Some Website Security Keys Have a Flaw, but Tools Can Now Detect It
Security researchers found a weakness in certain encryption keys used by websites. A new tool helps identify and fix these vulnerable keys before hackers can exploit them.
Source
Schneier on Security
Original headline: Factoring RSA Keys with Many Zeros
Plain-English summary by GetCyberRight. Read the full report at the source above.
Researchers have discovered a specific type of weakness in RSA keys, which are digital security tools that protect information sent between your computer and websites. The problem involves keys that contain many zeros in their mathematical structure. These flawed keys exist on real websites right now. A researcher named Hanno created an open source tool called badkeys that can scan and identify these vulnerable keys by checking public sources like website security certificates. This primarily affects website owners and system administrators rather than everyday internet users. However, if a website you use has one of these weak keys, the encrypted connection that protects your passwords, credit card numbers, and personal information could be vulnerable.
The good news is that security professionals can now use the badkeys tool to find and replace these flawed keys before criminals exploit them. For most families, there is nothing you need to do right now. The vulnerable keys are on the website side, not on your personal devices. Website administrators are the ones who need to take action. However, you can take these general safety steps:
- Make sure the websites you use for banking, shopping, and email show a padlock icon in the address bar.
- Use unique passwords for important accounts so that if one site is compromised, your other accounts stay safe.
- Enable two factor authentication on accounts that offer it, especially for banking and email. Moving forward, remember that website security is constantly evolving. While you cannot control the security choices websites make, you can control your own habits. Using strong, unique passwords and two factor authentication creates additional layers of protection even if a website's encryption has problems. Keep your devices updated, as security updates often include fixes for newly discovered vulnerabilities.
Curated from trusted cybersecurity sources by GetCyberRight
Source: Schneier on SecurityStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Police Now Need Warrants to Track Your Phone's Location History
A major Supreme Court ruling protects your family's privacy by requiring warrants before police can access geofence location data from tech companies.
3 min read
New 'Djinn' Malware Steals Login Credentials from Business Tools
A new type of malware is stealing passwords from cloud services and AI tools that businesses use. It targets work accounts that could give hackers wider access.
2 min read
New 'Djinn' Hacking Tool Targets Business Cloud Accounts
Hackers are using a new tool to steal cloud and AI system login credentials from businesses through a flaw in remote support software called SimpleHelp.
2 min readNissan Employee Data Breach: What Workers and Families Need to Know
A zero-day attack on Nissan's Oracle software exposed employee data. Here's what affected workers should do right now to protect themselves.
4 min read