Infineon / RSA troubles
Phil Pennock
phil.pennock at spodhuis.org
Mon Oct 16 22:18:34 CEST 2017
Is there anything to do around user support, key auto-blacklisting, etc
arising from:
https://arstechnica.com/information-technology/2017/10/crypto-failure-cripples-millions-of-high-security-keys-750k-estonian-ids/
?
} The researchers also found 2,892 PGP keys used for encrypted e-mail,
} 956 of which were factorizable. The researchers speculated that the
} majority of the PGP keys were generated using the Yubikey 4, which
} allows owners to use the faulty library to create on-chip RSA
} keys. Other functions of the USB device, including U2F
} authentication, remain unaffected. Yubico has more details here.
Interestingly:
} To spare time and cost, attackers can first test a public key to see
} if it's vulnerable to the attack. The test is inexpensive, requires
} less than 1 millisecond, and its creators believe it produces
} practically zero false positives and zero false negatives.
https://keychest.net/roca
I wonder if it's worth adding such a check to GnuPG in the import path?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 996 bytes
Desc: Digital signature
URL: <https://lists.gnupg.org/pipermail/verein/attachments/20171016/0cf79712/attachment.sig>
More information about the Verein
mailing list