I reported an insecure DKIM key to Deutsche Telekom / T-Systems. They first asked me to further explain things (not sure why 'Here's your DKIM private key' needs more explanation, but whatever...). Then they told me it's out of scope for their bugbounty.
I guess then there's really no reason not to tell you: They have a 384 bit RSA DKIM key configured at: dkim._domainkey.t-systems.nl
384 bit RSA is... how shall I put it? I think 512 bit is the lowest RSA key size that was ever really used. 384 bit RSA is crackable in a few hours on a modern PC (using cado-nfs). The private key is:
-----BEGIN RSA PRIVATE KEY-----
MIHxAgEAAjEAtTliQYV2Xvx1OGkDyOL799BTFEuobY2dn2AgtiKCQgrh78NVK1JK
j0yRXgNnPpGBAgMBAAECMF0t+TBZUCi8xATSMij7VLTxv5Xi5OIXesNiXOKtYIRP
LkpYfR5PggaMScfbmqSssQIZAMwOhm9d7Y7Qi7I2j1AlYbiqdtqO54T7FQIZAONa
9dJFkC6lM3EPXR+0SZ4dqwwpiM0nvQIYYgz8thi5JK264ohq9sTvnu9yKvUN9I09
AhgfgMYZKcxtujRjkSZtMzUUNLYzzDmJe90CGDKwqcBI0v9ChaR8WHht+/chMdxj
7ez94w==
-----END RSA PRIVATE KEY-----
isithran likes this.
reshared this
210561 ✨ [Q]
in reply to badkeys • • •niconiconi reshared this.
Lambda Crime [The Möth Society]
in reply to 210561 ✨ [Q] • • •210561 ✨ [Q]
in reply to Lambda Crime [The Möth Society] • • •Triss Hellsite
in reply to 210561 ✨ [Q] • • •nadja
in reply to 210561 ✨ [Q] • • •210561 ✨ [Q]
in reply to nadja • • •nadja
in reply to 210561 ✨ [Q] • • •crispycat
in reply to 210561 ✨ [Q] • • •210561 ✨ [Q]
in reply to crispycat • • •BenBE
in reply to badkeys • • •You had me at
-----BEGIN RSA PRIVATE KEY-----
1.3.6.1.4.1.61513 reshared this.
Klarname: #NichtMeineRegierung
in reply to badkeys • • •Momo
in reply to badkeys • • •Kevin Karhan
in reply to Momo • • •@momo sadly this is being normalized today.
dragonfrog
in reply to badkeys • • •Looks like they've fixed it now (?)
The TXT record is now
"v=DKIM1; k=rsa; g=*; s=email; p=MEwwDQYJKoZIhvcNAQEBBQADOwAwOAIxALU5YkGFdl78dThpA8ji+/fQUxRLqG2NnZ9gILYigkIK4e/DVStSSo9MkV4DZz6RgQIDAQAB"
I really hope they generated a new key, and didn't just switch from publishing the private key to the corresponding public one...
Millie
in reply to dragonfrog • • •@dragonfrog Most people might not be fluent in base64-encoded ASN.1, but a trained eye can see that it's the same key.
Hint: A sufficiently strong RSA key cannot possibly be that short, and you know it's a DER-encoded pubkey because it starts with "ME" and ends with "AQAB" (0x10001, common RSA public exponent)
buherator
in reply to badkeys • • •Jon Gerdes
in reply to buherator • • •I installed a MariaDB cluster backed set of PowerDNS servers for that exact reason! There were a couple of other reasons but that was what finally made me roll up my sleeves.
Michael Richardson
in reply to buherator • • •niconiconi reshared this.
wall-e
in reply to badkeys • • •irelephant
in reply to badkeys • • •niconiconi
in reply to badkeys • • •STUDIO KAMADA
stdkmd.net