October 30, 2017 By Shane Schick 2 min read

The use of a random number generator with hardcoded keys could launch a crypto attack, exposing private data through intranets, virtual private network (VPNs) and more, according to new security research.

A white paper from researchers at John Hopkins University and the University of Pennsylvania was the first to draw attention to the crypto attack method, which has been dubbed Don’t Use Hardcoded Keys (DUHK). By reverse engineering a set of firmware running on Fortinet devices, the researchers were able to compromise the encryption parameters in less than five minutes.

Exploiting Random Number Generation Algorithms

The vulnerability stems from a problem with the ANSI X9.31 Random Number Generation, an algorithm that can safeguard data in browsing sessions and other online use cases by creating encryption keys.

As Bitsonline explained, a U.S. government security standards body called Federal Information Processing Standards (FIPS) stopped supporting ANSI X9.31 almost two years ago, but it has been in devices from a number of security companies for a long time. The hardcoded seed key, used at device setup or when launching the algorithm, is essentially making such devices susceptible to the crypto attack.

If cybercriminals were to make use of DUHK, their victims would most likely remain in the dark since the crypto attack is passive in nature, Bleeping Computer warned.

This attack could affect more than 23,000 FortiGate 4x devices using older versions of FortiOS, the white paper said. In addition to Fortinet devices, it also affects products from Cisco, Neopost and more than a dozen others. The easiest way to know if your organization is safe is to determine whether your firewall or VPN achieved FIPS certification after January 2016.

Is ANSI X9.31 a Sitting DUHK?

Not everyone sees DUHK as a major threat. As Threatpost pointed out, potential problems with ANSI X9.31 have been known among security experts for close to 20 years. Using it to launch a crypto attack would also require a number of other mistakes to have been made in deploying a security appliance.

This is less about putting organizations on guard against a likely threat and more of a critique about how standards bodies such as FIPS run their certification processes — and how well those processes are keeping up to date with the constant rate of change in information technology.

More from

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Testing the limits of generative AI: How red teaming exposes vulnerabilities in AI models

4 min read - With generative artificial intelligence (gen AI) on the frontlines of information security, red teams play an essential role in identifying vulnerabilities that others can overlook.With the average cost of a data breach reaching an all-time high of $4.88 million in 2024, businesses need to know exactly where their vulnerabilities lie. Given the remarkable pace at which they’re adopting gen AI, there’s a good chance that some of those vulnerabilities lie in AI models themselves — or the data used to…

FBI, CISA issue warning for cross Apple-Android texting

3 min read - CISA and the FBI recently released a joint statement that the People's Republic of China (PRC) is targeting commercial telecommunications infrastructure as part of a significant cyber espionage campaign. As a result, the agencies released a joint guide, Enhanced Visibility and Hardening Guidance for Communications Infrastructure, with best practices organizations and agencies should adopt to protect against this espionage threat. According to the statement, PRC-affiliated actors compromised networks at multiple telecommunication companies. They stole customer call records data as well…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today