Blog | G5 Cyber Security

A bad couple of years for the cryptographic token industry

An attacker can extract sensitive keys from several popular cryptographic token devices. This is obviously not good, and it may have big implications for people who depend on tokens for their day-to-day security. The paper in question is Efficient Padding Oracle Attacks on Cryptographic Hardware by Bardou, Focardi, Kawamoto, Simionato, Steel and Tsay. The more specific (and important) lesson for cryptographic implementers is: if youre using PKCS#1v1.5 padding for RSA encryption, cut it out.”]

Source: https://blog.cryptographyengineering.com/2012/06/21/bad-couple-of-years-for-cryptographic/

Exit mobile version