add warning to crypto.Sign and crypto.SignEthereum

This commit is contained in:
Bas van Kervel 2016-08-25 18:04:41 +02:00
parent 42a26000ea
commit f116d1ab35

View file

@ -199,23 +199,32 @@ func SigToPub(hash, sig []byte) (*ecdsa.PublicKey, error) {
} }
// Sign calculates an ECDSA signature. // Sign calculates an ECDSA signature.
// Note: the signature is not Ethereum compliant. The yellow paper dictates // This function is susceptible to choosen plaintext attacks that can leak
// Ethereum singature to have a V value with and offset of 27 v in [27,28]. // information about the private key that is used for signing. Callers must
// be aware that the given hash cannot be choosen by an adversery. Common
// solution is to hash any input before calculating the signature.
//
// Note: the calculated signature is not Ethereum compliant. The yellow paper
// dictates Ethereum singature to have a V value with and offset of 27 v in [27,28].
// Use SignEthereum to get an Ethereum compliant signature. // Use SignEthereum to get an Ethereum compliant signature.
func Sign(hash []byte, prv *ecdsa.PrivateKey) (sig []byte, err error) { func Sign(data []byte, prv *ecdsa.PrivateKey) (sig []byte, err error) {
if len(hash) != 32 { if len(data) != 32 {
return nil, fmt.Errorf("hash is required to be exactly 32 bytes (%d)", len(hash)) return nil, fmt.Errorf("hash is required to be exactly 32 bytes (%d)", len(data))
} }
seckey := common.LeftPadBytes(prv.D.Bytes(), prv.Params().BitSize/8) seckey := common.LeftPadBytes(prv.D.Bytes(), prv.Params().BitSize/8)
defer zeroBytes(seckey) defer zeroBytes(seckey)
sig, err = secp256k1.Sign(hash, seckey) sig, err = secp256k1.Sign(data, seckey)
return return
} }
// SignEthereum calculates an Ethereum ECDSA signature. // SignEthereum calculates an Ethereum ECDSA signature.
func SignEthereum(hash []byte, prv *ecdsa.PrivateKey) ([]byte, error) { // This function is susceptible to choosen plaintext attacks that can leak
sig, err := Sign(hash, prv) // information about the private key that is used for signing. Callers must
// be aware that the given hash cannot be choosen by an adversery. Common
// solution is to hash any input before calculating the signature.
func SignEthereum(data []byte, prv *ecdsa.PrivateKey) ([]byte, error) {
sig, err := Sign(data, prv)
if err != nil { if err != nil {
return nil, err return nil, err
} }