Infineon / RSA troubles

Phil Pennock phil.pennock at spodhuis.org
Mon Oct 16 22:18:34 CEST 2017


Is there anything to do around user support, key auto-blacklisting, etc
arising from:

  https://arstechnica.com/information-technology/2017/10/crypto-failure-cripples-millions-of-high-security-keys-750k-estonian-ids/

?

} The researchers also found 2,892 PGP keys used for encrypted e-mail,
} 956 of which were factorizable. The researchers speculated that the
} majority of the PGP keys were generated using the Yubikey 4, which
} allows owners to use the faulty library to create on-chip RSA
} keys. Other functions of the USB device, including U2F
} authentication, remain unaffected. Yubico has more details here.

Interestingly:
} To spare time and cost, attackers can first test a public key to see
} if it's vulnerable to the attack. The test is inexpensive, requires
} less than 1 millisecond, and its creators believe it produces
} practically zero false positives and zero false negatives.

    https://keychest.net/roca

I wonder if it's worth adding such a check to GnuPG in the import path?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 996 bytes
Desc: Digital signature
URL: <https://lists.gnupg.org/pipermail/verein/attachments/20171016/0cf79712/attachment.sig>


More information about the Verein mailing list