{"id":11969,"date":"2020-01-15T12:08:16","date_gmt":"2020-01-15T17:08:16","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=11969"},"modified":"2020-11-03T10:11:43","modified_gmt":"2020-11-03T15:11:43","slug":"how-secure-is-rsa-in-an-increasingly-connected-world","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/how-secure-is-rsa-in-an-increasingly-connected-world\/","title":{"rendered":"How Secure is RSA in an Increasingly Connected World?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">KeyFactor\u2019s latest study shows that many IoT device manufacturers are\ngenerating insecure RSA keys<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">1 in 172. That\u2019s the number of RSA public key certificates\navailable through the internet that could be vulnerable to compromise due to\nshared cryptographic key factors. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These findings are according to a <a href=\"https:\/\/info.keyfactor.com\/factoring-rsa-keys-in-the-iot-era\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">recent report<\/a> on RSA certificate vulnerability from KeyFactor, a leading provider of secure digital identity management solutions and an established authority in the cybersecurity industry. A team of KeyFactor researchers presented their findings at the First IEEE Conference on Trust, Privacy, and Security in Intelligent Systems and Applications in December. The data indicates that due to improper random number generation, many RSA public keys are at risk of compromise because the researchers were able to use them to derive their private keys through a method known as \u201cfactoring.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Essentially, the research indicates that RSA is still\nsecure, but many companies are implementing it in insecure ways. As such, it underscores\nthe importance of organizations and manufacturers being \u201ccrypto agile\u201d and\nadhering to cryptographic best practices to maintain trust and security. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But just how big of a potential impact would compromising RSA keys have? While there\u2019s no single reliable resource we can point you to that shows <em>X% of certificates issued use RSA keys<\/em>, what we can tell you as a company that sells a lot of them is that it\u2019s a lot. Considering that Gartner forecasts that there will be <a href=\"https:\/\/www.thesslstore.com\/blog\/20-surprising-iot-statistics-you-dont-already-know\/\">25 billion IoT devices in use by 2021<\/a>, that\u2019s potentially a lot of vulnerable RSA certificate keys in the wild that cybercriminals could exploit. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we\u2019ll break down the data from the study,\nrehash what RSA is, and explore the implications of what the research means for\nyour organization. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Secure is RSA? Breaking Down the KeyFactor Research Data<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/kyf-logo-corporate-color.png\" alt=\"KeyFactor logo graphic\" class=\"wp-image-11970\" width=\"418\" height=\"62\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/kyf-logo-corporate-color.png 888w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/kyf-logo-corporate-color-300x45.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/kyf-logo-corporate-color-768x114.png 768w\" sizes=\"auto, (max-width: 418px) 100vw, 418px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.keyfactor.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">KeyFactor<\/a>, a company we work with at The SSL Store, has made a name for itself as an IoT device security leader in the industry since the company\u2019s inception in 2001. A force to be reckoned with, they\u2019re dedicated to empowering enterprises of all sizes through their award-winning PKI-as-a-service platform. They\u2019re also known for their research collaborations with other respected organizations such as <a href=\"https:\/\/www.ponemon.org\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">The Ponemon Institute<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This particular report on RSA certificate vulnerabilites,\nwritten by JD Kilgallin, states that the company collected and analyzed 175\nmillion RSA certificate public keys \u2014 75 million they discovered on the\ninternet, plus 100 million that were available through certificate transparency\n(CT) logs. They used a single Microsoft Azure cloud-hosted virtual machine and a\ngreatest common divisor (GCD) algorithm for shared factors to conduct their analysis.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s what they discovered:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Large numbers of RSA public keys can be\ncollected through multiple sources and mined for common key factors.<\/li><li>1 in 172 certificates use keys that share a key\nfactor with other certificates. <\/li><li>They were able to crack nearly 250,000 distinct\nkeys that correspond with 435,694 digital certificates.<\/li><li>At least 435,000 weak certificate keys are\nvulnerable to \u201cfactoring\u201d cyberattacks that exploit a key-related vulnerability.\n<\/li><li>The majority of the vulnerable certificates were\nfound on emerging IoT devices and network appliances.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The big takeaway here is that some IoT device manufacturers\nare using random number generators that lack strong entropy. It\u2019s more a matter\nof operator error than an actual weakness in the RSA algorithm itself. As a\nresult of using random number generators (RNGs) with low entropy, they\u2019re\ngenerating prime numbers with poor randomness, which leads to the generation of\nprivate keys that can be compromised more easily. