When Private Keys are Public: Results from the 2008 Debian OpenSSL Vulnerability Scott Yilek UC San Diego Eric Rescorla RTFM, Inc. Hovav Shacham UC San Diego firstname.lastname@example.org email@example.com firstname.lastname@example.org Brandon Enright Stefan Savage UC San Diego UC San Diego email@example.com ABSTRACT We report on the aftermath of the discovery of a severe vulnerability in the Debian Linux version of OpenSSL. Systems a ected by the bug generated predictable random numbers, most importantly public/private keypairs. To study user response to this vulnerability, we collected a novel dataset of daily remote scans of over 50,000 SSL/TLS-enabled Web servers, of which 751 displayed vulnerable certi cates. We report three primary results. First, as expected from previous work, we nd an extremely slow rate of xing, with 30% of the hosts vulnerable when we began our survey on day 4 after disclosure still vulnerable almost six months later. However, unlike conventional vulnerabilities, which typically show a short, fast xing phase, we observe a much atter curve with xing extending six months after the announcement. Second, we identify some predictive factors for the rate of upgrading. Third, we nd that certi cate authorities continued to issue certi cates to servers with weak keys
It’s your single place to instantly
discover and read the research
that matters to you.
Enjoy affordable access to
over 18 million articles from more than
15,000 peer-reviewed journals.
All for just $49/month
Query the DeepDyve database, plus search all of PubMed and Google Scholar seamlessly
Save any article or search result from DeepDyve, PubMed, and Google Scholar... all in one place.
Get unlimited, online access to over 18 million full-text articles from more than 15,000 scientific journals.
Read from thousands of the leading scholarly journals from SpringerNature, Elsevier, Wiley-Blackwell, Oxford University Press and more.
All the latest content is available, no embargo periods.
“Hi guys, I cannot tell you how much I love this resource. Incredible. I really believe you've hit the nail on the head with this site in regards to solving the research-purchase issue.”Daniel C.
“Whoa! It’s like Spotify but for academic articles.”@Phil_Robichaud
“I must say, @deepdyve is a fabulous solution to the independent researcher's problem of #access to #information.”@deepthiw
“My last article couldn't be possible without the platform @deepdyve that makes journal papers cheaper.”@JoseServera