Hello!
I am writing to inquire if OpenSSL uses exponent blinding to mitigate leakage of secrets during RSA decryption. For what I can see, Botan and Libgcrypt use exponent blinding for RSA and also ElGamal. However, I can only find "base blinding" in OpenSSL. Would anyone shed some lights on this? Thank you very much.
Best,
Shuai