Showing posts with label firmware. Show all posts
Showing posts with label firmware. Show all posts

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Saturday, November 16, 2019

Dell EMC PowerOne launches autonomous infrastructure that automates tasks, delivers ready-to-run resources in few clicks

Dell Technologies releases Dell EMC PowerOne autonomous infrastructure to make deploying, managing and consuming IT easier for organizations. 

PowerOne integrates PowerEdge compute, PowerMax storage, PowerSwitch networking and VMware virtualization into a single system combined with a built-in intelligence engine to automate thousands of manual steps over its lifecycle. 


At the heart of PowerOne's autonomous operations is a built-in, advanced automation engine. PowerOne empowers users to focus on their business, whether that means deploying workloads, applications, or developing new products and services. 


Much like lane assist, navigation and other features in autonomous vehicles, the vehicle does most operations on its own while the passenger must let the car know the desired destination. PowerOne's advanced automation allows administrators to state a desired business outcome – and the system calculates the best way to do the rest. 

The automation engine takes advantage of a Kubernetes microservices architecture and uses Ansible workflows to assist users by automating the component configuration and provisioning, delivering a customer-managed datacenter-as-a-service. 


PowerOne provides a single system-level application programming interface (API), giving users the control to create business objective-specific pools of resources. This API can be tied into existing tools, such as service portals, to deliver programmable versus manual IT operations. This is known as Infrastructure as Code - virtually eliminating the need to log in to individual component management systems. With PowerOne, organizations can create workload-ready VMware clusters in only a few clicks.

With PowerOne, users can assist  speeds installation and configuration using built-in workflows based on VMware Validated Designs and Dell EMC best practices. The Lifecycle Assist helps reduce infrastructure risk by simplifying daily operations and life cycle management with automated modular system updates and validation, continually checking the correct hardware and firmware settings. 


The offering also allows expansion that matches infrastructure with business needs by adding, removing or reassigning capacity and resources through automated provisioning and scaling features. Customers can align operations with business requirements.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...