There's now talk that this is in error, or even a hoax (though there are lots of people who think that "hoax" is a synonym for "wrong," and it's hard to tell here).
The web page at http://nenolod.net/~nenolod/sholes-keyleak-explained.html now says: This information is out-of-date. Several assumptions were made about the bootloader which made the feasibility of thisattack much less likely. Only chance of getting keys now is to factorize the public keys. Hash collision attack still seems possible. Follow @freemymoto for other efforts. I have an eyebrow raised because the words "factorize" and "Elgamal" are being used in the same sentence, but I am willing to accept that someone is using "factor" to mean "compute discrete log" as a tip of the slounge. Jon
_______________________________________________ cryptography mailing list [email protected] http://lists.randombit.net/mailman/listinfo/cryptography
