Skip to content

Comment on RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysisparent

Comments

It took 9 years to fix GPG?

GnuPG 2.x wasn't vulnerable, just the old 1.x: http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/00033... "GnuPG 1.4.16 avoids this attack by employing RSA blinding during decryption. GnuPG 2.x and current Gpg4win versions make use of Libgcrypt which employs RSA blinding anyway and are thus not vulnerable."

RSA blinding seems to protect against timing attacks, how does RSA blinding protect against this acoustic attack?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.