Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Lattice based ECDSA key recovery #680

Open
tomato42 opened this issue Jul 9, 2020 · 0 comments
Open

Lattice based ECDSA key recovery #680

tomato42 opened this issue Jul 9, 2020 · 0 comments
Labels
complex Issues that require good knowledge of tlsfuzzer internals enhancement new feature to be implemented help wanted

Comments

@tomato42
Copy link
Member

tomato42 commented Jul 9, 2020

If the nonces in ECDSA signatures have static bits, it's possible to recover private key from them. Log the signatures and check if we can't recover the private key this way

See:

@tomato42 tomato42 added enhancement new feature to be implemented help wanted complex Issues that require good knowledge of tlsfuzzer internals labels Jul 9, 2020
@tomato42 tomato42 added this to To do in Vulnerability testers via automation Jul 9, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
complex Issues that require good knowledge of tlsfuzzer internals enhancement new feature to be implemented help wanted
Projects
Development

No branches or pull requests

1 participant