Cryptography

共 37 篇文章。

不安全的原因

• Security

我们来看看那个人说的这段话:

I’d be really surprised if somebody is actually able to get a real-world attack on a real-world pgp key usage or similar out of it (and as to the covert channel, nobody cares). It’s a fairly interesting approach, but it’s certainly neither new nor HT-specific, or necessarily seem all that worrying in real life.(HT and modern CPU speeds just means that the covert channel is _faster_ than it has been before, since you can test the L1 at core speeds. I doubt it helps the key attack much, though, since faster in that case cuts both ways: the speed of testing the cache eviction may have gone up, but so has the speed of the operation you’re trying to follow, and you’d likely have a really hard time trying to catch things in real life).

It does show that if you want to hide key operations, you want to be careful. I don’t think HT is at fault per se.

阅读全文… ( 本文约 821 字,阅读大致需要 2 分钟 )

Aha... MD5 is vulnerable

• Security

Researchers have announced preliminary indications of previously unknown vulnerabilities in popular security algorithms that could permit hackers to easily install undetectable back doors into computer code or to counterfeit electronic signatures. French computer scientist Antoine Joux reported on Aug. 12 his discovery of a flaw in the MD5 algorithm, which is often used with digital signatures. The algorithm is known as a hash function, which extrapolates from all input a unique fingerprint; however, if a hacker could produce the same fingerprint with a different input stream, then the resulting hash collision would authenticate software as safe to download and execute even though it contains a back door. MD5 is employed by the open-source Apache Web server product as well as Sun Microsystems’ Solaris Fingerprint Database, and the flaw Joux uncovered means that a hacker can produce one hash collision in a few hours on a standard PC. Meanwhile, four Chinese researchers issued a paper reporting that the SHA-0 Secure Hash Algorithm could be subverted, while Israel Institute of Technology researchers Eli Biham and Rafi Chen revealed at the Crypto 2000 conference on Aug. 17 that they were investigating possible flaws in the SHA-1 algorithm, the only signing algorithm approved for use in the U.S. Digital Signature Standard. SHA-1, which is incorporated into popular programs such as SSL and PGP, is thought to be secure because knowingly producing hash collisions via existing methods is impossible. SHA-1 depends on a computer executing a routine 80 times as it tries to create a unique fingerprint, and Biham declared that he was able to copy the fingerprint for 36 of those 80 executions. If SHA-1 shares similar vulnerabilities with SHA-0, then attempts to falsify a fingerprint would be sped up about 500-fold.

阅读全文… ( 本文约 293 字,阅读大致需要 2 分钟 )

Is it practical to trust my mail system?

• Security

Yesterday someone has asked me about my diary system, I told her that my diary is managed by my own diary software, which is a close-source system (written in C#) and I do not want to share it with others because it is technically not a friendly one.

阅读全文… ( 本文约 180 字,阅读大致需要 1 分钟 )

P2P: 挟天下以令天子……

• Distributed Computing

选择P2P作为毕业设计的题目应该不是一个偶然,可以说,这个想法从大二就在酝酿,到了四年级,终于得以实现,不能不说是一大快事。

说到P2P,古人说,挟天子以令诸侯,然而,我一直怀疑,一个连自己都罩不住的天子,明明都被人「挟」了,如何得以号令天下?如果说他能罩得住自己,那么,连他都能「挟」了的人为什么不自己称王呢?总之,我一直觉得,挟天子以令诸侯这类事儿属于子虚乌有,多半是文人墨客笔下的夸张吧。

阅读全文… ( 本文约 490 字,阅读大致需要 1 分钟 )

Theo de Raddt requests cryptotest.c to be removed

• Security

Theo de Raddt has pointed out that the /dev/crypto testing program in FreeBSD, like in NetBSD, was derived from a test program which he never published with a free license. It has now been deleted from the NetBSD tree as well.

阅读全文… ( 本文约 267 字,阅读大致需要 2 分钟 )