A new DUHK attack allows hackers to recover encryption keys from VPN connections and browsing sessions

in #bitcoin7 years ago

duhk.jpg

This exploit is labeled “Don't Use Hard-coded Keys” (DUHK) which is a new cryptographic vulnerability that could allow hackers to recover encryption keys used in secure VPN connections and web browsing sessions. Dozens of vendors are affected – Fortinet, Cisco,Techguard, and others which rely on ANSI X9.31 RNG, which is an old “not so random” number generation algorithm.