HNHacker News
TopNewBestAskShowJobs

petrs

5 karma · joined June 20, 2016

[ my public key: https://keybase.io/multichoice; my proof: https://keybase.io/multichoice/sigs/6ieZ3KLmmJQ-jCDBHg9Dzgdh5Mz0kAI6T6gUVH0plFc ]
submissionscomments
petrs··on The Million-Key Question: Investigating the Origins of RSA Public Keys
You may also try online tool that classifies keys based on the results from paper: http://crcs.cz/rsapp/ Just insert encoded certificate or URL to https server and let tool to tell you what library generated that key(s).

If you will provide 5 keys all generated by the same library, the correct library should be within top three most probable sources with high (>95%) probability.

(if not, please submit feedback :))

petrs··on The Million-Key Question: Investigating the Origins of RSA Public Keys
Yes, this is an incorrect statement, sorry. It sneaked there after edits by proofreading service, but that is no excuse for us. Should be just NP. (I'm one of the authors of the paper)
petrs··on The Million-Key Question: Investigating the Origins of RSA Public Keys
Verification that TLS keys are mostly generated by OpenSSL and PGP keys by PGP/GPG are sanity check that method actually works.

If it will turn out, that particular library has vulnerability, one can quickly search for other vulnerable keys from large datasets like IPv4-wide TLS scans.