discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Factoring RSA Keys with Many Zeros

Researchers found a new class of weak RSA keys with many zeros, which can be factored easily. These keys are found in the wild, including in certificates issued to large organizations.

By Bruce Schneier·Jun 29·schneier.com·2 min read

Intelligence analysis by Llama 3.3 70B

Factoring RSA Keys with Many Zeros
Image: schneier.com

A new vulnerability in RSA keys with many zeros has been discovered, affecting a small minority of hosts on the internet. The vulnerability is due to independent cryptographic implementations failing in similar ways.

Why it matters

This discovery is important because it highlights the potential for deliberate backdoors in cryptographic implementations, which could compromise the security of online communications.

Imagine you have a special lock that keeps your online communications safe. This lock is like a secret code that only you and the person you're talking to can understand. But what if someone found a way to make this lock weaker, so that they could easily break in and read your messages? That's kind of what's happening with these weak RSA keys.

Analysis

Introduction to RSA Key Vulnerabilities

The discovery of weak RSA keys with many zeros is a significant finding in the field of cryptography. RSA keys are widely used to secure online communications, and any vulnerability in these keys could have serious consequences. The researchers found that these weak keys are not only theoretical, but are actually found in the wild, including in certificates issued to large organizations such as Yahoo and Verizon.

The Badkeys Project and Its Findings

The badkeys project is an open-source service that checks public keys for known vulnerabilities. The project collected a massive number of real-world keys from public sources, including Certificate Transparency logs, internet-wide TLS and SSH scans, PGP keys, and many others. By searching this dataset for unexpectedly sparse RSA moduli, the researchers uncovered a large number of keys with the patterns in Figure 1. Both patterns include several regularly spaced blocks of all zeros interleaved with seemingly random data.

Implications of the Discovery

The discovery of these weak RSA keys has significant implications for the security of online communications. The fact that these keys are found in the wild and are used by large organizations highlights the potential for deliberate backdoors in cryptographic implementations. This could be a deliberately designed backdoor, of the sort that has been written about in the past. The researchers speculate that some government agency may have figured out how to break this class of RSA keys and then convinced different providers to hand them out to users. This highlights the need for careful scrutiny of cryptographic implementations and the importance of using secure and trusted sources for cryptographic keys.

Key points

  • A new class of weak RSA keys with many zeros has been discovered
  • These keys are found in the wild, including in certificates issued to large organizations
  • The vulnerability is due to independent cryptographic implementations failing in similar ways
The Upside

The discovery of these weak RSA keys highlights the importance of careful scrutiny of cryptographic implementations. By identifying and addressing these vulnerabilities, we can improve the security of online communications and prevent potential backdoors. This is a positive step towards a more secure online environment.

The Downside

The fact that these weak RSA keys are found in the wild and are used by large organizations highlights the potential for deliberate backdoors in cryptographic implementations. This could compromise the security of online communications and have serious consequences. It's possible that more implementations may include the same bugs, which could lead to further vulnerabilities.

Originally reported at

schneier.com

Discernion covers the story. Read the full piece at the source.

Tagscryptographyencryptionkeysrsasecurity

Author

Bruce Schneier

Intelligence analysis by

Llama 3.3 70B

Published

Jun 29, 2026

Source

schneier.com

Share

Topics

cryptographyencryptionkeysrsasecurity

Related

More from this desk

Oct 7·bleepingcomputer.com

Ransomware recovery CEO charged over secret ransom payments

MonsterCloud CEO charged with fraud for secretly paying ransomware attackers, charging victims up to $19 million for recovery services.

Oct 7·wired.com

Shaq Got Hacked. Now He’s Pitching for a VPN

Shaq talks about his experience with cyber security and the importance of personal privacy. NordVPN is helping him raise awareness.

Oct 7·bleepingcomputer.com

FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins

FBI warns of ongoing FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators.

Oct 7·bleepingcomputer.com

Hackers Hijack Google Domains After Breaching ccTLD Registries

Hackers obtained unauthorized HTTPS certificates for Google domains and hijacked ccTLD domains for Ghana, American Samoa, and Sierra Leone. Google blocked unauthorized certificates and notified affected organizations.