lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 16 Apr 2014 12:23:08 +0200
From: Hanno Böck <>
To: Georgi Guninski <>
Subject: Re: [FD] Should openssl accept weak DSA/DH keys with g = +/- 1 ?

On Wed, 16 Apr 2014 11:44:00 +0300
Georgi Guninski <> wrote:

> AFAICT weak DH keys can't be recognized
> since they can be well formed.

Yes, I'm aware of that, has recently been discussed on the TLS WG list
also. But clients could (and should imho) reject obviously bogus
parameters like 8 bit moduli sizes.

The solution would be to change TLS to have a fixed set of "known good"
DH parameters written in the spec. This is also what the authors of the
triple handshake attack have proposed. Would also save traffic because
servers wouldn't have to send the DH parameter set, just an identifier.
But probably won't happen before TLS 1.3.

Hanno Böck


Download attachment "signature.asc" of type "application/pgp-signature" (837 bytes)

Sent through the Full Disclosure mailing list
Web Archives & RSS:

Powered by blists - more mailing lists