badkeys is an open source tool to check cryptographic keys for known vulnerabilities. Its developer @npub1syue...3cq9 gave a talk at German OWASP Day where he discussed how old bugs never die. He tested for the Debian OpenSSL bug discovered in 2008 & found hundreds of DKIM setups still vulnerable. Vulnerable hosts included prominent names like Cisco, Oracle, Skype, and Github. But he sees even older vulns including one which is over 300 years old.
Watch the talk here:
#NGI #NGI0

The Debian OpenSSL bug and other Public Private Keys
In early 2024, hundreds of DKIM setups still used cryptographic keys vulnerable to a bug from 2008 in Debian's OpenSSL package. Vulnerabl...

