<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-27T16:56:23Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by badkeys</title>
  <author>
    <name>badkeys</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1n6aeqhcc2aeerlmt2v9zee02rz9zxjxn76jg89dnskvkltd7vl6se2d6mm.rss" />
  <link href="https://nostr.ae/npub1n6aeqhcc2aeerlmt2v9zee02rz9zxjxn76jg89dnskvkltd7vl6se2d6mm" />
  <id>https://nostr.ae/npub1n6aeqhcc2aeerlmt2v9zee02rz9zxjxn76jg89dnskvkltd7vl6se2d6mm</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/112/880/053/945/794/536/original/88ee43323c38669f.png</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/112/880/053/945/794/536/original/88ee43323c38669f.png</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqswq3zm67k64nw8zz9lnh5qkygkaw9dlsm6wursz3xj5zdj42s7wdszyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl25wymhs</id>
    
      <title type="html">During #39c3 Nadia Heninger introduced me to Keegan Ryan, and we ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswq3zm67k64nw8zz9lnh5qkygkaw9dlsm6wursz3xj5zdj42s7wdszyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl25wymhs" />
    <content type="html">
      During #39c3 Nadia Heninger introduced me to Keegan Ryan, and we talked about things that could go wrong in RSA, and how to detect keys with suspicious patterns created by defect RNGs. At some point, Keegan said: &amp;#34;You could check the Hamming Weight of the Modulus.&amp;#34; And I replied: &amp;#34;I don&amp;#39;t know what that means.&amp;#34;&lt;br/&gt;But it&amp;#39;s actually quite simple. The Hamming Weight is the ratio of symbols, if we look at bits, how many 0s vs 1s are there. For a &amp;#34;proper&amp;#34;, randomly generated RSA key, the ratio should be close to 0.5. If it&amp;#39;s significantly different from that, it&amp;#39;s likely not randomly generated.&lt;br/&gt;We ended up finding some keys with repeating zero-byte patterns.It is possible to represent those as polynomials. Unlike integer numbers, polynomials can be factored efficiently, which means these keys can be broken.&lt;br/&gt;&lt;br/&gt;We found SSH host keys that we could trace back to a software called CompleteFTP (which, furthermore, had another RSA vulnerability in its Linux version and also generated vulnerable DSA keys - all fixed in the latest version of CompleteFTP, but keys need to be regenerated). We furthermore identified another class of vulnerable keys (with a different width of zero byte patterns) in TLS certs (both self-signed and WebPKI-signed, but all expired, so no revocations), most of them from Verizon&#43;Yahoo, but we were unable to identify the vulnerable RSA implementation.&lt;br/&gt;&lt;br/&gt;If you&amp;#39;re interested in the details of the attack, check Keegan&amp;#39;s blog post:&lt;br/&gt;&lt;a href=&#34;https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/&#34;&gt;https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The latest badkeys version 0.0.18 detects all affected vulnerable keys.
    </content>
    <updated>2026-06-12T13:01:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9ryrv7g4varygr7z4khafg49u8az9jzeh4wnvg7eqk7qr276082gzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl26qlqgl</id>
    
      <title type="html">I reported an insecure DKIM key to Deutsche Telekom / T-Systems. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9ryrv7g4varygr7z4khafg49u8az9jzeh4wnvg7eqk7qr276082gzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl26qlqgl" />
    <content type="html">
      I reported an insecure DKIM key to Deutsche Telekom / T-Systems. They first asked me to further explain things (not sure why &amp;#39;Here&amp;#39;s your DKIM private key&amp;#39; needs more explanation, but whatever...). Then they told me it&amp;#39;s out of scope for their bugbounty.&lt;br/&gt;&lt;br/&gt;I guess then there&amp;#39;s really no reason not to tell you: They have a 384 bit RSA DKIM key configured at: dkim._domainkey.t-systems.nl&lt;br/&gt;&lt;br/&gt;384 bit RSA is... how shall I put it? I think 512 bit is the lowest RSA key size that was ever really used. 384 bit RSA is crackable in a few hours on a modern PC (using cado-nfs). The private key is:&lt;br/&gt;-----BEGIN RSA PRIVATE KEY-----&lt;br/&gt;MIHxAgEAAjEAtTliQYV2Xvx1OGkDyOL799BTFEuobY2dn2AgtiKCQgrh78NVK1JK&lt;br/&gt;j0yRXgNnPpGBAgMBAAECMF0t&#43;TBZUCi8xATSMij7VLTxv5Xi5OIXesNiXOKtYIRP&lt;br/&gt;LkpYfR5PggaMScfbmqSssQIZAMwOhm9d7Y7Qi7I2j1AlYbiqdtqO54T7FQIZAONa&lt;br/&gt;9dJFkC6lM3EPXR&#43;0SZ4dqwwpiM0nvQIYYgz8thi5JK264ohq9sTvnu9yKvUN9I09&lt;br/&gt;AhgfgMYZKcxtujRjkSZtMzUUNLYzzDmJe90CGDKwqcBI0v9ChaR8WHht&#43;/chMdxj&lt;br/&gt;7ez94w==&lt;br/&gt;-----END RSA PRIVATE KEY-----
    </content>
    <updated>2026-04-15T07:34:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxaz8d9hmhwxtt92j5dnp829l8r7alz62qeea65rq70gzuuh5aqfqzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2n60est</id>
    
