Baochip-1x: What It Is, Why I'm Doing It Now, and How It Came About
17 points by brewcrew
by zachbee
0 subcomment
Their AES implementation uses old-school 2-share boolean masking [1], which has been shown to be insecure since 2005 [2][3]. A modern implementation would use domain-oriented masking [4], like OpenTitan does. Pretty bad look for Crossbar.