TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Factoring RSA keys from certified smart cards

97 pointsby pedro84over 11 years ago

4 comments

zokierover 11 years ago
&gt; MOICA estimates that approximately 10000 cards were deployed in non-FIPS mode as a result of &quot;human error&quot;.<p>While it&#x27;s bit silly that the so called secure cards can be configured into non-secure modes, I think it&#x27;s important to note that again we have the human factor messing our nice cryptosystems. The security of the FIPS mode might be questionable too due the behaviour of the HW RNG, it should still improve the security significantly over the non-FIPS mode which was the one found broken in this analysis.
评论 #6397205 未加载
kolunover 11 years ago
I got one for filing tax report. Is there a way for an non-expert like me to tell whether the one I have is vulnerable to attack?
评论 #6397010 未加载
评论 #6396161 未加载
tikumsover 11 years ago
Dan Goodin from Ars Technica shares more details about the paper:<p><a href="http://arstechnica.com/security/2013/09/fatal-crypto-flaw-in-some-government-certified-smartcards-makes-forgery-a-snap/" rel="nofollow">http:&#x2F;&#x2F;arstechnica.com&#x2F;security&#x2F;2013&#x2F;09&#x2F;fatal-crypto-flaw-in...</a>
jlgaddisover 11 years ago
I&#x27;m curious why they chose these particular cards. Cards from Gemalto seem like a more obvious choice (to me).