Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 55 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow 1024-bit RSA encryption cracked by carefully starving CPU of electricity
EH-Net
May 25, 2012, 06:15:09 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: 1024-bit RSA encryption cracked by carefully starving CPU of electricity  (Read 6069 times)
0 Members and 2 Guests are viewing this topic.
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« on: March 09, 2010, 02:29:31 AM »

Quote
"Now, three eggheads (or Wolverines, as it were) at the University of Michigan claim they can break it simply by tweaking a device's power supply. By fluctuating the voltage to the CPU such that it generated a single hardware error per clock cycle, they found that they could cause the server to flip single bits of the private key at a time, allowing them to slowly piece together the password.

http://www.engadget.com/2010/03/09/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-ele/
Logged
zeroflaw
Full Member
***
Offline Offline

Posts: 184



View Profile
« Reply #1 on: March 09, 2010, 05:57:34 AM »

Man, how do they come up with stuff like that  Huh Very interesting.
Logged

ZF
Ketchup
Hero Member
*****
Offline Offline

Posts: 1006



View Profile
« Reply #2 on: March 09, 2010, 07:05:25 AM »

It's actually pretty impressive.  104 hours to crack 1024 bit encryption is very significant. 
Logged

~~~~~~~~~~~~~~
Ketchup
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #3 on: March 09, 2010, 07:42:40 AM »

Quote
"... By fluctuating the voltage to the CPU such that it generated a single hardware error per clock cycle, they found that they could cause the server to flip single bits of the private key at a time, allowing them to slowly piece together the password.

Wow!  I don't know about anyone else, but I NEVER would've even begun to think of something like that.  Amazing results, from amazing people.  For those that don't know their history, U of M is also the originator of LDAP.  (Note, I'm an Ohio State Buckeye fan, so go Bucks!  But I've got to give credit, where credit is due...)
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
former33t
Full Member
***
Offline Offline

Posts: 228


View Profile
« Reply #4 on: March 09, 2010, 05:27:36 PM »

Yeah, I can't wait to see the full writeup on this.

I'm surprised that DoD hasn't stopped this from being presented.  In the US, you are required to submit research on number theory to DoD for pre-publication review (the original intent was to give them a heads up on a prime factorization flaw to avoid breaking public key crypto).  While some may argue, I think this falls squarely into number theory and personally, I don't think it should be released until RSA has a chance to review the attack and fix the flaw (if that's even possible).  I'm normally for information disclosure, but RSA is too fundamental to the economy IMHO.
Logged

Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #5 on: March 09, 2010, 11:53:18 PM »

In the US, you are required to submit research on number theory to DoD for pre-publication review (the original intent was to give them a heads up on a prime factorization flaw to avoid breaking public key crypto).

Interesting, didn't know that before. Looking forward to the full paper as well.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.267 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.