Feeds

US-CERT warns DKIM email open to spoofing

Mathematician accidentally spots flaw

High performance access to file storage

US-CERT has issued a warning that DomainKeys Identified Mail (DKIM) verifiers that use low-grade encryption are open to being spoofed and need to be upgraded to combat attackers wielding contemporary quantities of computing power.

You might think this is no big deal – after all the value of strong cryptography has been recognized for years. Unfortunately this problem has been found to affect some of the biggest names in the tech industry, including Google, Microsoft, Amazon, PayPal and several large banks.

The DKIM system adds a signature file to messages that can be checked to ascertain the domain of the sender by checking with DNS. It also takes a cryptographic hash of the message, using the SHA-256 cryptographic hash and RSA public key encryption scheme, so it can't be altered en route.

The problem stems from the very weak key lengths that are being used by companies that should know better. To make matters more embarrassing the problem was spotted by complete accident by Floridian mathematician Zachary Harris, who used it to spoof an email to Google CEO Larry Page.

Harris told Wired that he received an email from a Google recruiter, asking him to interview with the company for a site-reliability engineering position. Smelling a rat, he looked at the email in more depth and saw that Google was only using a 512-bit key, which isn’t particularly secure these days.

"A 384-bit key I can factor on my laptop in 24 hours," he said. "The 512-bit keys I can factor in about 72 hours using Amazon Web Services for $75. And I did do a number of those."

Thinking the recruiter might have introduced the vulnerability as a creative test if he was suitable for the job, Harris used the flaw to spoof and email to Larry Page from fellow co-founder Sergey Brin, in which he plugged his own website as something worthy of attention. He got no response, but two days later noticed Google had upped its key length to 2,048 bits and he was suddenly getting a lot of IP hits from the Chocolate Factory.

After doing some digging around Harris discovered this was a surprisingly common problem. Amazon, Twitter, eBay and Yahoo! were all using 512-bit keys and even Paypal and banks like HSBC were still on 768-bit systems, despite the standard recommending at least 1,028-bit as a minimum.

"Those are not factorable by a normal person like me with my resources alone. But the government of Iran probably could, or a large group with sufficient computing resources could pull it off," he warned.

Harris contacted those companies he had found were vulnerable and most, but not all, upgraded their systems to much higher keys. He also contacted CERT Coordination Center at Carnegie Mellon University so an alert could be put out before he went public.

Upgrading key length isn't difficult, but companies also need to revoke the old ones and remove test keys from files. Some receiving domains are still accepting test keys that have never been revoked he said.

With spoofed emails an increasing problem you'd think something so simple could have been spotted earlier. The industry still has a lot of catching up to do it seems. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.