3 ms·
This was originally presented was in 2004, but since then has been refined in a number of ways. The detailed paper that includes the full key extraction attack
by longwave 13y ago
This was originally presented was in 2004, but since then has been refined in a number of ways. The detailed paper that includes the full key extraction attack was only released today, coinciding with the GnuPG security update that mitigates against the attack.
- gwern 13y agoIt took 9 years to fix GPG?
- edwintorok 13y agoGnuPG 2.x wasn't vulnerable, just the old 1.x: http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/000337.html http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/00033... "GnuPG 1.4.16 avoids this attack by employing RSA blinding during decryption. GnuPG 2.x and current Gpg4win versions make use of Libgcrypt which employs RSA blinding anyway and are thus not vulnerable."
- tripzilch 13y agoRSA blinding seems to protect against timing attacks, how does RSA blinding protect against this acoustic attack?