3 ms·
I'm no expert but it's obvious he hasn't seeded PRNG so the key pair could be weak. What do you see?
by n00body 10y ago
I'm no expert but it's obvious he hasn't seeded PRNG so the key pair could be weak. What do you see?
- tptacek 10y agoI think he's using OpenSSL's RNG (that's what BN_rand is). I think (but, if you put it to me, am not off the top of my head 100% certain) that OpenSSL's RNG will automatically initialize itself if you don't.
- n00body 10y agoWhat are the hashes of? :D
- tptacek 10y agoShort strings describing crypto bugs. So when you find something I didn't, I can't claim to have found it myself first.
- n00body 10y agoNo padding used for keys sent by client? Public Key sent by server not verified by client? Keys sent by client are not verified by server? I suspect there are whole heap of problems wrong with this but thats just what i see atm.
- tptacek 10y ago1. Yep, that's one of my issues (echo unpadded rsa | openssl sha -sha256) 2. That's an issue but I didn't count it because the blog post cops to that problem.