Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Test the server key to check if it is not factorable #175

Open
tomato42 opened this issue Feb 25, 2019 · 2 comments
Open

Test the server key to check if it is not factorable #175

tomato42 opened this issue Feb 25, 2019 · 2 comments

Comments

@tomato42
Copy link
Member

There are not insignificant number of devices that generate or use RSA keys that can be factored, there should be either a mode, or few simple checks to see if the key can't be easily factored.

https://freedom-to-tinker.com/2012/02/15/new-research-theres-no-need-panic-over-factorable-keys-just-mind-your-ps-and-qs/

@jvehent
Copy link
Contributor

jvehent commented Feb 26, 2019

I think this would be better as an analysis worker in tls-observatory.

@tomato42
Copy link
Member Author

yeah, full blown test is definitely not doable by the regular test, but they did find few primes that are common, so checking few dozen of those could be done during the scan (for single host run) or when aggregating results (when scanning multiple hosts)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants