Attacks/Breaches

10/17/2017
04:50 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Factorization Bug Exposes Millions Of Crypto Keys To 'ROCA' Exploit

Products from Lenovo, HPE, Google, Microsoft, and others impacted by flaw in Infineon chipset.

The set of key reinstallation vulnerabilities disclosed Monday in the WPA2 protocol is actually the second disclosure in recent days to hammer home just how difficult it can be getting cryptography right.

Last week a team of security researchers from Masaryk University in the Czech Republic and other organizations disclosed a bug in a Trusted Platform Module (TPM) chipset from Infineon Technologies AG that some believe is worse than the KRACK WiFi flaws.

The factorization vulnerability gives attackers a way to recover the private half of any RSA encryption key generated by the chipset, using only the public key. Unlike the KRACK flaws, an attacker does not need to be close to a vulnerable device or have access to it, in order to exploit the flaw. Any RSA key generated by a vulnerable Infineon chipset is open to attack, the researchers said in an alert.

"It's a huge deal in terms of the integrity of the infrastructure. Once the private key is derived, integrity is lost." says Scott Petry CEO and Founder of Authentic8.

"The practical nature of the vulnerability is a function of how broad the TPM installed base is and whether an attacker can determine a vulnerable private key from the public part — in other words, can an attacker determine if a key was generated by the chipset or not," he says.

According to the researchers, the bug makes factorization of 1024 and 2048 bit key lengths practically possible in terms of time and cost. "The worst cases for the factorization of 1024-bit and 2048-bit keys are less than 3 CPU-months and 100 CPU-years, respectively, on a single core of a common recent CPU, while the expected time is half of that of the worst case," the researchers said.

Using multiple CPUs to do the factorization can reduce the time significantly. At current prices, an attacker would spend about $76 to do the factorization for a 1024-bit key using an Amazon AWS c4 instance and roughly $40,000 to do the same with a 2,048-bit key.  Currently, at least 760,000 keys generated by the chipset are confirmed to be vulnerable. But it is quite possible that between two and three magnitudes more keys are broken.

The researchers will present a research paper titled "The Return of Coppersmith's Attack: Practical Factorization of Widely Used RSA Moduli' (ROCA) that will describe the attack more in detail Nov. 2 at the ACM CCS conference in Dallas.

The ROCA issue impacts any product in which the buggy chipset is integrated. The list includes products from Google, Microsoft, HPE, Lenovo and Fujitsu as well as trusted boot devices, authentication tokens and software package signing tools from other vendors. All of the vendors have released updates and advice to mitigate the issue. Infineon itself was informed about the bug in February and given time to address the issue before public disclosure. The company has developed firmware updates and made it available to OS and device makers.

"Cryptography is undoubtedly the most difficult problem to get right when it comes to information security," says Sean Dillon, senior security researcher at RiskSense.

If the number of cryptographic weaknesses that have been discovered in once widely trusted algorithms in recent years is any indication, more related vulnerabilities continue to be found for years to come, he predicts.

Vulnerabilities such as the ROCA flaw suggest the use of quantum computing and large prime factorization is not just a research concept, he says. Rather they portend "practical attack(s) that can break the entire trust model, even amongst big players such as governments and financial institutions," Dillon says.

Related content:

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
Most Malware Arrives Via Email
Dark Reading Staff 10/11/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
CVE-2018-18375
PUBLISHED: 2018-10-16
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
CVE-2018-18376
PUBLISHED: 2018-10-16
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
CVE-2018-18377
PUBLISHED: 2018-10-16
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.
CVE-2018-17534
PUBLISHED: 2018-10-15
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.