XSS Worm : Cross Site Scripting & Web 2.0 Security

Application Vulnerability Information Portal

WARNING: Math Bugs put Global Commerce at Risk

Posted by xssworm on November 19th, 2007

“One of the world’s most prominent cryptographers issued a warning on Friday about a hypothetical incident in which a math error in a widely used computing chip places the security of the global electronic commerce system at risk.”

“Adi Shamir, a professor at the Weizmann Institute of Science in Israel, circulated a research note about the problem to a small group of colleagues. He wrote that the increasing complexity of modern microprocessor chips is almost certain to lead to undetected errors.”

“A subtle math error would make it possible for an attacker to break the protection afforded to some electronic messages by a popular technique known as public key cryptography.”

Math Bugs

Mr. Shamir wrote that if an intelligence organization discovered a math error in a widely used chip, then security software on a PC with that chip could be “trivially broken with a single chosen message.”

Executing the attack would require only knowledge of the math flaw and the ability to send a “poisoned” encrypted message to a protected computer, he wrote. It would then be possible to compute the value of the secret key used by the targeted system. With this approach, “millions of PC’s can be attacked simultaneously, without having to manipulate the operating environment of each one of them individually,” Mr. Shamir wrote.

An Intel spokesman noted that the flaw was a theoretical one and something that required a lot of contingencies.

Mr. Shamir said he had no evidence that anyone is using an attack like the one he described.

Thank you to John Markoff for writing this useful warning article.

Source: John Markoff @ NYTIMES

These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • blinkbits
  • BlinkList
  • blogmarks
  • BlogMemes
  • Book.mark.hu
  • Bumpzee
  • co.mments
  • connotea
  • De.lirio.us
  • DotNetKicks
  • DZone
  • Fark
  • feedmelinks
  • Fleck
  • Furl
  • Gwar
  • Haohao
  • Hemidemi
  • IndiaGram
  • IndianPad
  • Internetmedia
  • kick.ie
  • LinkaGoGo
  • Linkter
  • Ma.gnolia
  • MisterWong
  • MyShare
  • Netscape
  • Netvouz
  • NewsVine
  • PlugIM
  • PopCurrent
  • ppnow
  • RawSugar
  • Rec6
  • Reddit
  • scuttle
  • Shadows
  • Simpy
  • Slashdot
  • Smarking
  • SphereIt
  • Spurl
  • StumbleUpon
  • Taggly
  • TailRank
  • Technorati
  • ThisNext
  • Webride
  • Wists
  • YahooMyWeb

6 Responses to “WARNING: Math Bugs put Global Commerce at Risk”

  1. Wordpress Fckeditor Says:

    Would you like to make a substantial income by building Adsense Websites and displaying ads? This set of scripts automates the task and allows you to continue in your regular job. Only a few hours a week will have you up and running and generating a great income. Look at the amm-info dot com site for specific information.

  2. How To Hack A Myspace Says:

    Wow, am I the only one who just does not get this ?

  3. Daniel Says:

    I read similar article also named WARNING: Math Bugs put Global Commerce at Risk, and it was completely different. Personally, I agree with you more, because this article makes a little bit more sense for me

  4. Jim Spence Says:

    Friday In searching for sites related to AdSense but more specifically to %KEYWORD, I found your site which has great content.

  5. digglit Says:

    electronic commerceWARNING: Math Bugs put Global Commerce at Risk

  6. Global Domain Says:

    Good site I “Stumbledupon” it today and gave it a stumble for you.. looking forward to seeing what else you have..later

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>