x
This website is using cookies. We use cookies to ensure that we give you the best experience on our website. More info. That's Fine
HPC:Factor Logo 
 
Latest Forum Activity

Is nPOPuk 3.04 with SSL secure?

I dunk for bananas Page Icon Posted 2022-11-18 5:26 PM
#
Avatar image of I dunk for bananas
H/PC Elite

Posts:
702
Location:
Europe
Status:
I recall there being some kind of security vulnerability with one of the components (I believe cert checking), would this affect that specific version?
 Top of the page
C:Amie Page Icon Posted 2022-11-18 6:05 PM
#
Avatar image of C:Amie
Administrator
H/PC Oracle

Posts:
17,975
Location:
United Kingdom
Status:
The source performs no chain validation or CRL verification at all. All versions.
 Top of the page
I dunk for bananas Page Icon Posted 2022-11-18 6:42 PM
#
Avatar image of I dunk for bananas
H/PC Elite

Posts:
702
Location:
Europe
Status:
Quote
C:Amie - 2022-11-18 6:05 PM

The source performs no chain validation or CRL verification at all. All versions.


How would you personally rate that risk?
 Top of the page
C:Amie Page Icon Posted 2022-11-18 8:05 PM
#
Avatar image of C:Amie
Administrator
H/PC Oracle

Posts:
17,975
Location:
United Kingdom
Status:
If someone successfully steals a private key, your device will recognise it unchallenged in-perpetuity regardless of whether it expires or was revoked.

The question is: what are the odds that someone gets hold of the private key.
 Top of the page
I dunk for bananas Page Icon Posted 2022-11-26 8:04 PM
#
Avatar image of I dunk for bananas
H/PC Elite

Posts:
702
Location:
Europe
Status:
Quote
C:Amie - 2022-11-18 8:05 PM

If someone successfully steals a private key, your device will recognise it unchallenged in-perpetuity regardless of whether it expires or was revoked.

The question is: what are the odds that someone gets hold of the private key.


How would something like that be possible? Like, via a breach of Google if I'm using Gmail for instance? I'm sorry, I'm not very knowledgeable on the subject
 Top of the page
C:Amie Page Icon Posted 2022-11-27 11:32 AM
#
Avatar image of C:Amie
Administrator
H/PC Oracle

Posts:
17,975
Location:
United Kingdom
Status:
1. Insurmountably improbable computational luck at reverse brute forcing RSA/SHA2
2. Access to the server and the ability to compromise its internal key repository such that you can get access to the private key
3. Having access to a quantum computer and enough knowledge/time to orchestrate what so far hasn't been clearly demonstrated as being viable

It has absolutely nothing to do with you, your account or your device what so ever. If Google lost it, every Google service running on that key would be impacted.
 Top of the page
Jump to forum:
Seconds to generate: 0.140 - Cached queries : 64 - Executed queries : 8