A thread on the Tasmota TLS MitM attack I found a few months ago since getting a proper blog post about it is taking me forever.

Tasmota is an open source firmware that runs on a number of ESP8266-based IoT home automation devices, which talks to an MQTT broker for management.

MQTT can be run over TLS to provide confidentiality and integrity, but given the constraints of running on an ESP8266 device, standard TLS certificate validation is rather heavy. As an alternative, Tasmota implements fingerprint based validation, like SSH
The fingerprint validation can do "trust on first use" (TOFU) and just remember the server's public key. This can work well if you're hosting your own MQTT server, and you can just use a self signed certificate. The fingerprint algorithm was even based on how SSH does it.
If you read RFC4253, it describes the RSA key format with the following encoding

string "ssh-rsa"
mpint e
mpint n

where e is the public exponent (usually 65537) and n is the modulus.

Slight problem. RFC4253 doesn't explain what an mpint is.
You have to go dig up RFC4251 for what an mpint is. The precise details don't really matter for this bug, but the critical detail is that an mpint is length-prefixed, which makes it unambiguous where when mpint ends and the next begins.

Tasmota's implementation missed this.
Instead, everything was simply concatenated together with no delimiter. That means each fingerprint actually matches a "family" of RSA keys with identical serialization with the public exponent ending and the modulus beginning in different places.
As an example (with tiny number), we could have e=17 and n=389436408973, with a serialization of "ssh-rsa17389436408973". But e=17389 and n=436408973 gives the same serialization and is much easier to factor - it's 7 * 11 * 13 * 435973.
A quick bit about RSA - keys are normally formed from two large prime numbers that are around the same size, which are multiplied together to form the modulus. The security of RSA depends on it being difficult to decompose the modulus into its prime factors.
The math behind RSA also works perfectly fine with more than two prime numbers - and this is even supported (though rarely used) by modern implementations. The question is, can factors actually be found for collisions of arbitrary RSA keys under Tasmota's scheme?
There are two ways to factor numbers large enough to use as RSA keys - general number field sieve and elliptic curve method.

GNFS's difficulty depends on the size of the number, and these are too big.

ECM, however, depends on the size of the second largest factor.
For a normal RSA number with two primes, GNFS would be faster, but if the primes are small enough, ECM is feasible.

So, then, to attack the key, the family of RSA keys that match the fingerprint are all generated, and then ECM is used to try to factor them.
The ECM attempt can be time bounded. I found a few minutes per key worked reasonably well, and gave about a 99% success rate in finding one usable factorization.
As a "nothing up my sleeve" demo, I picked this key here that covers nsa[.]gov (among other domains):

https://t.co/1AITBNXWIv
I was able to find a colliding key with a factorization of 13, 1,091, 15,032,926,429, and a 340 digit prime that won't fit in this tweet.

The attack also worked just fine on my LAN and I was able to pull off a MitM attack.
I supplied a patch to Tasmota to remediate this. My patch adds length prefixes to the RSA key serialization to make it unambigious, and will automatically update the fingerprint so long as the server's key isn't "suspicious".

https://t.co/quyAT5uzw4
I believe my code made it into Tasmota 8.4.0, so if you're running an up to date version you're protected - though I imagine most folks aren't bothering with TLS on their home networks.

I am the sort of person who thinks that running transport mode IPSec at home is a good time.
This was one of the coolest crypto exploits I've ever written.

I published a blog post a couple months ago about constructing multi-prime RSA keys in python, which was part of my attack for this.
I did need to patch OpenSSL to remove the limits on the maximum number of primes it allowed, but that was pretty simple.

I think that wraps this thread.

More from Trading

FREE MINI STOCK MBA
If you wish to learn abt trading,psychology,options,business etc
You can go through this thread.
Other than this I do post videos on my YT channel : -Abhishek Kar & Tradiostation
-Intraday views on FREE telegram : Abhishek Kar Official
RT will be appreciated

1. Threads to learn Options
https://t.co/wabkek43I8

2. https://t.co/OIDenHKdWN

3. Some core rules to investing
https://t.co/37d1pygp7P

4.Summing up 2020 Trading lessons
https://t.co/jSUb1lSGbQ

5.Effects of margin change on


6. Exciting story about a trader who destroyed a Bank
https://t.co/CsEEhIsD3q

7. Some Thought Provoking facts about stock markets
https://t.co/IjxpX5Wx24

8. A dose on Trading and investing


9. Top 5 resources to learn everything about stocks
https://t.co/6KnIySBGIG

10. Some Pro Tips on Trading
https://t.co/EiSGikt7jv

11. Wisdom on stuffs you should not do
https://t.co/bI2dH0XTSS

12. Reasons why you are losing the


13. The DARK side of stock market
https://t.co/qsteGcbquI

14. Stocks where you should NOT invest
https://t.co/2tD5q0K3UQ

15. Lessons from MILLIONAIRE trader
https://t.co/Pec6LmUtGa

16. Lessons from my
๐—ก๐—ถ๐—ณ๐˜๐˜†-๐—•๐—ฎ๐—ป๐—ธ๐—ป๐—ถ๐—ณ๐˜๐˜† ๐—ข๐—ฝ๐˜๐—ถ๐—ผ๐—ป ๐—•๐˜‚๐˜†๐—ถ๐—ป๐—ด ๐—ฆ๐˜๐—ฟ๐—ฎ๐˜๐—ฒ๐—ด๐˜†

Complete Backtest and Indicator link

๐Ÿงต A Thread ๐Ÿงต

๐—ฆ๐—ฒ๐˜๐˜‚๐—ฝ:
๐Ÿ”ธ Monthly Option Buying
๐Ÿ”ธ 50 ema on 3 min timeframe
๐Ÿ”ธ Supertrend 10 , 3
๐Ÿ”ธ Chart : Banknifty , Nifty Futures as we backtested on futures
๐Ÿ”ธ Entry 9:20 to 3:00
๐Ÿ”ธ Max 3 Entries per day
๐Ÿ”ธ Premium nearest to 200 Rs only

[2/18]

Why Monthly Option buying ?
๐Ÿ”ธ Less theta decay compared to weekly options
๐Ÿ”ธ Less Volatility
๐Ÿ”ธ Supertrend and MA Settings
[3/18]


๐Ÿ”ธ Indicator Link
๐Ÿ”ธ Click on the below ๐˜ญ๐˜ช๐˜ฏ๐˜ฌ -> ๐˜ˆ๐˜ฅ๐˜ฅ ๐˜ต๐˜ฐ ๐˜๐˜ข๐˜ท๐˜ฐ๐˜ถ๐˜ณ๐˜ช๐˜ต๐˜ฆ๐˜ด -> ๐˜ˆ๐˜ฅ๐˜ฅ ๐˜ฐ๐˜ฏ ๐˜Š๐˜ฉ๐˜ข๐˜ณ๐˜ต from favourites and start using it !

๐Ÿ”ธ
https://t.co/zVXavqLBto
[4/18]

๐—œ๐—ป๐—ฑ๐—ถ๐—ฐ๐—ฎ๐˜๐—ผ๐—ฟ ๐—ฆ๐—ฒ๐˜๐˜๐—ถ๐—ป๐—ด๐˜€ :
๐Ÿ”ธ Max 6 Trades per day ( Both CE and PE buy)
๐Ÿ”ธ Timings 9:20 am to 3:00 pm
๐Ÿ”ธ Supertrend : 10,3
๐Ÿ”ธ Moving Average 50 ema
[5/18]

You May Also Like

First thread of the year because I have time during MCO. As requested, a thread on the gods and spirits of Malay folk religion. Some are indigenous, some are of Indian origin, some have Islamic


Before I begin, it might be worth explaining the Malay conception of the spirit world. At its deepest level, Malay religious belief is animist. All living beings and even certain objects are said to have a soul. Natural phenomena are either controlled by or personified as spirits

Although these beings had to be respected, not all of them were powerful enough to be considered gods. Offerings would be made to the spirits that had greater influence on human life. Spells and incantations would invoke their


Two known examples of such elemental spirits that had god-like status are Raja Angin (king of the wind) and Mambang Tali Arus (spirit of river currents). There were undoubtedly many more which have been lost to time

Contact with ancient India brought the influence of Hinduism and Buddhism to SEA. What we now call Hinduism similarly developed in India out of native animism and the more formal Vedic tradition. This can be seen in the multitude of sacred animals and location-specific Hindu gods
@franciscodeasis https://t.co/OuQaBRFPu7
Unfortunately the "This work includes the identification of viral sequences in bat samples, and has resulted in the isolation of three bat SARS-related coronaviruses that are now used as reagents to test therapeutics and vaccines." were BEFORE the


chimeric infectious clone grants were there.https://t.co/DAArwFkz6v is in 2017, Rs4231.
https://t.co/UgXygDjYbW is in 2016, RsSHC014 and RsWIV16.
https://t.co/krO69CsJ94 is in 2013, RsWIV1. notice that this is before the beginning of the project

starting in 2016. Also remember that they told about only 3 isolates/live viruses. RsSHC014 is a live infectious clone that is just as alive as those other "Isolates".

P.D. somehow is able to use funds that he have yet recieved yet, and send results and sequences from late 2019 back in time into 2015,2013 and 2016!

https://t.co/4wC7k1Lh54 Ref 3: Why ALL your pangolin samples were PCR negative? to avoid deep sequencing and accidentally reveal Paguma Larvata and Oryctolagus Cuniculus?