Blog | G5 Cyber Security

New research: There’s no need to panic over factorable keysjust mind your Ps and Qs

An attacker can impersonate a web site or possibly decrypt encrypted traffic to that web site. The problem mainly affects embedded devices such as routers and VPN devices, not full-blown web servers. We suspect that more than 200,000 devices, representing 4.1% of the SSL keys in our dataset, were generated with poor entropy. Only one of the factorable SSL keys was signed by a trusted certificate authority and it has already expired. There are signed certificates using repeated keys; some of them are generated by vulnerable devices. Some of these are due to website owners submitting known weak keys to be signed.”]

Source: https://freedom-to-tinker.com/2012/02/15/new-research-theres-no-need-panic-over-factorable-keys-just-mind-your-ps-and-qs/

Exit mobile version