Actions
Bug #2657
closedPotential weakness of the captive portal voucher system (design issue)
Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Captive Portal
Target version:
-
Start date:
10/11/2012
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:
Description
If the holder of a voucher can guess the encoded roll and ticket IDs and magic number (in particular if the default configuration magic number or no magic number at all is used), it is possible to deduce the RSA modulus employed by the voucher system and factor it due to its short length.
See the enclosed paper which has been submitted to the IACR ePrint archive.
Files
Actions