Microsoft announces deprecation of 1024-bit RSA keys in Windows

March 18, 2024 at 03:56PM Microsoft will soon deprecate RSA keys shorter than 2048 bits in Windows TLS to enhance security. With 2048-bit keys offering greater strength, Microsoft’s decision aims to protect organizations from weak encryption. The move may affect older software and devices, but a grace period is likely before formal deprecation begins. Organizations … Read more

Researchers extract RSA keys from SSH server signing errors

November 20, 2023 at 09:42AM Academic researchers have discovered that passive network attackers can retrieve secret RSA keys from errors in SSH connection attempts. These attacks exploit faults during signature computation, allowing attackers to compute the private key. The researchers recommend implementing validation of signatures before sending them to prevent secret key retrieval. Cisco and … Read more