A flaw in a widely used code library has fatally undermined the security of encryption keys used in some of the highest-stakes settings. The flaw allows attackers to calculate the private portion of any vulnerable key using nothing more than the corresponding public portion. Hackers can then use the private key to impersonate key owners, decrypt data, sneak malicious code into digitally signed software, and bypass protections that prevent accessing or tampering with stolen PCs. The code library was developed by German chipmaker Infineon and has been generating weak keys since 2012.”]

