I'm surprised to learn that Go did not already check the result of calculations; that's a pretty standard countermeasure, also to e.g. protect your private key on somewhat-unreliable hardware.
I'm surprised to learn that Go did not already check the result of calculations; that's a pretty standard countermeasure, also to e.g. protect your private key on somewhat-unreliable hardware.
There was a carry propagation bug in OpenSSL/BoringSSL/LibreSSL just a few weeks ago.
And nit: The OpenSSL bug didn't affect libressl (I discovered it, I checked for that).
hannob gave the reason, but bug could also be unwittingly removed by separate cleanup e.g. generic replacement of unsafe functions/practices by safer ones.
Yeah. As the announcement says, it's coming in 1.6 and we (CloudFlare) backported it in our public tree, in case anyone else wants to use it: https://github.com/cloudflare/go/commits/go1.5.3-cloudflare1
However, I was proposing verifying the signature - which involves only the public key and the signed data, neither of which are likely to be all that sensitive.
(The situation is more subtle for RSA decryption.)