5 ms·
What are the odds that this was intentional? TPM and Bitlocker have been two of the biggest conjectured targets of compromise. To the point that most security p
by slackingoff2017 9y ago
What are the odds that this was intentional? TPM and Bitlocker have been two of the biggest conjectured targets of compromise. To the point that most security people/libraries use neither. Maybe they were right?
If this is true one of Stackoverflow comments is quite chilling
It would be a terrible idea and it would raise suspicions of a deliberate trapdoor if the primes for RSA were chosen from a quadratic progression rather than randomly
- throwaway613834 9y ago> If this is true one of Stackoverflow comments is quite chilling MathOverflow?
- slackingoff2017 9y agoHaha same difference. Mathoverflow is just a lot more hardcore :)
- tptacek 9y agoThat comment isn't intended to be "chilling"; it's intended to be the opposite. This is a terrible cryptographic backdoor. If you're going to backdoor cryptography, you do it cryptographically, so that only you and your partners can decrypt it (this is called a "NOBUS" backdoor, for "nobody but us"). The only reason nobody found the Infineon bug already is that nobody seriously looked for it. The most plausible explanation for the Infineon bug is also the most widespread: there's prime number generation advice for quickly generating primes on low-power devices like smartcards, and that advice was badly flawed. (This isn't the first time primegen bugs have created factorable public keys in the wild; Henninger has a similar attack relating to p = randomprime(start=0), q = randomprime(start=p)).
- wybiral 9y agoIf you could introduce a bias in implementations to generate primes of the form more often than random then it could be useful, right? I'm not wearing my tin foil hat so I realize that in order to do that in the first place you'd probably already have enough influence to do much more than this. But just for the sake of a hypothetical...
- tptacek 9y agoThere are backdoors you can introduce from that position that don't involve an n * 2^-700 probability of the pattern occurring non-maliciously.
- wybiral 9y agoDo tell... I've looked through the source of several common RSA keygen implementations and noticed that there usually aren't many sanity checks afterwards. But I've never really thought about what can go wrong there (by random chance or by exploit). /me puts on tin foil hat ... what could the lizard people plant in there?
- slackingoff2017 9y agoDon your shiny crinkly hats, but after https://en.m.wikipedia.org/wiki/Dual_EC_DRBG https://en.m.wikipedia.org/wiki/Dual_EC_DRBG I started believing that NSA involvement is not subtle in their exploits. They only need to fool laymen, and backdoored primes are an easy way to do so. The number of true cryptography experts beyond their walls is a dozen in the world at best. Case in point https://en.m.wikipedia.org/wiki/Daniel_J._Bernstein https://en.m.wikipedia.org/wiki/Daniel_J._Bernstein . And BTW he's been sued by the US government for ???. Thank God the EFF has decent funding.
- tptacek 9y ago"The number of true cryptography experts beyond [the walls of the NSA] is a dozen in the world at best"? This kind of logic is super common on HN threads and it's incoherent. If the expertise and capabilities of the NSA with respect to basic cryptographic mathematics is so unknowable that thousands of published academic cryptographers are wasting their time, then what makes you think a random amateur Math Overflow post has somehow stumbled on a deep secret of NSA RSA subterfuge? For whatever it's worth to you, Dan Bernstein was not sued by the US Government. Dan Bernstein sued the US Government, over export restrictions on cryptography in the 1990s; his suit was mooted by the relaxation of those restrictions.
- theWatcher37 9y agoNSA made seemingly bening improvements to crypto standards that the academic community only discovered as valuable over a decade later. They’re the largest single employer of mathmaticians in the world.
- monocasa 9y ago> NSA made seemingly bening improvements to crypto standards that the academic community only discovered as valuable over a decade later. At the same time, they negotiated DES's key length down. It was 64 bits originally, the NSA wanted only 48 bits, IBM and the NSA compromised on 56 bits.
- 9y ago
- vel0city 9y agoThe recent Infineon weakness is not a flaw in TPMs in general or Bitlocker. This is a flaw related to certain TPMs, and is only applicable to Bitlocker if you used those affected TPMs with Bitlocker. FWIW, this same flaw could relate to PGP keys generated with the affected TPMs. This same flaw was related to PIVs issued on Estonian IDs, which I doubt are commonly used for Bitlocker.