Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

By definition, it still has to be loaded in RAM, so this strategy is unfortunately moot.


How is it any more moot than the private key loaded into RAM by your https server? It's still not on disk, and it's still more difficult to extract from memory than from the disk.


Agreed, sshd is not any different from the key being loaded into RAM by your http server.

But it's even easier and faster to grab a key from RAM. Could just use a debugger or a handy tool like aeskeyfinder or...

https://github.com/mmozeiko/aes-finder

(or another handy tool like heartbleed ;))




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: