Post B5LWrsvemzH9xsIoKm by lunareclipse@snug.moe
 (DIR) More posts by lunareclipse@snug.moe
 (DIR) Post #B5KOsBvDBGa84vll6u by badkeys@infosec.exchange
       7 likes, 13 repeats
       
       I reported an insecure DKIM key to Deutsche Telekom / T-Systems. They first asked me to further explain things (not sure why 'Here's your DKIM private key' needs more explanation, but whatever...). Then they told me it's out of scope for their bugbounty.I guess then there's really no reason not to tell you: They have a 384 bit RSA DKIM key configured at: dkim._domainkey.t-systems.nl384 bit RSA is... how shall I put it? I think 512 bit is the lowest RSA key size that was ever really used. 384 bit RSA is crackable in a few hours on a modern PC (using cado-nfs). The private key is:-----BEGIN RSA PRIVATE KEY-----MIHxAgEAAjEAtTliQYV2Xvx1OGkDyOL799BTFEuobY2dn2AgtiKCQgrh78NVK1JKj0yRXgNnPpGBAgMBAAECMF0t+TBZUCi8xATSMij7VLTxv5Xi5OIXesNiXOKtYIRPLkpYfR5PggaMScfbmqSssQIZAMwOhm9d7Y7Qi7I2j1AlYbiqdtqO54T7FQIZAONa9dJFkC6lM3EPXR+0SZ4dqwwpiM0nvQIYYgz8thi5JK264ohq9sTvnu9yKvUN9I09AhgfgMYZKcxtujRjkSZtMzUUNLYzzDmJe90CGDKwqcBI0v9ChaR8WHht+/chMdxj7ez94w==-----END RSA PRIVATE KEY-----
       
 (DIR) Post #B5KXNzOk4uda8YFtjM by q@glauca.space
       0 likes, 2 repeats
       
       @badkeys You thought 384-bit was bad? I recently found a live, in daily use, 256-bit key in a, shall we say, large government entity that should know better (would rather not say much more publicly as its relevant to a paper under submission).
       
 (DIR) Post #B5KXSLehGfpSKDnS5I by dragonfrog@mastodon.sdf.org
       0 likes, 0 repeats
       
       @badkeys Looks like they've fixed it now (?)The TXT record is now"v=DKIM1; k=rsa; g=*; s=email; p=MEwwDQYJKoZIhvcNAQEBBQADOwAwOAIxALU5YkGFdl78dThpA8ji+/fQUxRLqG2NnZ9gILYigkIK4e/DVStSSo9MkV4DZz6RgQIDAQAB"I really hope they generated a new key, and didn't just switch from publishing the private key to the corresponding public one...
       
 (DIR) Post #B5KXSMFD4v2I9Ssbzs by millie@infosec.exchange
       2 likes, 1 repeats
       
       @dragonfrog @badkeys Most people might not be fluent in base64-encoded ASN.1, but a trained eye can see that it's the same key.Hint: A sufficiently strong RSA key cannot possibly be that short, and you know it's a DER-encoded pubkey because it starts with "ME"  and ends with "AQAB" (0x10001, common RSA public exponent)
       
 (DIR) Post #B5LLABYF5jUdU2JIkC by selea@social.linux.pizza
       0 likes, 0 repeats
       
       @badkeys What wat. they published the private key?!
       
 (DIR) Post #B5LPdJ7kPnXlBU3kuG by kramse@helvede.net
       1 likes, 0 repeats
       
       @selea @badkeys no, sounds like they stayed for tooo long on a short length that could be cracked quickly.they should upgrade to more bits, and re-roll their keys
       
 (DIR) Post #B5LQYJUzh3ymqy7Dma by linear@nya.social
       0 likes, 0 repeats
       
       @badkeys@infosec.exchange just a few days ago i broke an rsa384 key using yafu on my home server (a ~6 year old dell poweredge, fairly decent spec) as a practice run for something, and it took under 5 minutes
       
 (DIR) Post #B5LQb7o9cIh3SmPynw by linear@nya.social
       0 likes, 0 repeats
       
       @badkeys@infosec.exchange the yafu help describes using siqs for this, which would take that server 2 to 3 hours, but using nfs it took only minutes
       
 (DIR) Post #B5LWrY9m1J5dXZkHvE by kate@mk.absturztau.be
       0 likes, 0 repeats
       
       @badkeys@infosec.exchange ..OMFG ..​:ablobcatcrumpled:​
       
 (DIR) Post #B5LWrsvemzH9xsIoKm by lunareclipse@snug.moe
       0 likes, 1 repeats
       
       @badkeys bad companies that don't pay out bug bounties can have uncoordinated public disclosure as a treat :3
       
 (DIR) Post #B5LWsr6j2xmSbZwUuu by irelephant@app.wafrn.net
       0 likes, 1 repeats
       
       @badkeys@infosec.exchangesend an email coming from them.
       
 (DIR) Post #B5Lg9W9p5hO28kPYn2 by buherator@infosec.place
       0 likes, 0 repeats
       
       @badkeys My educated guess is they couldn't fit larger keys into their DNS records...
       
 (DIR) Post #B5Lg9WRu0Tqf2orzyC by mcr314@todon.nl
       0 likes, 1 repeats
       
       @buherator @badkeys No, they thought they were generating an ECDSA key, for which a 256 or 384 bit would be strong.  But, they didn't provide the right arguments, and wound up with RSA.  I think the OP posted the private key that they were able to crack trivially.
       
 (DIR) Post #B5Lh9x3z9hnVXcS3cW by niconiconi@mk.absturztau.be
       0 likes, 0 repeats
       
       @badkeys@infosec.exchange 384-bit RSA is a ~116-digit decimal number. You know it's insecure, because factoring special long decimal numbers of cultural or meme significance has been a niche hobby since the year 2000 by Makoto Kamada, among others. We were the main users of these crypto tools when nobody was cracking any keys. The factored numbers typically have ~200 to 300 digits. I personally factored the number 23333....333333 (203 digits) in 2018 using GGNFS-0.77.1 + msieve 1.51 after running it for 254 hours, the answer was 13249578499 x 141923698309 x 341814137379262820703619531241772438672418960504220543 x 36301935597796613387875174789602896631621794317547997731884133406295200433460476448871588607865425544775288572131035081371416741.