4 ms·
From my understanding, this doesn't show that he can break RSA but rather that the key generator that generated the keys in the GPG strong suite were completely
by green7ea 11y ago
From my understanding, this doesn't show that he can break RSA but rather that the key generator that generated the keys in the GPG strong suite were completely broken. The factors were 7 and 77 which is completly ridiculous, they should be in the range of 2^2048. This does mean further scrutiny on key generators is a must.
- acqq 11y agoExactly. The GPG that generated that keypair was obviously not doing what it was supposed to do. It can be something on the level of the famous Debian patch fiasco. The worrying thing is that nobody until now published such findings. The second found p is 21(!?) Edit: see the new post from agwa, if all the keys with bad properties came the same way it's much less worrying.
- ikeboy 11y agohttps://eprint.iacr.org/2012/064.pdf https://eprint.iacr.org/2012/064.pdf https://factorable.net/weakkeys12.extended.pdf https://factorable.net/weakkeys12.extended.pdf
- acqq 11y agoThanks. The first paper mentions some 157 PGP keys and some "probably copy-paste errors." Maybe somebody can tell more about it, I wasn't able to evaluate the effects. The second didn't analyze PGP keys, but otherwise was certainly impressive.
- ikeboy 11y agohttp://shoestringfoundation.org/cgi-bin/blosxom.cgi/2004/07/01#non-pgp-key http://shoestringfoundation.org/cgi-bin/blosxom.cgi/2004/07/...
- noondip 11y agoA look at the PGP ecosystem through the key server data https://eprint.iacr.org/2015/262.pdf https://eprint.iacr.org/2015/262.pdf
- acqq 11y agoThat one sounds optimistic: "Based on my research it seems that over a very long time the use of PGP implementations with deeply awed random number generation functions was very rare."