The Debian OpenSSL bug and other Public Private Keys (god2024) episode artwork

EPISODE · Nov 13, 2024 · 21 MIN

The Debian OpenSSL bug and other Public Private Keys (god2024)

from Chaos Computer Club - archive feed · host Hanno Böck

In early 2024, hundreds of DKIM setups still used cryptographic keys vulnerable to a bug from 2008 in Debian's OpenSSL package. Vulnerable hosts included prominent names like Cisco, Oracle, Skype, and Github. In 2022, it was discovered that printers generated TLS keys that could be trivially broken with an over 300-year-old algorithm by Pierre de Fermat. Vulnerabilities in public/private key generation are amongst the most severe ones in cryptographic software. The speaker has developed the open-source tool badkeys, a tool to check cryptographic keys for known vulnerabilities. The talk will cover some of the findings and plans for future improvements in badkeys. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Episode metadata supplied by the publisher feed · Published Nov 13, 2024

Embed this episode

NOW PLAYING

The Debian OpenSSL bug and other Public Private Keys (god2024)

0:00 21:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - archive feed?

This episode is 21 minutes long.

When was this Chaos Computer Club - archive feed episode published?

This episode was published on November 13, 2024.

Can I download this Chaos Computer Club - archive feed episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!