c.r.s.
Goto Top

Get Your Hands Off My Laptop

Wissenschaftler der Uni Tel Aviv zeigen die Möglichkeit, private RSA- und Elgamal-Schlüssel aus dem schwankenden Erdungspotenzial von Laptops (=ungeerdeten Rechnern) zu extrahieren.

Patch-Hinweis:

We have disclosed our attack to GnuPG developers under CVE-2013-4576, suggested suitable countermeasures, and worked with the developers to test them. New versions of GnuPG 1.x and of libgcrypt (which underlies GnuPG 2.x), containing these countermeasures and resistant to the key-extraction attack described here, were released concurrently with the first public posting of these results.

http://www.tau.ac.il/~tromer/handsoff/

Content-Key: 246776

Url: https://administrator.de/contentid/246776

Printed on: May 27, 2024 at 00:05 o'clock