Revisiting the Pervasiveness of Weak Keys in Network Devices
Philippe Elbaz–Vincent, Mohamed Traore · 2021
Since 2012, several academic teams reported vulnerabilities in the RSA keys of HTTPS hosts on the Internet and traced the issue to several weaknesses. In 2016, a complementary study measured the actions taken by vendors and end users over time in response to the original disclosure by analyzing a large set of RSA moduli and discovered that RSA weak keys were still widespread with almost no action taken by the vendors. In this paper, we have reappraised their investigations with a focus on larger RSA moduli (2048 bits) and attempted to provide complementary analysis on some unexpected anomalies.