So these researchers collected ~200 million TLS handshakes, and found a few hundred that were miscomputed, they suspect by bit errors. However, I do not believe modern computational devices are so unreliable. If I computed 200 million TLS exchanges on my home PC over a few days, I wouldn't expect a single one to be miscomputed. Servers with ECC memory ought to be another order of magnitude more reliable. So why do we…
The research doesn't necessarily imply that any typical device has such a high failure probability. From the paper: > The three private keys revealed by the 11 faulty [RSA] signatures in our [passively observed] data were associated with three certificates that were served from four different IP addresses associated with Baidu. [...] > After we disclosed to Baidu, they informed us that the traffic we observed was bet…
Re: Open to a fault: On the passive compromise of TLS keys via transient errors [pdf]
#11Yea it's just a coincidence that most of the key leaks identified in a US university campus internet are from Baidu. Just a random hardware error, nothing suspicious at all...