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what does this mean in terms of information security? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kilgallin cautions the following:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>In 2019, with the large number of devices on the Internet and in other data sets like Certificate Transparency (CT) logs,<\/em>\u00a0<em>this attack presents a serious threat if proper precautions are not in place. As the number of keys grows, it is more likely that weakly generated factors in RSA public keys will be discovered. Coupled with the availability of cheap computing resources and sensitivity of communications, the attack is as potent as ever.\u201d<\/em><\/p><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">How Factoring Factors into RSA Key Vulnerabilities<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">At the most basic level, RSA public keys are the result of two large, randomly generated prime factors. They\u2019re created using random number generators. This means that the entire <a href=\"https:\/\/www.thesslstore.com\/blog\/is-it-still-safe-to-use-rsa-encryption\/\">security premise of the RSA algorithm<\/a> is based on using prime factorization as a method of one way encryption. So, in other words, it\u2019s operating under the assumption that no one can determine two randomly-generated prime numbers within a reasonable amount of time \u2014 that no one can crack the encryption of an SSL\/TLS certificate until long after it\u2019s replaced or expired. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Well, considering that it took a <a href=\"https:\/\/eprint.iacr.org\/2010\/006.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">group of researchers<\/a> more than 1,500 years of computing time (across hundreds of computers) to factor a 232-digit algorithm, that assumption seems plausible. But in reality, RSA is sometimes not as secure as we\u2019d like it to be. It\u2019s not that RSA itself is insecure \u2014 it\u2019s that some companies implement it in a weak way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s because some random number generators aren\u2019t really\nthat random. Furthermore, considering that the same RNGs are frequently used\ntime and again, it reduces their effectiveness. If RSA public keys are generated\nwith poor randomness, it means they could be vulnerable to a factoring\ncyberattack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this type of attack, cybercriminals collect large sums of\npublic keys from the internet and analyze them to determine whether any two\nshare the same factor. If two RSA moduli share one prime factor, it could\nresult in a collision when applied to a large dataset. What this does is allow\nthe actor to crack the corresponding private key. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All of this leads to this concern: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>As the number of keys grows, it is more likely that weakly generated factors in RSA public keys will be discovered. Coupled with the availability of cheap computing resources and sensitivity of communications, the attack is as potent as ever.\u201d<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Yikes. But there is a bit of light at the end of the tunnel.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why You Should Use CA-Issued Certificates Instead of Non-Trusted\nCertificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">According to the report concerning the factoring attacks, \u201conly 5 of 100\nmillion certificates found in a sample from Certificate Transparency logs are\ncompromised by the same technique.\u201d What this means is that only the five\ncompromised certificates found in CT logs were publicly-trusted (and no longer\nin use online) \u2014 the rest were \u201cself-signed, privately-rooted, or device\ncertificates.\u201d But, still, that\u2019s five too many for our taste.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve talked about the <a href=\"https:\/\/www.thesslstore.com\/blog\/risks-of-using-self-signed-certificates\/\">risks of using self-signed certificates<\/a> in external-facing applications in the past. It\u2019s one thing to use them on intranets and internal-facing applications; it\u2019s another to use them to secure sites or devices that are discoverable via the internet. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The\ndiscrepancy between the number of CA-signed certificates that were compromised\nand the others, the researchers say, is likely due to IoT devices being more\neasily accessible on the internet and by the design constraints and entropy\nlimitations of power-restricted devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the\nreport, Kilgallin says:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>These concerning findings highlight the need for device manufacturers, website and network administrators, and the public at large to consider security, and especially secure random number generation, as a paramount requirement of any connected system.\u201d<\/em><\/p><\/blockquote>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<p class=\"wp-block-paragraph\">We keep talking\nabout RSA encryption, RSA algorithms, and RSA keys. But what exactly is RSA\nitself? Let\u2019s take a moment for a brief review for those of us who aren\u2019t as\nfamiliar with this type of cryptography.