Paul Bottinelli

29 posts

Paul Bottinelli

Paul Bottinelli

@paulbottinelli

Cryptography @ Trail of Bits

Waterloo, Ontario Katılım Eylül 2009
177 Takip Edilen90 Takipçiler
Giacomo 🪿
Giacomo 🪿@isogenies·
@durumcrustulum This feels like when I clean up my desktop by moving everything into a new directory called “old desktop” haha
English
2
0
3
145
Deirdre Connolly¹
Deirdre Connolly¹@durumcrustulum·
Just closed a bunch of tabs by adding them to Paperpile 😅
English
2
0
1
824
Giacomo 🪿
Giacomo 🪿@isogenies·
A ⭐️ for first person to recognise the diagram 🐙
English
4
0
2
0
Giacomo 🪿
Giacomo 🪿@isogenies·
Sneak peak of something I'm working on with friends.
Giacomo 🪿 tweet media
English
3
0
16
0
Paul Bottinelli
Paul Bottinelli@paulbottinelli·
@fasterthanlime @rivovasta It has! Long gone are our university days, studying together in the dark corridors of EPFL.. I'm doing quite well, currently living in Canada and enjoying the fall colours here. I hope you're doing well too!
English
1
0
1
0
Paul Bottinelli
Paul Bottinelli@paulbottinelli·
@CryptoHack__ Here's mine, using your convenient script: username: paulbottinelli hash: 201eb16d28a9a61d9b2975eba59d889884b9347554fe731e0585fdc96c45474c Cheers ;)
English
0
0
1
0
CryptoHack
CryptoHack@CryptoHack__·
🧩To celebrate reaching 5000 followers, here's a little puzzle for you all🧩 Using only public data, can you find a way to sign a message which the below code will verify?
CryptoHack tweet media
English
16
6
42
0
Paul Bottinelli
Paul Bottinelli@paulbottinelli·
@master_mitch @NCCGroupInfosec Yes, that is absolutely correct and was passed along as a recommendation to the devs during the disclosure. That second check should also have prevented the forgery described.
English
0
0
1
0
mitch
mitch@master_mitch·
@NCCGroupInfosec The advisory says the first check is missing. Isn't the second check (third bulletpoint) missing as well? -> "return Invalid if (x, y) is the point at infinity"
English
1
0
0
0
Paul Bottinelli retweetledi
CryptoHack
CryptoHack@CryptoHack__·
My colleague just published this finding, which feels just like an (easy) CTF challenge in the wild! Never trust user input (and handle errors when looking at modular inverses!)! research.nccgroup.com/2021/11/08/tec…
English
1
8
46
0
Paul Bottinelli retweetledi
Ollie Whitehouse
Ollie Whitehouse@ollieatnowhere·
Great work here by @paulbottinelli from NCC Group's Cryptography Services practice.. ..you know, like the node package manager reports around 16k weekly downloads for the ecdsa-node implementation while the Python implementation boasts over 7.3M downloads in the last 90 days..
NCC Group Research & Technology@NCCGroupInfosec

Technical Advisory – Arbitrary Signature Forgery in Stark Bank ECDSA Libraries, by Paul Bottinelli research.nccgroup.com/2021/11/08/tec…

English
1
7
14
0
Paul Bottinelli
Paul Bottinelli@paulbottinelli·
@AnomalRoil There is a small mistake in the decomposition of the following: pq=kp+p+q−1 You wrote: "Which we can simplify in pq=k(p+1)+q−1" But it should be: pq=p(k+1)+q−1
English
1
0
0
0