Re: Security advisory for YubiKey 4: RSA generation broken

2017-10-17 Thread NIIBE Yutaka
Hello, For the particular vulnerability, I don't think Gnuk is affected. Here are (at least) three different things to discuss; (1) whether or not key generation on device uses secret parameters, (2) prime number generation method, and (3) entropy source. Since key generation takes time and

Re: Security advisory for YubiKey 4: RSA generation broken

2017-10-17 Thread Marc Haber
On Mon, Oct 16, 2017 at 03:22:35PM -0400, Antoine Beaupré wrote: > What I would like to know is whether other keycards, like the Nitrokey > Start, FST-01 or the Zeitcontrol smartcards, are affected. > > I suspect only the Nitrokey PRO and Zeitcontrol cards *could* be > affected (and may not be,