Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Four researchers working separately have demonstrated a server's private encryption key can be obtained using the Heartbleed bug, an attack thought possible but unconfirmed.. The findings come shortly after a challenge created by CloudFlare, a San Francisco-based company that runs a security and redundancy service for website operators. The link for this article located at Network World is no longer available. . The findings come shortly after a challenge created by CloudFlare, a San Francisco-based company tha. researchers, working, separately, demonstrated, server's, private, encryption, obtai. . LinuxSecurity.com Team
Below is what we thought as of 12:27pm UTC. To verify our belief we crowd sourced the investigation. It turns out we were wrong. While it takes effort, it is possible to extract private SSL keys. The challenge was solved by Software Engineer Fedor Indutny and Ilkka Mattila at NCSC-FI roughly 9 hours after the challenge was first published.. Fedor sent 2.5 million requests over the course of the day and Ilkka sent around 100K requests. Our recommendation based on this finding is that everyone reissue and revoke their private keys. CloudFlare has accelerated this effort on behalf of the customers whose SSL keys we manage. You can read more here. The link for this article located at CloudFare is no longer available. . Uncover the methods employed to retrieve private SSL keys via the Heartbleed vulnerability, alongside essential security measures to implement.. Heartbleed Attack, SSL Key Compromise, Cybersecurity Threats. . LinuxSecurity.com Team
Security researchers have discovered a "timing attack" that creates a possible mechanism for a hacker to extract the secret key of a TLS/SSL server that uses elliptic curve cryptography (ECC).. Elliptic curve cryptography is a type of public-key algorithm that uses the maths of elliptic curves rather than integer factorisation, which is used by RSA as a one-way function. By using ECC it is possible to provide equivalent levels of difficulty for a brute-force attack as can be provided by the more familiar integer-factorisation approaches, but using smaller key lengths. The approach has benefits for mobile and low-power systems. The link for this article located at The Register UK is no longer available. . New vulnerabilities in ECC raise concerns about SSL security; highlights the need for robust cryptographic measures.. Timing Attack, SSL Security, ECC Cryptography, Key Exposure. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.