3 ms·
The TL;DR by Ryan Castellucci is excellent: https://twitter.com/ryancdotorg/status/1214578765998645249 https://twitter.com/ryancdotorg/status/121457876599864524
by CiPHPerCoder 7y ago
The TL;DR by Ryan Castellucci is excellent: https://twitter.com/ryancdotorg/status/1214578765998645249 https://twitter.com/ryancdotorg/status/1214578765998645249
> Neat attack. TL;DR: A "non-exportable" finite field Diffie-Hellman private key can be extracted because the key object isn't bound to specific group parameters. XSS the site, do some operations with deliberately weak group parameters, solve for key.
- ecesena 7y agoThe author found the bug inspired by: https://github.com/google/wycheproof https://github.com/google/wycheproof (it's in the thread of the original tweet, though the thread is in Italian: https://twitter.com/asanso/status/1214450115777351681 https://twitter.com/asanso/status/1214450115777351681)