3 ms·
This attack has been known for at least seven years: https://eprint.iacr.org/2012/064.pdf https://eprint.iacr.org/2012/064.pdf (discussion: https://news.ycombin
by bgrainger 7y ago
This attack has been known for at least seven years: https://eprint.iacr.org/2012/064.pdf https://eprint.iacr.org/2012/064.pdf (discussion: https://news.ycombinator.com/item?id=3591429 https://news.ycombinator.com/item?id=3591429).
Back then, "two out of every one thousand RSA moduli that we collected offer no security".
- kwantam 7y agoIndeed! Another publication on this topic from that time: https://www.usenix.org/conference/usenixsecurity12/technical-sessions/presentation/heninger https://www.usenix.org/conference/usenixsecurity12/technical... and commentary on the paper from a few years later https://blog.acolyer.org/2015/09/16/mining-your-ps-and-qs-detection-of-widespread-weak-keys-in-network-devices/ https://blog.acolyer.org/2015/09/16/mining-your-ps-and-qs-de... ah, and a blog post from Nadia Heninger (one of the authors) prior to publication https://freedom-to-tinker.com/2012/02/15/new-research-theres-no-need-panic-over-factorable-keys-just-mind-your-ps-and-qs/ https://freedom-to-tinker.com/2012/02/15/new-research-theres...