• Home
  • Mail
  • Flickr
  • Tumblr
  • News
  • Sports
  • Finance
  • Entertainment
  • Lifestyle
  • Answers
  • Groups
  • More
Yahoo
    • Skip to Navigation
    • Skip to Market Summary
    • Skip to Main Content
    • Skip to Related Content
    • Sign in
    Finance Home
    • Watchlists
    • My Portfolio
    • My Screeners
    • Markets
    • Industries
    • Personal Finance
    • Technology
    • Originals
    • Events
    U.S. Markets close in 22 mins
    • S&P 500
      2,608.23
      +26.35(+1.02%)

    • Dow 30
      23,962.98
      +318.79(+1.35%)

    • Nasdaq
      6,929.97
      +59.85(+0.87%)

    The Final Round

    Tech rebound boosts Wall Street, Spotify debuts

    Live at 3:55 p.m. ET

    The encryption many major companies rely on has a serious flaw

    Mallory Locklear
    EngadgetOctober 16, 2017
    Reblog
    Share
    Tweet
    Share

    Researchers at Masaryk University in the Czech Republic uncovered a major security vulnerability in RSA keys generated by Infineon Technologies-produced chips. These chips are used in products manufactured by Acer, ASUS, Fujitsu, HP, Lenovo, LG, Samsung, Toshiba and Chromebook vendors, reports Bleeping Computer and the RSA keys generated by Infineon's chips are used in government-issued identity documents, during software signing, in authentication tokens, with message protection like PGP, in programmable smartcards and during secure browsing.

    The researchers say that key lengths of 1024 and 2048 bits are able to be figured out with little effort using the public portion of the key. "A remote attacker can compute an RSA private key from the value of a public key. The private key can be misused for impersonation of a legitimate owner, decryption of sensitive messages, forgery of signatures (such as for software releases) and other related attacks," they said in a report. "The vulnerability does NOT depend on a weak or a faulty random number generator - all RSA keys generated by a vulnerable chip are impacted. The attack was practically verified for several randomly selected 1024-bit RSA keys and for several selected 2048-bit keys." And the affected RSA library has been generating weak keys since 2012. "The currently confirmed number of vulnerable keys found is about 760,000 but possibly up to two to three magnitudes more are vulnerable," said the researchers. As Ars Technica reports, a number of the vulnerable keys included those used in Estonian government-issued documents like e-residency cards.

    The vulnerability was discovered and reported to Infineon in February and as per the agreed upon delay before public disclosure, the researchers will be releasing their full report on November 2nd at the ACM Conference on Computer and Communications Security. The delay is to ensure that people have time to change affected keys before the details of how the vulnerability works are released. It has also allowed vendors like Microsoft, Google, HP, Lenovo and Fujitsu to release software updates to mitigate the impact of the flaw.

    The researchers have released a blog post about the vulnerability, which includes tools for testing whether existing RSA keys are secure or vulnerable. It also provides advice on what to do if you find your RSA key is compromised.

    CRoCS

    • This article originally appeared on Engadget.
    Reblog
    Share
    Tweet
    Share
    Recently Viewed
    Your list is empty.

    What to Read Next

    • Facebook launches bulk app removal tool amidst privacy scandal

      TechCrunch
    • Changez votre Forfait

      RED by SFRAnnonces
    • Spotify shares open for trading at $165.90

      Reuters
    • World financial markets are betting that Trump is all talk and no action

      Yahoo Finance
    • SoftBank leads $450M investment in Paytm's e-commerce business

      TechCrunch
    • Nouveau Crossland X. C'est la belle vie

      OpelAnnonces
    • David Pogue's Rated:App PUBG

      Yahoo Finance Video
    • Tech rebound boosts Wall Street, Spotify debuts

      Yahoo Finance
    • NASA explores ‘quiet’ supersonic flight over land

      Engadget
    • Conception haut de gamme et mobilité maximale

      DellAnnonces
    • Elon Musk just took charge of Model 3 production, saying it's his 'most critical' job right now

      TechCrunch
    • Here are the five things I learned installing a smart mirror

      TechCrunch
    • Tesla says no need for capital raise as Model 3 output rises

      Reuters
    • Faites de l’extraordinaire votre quotidien

      SEATAnnonces
    • MARKETS: Spotify tanks on trading debut, tracking the dead cat tech bounce, waxing philosophical on bitcoin

      Yahoo Finance Video
    • The 10 best iPhone and Android games of the month

      Yahoo Finance