Light

Episode #884 Quiz

TLS PRIVATE KEY LEAKAGE
Date: 2022-08-16 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Researchers passively and actively monitored billions of TLS handshakes, exploiting transient RSA signature faults in TLS 1.0–1.2. Faulty CRT-based PKCS#1 v1.5 signatures leaked private keys, enabling retrospective decryption and impersonation. Mitigations include validating signatures before sending, using RSA-PSS, and migrating to TLS 1.3’s encrypted, forward-secure handshake.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific flaw did Microsoft previously dismiss in its MSDT handling before it became CVE-2022-34713?
Question 2: What was the key operational difference between the passive TLS attack and the active TLS scans described in the episode?
Question 3: Why does the episode say TLS 1.3 reduces the risk of this RSA fault attack compared with TLS 1.2?
Question 4: What did the researchers report about the scale of their passive TLS collection before finding compromised keys?
Question 5: What specific practical warning did the episode give about publicly exposing services like SMB and VNC?
Cancel