Security researchers have identified a new class of vulnerable RSA keys containing sparse patterns of zeros, which were discovered in real-world deployments across various internet services and software products.
Key Points
- The badkeys project identified RSA and DSA keys with predictable, sparse patterns of zeros in public Certificate Transparency logs and internet-wide scans.
- Affected entities include certificates previously issued to Yahoo and Verizon, as well as devices running NetApp software.
- Vulnerable SSH hosts were linked to specific versions of CompleteFTP software, specifically versions 10.0.012.0.0 and 10.0.023.0.4.
- Researchers suggest these cryptographic failures may stem from flawed key generation implementations rather than isolated incidents.
- The findings highlight the need for specialized cryptanalytic algorithms to detect similar vulnerabilities in other software implementations.