An attack on all e-commerce should have the effect of enabling an attacker to impersonate any server – which is far from reality here. However, this finding does bring a very important issue in generating random numbers and in also generating RSA keys that are not “weak keys”. The software or hardware used to generate keys should be tested against known weaknesses at all times, and customers should ask vendors questions about the process they used to test their cryptographic software. Of course, using other strong cryptographic methods is also a good idea – but also if the keys and random numbers are generated correctly.
Announcements
RSA Weakness and e-Commerce Authentication
RSA key weakness
More Insights
Editors' Choice
Webinars
Reports
- How to Deploy Zero Trust for Remote Workforce Security
- What Ransomware Groups Look for in Enterprise Victims
- Everything You Need to Know About DNS Attacks
- Securing the Remote Worker: How to Mitigate Off-Site Cyberattacks
- How Enterprises Are Managing Application Security Risks in a Heightened Threat Environment
White Papers
More Insights