* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Thursday, May 22, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Wilmington’s future of fun: 5 recreation and entertainment spaces planned in the Port City – Wilmington Star-News

    Exciting Developments Ahead: 5 New Recreation and Entertainment Spaces Coming to Wilmington!

    Jason Momoa Is Done With Peace in Apple’s ‘Chief of War’ Teaser – Yahoo

    Jason Momoa Embraces Chaos in Gripping Teaser for Apple’s ‘Chief of War’

    AI Entertainment Studio Promise Inks Deal With Google, Raises Investment from Michael Ovitz’s Crossbeam – The Hollywood Reporter

    AI Entertainment Studio Promise Secures Major Deal with Google and Attracts Investment from Michael Ovitz’s Crossbeam!

    Jennifer Lawrence and Robert Pattinson Did This “Humiliating” Thing to Prep for Sex Scenes – Yahoo

    Jennifer Lawrence and Robert Pattinson’s Hilarious Preparation for Steamy Sex Scenes!

    Meet the Cast of FX’s New Comedy ‘Adults’ – WFXG

    Meet the Cast of FX’s New Comedy ‘Adults’ – WFXG

    First Celebrities Playing in the 2025 American Century Championship Announced – El Paso Inc.

    Exciting Lineup Revealed: First Celebrities Set to Compete in the 2025 American Century Championship!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Novotech Honored with Triple Win in 2025 Pharmaceutical Technology Excellence Awards – Morningstar

    Novotech Celebrates Triple Triumph at the 2025 Pharmaceutical Technology Excellence Awards!

    Experts Issue Warning on New TSA Technology – Men’s Journal

    Experts Sound Alarm Over New TSA Technology: What You Need to Know

    Cellino’s iPSC Manufacturing Technology Receives FDA Advanced Manufacturing Technology (AMT) Designation – Business Wire

    Cellino’s Groundbreaking iPSC Manufacturing Technology Earns FDA’s Advanced Manufacturing Designation!

    New technology adapting the study of Anatomy | Why’s Guy’s – WCIA.com

    Revolutionizing Anatomy: How Cutting-Edge Technology is Transforming the Study of the Human Body

    We Think GigaCloud Technology’s (NASDAQ:GCT) Solid Earnings Are Understated – Yahoo Finance

    Unlocking Potential: Why GigaCloud Technology’s Impressive Earnings Deserve More Recognition

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Wilmington’s future of fun: 5 recreation and entertainment spaces planned in the Port City – Wilmington Star-News

    Exciting Developments Ahead: 5 New Recreation and Entertainment Spaces Coming to Wilmington!

    Jason Momoa Is Done With Peace in Apple’s ‘Chief of War’ Teaser – Yahoo

    Jason Momoa Embraces Chaos in Gripping Teaser for Apple’s ‘Chief of War’

    AI Entertainment Studio Promise Inks Deal With Google, Raises Investment from Michael Ovitz’s Crossbeam – The Hollywood Reporter

    AI Entertainment Studio Promise Secures Major Deal with Google and Attracts Investment from Michael Ovitz’s Crossbeam!

    Jennifer Lawrence and Robert Pattinson Did This “Humiliating” Thing to Prep for Sex Scenes – Yahoo

    Jennifer Lawrence and Robert Pattinson’s Hilarious Preparation for Steamy Sex Scenes!

    Meet the Cast of FX’s New Comedy ‘Adults’ – WFXG

    Meet the Cast of FX’s New Comedy ‘Adults’ – WFXG

    First Celebrities Playing in the 2025 American Century Championship Announced – El Paso Inc.

    Exciting Lineup Revealed: First Celebrities Set to Compete in the 2025 American Century Championship!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Novotech Honored with Triple Win in 2025 Pharmaceutical Technology Excellence Awards – Morningstar

    Novotech Celebrates Triple Triumph at the 2025 Pharmaceutical Technology Excellence Awards!

    Experts Issue Warning on New TSA Technology – Men’s Journal

    Experts Sound Alarm Over New TSA Technology: What You Need to Know

    Cellino’s iPSC Manufacturing Technology Receives FDA Advanced Manufacturing Technology (AMT) Designation – Business Wire

    Cellino’s Groundbreaking iPSC Manufacturing Technology Earns FDA’s Advanced Manufacturing Designation!

    New technology adapting the study of Anatomy | Why’s Guy’s – WCIA.com

    Revolutionizing Anatomy: How Cutting-Edge Technology is Transforming the Study of the Human Body

    We Think GigaCloud Technology’s (NASDAQ:GCT) Solid Earnings Are Understated – Yahoo Finance

    Unlocking Potential: Why GigaCloud Technology’s Impressive Earnings Deserve More Recognition

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

In a first, cryptographic keys protecting SSH connections stolen in new attack

November 13, 2023
in Technology
In a first, cryptographic keys protecting SSH connections stolen in new attack
Share on FacebookShare on Twitter

In a first, cryptographic keys protecting SSH connections stolen in new attack

Getty Images

For the first time, researchers have demonstrated that a large portion of cryptographic keys used to protect data in computer-to-server SSH traffic are vulnerable to complete compromise when naturally occurring computational errors occur while the connection is being established.

Underscoring the importance of their discovery, the researchers used their findings to calculate the private portion of almost 200 unique SSH keys they observed in public Internet scans taken over the past seven years. The researchers suspect keys used in IPsec connections could suffer the same fate. SSH is the cryptographic protocol used in secure shell connections that allows computers to remotely access servers, usually in security-sensitive enterprise environments. IPsec is a protocol used by virtual private networks that route traffic through an encrypted tunnel.

