Episode #884 Quiz
TLS PRIVATE KEY LEAKAGE
Date: 2022-08-16 | Length: 1.75 hrs | Episode page at twit.tv
About this episode
Researchers passively and actively monitored billions of TLS handshakes, exploiting transient RSA signature faults in TLS 1.0–1.2. Faulty CRT-based PKCS#1 v1.5 signatures leaked private keys, enabling retrospective decryption and impersonation. Mitigations include validating signatures before sending, using RSA-PSS, and migrating to TLS 1.3’s encrypted, forward-secure handshake.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.