Researchers demonstrated that remote timing attacks against OpenSSL could recover long-term private keys from general-purpose servers, overturning the assumption that such side channels were only practical against local devices. One line of work showed that OpenSSL 0.9.7 systems using RSA without blinding—including deployments such as Apache mod_ssl and stunnel—leaked enough information during CRT-based decryption to extract a 1024-bit RSA private key with roughly 1 million to 1.4 million queries in about two hours under typical conditions. The leakage stemmed from timing differences tied to Montgomery extra reductions and the choice between Karatsuba and normal multiplication, and the attack was shown to work across processes, virtual machines, and routed campus networks.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
A 2016 USENIX Security paper introduced CacheBleed, a cache-based side-channel attack affecting OpenSSL RSA implementations on Intel processors. The work showed that fine-grained cache-bank conflicts could leak secret-dependent information and enable recovery of RSA private keys despite constant-time countermeasures.
The 2011 research proposed padding the nonce scalar to a fixed bit length before scalar multiplication to eliminate the timing leak in OpenSSL’s ECDSA implementation. The authors reported that the patch blocked the attack with negligible performance overhead.
Billy Bob Brumley and Nicola Tuveri described a practical remote timing side channel in OpenSSL’s Montgomery ladder implementation for binary-field elliptic curves, where nonce bit-length leakage during ECDSA operations could be measured from TLS handshakes. They showed that an attacker could combine timing data and collected signatures with a lattice attack to recover a server’s long-term ECDSA private key.
David Brumley and Dan Boneh showed that remote timing attacks against OpenSSL 0.9.7 without RSA blinding could recover a 1024-bit RSA private key from general-purpose servers, including Apache mod_ssl and stunnel deployments. Their experiments demonstrated feasibility across local processes, virtual machines, and routed campus networks, with key recovery in roughly two hours using about one million to 1.4 million queries.
Following the RSA timing-attack research, OpenSSL later enabled RSA blinding by default as a mitigation against the disclosed side channel. The papers also note that Mozilla NSS and some hardware crypto accelerators already had effective protections in place.
On 2003-03-17, OpenSSL warned that versions 0.9.7a and 0.9.6i were vulnerable to RSA timing attacks when blinding was not enabled, affecting many SSL/TLS deployments such as Apache mod_ssl. The project released a patch to enable RSA blinding by default, advised users to rebuild and reinstall OpenSSL and dependent applications, and noted the issue as CVE candidate CAN-2003-0147.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
eprint.iacr.org
Open sourceeprint.iacr.org
Open sourcekb.cert.org
Open sourceopenssl.org
Open sourceeprint.iacr.org
Open sourcecryptodeeptech.ru
Open sourcecrypto.stanford.edu
Open sourceusenix.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.