As cited
Copy frozen at (site build).
research
Factoring RSA Keys with Many Zeros
Researchers discovered a new class of weak RSA keys characterized by regularly spaced blocks of zeros in their moduli, found in real-world deployments including expired certificates for Yahoo and Verizon, and SSH hosts running CompleteFTP software. The CompleteFTP vulnerability affects RSA keys generated in versions 10.0.0 through 12.0.0 and DSA keys up to version 23.0.4, with cryptanalytic algorithms potentially tailored to exploit this specific weakness. The findings suggest independent implementations failed similarly, raising questions about whether additional cryptographic products contain comparable flaws.
Why it matters: If you manage keys or certificates from affected vendors (especially older CompleteFTP deployments), verify your RSA implementations are not generating sparse moduli that could be factored.
- Source published
- First seen by Cybersecurity Tracker