[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <8312.1329933242@turing-police.cc.vt.edu>
Date: Wed, 22 Feb 2012 12:54:02 -0500
From: Valdis.Kletnieks@...edu
To: Ramo <ramo@...dvikings.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: RSA and random number generation
On Wed, 22 Feb 2012 09:09:46 +1100, Ramo said:
> I'll just leave this here.....
>
> http://eprint.iacr.org/2012/064.pdf
As an interesting crypto research item, it's actually very good work.
However, for those of us in the trenches, it's mostly a non-issue, actually -
see Dan Kaminsky's analysis of the actual situation:
http://dankaminsky.com/2012/02/17/primalfear/
Bottom line: The bug allows you to MITM the same embedded webservers
in routers and wireless boxes that you were *already* able to easily MITM
because the devices used self-signed certs and other crappy key management
issues.
Content of type "application/pgp-signature" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists