GitHub has blocked SSH keys generated using the keypair library

GitHub has blocked SSH keys of users of Git clients that use the JavaScript library keypair for key generation. For example, keys from the Git client GitKraken have been affected. This vulnerability leads to the generation of predictable RSA keys due to an error significantly reducing the quality of entropy when generating a random sequence for keys. The issue has been resolved in keypair versions 1.0.4 and GitKraken 8.0.1.

The vulnerability arose from the use of the call "b.putByte(String.fromCharCode(next & 0xFF))" during key formation, while the method putByte called the method fromCharCode again. The double call to fromCharCode ("String.fromCharCode(String.fromCharCode(next & 0xFF))") resulted in most of the buffer with entropy being filled with zeros, meaning that the key was generated based on "random" data that was 97% zeros.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster