5 ms·
A short discussion on my blog: https://www.dancvrcek.com/re-investigating-the-origins-of-rsa-public-keys/ https://www.dancvrcek.com/re-investigating-the-origins
by dc352 10y ago
A short discussion on my blog: https://www.dancvrcek.com/re-investigating-the-origins-of-rsa-public-keys/ https://www.dancvrcek.com/re-investigating-the-origins-of-rs...
- tptacek 10y agoIt seems pretty unlikely that we're ever going to uncover a practical vulnerability owing to the observations of this paper.
- acqq 10y agoYes, from what I've read, the researchers discovered that the PGP keys were made by the PGP software and so on.
- schoen 10y agoThis kind of inference can be interesting, because occasionally people try to convert a private key from one type to another; for example, there are scripts to convert a private key between PEM, OpenSSH, and GPG formats so that you can re-use it for different applications. (One application for this is to use GPG signatures on public keys to authenticate users and/or servers in SSH.) So this research might allow someone who didn't already know to recognize more about where a key came from.
- petrs 10y agoVerification that TLS keys are mostly generated by OpenSSL and PGP keys by PGP/GPG are sanity check that method actually works. If it will turn out, that particular library has vulnerability, one can quickly search for other vulnerable keys from large datasets like IPv4-wide TLS scans.
- pm24601 10y agoThe impact isn't in discovering a vuln in the software. The impact (as stated in the abstract) is a way to further fingerprint and de-anonymize Tor users and other users who are trying to maintain privacy.
- tptacek 10y agoI'm responding to the last paragraph of the post. I acknowledge the privacy implications.
- ComodoHacker 10y agoAuthors had uncovered vulnerabilities and defects in particular smart card models during their research.