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A Quick RSA Refresher<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">RSA, named after the MIT cryptographers who created it (Ron\nRivest, Adi Shamir, and Leonard Adleman), is one of the two most popular public\nkey encryption algorithms in use today. In SSL\/TLS, it can be used for digital\nsignatures and key exchange to establish a secure, encrypted communication\nchannel. This way, you don\u2019t leave your sensitive data at risk by transmitting\nit through a non-secure channel. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The RSA algorithm is comprised of four essential components:\n<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>key generation<\/li><li>key distribution<\/li><li>encryption<\/li><li>decryption<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em>But, wait, we\u2019re talking about the RSA algorithm. I\nthought we were supposed to be talking about RSA encryption keys?<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We are\u2026 in a roundabout sort of way. RSA refers to both a\nsignature algorithm (a cryptographic operation) and an encryption key pair. The\nRSA algorithm is used to generate an RSA key pair that includes both private\nand public keys. The first generates digital signatures, whereas the second\nverifies those created signatures. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But when we talk about an encryption key, what do we really\nmean?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What Is an Encryption Key?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A cryptographic key, in a nutshell, is a string of\nrandomly-ordered bits (binary digits) \u2014 meaning a gargantuan string of hundreds\nor even thousands of 1s and 0s. Keys are integral to modern day public key\ninfrastructure (PKI) and encryption as a whole. Keys in cryptography are like the\nrice to your sushi or the cream filling for your Oreo cookies \u2014 they\u2019re\nessential components. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the olden days (you know, before modern technology), a\nkey was the secret roadmap, if you will, of an encryption technique. It\u2019s what\nthe sender would use to encrypt the message, and the recipient would use to\ndecrypt the message. It\u2019s much the same today, but instead of using hand-written\nkeys that are written in invisible ink or hidden away, they\u2019re digital bits of\ninformation that are transmitted electronically.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A key can be either <a href=\"https:\/\/www.thesslstore.com\/blog\/difference-asymmetric-encryption-algorithms-vs-symmetric-encryption-algorithms\/\">asymmetric or symmetric<\/a>. RSA keys are asymmetric. Every asymmetric key comes in a pair of mathematically-related but different public and private keys, and each key serves as different purpose \u2014 to encrypt (public key) and to decrypt (private key) data, as well as to create a shared key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a certificate\u2019s RSA public key that was generated with\nweak entropy is targeted through a factoring attack, then its shared prime\nnumbers could be used to derive the certificate\u2019s private key, making RSA\nessentially useless.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But, thankfully, RSA isn\u2019t the only hitter in the game. There\u2019s\nanother type of key that we haven\u2019t mentioned yet \u2014 ECC. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why ECC Needs to Take on a Bigger Role in PKI<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/elliptic-curve-crypt-image00.png\" alt=\"Graphic: An illustration of an elliptic curve\" class=\"wp-image-9675\" width=\"332\" height=\"333\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/elliptic-curve-crypt-image00.png 409w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/elliptic-curve-crypt-image00-300x300.png 300w\" sizes=\"auto, (max-width: 332px) 100vw, 332px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">ECC, or <a href=\"https:\/\/www.thesslstore.com\/blog\/you-should-be-using-ecc-for-your-ssl-tls-certificates\/\">elliptic curve cryptography<\/a>, is an approach to cryptography that offers greater security and performance than RSA. That\u2019s because it doesn\u2019t rely on random number generation. Instead of RNG, ECC takes advantage of the math behind elliptic curves. If you don\u2019t know what I\u2019m talking about, think back to your school days and the joys of plotting using coordinates on the Y- and X- axes (yeah, that\u2019s still a thing of nightmares for me, too). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I won\u2019t get into the actual calculations of elliptic curves\nhere \u2014 you can read more about that in one of our other <a href=\"https:\/\/www.thesslstore.com\/blog\/you-should-be-using-ecc-for-your-ssl-tls-certificates\/\">blog\nposts on ECC<\/a>. But the point here is that it\u2019s a public key cryptosystem\nthat relies on mathematical calculations based on specific points on an\nelliptic curve rather than a random number generator that could fail. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another benefit of ECC over RSA is that ECC scales well. That\u2019s\nbecause its keys are smaller, which results in less computational overhead and\nbetter performance. <\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"\"><tbody><tr><td>\n  RSA Key Size\n  (Measured in Bits)\n  <\/td><td>\n  ECC Key Size\n  (Measured in Bits)\n  <\/td><\/tr><tr><td>\n  1024\n  <\/td><td>\n  160\n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/www.thesslstore.com\/blog\/generate-2048-bit-csr\/\">2048<\/a> (standard)\n  <\/td><td>\n  224\n  <\/td><\/tr><tr><td>\n  3072\n  <\/td><td>\n  256\n  <\/td><\/tr><tr><td>\n  7680\n  <\/td><td>\n  384\n  <\/td><\/tr><tr><td>\n  15360\n  <\/td><td>\n  521\n  <\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">See what I mean? