Badkeys: Finding Weak Cryptographic Keys At Scale by Hanno Böck | Nullcon Berlin
About this talk
This talk addresses the need for a service comparable to "Have I been pwned?" specifically for cryptographic keys. The speaker, Hanno Böck, introduces badkeys, a tool, web service, and API designed to check cryptographic keys for known vulnerabilities. He outlines the history of significant cryptographic weaknesses in public keys used in protocols like SSH and TLS, including notable incidents such as the 2008 Debian OpenSSL bug and the 2021 keypair vulnerability. The presentation discusses findings from a research project that reveals both previously unknown and known vulnerabilities found in live TLS certificates, demonstrating the relevance of accessible databases for assessing cryptographic security.
More from this event
See all 19 talks →
Keynote | High-assurance Code Reviews: How Consulting Works When The Risks Are High by Dan Guido
49:15
Night Track | GNU Anastasis: Privacy-Preserving Key Backup And Recovery by Christian Grothoff
28:47
Fuzzware: Automating & Scaling Fuzzing For Firmware by Tobias Scharnowski & Marius Muench | Nullcon
39:10
CXO Panel | Digital Identity In The Age Of Fintech | Nullcon Berlin 2022
56:07