@eshard@infosec.exchange avatar eshard , to random

Everyone thought the “hedged” mode of ML-DSA (Dilithium) fixed fault attacks. New research presented at CHES shows that’s not the case. A "fault then correct" trick still works.

We break it down in our latest Expert Review. ➡️ https://eshard.com/posts/expert-review-6-dilithium-dis-faulting