Archive for March, 2010

Fault-Based Attack of RSA Authentication

Sunday, March 7th, 2010

A vulnerability discovered in the openSSL library could compromise the secrecy of a device’s cryptographic key.

Scientists, from the University of Michigan’s electrical engineering and computer science departments have found a way to extract the private SSL key from a device by creating fluctuations in the power supply and reading the output whilst the device was encrypting data using the private key.

(more…)

Mariposa Botnet is No More

Saturday, March 6th, 2010

Spanish law-enforcement agencies have recently shut down a 12M PC botnet, codenamed Mariposa (spanish for “butterfly”), distributed in more than 190 countries. Considering a typical size of such a malicious coalition at around 5K members, one may put into perspective how much of a security risk a network of millions of infected PCs really is. (more…)