Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageResearch Desk
Research

Factoring RSA Keys with Many Zeros

Schneier highlights research showing that RSA keys with abnormally many zero bits are factorable and exist in production — a subtle implementation weakness the badkeys project is now flagging at scale.

Summary written by editorial AI · Source link below

Filed by Schneier on Security1 min readRead at source ↗

Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number of real-world keys from public sources, including Certificate Transparency logs, internet-wide TLS and SSH scans, PGP keys, and many others. By searching this dataset for unexpectedly sparse RSA moduli, we uncover

Editorial Analysis

Why it matters

Weak RSA keys generated by flawed implementations can silently undermine TLS and code-signing trust chains without triggering conventional vulnerability scanners.

What to do

Run the open-source badkeys scanner against your certificate inventory to identify and rotate any structurally weak RSA keys.

Board brief

Some production RSA keys are mathematically breakable due to implementation flaws — a certificate audit is advisable.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Schneier on Security

External link — opens at Schneier on Security in a new tab.

§
Continue with

More from the Research Desk