The vulnerability occurs when there are errors during the signature generation that takes place when a client and server are establishing a connection. It affects only keys using the RSA cryptographic algorithm, which the researchers found in roughly a third of the SSH signatures they examined. That translates to roughly 1 billion signatures out of the 3.2 billion signatures examined. Of the roughly 1 billion RSA signatures, about one in a million exposed the private key of the host.

While the percentage is infinitesimally small, the finding is nonetheless surprising for several reasons—most notably because most SSH software in use has deployed a countermeasure for decades that checks for signature faults before sending a signature over the Internet. Another reason for the surprise is that until now, researchers believed that signature faults exposed only RSA keys used in the TLS—or Transport Layer Security—protocol encrypting Web and email connections. They believed SSH traffic was immune from such attacks because passive attackers—meaning adversaries simply observing traffic as it goes by—couldn’t see some of the necessary information when the errors happened.

The researchers noted that since the 2018 release of TLS version 1.3, the protocol has encrypted handshake messages occurring while a web or email session is being negotiated. That has acted as an additional countermeasure protecting key compromise in the event of a computational error. Keegan Ryan, a researcher at the University of California San Diego and one of the authors of the research, suggested it may be time for other protocols to include the same additional protection.

In an email, Ryan wrote:

Even though the SSH protocol has been around for almost 18 years and is extremely widely deployed, we’re still finding new ways to exploit errors in cryptographic protocols and identifying vulnerable implementations. In our data, about one in a million SSH signatures exposed the private key of the SSH host. While this is rare, the massive amount of traffic on the Internet implies that these RSA faults in SSH happen regularly. Even though the vast majority of SSH connections are not affected, it’s still important that these failures are defended against. It only takes one bad signature in an unprotected implementation to reveal the key.

It’s fortunate that the most popular SSH implementations include countermeasures to prevent RSA signature faults from leading to catastrophic key leakage, but implementations that did not were still common enough to appear in our data.

The new findings are laid out in a paper published earlier this month titled “Passive SSH Key Compromise via Lattices.” It builds on a series of discoveries spanning more than two decades. In 1996 and 1997, researchers published findings that, taken together, concluded that when naturally occurring computational errors resulted in a single faulty RSA signature, an adversary could use it to compute the private portion of the underlying key pair.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Ars Technica – https://arstechnica.com/?p=1983026

Tags: cryptographicFirsttechnology
Previous Post

Daily Telescope: An amazing, colorful view of the Universe

Next Post

We’ll know soon if Astra—the commercial space company—has a future

Everyone is Moving to Chengdu. What Does That Say About China’s Economy? – The New York Times

Chengdu’s Rising Appeal: What the Migration Trend Reveals About China’s Economy

May 22, 2025
Wilmington’s future of fun: 5 recreation and entertainment spaces planned in the Port City – Wilmington Star-News

Exciting Developments Ahead: 5 New Recreation and Entertainment Spaces Coming to Wilmington!

May 22, 2025
Aetna, Sutter Health in contract dispute. Aetna says some patients may lose coverage. – Sacramento Bee

Aetna, Sutter Health in contract dispute. Aetna says some patients may lose coverage. – Sacramento Bee

May 22, 2025
The Politics of Belligerence Are Back in Bangladesh – Bloomberg.com

The Politics of Belligerence Are Back in Bangladesh – Bloomberg.com

May 22, 2025
Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

May 22, 2025
Feld Motor Sports Wins Two Telly Awards for SMX Content – SupercrossLive

Feld Motor Sports Wins Two Telly Awards for SMX Content – SupercrossLive

May 21, 2025
New BS in Ecology, Evolution and Environmental Biology degree program prepares students for diverse careers – Oakland University

Unlock Your Future: Explore the New BS in Ecology, Evolution, and Environmental Biology Degree!

May 21, 2025
Los Alamos Faith And Science Forum 2025 Summer Series – Los Alamos Daily Post

Explore the Intersection of Faith and Science: Join the 2025 Summer Series in Los Alamos!

May 21, 2025
🧪 Science with Sarah: Cloud in a jar ☁️ – KSAT

Create Your Own Cloud in a Jar: A Fun Science Experiment with Sarah!

May 21, 2025
Simple lifestyle changes to avoid prostate cancer – Times of India

Simple lifestyle changes to avoid prostate cancer – Times of India

May 21, 2025

Categories

Archives

May 2025
MTWTFSS
 1234
567891011
12131415161718
19202122232425
262728293031 
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (627)
  • Economy (641)
  • Entertainment (21,555)
  • General (15,224)
  • Health (9,683)
  • Lifestyle (645)
  • News (22,149)
  • People (643)
  • Politics (649)
  • Science (15,864)
  • Sports (21,151)
  • Technology (15,631)
  • World (630)

Recent News

Everyone is Moving to Chengdu. What Does That Say About China’s Economy? – The New York Times

Chengdu’s Rising Appeal: What the Migration Trend Reveals About China’s Economy

May 22, 2025
Wilmington’s future of fun: 5 recreation and entertainment spaces planned in the Port City – Wilmington Star-News

Exciting Developments Ahead: 5 New Recreation and Entertainment Spaces Coming to Wilmington!

May 22, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version