'Severe' OpenSSL vuln busts public key crypto (Register)
[Posted March 6, 2010 by corbet]
'Severe' OpenSSL vuln busts public key crypto (Register)
[Security] Posted Mar 6, 2010 14:42 UTC (Sat) by corbet
The Register has posted an
article on a reported OpenSSL vulnerability that allows attackers to
obtain a system's private key. Before hitting the panic button, though,
it's worth seeing what's involved in carrying out this attack: "The
university scientists found that they could deduce tiny pieces of a private
key by injecting slight fluctuations in a device's power supply as it was
processing encrypted messages. In a little more than 100 hours, they fed
the device enough 'transient faults' that they were able to assemble the
entirety of its 1024-bit key." It could be a problem for keys
hidden in embedded systems, but that is probably about the extent of it.
Comments (22 posted)