Weak Keys Remain Widespread in Network Devices

Marcella Hastings, Joshua Fried, Nadia Heninger · 2016

In 2012, two academic groups reported having computed the RSA private keys for 0.5% of HTTPS hosts on the internet, and traced the underlying issue to widespread random number generation failures on networked devices. The vulnerability was reported to dozens of vendors, several of whom responded with security advisories, and the Linux kernel was patched to fix a boottime entropy hole that contributed to the failures.

Read the paper · More papers on PaperTik