Elektrine lite

← Feed

@phlogiston@mastodon.nz

2026-09-29 02:41 UTC

@darkuncle@infosec.exchange An interesting thing is this: While TLS does not expose a weak mode of using RSA, the majority of X.509 certs on the web are RSA (approx. 2/3). See below for a link to the source for this. But certificates are also used for other things, e.g. code signing, token issuing, etc. And who knows whether any of those use cases will *always* be avoiding the classic RSA padding for signatures. So a move to the more efficient and compact ECDSA or (even (better)) to EdDSA would be appreciated. This move will also more likely level the path towards allowing for better cryptographic agility to adopt hybrid #PQC ciphers in the future. BTW, kudos to Let's Encrypt! There the entire chain is using ECDSA signed certs down to the web site using it. https://ecdsa.com/research #cryptography #RSA #ECC

Replies (1)

  • @darkuncle@infosec.exchange 2026-09-29 02:46

    @phlogiston@mastodon.nz My understanding (enthusiastic amateur level) is that almost no certificates use RSA without some kind of padding that would prevent this particular attack (notably, Privacy Pass used by Cloudflare and Apple is an exception, which is ironic given their respective relatively stellar records on secure cryptographic implementations)

    Open ##4889732