{"id":532943,"date":"2024-04-17T17:01:22","date_gmt":"2024-04-17T15:01:22","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=532943"},"modified":"2024-04-17T17:04:43","modified_gmt":"2024-04-17T15:04:43","slug":"putty-vulnerability-allows-attackers-to-uncover-private-keys","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/532943-putty-vulnerability-allows-attackers-to-uncover-private-keys.html","title":{"rendered":"PuTTY vulnerability allows attackers to uncover private keys"},"content":{"rendered":"<p>A vulnerability within PuTTY version 0.68 through 0.80 allows attackers to recover a user\u2019s private key using at least 60 digital signatures that use the Elliptic Curve Digital Signature Algorithm (ECDSA).<\/p>\n<p>Researchers from Ruhr University Bochum, Fabian Baumer and Marcus Brinkman, first discovered the vulnerability, which is tracked as <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-31497\" target=\"_blank\" rel=\"noopener\">CVE-2024-31497<\/a><\/strong>.<\/p>\n<p>PuTTY is an open-source terminal emulator, serial console, and network file transfer application for Windows.<\/p>\n<p>It lets users remotely access and manage servers and other networked devices.<\/p>\n<p>The terminal uses network protocols such as SSH to establish an encrypted connection.<\/p>\n<p>They found that PuTTY generates biased ECDSA nonces because Windows lacks a robust cryptographic random generator.<\/p>\n<p>\u201cBias\u201d in this context means the cryptographic nonces are not random enough to prevent a cryptanalyst from reverse engineering private keys from publicly available digital signatures.<\/p>\n<p>As a result, attackers can recover a user\u2019s full private key if they\u2019ve seen around 60 of their ECDSA digital signatures.<\/p>\n<p>These signatures are not considered private data and may be readily found online, including in commits made to git version control repositories.<\/p>\n<p>Digital signatures are created by signing a hash digest (also called a hash code) of specific data, such as the contents of an email or code committed to a git repository.<\/p>\n<p>Hashes are numeric values that are long enough (usually between 160 and 512 bits) to be considered a unique representation of a piece of data.<\/p>\n<p>Crucially, hashes are non-reversible \u2014 you can\u2019t reverse the hashing algorithm to regain the original data.<\/p>\n<p>You essentially sign a hash by \u201cencrypting\u201d it using your private key. Others can then \u201cdecrypt\u201d it using your public key.<\/p>\n<p>Someone can then compute the hash of a message or piece of code and compare it to the decrypted hash attached to it.<\/p>\n<p>This allows them to verify who wrote it and that it wasn\u2019t manipulated in any way \u2014 provided the sender\u2019s private key has remained secure.<\/p>\n<p>Thus, gaining access to a user\u2019s private key can be extremely valuable to attackers.<\/p>\n<p>Once attackers have a user\u2019s private key, they can digitally sign anything as that person, decrypt data that was encrypted using their public key, or potentially intercept Internet traffic secured using their private key.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers have identified a security flaw in PuTTY that allows attackers to recover private keys from digital signatures.<\/p>\n","protected":false},"author":341175,"featured_media":414496,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[5280,5276,93813,93809,51815,93811,93807,30044],"class_list":["post-532943","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyber-analytics","tag-cyber-security","tag-ecdsa","tag-fabian-baumer","tag-hash-function","tag-marcus-brinkman","tag-putty","tag-ssh"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/532943"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341175"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=532943"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/532943\/revisions"}],"predecessor-version":[{"id":532955,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/532943\/revisions\/532955"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/414496"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=532943"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=532943"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=532943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}