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A third advantage ECC has over RSA is that there\u2019s a variation of it \u2014 supersingular elliptic curve isogeny cryptography \u2014 that\u2019s also less vulnerable to concerns that stem from quantum computing. The <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2016\/NIST.IR.8105.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">National Institute of Standards and Technology<\/a> (NIST) predicts that the public key cryptography we know and use today will fail once quantum computing becomes mainstream. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the <a href=\"https:\/\/www.thesslstore.com\/blog\/post-quantum-cryptography-10-things-you-need-to-know\/\">impact of quantum computing on existing cryptosystems<\/a> is a whole \u2018nother conversation in and of itself. And don\u2019t worry, the sky isn\u2019t falling \u2014 CAs are ahead of the curve in developing new cryptographic methods that will be quantum secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The drawback of ECC is that it isn\u2019t frequently used because\nit\u2019s not as widely supported as RSA. While it\u2019s supported by most modern\noperating systems and web browsers \u2014 including Chrome, Safari, Firefox, and IE\n\u2014 ECC isn\u2019t yet supported by a lot of the web hosting control panels (such as cPanel)\nas of yet. Unfortunately, this means that many website owners can\u2019t yet use ECC\neven if they want to. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Does All of This Mean for Your Organization?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Overall, the KeyFactor research showcases how weak some RSA\nkeys are that are currently in use across the internet. It also drives home the\npoint that organizations and device manufacturers in particular need to do more\nto protect the consumers who trust them to protect their sensitive or\nconfidential information and privacy. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What this means for device manufacturers is that they need\nto: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Ensure that their devices have access to\nsufficient entropy. <\/li><li>Adhere to cryptography best practices. <\/li><li>Be more crypto-agile in their approach to IoT\nsecurity.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">KeyFactor researchers define crypto agility as \u201cknowing\neverywhere cryptography is used across your organization (i.e. certificates,\nalgorithms, protocols, and libraries), and being able to quickly identify and\nremediate vulnerabilities, without disruption.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To be crypto agile, you need to stay abreast of compromises\nand breaches in security and also try to stay one step ahead of cybercriminals.\nYou also need to be responsive to changes. In IoT device security, that means\nyou need to be able to maintain trust by keeping your devices secure throughout\ntheir lifecycles. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In PKI, it in part boils down to using automated <a href=\"https:\/\/www.thesslstore.com\/partner\/comodo-certificate-management.aspx\">certificate management solutions<\/a>. A reliable certificate management solution provides visibility into your network and helps you to easily track, monitor, and renew your certificates to avoid certificate outages. Throw away the spreadsheets and get rid of your manual tracking processes \u2014 automation is the name of the game. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TL;DR<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So, let us take a moment to summarize everything we\u2019ve\nreally touched on in this article. KeyFactor research shows that:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>RSA is secure, but it\u2019s being implemented\ninsecurely in many cases by IoT manufacturers.<\/li><li>More than 1 in every 172 RSA keys are at risk of\ncompromise due to factoring attacks. <\/li><li>ECC is a more secure alternative to RSA because:<ul><li>ECC keys are smaller yet more secure than RSA\nbecause they don\u2019t rely on RNGs.<\/li><\/ul><ul><li>ECC scales well due to its lower computational\noverhead.<\/li><\/ul><ul><li>ECC is more resistant to quantum computing.<\/li><\/ul><ul><li>ECC is widely supported by all the major OS and\nbrowsers.<\/li><\/ul><\/li><li>Organizations and IoT device manufacturers alike\nneed to be more crypto agile in their approach to security. <\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>KeyFactor\u2019s latest study shows that many IoT device manufacturers are generating insecure RSA keys 1 in 172. That\u2019s the number of RSA public key certificates available through the internet that&#8230;<\/p>\n","protected":false},"author":17,"featured_media":11977,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130,10200],"tags":[3802,9431],"class_list":["post-11969","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","category-monthly-digest","tag-iot","tag-rsa","post-with-tags"],"views":35487,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/rsa-encryption.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11969","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=11969"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11969\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/11977"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=11969"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=11969"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=11969"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}