oss-sec mailing list archives

Re: broken RSA keys


From: Stanislav Datskovskiy <stas () loper-os org>
Date: Thu, 5 May 2016 08:42:13 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On Thu, May 5, 2016 at 5:23 AM, Hanno Böck <hanno () hboeck de> wrote:
Hi,

as I know the first ones to use this on publicly available keysets in
order to find vulnerable keys. The implementation from Nadia Heninger is
freely available [1] and some code to turn a pgp keyserver dump into a
mysql database is available from me [2]. So everyone should be able to
replicate what I'm saying

Where, exactly, did you get your public keys? Would you consider sharing?
Quite a few of your moduli are not in my SKS dumps.

Best,
- -S
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBCgAGBQJXKz+IAAoJELmCKKABq//HVf8H/1ZpDz5+sS/2cEc/TJXXrb9l
QuoQpRpRKSzaAJ239zeojqbvLNZ4s/p+CvczqNEQ2QhHxc4cRlcUTeq6f/54py4N
qemE5A4OUfrIgQzH/UPpXRY+N6IKiXL1wP9hMgKsDVV+x9h2ENdoa2GQlsuDenyU
OQFQoizVsU2XzOAY4MkEJKdY3oHU1yx14Bs93ayW2aN5K2ZWs9pM3zCAV+kWmH3O
47vANi7DdBTzBoixzZflruoGe6rRMDfft4vx+ngiGcPBkN5NyEpzTbPM9tAtyncJ
g8H9ygaHJoLc89iScW4HmQuLW3HEaHaMwPYv2x78X+ubFGQuoWwNADcE6kBJwSw=
=PLnp
-----END PGP SIGNATURE-----


Current thread: