We're currently passing verification from a lab for our secure PQC solution where we use xoshiro. During the code review they revealed that we shouldn't use bytes for randomization because they're vulnerable to template attacks. Each byte have only 255 variants and they can be distinguished between each other when measuring power consumption.
To avoid this, we need to construct xoshiro directly from the state (using u32). Would you be open to adding additional (non-trait) constructor that creates xoshiro from a state without constructing it byte by byte?
We're currently passing verification from a lab for our secure PQC solution where we use xoshiro. During the code review they revealed that we shouldn't use bytes for randomization because they're vulnerable to template attacks. Each byte have only 255 variants and they can be distinguished between each other when measuring power consumption.
To avoid this, we need to construct xoshiro directly from the state (using
u32). Would you be open to adding additional (non-trait) constructor that creates xoshiro from a state without constructing it byte by byte?