SShortSingh.
Back to feed

Rust post-quantum crypto library ML-KEM passes independent differential verification

0
·5 views

A verification harness called iraca has confirmed that RustCrypto's ml-kem crate, which implements the post-quantum standard ML-KEM (FIPS 203), produces byte-for-byte identical outputs to the official pq-crystals C reference implementation across key generation, encapsulation, and decapsulation. Testing was conducted across 128 random seeds plus a fixed test vector, with no discrepancies found. The harness also confirmed that RustCrypto correctly rejects non-canonical encapsulation keys as required by FIPS 203, verified through both source review and 128 adversarial samples. Developers stress this is a targeted conformance check, not a full security audit, and does not cover side-channel vulnerabilities such as those in the KyberSlash class. The tool is open for reuse by maintainers of other post-quantum implementations seeking independent differential or adversarial verification.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Developer Shares Open Java Practice Problem Repository on GitHub

A developer has published a collection of Java practice problems they have solved, making the repository publicly available on GitHub under the name MyJavaExercises. The project is intended as a learning resource for others interested in Java programming. The author plans to continue adding new problems to the repository over time. Visitors are also encouraged to suggest more accurate or optimized solutions to existing problems.

0
ProgrammingGitHub Blog ·

GitHub AI Security Agent Uncovers 24 Vulnerabilities in Android Apps

GitHub researchers used an open-source AI-powered security agent to identify 24 vulnerabilities in Android applications. The findings were made possible through targeted AI task flows designed to detect critical security flaws. The team has detailed the specific bugs uncovered during the process, highlighting the agent's effectiveness in automated vulnerability discovery. GitHub has also made the tool publicly available, allowing developers to run the same security agent on their own Android applications.

0
ProgrammingDEV Community ·

Developer builds open-source fuzzy search library inside PostgreSQL without schema changes

A software developer built an open-source PHP library called Fuzzphony to enable forgiving, typo-tolerant search within an existing PostgreSQL database after being unable to modify the schema or add new infrastructure like Elasticsearch. The library leverages built-in PostgreSQL features — full-text search via tsvector and tsquery, the unaccent extension, and pg_trgm trigram similarity — to handle typos, accent variations, and word stemming. Fuzzphony maintains its own shadow index tables alongside the original data, avoiding any changes to production schemas. The library supports ranked results, field weighting, filter columns, query exclusions, and user-input sanitisation, with warnings returned for malformed queries. Currently at version 0.4 and under active development, Fuzzphony is open source with a stable core but an API that may change before the 1.0 release.

0
ProgrammingDEV Community ·

Developer Builds AI Incident Response Tool That Learns from Past Outages

A developer created MemoryOps, an AI-powered incident response platform for DevOps and SRE teams, designed to eliminate hallucinated citations during live outages. The tool combines a React frontend, FastAPI backend, and SQLite database with a persistent memory layer called Hindsight and the Groq Cloud LLM for reasoning. When an incident is resolved, structured learnings are stored in Hindsight and later retrieved to ground AI recommendations in verified past experience rather than invented references. The system is deliberately human-supervised, meaning no actions are taken autonomously and engineers remain in full control throughout the workflow. The architecture separates real-time incident data from historical learnings, with SQLite tracking current incidents and Hindsight supplying context from previously resolved ones.