Crypto Implementation Failure

March 4th, 2010 admin

Look at this new AES-encrypted USB memory stick. You enter the key directly into the stick via the keypad, thereby bypassing any eavesdropping software on the computer. The problem is that in order to get full 256-bit entropy in the key, you need to enter 77 decimal digits using the keypad. I can’t imagine anyone doing that; they’ll enter an…


Originally posted on Schneier

 
  Related Posts
Generations Of Communications and How They Influence Business and Products
Part 1: One of the reasons I enjoy creating software is that I’m fascinated by researching and understanding users of the technology we create. I sometimes refer to myself as a software anthropologist. That’s part of why I also enjoy user interface design. So, enough about me… lets get on to the topic. Over time, I’ve noticed... 
Crypto Comic Book
I have no idea….  Read More →
Cryptography Failure Story
By Russian spies: Ricci said the steganographic program was activated by pressing control-alt-E and then typing in a 27-character password, which the FBI found written down on a piece of paper during one of its searches….  Read More →
German TV on the Failure of Full-Body Scanners
The video is worth watching, even if you don’t speak German. The scanner caught a subject’s cell phone and Swiss Army knife — and the microphone he was wearing — but missed all the components to make a bomb that he hid on his body. Admittedly, he only faced the scanner from the front and not from the side. But…  Read More →
Online Credit/Debit Card Security Failure
Ross Anderson reports: Online transactions with credit cards or debit cards are increasingly verified using the 3D Secure system, which is branded as “Verified by VISA” and “MasterCard SecureCode”. This is now the most widely-used single sign-on scheme ever, with over 200 million cardholders registered. It’s getting hard... 
Review of Crypto Posted
Review of Crypto Posted
Amazon.com just posted my four star review of Crypto by Steven Levy. From the review : Steven Levy’s “Crypto” is a fascinating look at part of the story of modern cryptography, at least from the point of view of key non-government cryptographers. The author clearly conducted plenty of research into the lives of certain individuals,... 
Report: Google Hackers Stole Source Code of Global Password System
The hackers who breached Google’s network last year were able to nab the source code for the company’s global password system, according to The New York Times . The single sign-on password system, which Google referred to internally as “Gaia,” allows users to log into a constellation of services the company offers —... 
Software Liabilities in the UK
The British High Court ruled that a software vendor’s EULA — which denied all liability for poor software — was not reasonable. I wrote about software liabilities back in 2003….  Read More →
Google Launches Encrypted Search
Google Launches Encrypted Search
Google users can now run encrypted searches using the company’s flagship search site simply by navigating to https://www.google.com . UPDATE: Many users are being redirected to the non-encrypted main site — a function of Google rolling this out to all its servers. Also it is necessary to include WWW. Don’t assume your searches... 
WikiLeaks Posts Mysterious ‘Insurance’ File
WikiLeaks Posts Mysterious ‘Insurance’ File
In the wake of strong U.S. government statements condemning WikiLeaks’ recent publishing of 77,000 Afghan War documents, the secret-spilling site has posted a mysterious encrypted file labeled “insurance.” The huge file, posted on the Afghan War page at the WikiLeaks site, is 1.4 GB and is encrypted with AES256. The file’s... 
  Related Tweets from Twitter
re5et (re5et)  : aaaahahhaah http://www.schneier.com/blog/archives/2010/07/pork-filled_cou.html..
Updated : 2010-07-31T05:27:10Z   |  Reply  |  View Tweet
technomancy (Phil Hagelberg)  : Pork bomb! http://www.schneier.com/blog/archives/2010/07/pork-filled_cou.html..
Updated : 2010-07-31T05:24:34Z   |  Reply  |  View Tweet
wood_lam (wood lam)  : Schneier has a post about WikiLeaks: http://www.schneier.com/blog/archives/2010/06/wikileaks.html..
Updated : 2010-07-31T04:17:48Z   |  Reply  |  View Tweet
lifeasdaddy (Bob Meade)  : Powers that be want you to have smart electricity meters in your house. But what about the devastating security hole? http://bit.ly/c2iqfn..
Updated : 2010-07-31T01:44:48Z   |  Reply  |  View Tweet
sambowne (Sam Bowne)  : @mrdomino @sciencequiche SHA-1 collisions have been found http://tinyurl.com/4bmcc..
Updated : 2010-07-31T01:24:18Z   |  Reply  |  View Tweet
  Related News from Digg
No comments yet.
You must be logged in to post a comment.
TOP