There are fewer than 2^273 atoms (i.e. a 273 bit number) in the universe; but if your ECDSA crypto algorithm demands 521 bits of random data yet you supply a mere 512 bits…

Numbers in cryptography are far beyond “astronomical” but it’s still so easy to make a mess by trying to shortcut them. It appears (?) that the PuTTY SSH client short-changed the ECDSA signature algorithm by 9 bits of entropy (viz: it reduced the desired random, entropic space to 1/512th of its expected size — aaaaand chaos ensued.

Oops.

Via: https://infosec.exchange/@tqbf/112277259036150138

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *