194
submitted 10 months ago by boem@lemmy.world to c/technology@lemmy.world
top 6 comments
sorted by: hot top controversial new old
[-] lemmyvore@feddit.nl 80 points 10 months ago

Only affects RSA keys, and then only 1 in a million keys are vulnerable. So this is mostly of academic (rather than practical) interest, but nevertheless it will lead to further hardening of the SSH protocol which is nice.

[-] PlasticExistence@lemmy.world 24 points 10 months ago

It also appears to only affect non-OpenSSH secure shell implementations.

[-] Damage@feddit.it 24 points 10 months ago

Oh, so like 3 users

[-] deafboy@lemmy.world 1 points 10 months ago

Security of a sufficiently long RSA key was the one true constant in my life. Poof... There it goes!

Once attackers have possession of the secret key through passive observation of traffic, they can mount an active Mallory-in-the-middle

Mallory in the middle would be a sick punkrock band name though.

[-] autotldr@lemmings.world 16 points 10 months ago

This is the best summary I could come up with:


Underscoring the importance of their discovery, the researchers used their findings to calculate the private portion of almost 200 unique SSH keys they observed in public Internet scans taken over the past seven years.

SSH is the cryptographic protocol used in secure shell connections that allows computers to remotely access servers, usually in security-sensitive enterprise environments.

The vulnerability occurs when there are errors during the signature generation that takes place when a client and server are establishing a connection.

Another reason for the surprise is that until now, researchers believed that signature faults exposed only RSA keys used in the TLS—or Transport Layer Security—protocol encrypting Web and email connections.

The researchers noted that since the 2018 release of TLS version 1.3, the protocol has encrypted handshake messages occurring while a web or email session is being negotiated.

The new findings are laid out in a paper published earlier this month titled "Passive SSH Key Compromise via Lattices."


The original article contains 596 words, the summary contains 157 words. Saved 74%. I'm a bot and I'm open source!

this post was submitted on 13 Nov 2023
194 points (98.0% liked)

Technology

57944 readers
3518 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS