ANSI C by Anonymous Coward · · Score: -1, Troll

    Mod parent up. Thanks. Annoying SLASHVERTISEMENT!

  5. Re:ANSI C by iwein · · Score: 0, Troll

    Yes, it would be nice to have a way to compile beautiful mathematical functions to machine code. Sadly you're dependent on those people that are writing the grammar and reference implementation of the compiler. What if they need one of those pesky algorithms for that?

    --
    Show a man some news, distract him for an hour. Show a man some mod points, distract him for the rest of his life.