Perimeter
2/8/2012
11:16 PM
Taher Elgamal
Taher Elgamal
Commentary
Connect Directly
RSS
E-Mail
50%
50%

RSA Weakness and e-Commerce Authentication

RSA key weakness

The recently disclosed weakness in the RSA keys found on the web created a lot of activity in the scientific and the commercial world. What does that mean to everyday e-commerce transactions and how much trust should we have in them. This particular weakness in some of the RSA keys used in a server certificate for example can enable someone to impersonate a server identity, since an attacker can compute the server’s private key used in signing and authenticating the server to the browsers. This is not a trivial weakness obviously. However, it should not be perceived as an attack on all e-commerce as advertised since the other keys that are generated properly will not have any issue and the trust in them is not affected.

An attack on all e-commerce should have the effect of enabling an attacker to impersonate any server – which is far from reality here. However, this finding does bring a very important issue in generating random numbers and in also generating RSA keys that are not “weak keys”. The software or hardware used to generate keys should be tested against known weaknesses at all times, and customers should ask vendors questions about the process they used to test their cryptographic software. Of course, using other strong cryptographic methods is also a good idea – but also if the keys and random numbers are generated correctly.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2886
Published: 2014-09-18
GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during ins...

CVE-2014-4352
Published: 2014-09-18
Address Book in Apple iOS before 8 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.

CVE-2014-4353
Published: 2014-09-18
Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by leveraging the presence of an attachment after the deletion of its parent (1) iMessage or (2) MMS.

CVE-2014-4354
Published: 2014-09-18
Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote attackers to bypass intended access restrictions via a Bluetooth session.

CVE-2014-4356
Published: 2014-09-18
Apple iOS before 8 does not follow the intended configuration setting for text-message preview on the lock screen, which allows physically proximate attackers to obtain sensitive information by reading this screen.

Best of the Web
Dark Reading Radio