A team of researchers has identified a new kind of weak RSA key: keys with large blocks of zeros embedded in their structure. And they’re not just theoretical — thousands are deployed in the wild right now.
Researchers found the keys during development of the badkeys project, an open-source tool that checks public keys for known vulnerabilities. Hanno Böck collected massive numbers of real-world keys from Certificate Transparency logs, internet-wide TLS and SSH scans, and PGP key servers. The discovery was that some RSA moduli are surprisingly sparse.
Two patterns emerged. Pattern 1 shows up in certificates issued to Yahoo, Verizon, and some NetApp devices. Those certs have already expired. Pattern 2 affects SSH hosts running CompleteFTP from EnterpriseDT. Vulnerable versions span from December 2016 to December 2023.
Here’s what bugs me: independent implementations failed in similar ways. That’s either a coincidence or something worse. Tailoring cryptanalytic methods for this specific failure mode makes sense regardless.
What’s the actual risk? Small minority of hosts. But the pattern itself — different codebases producing the same weakness — raises questions about whether this was accidental.
