Factoring RSA Keys with Many Zeros
Schneier highlights research showing that RSA keys with abnormally many zero bits are factorable and exist in production — a subtle implementation weakness the badkeys project is now flagging at scale.
Summary written by editorial AI · Source link below
Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number of real-world keys from public sources, including Certificate Transparency logs, internet-wide TLS and SSH scans, PGP keys, and many others. By searching this dataset for unexpectedly sparse RSA moduli, we uncover
Editorial Analysis
Weak RSA keys generated by flawed implementations can silently undermine TLS and code-signing trust chains without triggering conventional vulnerability scanners.
Run the open-source badkeys scanner against your certificate inventory to identify and rotate any structurally weak RSA keys.
Some production RSA keys are mathematically breakable due to implementation flaws — a certificate audit is advisable.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Schneier on Security in a new tab.
More from the Research Desk
- 39 New Methods That Compromise Passkey Authentication3d
- Security Vulnerability in a Voting System3d
- Selfie-Capture Dynamics as an Auxiliary Signal Against Deepfakes and Injection Attacks for Mobile Identity Verification4d
- How Reliable Is the Multi-Input Heuristic for Bitcoin Address Clustering in Law Enforcement Contexts?4d
- Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks4d