3 ms·
> If a certain key generator is generating predictable or not-entirely-random keys and you can identify which system use those implementation, it can help scrip
by timv 10y ago
> If a certain key generator is generating predictable or not-entirely-random keys and you can identify which system use those implementation, it can help script an attack vector
Even then it's only relevant if fingerprinting makes the attack substantially easier that simply trying the exploit.
Suppose that NastySSL 0.0.1 has a bug that reduces the strength of the keys it generates.
If the bug (i.e. the reduction in strength) is significant, but not extreme, so that it takes about 48 hours of CPU time to break a key, then it would absolutely be useful to be able to fingerprint the keys produced by that tool.
If, on the other hand, the bug is extreme, so that I can break keys in seconds (perhaps only in a subset of cases), then the fingerprinting might be helpful in saving me a few milliseconds, but it's not that big a deal.
It's an interesting (but not overly surprising) line of research, and I expect that someone will find a way to make use of it in some sort of future attack vector, but it's hard to see an immediately obvious attack at face value.