      <title type="html">In the recently released badkeys v0.0.17, a new check for an RSA ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxaz8d9hmhwxtt92j5dnp829l8r7alz62qeea65rq70gzuuh5aqfqzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2n60est" />
    <content type="html">
      In the recently released badkeys v0.0.17, a new check for an RSA vulnerability has been added: RSA keys with small private d values, also known as Wiener&amp;#39;s attack: &lt;a href=&#34;https://badkeys.info/docs/smalld.html&#34;&gt;https://badkeys.info/docs/smalld.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;RSA keys have a public exponent e and a private exponent d. Usually, we set the public exponent to a small value (these days, largely standardized to e=65537), which automatically means the private value d is about as large as the public modulus.  d/e are interexchangable, and it&amp;#39;s possible to create insecure keys with small d and large e value. Wiener&amp;#39;s attack (first published 1989) allows breaking such keys.&lt;br/&gt;&lt;br/&gt;This weakness can be entirely prevented if one simply does not support keys with large public e values. This is, e.g., the case in the go crypto library, see, e.g., this old (2012) blogpost by &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1h2qen7s0kg54lzfyyag780pdrmu37jj56f59nenne2qfgr7u92nsw3lajr&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Adam Langley&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1h2q…lajr&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; &lt;a href=&#34;https://www.imperialviolet.org/2012/03/16/rsae.html&#34;&gt;https://www.imperialviolet.org/2012/03/16/rsae.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Even more secure is to fix the e value to its common default (e=65537). This is small enough to be still fast, and it avoids both attacks relying on large e (Wiener&amp;#39;s attack) and very small e values like 3 (Bleichenbacher&amp;#39;s Signature Forgery/BERserk, Coppersmith/Håstad attack).
    </content>
    <updated>2026-02-22T07:55:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2t2sqznzdnds372tv0rtw25e38qavrvym8hmf5v6dmz743smc5tqzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2jwpf5a</id>
    
      <title type="html">Is anyone aware of an OCR tool that is reliable enough for ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2t2sqznzdnds372tv0rtw25e38qavrvym8hmf5v6dmz743smc5tqzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2jwpf5a" />
    <content type="html">
      Is anyone aware of an OCR tool that is reliable enough for non-text content like base64 that it can decode something like this?&lt;br/&gt;&lt;br/&gt;(Context is something that was just posted on the dev-security-policy list and I currently can&amp;#39;t judge the severity, but it happens every now and then that I see private or public keys in images that I&amp;#39;d like to get OCRed, source of this one: &lt;a href=&#34;https://archive.ph/u6U2p&#34;&gt;https://archive.ph/u6U2p&lt;/a&gt; )&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/932/333/426/191/529/original/d2642b5ad9865008.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-01-21T09:18:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyjha687g0swwps0uwvd04wyzj0s7shmvqc3tpkw9swxjt790jqmszyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2q46g8p</id>
    
      <title type="html">JSON Web Keys have a very peculiar property. It is a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyjha687g0swwps0uwvd04wyzj0s7shmvqc3tpkw9swxjt790jqmszyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2q46g8p" />
    <content type="html">
      JSON Web Keys have a very peculiar property. It is a cryptographic key serialization format where public and private keys look almost the same. The only difference is that private keys contain more values. This means one can accidentally use a private key instead of a public key. Which works, but isn&amp;#39;t very secure.&lt;br/&gt;After my recent presentation at the [@owasp_de](&lt;a href=&#34;https://infosec.exchange/@owasp_de&#34;&gt;https://infosec.exchange/@owasp_de&lt;/a&gt; ) Day, I was asked to have a look at OpenID Connect keys. Which are, well, in JWK format. I guess you can see where this is going.&lt;br/&gt;&lt;a href=&#34;https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html&#34;&gt;https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html&lt;/a&gt;
    </content>
    <updated>2025-02-25T11:15:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszqfrzey0m6ess7aw45q3dsndenv03jchexkwkzvjcu9nshjq065qzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2jmvzvx</id>
    
      <title type="html">@npub1stt…ddpm @npub1lcc…lcye nothing spectacular, random ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszqfrzey0m6ess7aw45q3dsndenv03jchexkwkzvjcu9nshjq065qzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2jmvzvx" />
    <content type="html">
      &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1sttn3l2n40lkk5eyt2czgeqnsct9ql6ltau6nmcqq4s8422ahcjqkjddpm&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Dr. Christopher Kunz&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1stt…ddpm&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1lcc6wn885u6k395x5j5tmdm94r6dh9zajxm8gyk82pv2s2j3el7sc6lcye&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Kevin Beaumont&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1lcc…lcye&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; nothing spectacular, random small  company webpages and some likely internal hostnames.
    </content>
    <updated>2025-01-18T08:25:02Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz5e6qzqfdtjz6tvrnf6gle7w323wykuws7rnwxvkmjtx4t3c2y3qzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2ta4hha</id>
    
      <title type="html">I discovered a certificate using a &amp;#34;public private key&amp;#34;, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz5e6qzqfdtjz6tvrnf6gle7w323wykuws7rnwxvkmjtx4t3c2y3qzyz0thyzlrpth8y0lddfs5t89agvg5g6g60m2fqu4kwzejmadhenl2ta4hha" />
    <content type="html">
      I discovered a certificate using a &amp;#34;public private key&amp;#34;, in this case a key that is part of OpenSSL&amp;#39;s test suite. This would not necessarily be a particularly interesting event. It happens every now and then that people use private keys they find on the Internet, likely due to a lack of understanding of public key cryptography. I usually report them for revocation, and move on. However, this one is a bit more unusual. It has been issued by the CA Digicert - for a domain owned by Digicert. &lt;a href=&#34;https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/d21mtDJ7YXQ&#34;&gt;https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/d21mtDJ7YXQ&lt;/a&gt;
    </content>
    <updated>2024-11-25T15:51:04Z</updated>
  </entry>

</feed>