Badkeys: Finding Weak Cryptographic Keys At Scale by Hanno Böck | Nullcon Berlin

39:03 · 05 Apr 2022 – 07 Apr 2022 · YouTube

About this talk

This talk addresses the need for a service comparable to "Have I been pwned?" specifically for cryptographic keys. The speaker, Hanno Böck, introduces badkeys, a tool, web service, and API designed to check cryptographic keys for known vulnerabilities. He outlines the history of significant cryptographic weaknesses in public keys used in protocols like SSH and TLS, including notable incidents such as the 2008 Debian OpenSSL bug and the 2021 keypair vulnerability. The presentation discusses findings from a research project that reveals both previously unknown and known vulnerabilities found in live TLS certificates, demonstrating the relevance of accessible databases for assessing cryptographic security.

From event

Nullcon Berlin 2022

05 Apr 2022 – 07 Apr 2022

All event videos
Back to Watch