DEF CON 31 - Assessing Security of Certificates at Scale - David McGrew, Brandon Enright, Andrew Chi

  Рет қаралды 1,151

DEFCONConference

DEFCONConference

9 ай бұрын

The security of digital certificates is too often undermined by the use of poor entropy sources in key generation. Flawed entropy can be hard to discover, especially when analyzing individual devices. However, some flaws can be detected when a large set of keys from the same entropy source are analyzed, as was dramatically demonstrated in 2012 and 2016 by the detection of weak HTTPS keys on the Internet.
In this talk, we present tools and techniques to identify weak keys at scale, by checking issued certificates obtained from passive monitoring, active network scans, or certificate authority logs. Our tools use efficient multithreaded implementations of network monitors, scanners, certificate parsers, and mathematical tests. The batch greatest common divisor test (BGCD) identifies RSA public keys with common factors, and outputs the corresponding private keys. The common key test identifies distinct devices that share identical keys. We report on findings from both tests and demonstrate how to audit HTTPS servers, run BGCD on 100M+ keys, identify RSA keys with common factors, and generate the corresponding private keys. Because nothing convinces like an attack, we show how to produce and use PEM files for factored keys.

Пікірлер: 1
@liljemark1
@liljemark1 8 ай бұрын
Good stuff!
When someone reclines their seat ✈️
00:21
Adam W
Рет қаралды 23 МЛН
WHY IS A CAR MORE EXPENSIVE THAN A GIRL?
00:37
Levsob
Рет қаралды 19 МЛН
Ну Лилит))) прода в онк: завидные котики
00:51
Tech Talk: What is Public Key Infrastructure (PKI)?
9:22
IBM Technology
Рет қаралды 102 М.
Transport Layer Security (TLS) - Computerphile
15:33
Computerphile
Рет қаралды 468 М.
DEF CON 31 - Defeating VPN Always On - Maxime Clementz
40:07
DEFCONConference
Рет қаралды 12 М.
DEF CON 31 - Terminally Owned - 60 Years of Escaping - David Leadbeater
47:34
eBPF: Unlocking the Kernel [OFFICIAL DOCUMENTARY]
30:00
Speakeasy Productions
Рет қаралды 85 М.
SSL, TLS, HTTPS Explained
5:54
ByteByteGo
Рет қаралды 675 М.
Интереснее чем Apple Store - шоурум BigGeek
0:42
Эффект Карбонаро и бумажный телефон
1:01
История одного вокалиста
Рет қаралды 2,8 МЛН