RSA 1024-bit encryption cracked

Page 1 of 2 12 LastLast

    RSA 1024-bit encryption cracked


    Posted: 10 Mar 2010
    Three University of Michigan computer scientists say they have found a way to exploit a weakness in RSA security technology used to protect everything from media players to smartphones and e-commerce servers.

    While guessing the 1,000-plus digits of binary code in a private key would take unfathomable hours, the researchers say that by varying electric current to a secured computer using an inexpensive purpose-built device they were able to stress out the computer and figure out the 1,024-bit private key in about 100 hours – all without leaving a trace.

    RSA 1024-bit private key encryption cracked - Techworld.com

    Researchers find weakness in common digital security system - University of Michigan
    dmex's Avatar Posted By: dmex
    10 Mar 2010



  1. Posts : 535
    Windows 7 Pro 64bit
       #1

    100 hours still seems like alot of time to get into some things XD
      My Computer


  2. Posts : 761
    Windows 2000 5.0 Build 2195
       #2

    Compare that to the possible thousands of thousands of years it would take to simply guess.
      My Computer


  3. Posts : 535
    Windows 7 Pro 64bit
       #3

    arkhi said:
    Compare that to the possible thousands of thousands of years it would take to simply guess.
    i know, but its still not practical now is it XD
      My Computer


  4. Posts : 1,289
    Thread Starter
       #4

    cloud8521 said:
    arkhi said:
    Compare that to the possible thousands of thousands of years it would take to simply guess.
    i know, but its still not practical now is it XD
    No it wouldn't be practical for you maybe since you wouldn't be cracking any encrypted files, e-mails, SSL private keys, PGP encrypted hard-disks, games, consoles, etc.. but their all now vulnerable if you where using less than 1024bit encryption and the majority use 512bit halving the time down to 50 hours required to crack the protected key.

    I did find it interesting that starving a machine of power could result in being able to crack the encryption easier.
      My Computer


  5. Posts : 1,487
    Windows 7 x64 / Same
       #5

    cloud8521 said:
    100 hours still seems like alot of time to get into some things XD

    100 hours <<<<<<<<<< Age of the Universe (14.5 Billion years)


    dmex said:
    I did find it interesting that starving a machine of power could result in being able to crack the encryption easier.
    Yes, that is surprising to me as well--And EXTREMELY worrisome.
      My Computer


  6. Posts : 1,426
    7 Pro
       #6

    Am interested to see this practice being used for other 'cracks'.
      My Computer


  7. Posts : 383
    Black Label 7 x64
       #7

    To paraphrase Lee Corso - not so fast, my friend.

    Put very simply, the U of M researchers “compromised” RSA by performing the elegant equivalent of punching someone in the face until they give you the key. I think we can all agree that this is not a fundamental violation of the algorithm as Engadget suggests, nor is it a flaw that “RSA” (RSA is not an organization) needs to address.
    I'm too stupid to verify or reject the U of M claim, just passing along an item I found reading about it.
      My Computer


  8. Posts : 1,289
    Thread Starter
       #8

    Colonel Travis said:
    To paraphrase Lee Corso - not so fast, my friend.

    Put very simply, the U of M researchers “compromised” RSA by performing the elegant equivalent of punching someone in the face until they give you the key. I think we can all agree that this is not a fundamental violation of the algorithm as Engadget suggests, nor is it a flaw that “RSA” (RSA is not an organization) needs to address.
    I'm too stupid to verify or reject the U of M claim, just passing along an item I found reading about it.
    Any method that allows anybody to gain access to encrypted data in less than 100 hours is a weakness no matter if they need physical access.

    If someone stole your machine you would hope your files are never recovered by the thief. Just think if your doctors laptop or your <inset bank employee or government with your personal data here> laptop was stolen, it would take them less than 100 hours to get all that data and yours.
      My Computer


  9. Posts : 795
    windows 7 RTM x64
       #9

    Physical access for 100hrs? So they have to steal the physical box to do this. This is a reason why we are moving to thinclients for security purposes, running the apps with confidential stuff on the citrix server.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 21:18.
Find Us