5 ms·
A related public key news: https://arstechnica.com/information-technology/2017/10/crypto-failure-cripples-millions-of-high-security-keys-750k-estonian-ids/ htt
by srcmap 9y ago
A related public key news:
https://arstechnica.com/information-technology/2017/10/crypto-failure-cripples-millions-of-high-security-keys-750k-estonian-ids/ https://arstechnica.com/information-technology/2017/10/crypt...
It compromises the TPM 1.2 and Microsoft Bitlocker HDD encruption.
The researchers also scanned the Internet for fingerprinted keys and quickly found hits in a variety of surprising places. They found 447 fingerprinted keys—237 of them factorizable—used to sign GitHub submissions, some for very popular software packages. GitHub has since been notified of the fingerprinted keys and is in the process of getting users to change them.
The researchers also found 2,892 PGP keys used for encrypted e-mail, 956 of which were factorizable. The researchers speculated that the majority of the PGP keys were generated using the Yubikey 4, which allows owners to use the faulty library to create on-chip RSA keys. Other functions of the USB device, including U2F authentication, remain unaffected. Yubico has more details here.
- gruez 9y agois there a reason why bitlocker would use rsa for encryption? afaik how bitlocker worked with tpm was that it would generate a (symmetric) key, store it in the tpm, then seal it, binding it to the current PCR value. on boot, it would unseal it (which will succeed unless the PCR changed).
- tptacek 9y agoIt doesn't. Intel-compatible TPMs do, and Bitlocker will take advantage of those to get a hardware root of trust for the volume master key. Without it, it'll use AES.
- mjg59 9y agoThe aes key is encrypted using an rsa key that was generated on the TPM - the TPM PCR values need to be valid for the TPM to decrypt and release the decrypted aes key.
- slackingoff2017 9y agoWhat are the odds that this was intentional? TPM and Bitlocker have been two of the biggest conjectured targets of compromise. To the point that most security people/libraries use neither. Maybe they were right? If this is true one of Stackoverflow comments is quite chilling It would be a terrible idea and it would raise suspicions of a deliberate trapdoor if the primes for RSA were chosen from a quadratic progression rather than randomly
- throwaway613834 9y ago> If this is true one of Stackoverflow comments is quite chilling MathOverflow?
- slackingoff2017 9y agoHaha same difference. Mathoverflow is just a lot more hardcore :)
- tptacek 9y agoThat comment isn't intended to be "chilling"; it's intended to be the opposite. This is a terrible cryptographic backdoor. If you're going to backdoor cryptography, you do it cryptographically, so that only you and your partners can decrypt it (this is called a "NOBUS" backdoor, for "nobody but us"). The only reason nobody found the Infineon bug already is that nobody seriously looked for it. The most plausible explanation for the Infineon bug is also the most widespread: there's prime number generation advice for quickly generating primes on low-power devices like smartcards, and that advice was badly flawed. (This isn't the first time primegen bugs have created factorable public keys in the wild; Henninger has a similar attack relating to p = randomprime(start=0), q = randomprime(start=p)).
- wybiral 9y agoIf you could introduce a bias in implementations to generate primes of the form more often than random then it could be useful, right? I'm not wearing my tin foil hat so I realize that in order to do that in the first place you'd probably already have enough influence to do much more than this. But just for the sake of a hypothetical...
- wybiral 9y agoMore on the actual ROCA vulnerability for anyone curious: https://crocs.fi.muni.cz/public/papers/rsa_ccs17 https://crocs.fi.muni.cz/public/papers/rsa_ccs17 https://crypto.stackexchange.com/questions/52292/what-is-fast-prime https://crypto.stackexchange.com/questions/52292/what-is-fas...
- xelxebar 9y agoWait. My Yubikey 4-generated let's might be bunk? How can I check this?