Skip to content

Comment on Estonia blocks electronic ID cards over identity-theft risk

Comments

The vulnerability in question: *The Return of Coppersmith’s A‚ttack: Practical Factorization of Widely Used RSA Moduli∗ https://crocs.fi.muni.cz/_media/public/papers/nemec_roca_ccs...

Estonian ID card uses 2048 byte keys which means generating a private key from a public key takes 140.8 CPU years which is quite fast/trivial/cheap using a distributed approach (botnet, your already existing HW that you use for mining etc).. considering the implications.

https://www.schneier.com/blog/archives/2017/09/security_flaw...

Estonian ID card uses 2048 byte keys which means generating a private key from a public key takes 140.8 CPU years

To clarify, 2048 bit RSA keys are fine. But the smartcard that generates these used a too predictable algorithm for generating the keys.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.