Most examples here and in the comments seem to involve an entire RSA prime coming through unredacted, and dealing with various ASN.1 shenanigans to figure out which bits actually belong to the prime.
But the situation is potentially still quite bad even if you have less information than that. See Heninger and Shacham (2008):
Comments
Most examples here and in the comments seem to involve an entire RSA prime coming through unredacted, and dealing with various ASN.1 shenanigans to figure out which bits actually belong to the prime.
But the situation is potentially still quite bad even if you have less information than that. See Heninger and Shacham (2008):
https://eprint.iacr.org/2008/510.pdf