Whoops, @Yubico just scored 31% on the Sony PS3 Epic Fail scale. Collect three signatures from a FIPS Yubikey and you can calculate the private key.https://www.yubico.com/support/security-advisories/ysa-2019-02/ …
-
-
Do you plan to publish a more elaborated post on how to get the private key from the 3 signatures?
1 reply 0 retweets 10 likes -
I don't know where the number 3 comes from, but it's described here https://crypto.stackexchange.com/questions/44644/how-does-the-biased-k-attack-on-ecdsa-work …. Yubikey only said several
1 reply 3 retweets 8 likes -
It's just a guess based on the fraction of random bits leaked (80/256). Might be a few more depending on circumstances, but it's ~that order of magnitude.
2 replies 0 retweets 8 likes -
Replying to @marcan42 @marksteward and
That wasn't my read of it. My read is that during key generation 80 bits are static (left over from boot POST memory content). I don't think collecting any number of sigs/pubkeys will help leak the non-static bits.
2 replies 0 retweets 0 likes
80 bits of the random nonce are static during ECDSA *signature* generation too, not just key generation, and *that* leaks the whole key (regardless of how it was generated) after just a few signatures. See the stackexchange that was leaked earlier.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.