UA-9726592-1
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, October 3, 2011

Cryptome: SSL Was Broken by Design


SSL Was Broken by Design


SSL is not secure

Date: Sat, 01 Oct 2011 08:11:15 -0400
From: William Allen Simpson <william.allen.simpson[at]gmail.com>
To: cryptography[at]randombit.net
Subject: Re: [cryptography] SSL *was* "broken by design"
On 20/09/11 01:53 AM, Andy Steingruebl wrote:
SSH doesn't solve phishing either. Is it a total failure also? I don't think so. SSL is used for a lot more than HTTPS. Any proposal to "fix" it *must* take that into account. - Andy


>  Irrelevant, because SSH at the architectural level and SSH at the protocol level are aligned and in balance. There is no discord because SSH was never really taken out of its intended design framework. That's arguably because the designer wasn't facing the


>political forces of the times, which the designers of SSL drowned in. For whatever reasons, we can skip that and look at the results: SSH was pretty much always used in accordance with its original design-assumptions, whereas SSL was pretty much never used

> in accordance with its original design-assumptions.


On 9/20/11 12:51 PM, ianG wrote:

Actually, SSH faced a lot of the same political pressures as SSL.  SSH didn't cave!  Instead, they carefully did all the work by non-US persons outside the US -- even though that meant some foreign developers of OpenSSH had to drive across the US border into Canada.

Meanwhile, back when Netscape was located near the Stanford campus (an easy walk from  the computing center), Paul Mockapetris got me to visit. I sat down with Taher Elgamal and others, explaining what we were doing with Photuris.

To the best of my memory, we thought it would be better to:

1) Authenticate the list of supported methods/transforms.  We did that in Photuris to avoid MITM attackers choosing the lowest common denominator. And not only the parameters, but the length fields of the parameters, too. [Phil] Karn had insisted on cheap Photuris renegotiation from the start, and that requires protection against substitution.
2) Hide the certificates/users.  We called that "party privacy protection".  We used the initial D-H exchange to create a temporary stream key, and "masked" the data with the stream (simply an MD5 hash).
3) Require Perfect Forward Secrecy.  We'd not managed to get IPsec to do that.  It was a big argument at the time.  Even today, not all TLS suites provide PFS.
4) Authenticate outside of encryption, so we could quickly and cheaply check before doing a more computationally intensive decryption.  We managed to force that into IPsec, and hoped to get Netscape to do the same for SSL (now TLS).  IIRC, that's since been proven to be more secure, but we didn't know it at the time.  We were mostly interested in practicality.

So how was it that Netscape SSL had exactly the same faults as IPsec, ISAKMP, Oakley, IKE?  Political pressure!  Somebody really REALLY wanted to be able track users and intercept/substitute....
Do I have proof?  No, it's merely circumstantial.  Also, my multi-year FBI personal investigation over PPP CHAP was coincidental, too.

Netscape caved, for their commercial interests.  There was also the CA business model.  User's own interests took last place.

So, arguing about ease of use is a waste of time, as long as the easy to use protocol was designed to be broken.  It really is time to start over.

If you are not a tech, you might wonder what this exchange is about. Essentially, it means the government and some astute hackers can break HTTPS which uses SSL for secure transactions. 


These security protocols are used in Virtual Private Networks (VPN) and for credit card transactions. 


Essentially the US government, NSA in particular, insists on a backdoor to all security protocols used on the Internet. 


If you are using a VPN, make sure the provider is in Canada, Sweden, Russia or another country that does not have a reciprocity agreement with the US. This will prevent the police from using a subpoena to get server logs on your Internet activity. 


This will keep the local and state police out of your PC, but not the federal government (Homeland Security/FBI or NSA). However, the Patriot Act allows the federal , state and local government to communicate freely and these organization operate with combined task forces. 


Subscribe to the Rightardia feed: http://feeds.feedburner.com/blogspot/UFPYA   Netcraft rank: 6627 http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com Creative Commons License
Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.
Permissions beyond the scope of this license may be available at rightardia@gmail.com.

Wednesday, July 20, 2011

Home Network Security 101

Your children can get in trouble at both school and home with data networks using both the Internet and cell phones. Many children have got into major problems at school with sexting images over cellphone networks. Kids can also get into a world of hurt on the Internet using peer to peer  (P2P) file sharing networks such as FrostWire and BitTorrent.
Frostwire logo

FrostWire follows a line of Windows P2P software as Morpheus, Grokster, Kazaa and Limewire which ceased operations after being sued by the Motion Picture Association of America (MPAA) or Recording Industry Association of America. (RIAA). Some of these companies  were closed down by the courts and others morphed into legitimate companies.

Limewire was recently closed down in federal court which probably caused crocodile tears in police departments acrsoss the US. Limewire is notorious for pornography. About 30 per cent of the Limewire downloads were porn and a certain per cent of that was illegal porn that pedophiles swap and the police try to find.

Although Limewire is gone, it has been replaced by Frostwire that uses the exact same TCP ports. If your child has Frostwire on their PC, you should be concerned. Frsotwire can also download the faster Torrents.

The police crawl the Gnutella P2P network which provides one of the backbones for P2P file sharing. This means the police can see any P2P files that your child downloads. If your child is continually downloading files, it may be just matter of time before he or she will gets the attention of the police, or the MPAA if your child is downloading copy righted movies

According to Wikipedia, Gnutella is a large peer-to-peer network which, at the time of its creation, was the first decentralized peer-to-peer network of its kind, leading to other, later networks adopting the model. It celebrated a decade of existence on March 14, 2010 and has a user base in the millions for peer-to-peer file sharing.
In June 2005, Gnutella's population was 1.81 million computers and increased to more than three million nodes by January 2006. 

In another article, Rightardia mentioned that file sharing should be disabled for P2P programs like Frostwire. This will prevent the police from crawling your child's file sharing folder. However, if your child is downloading Torrent files, these files have embedded trackers that do not require a shared folder for other P2P users including the police to acquire the file your child had just downloaded.

You can disable ports on your home router or cable modem to disable P2P file sharing and to impede the downlaod of torrents.

You can also block file sharing on your home router or cable modem. Here is the way an SMC firewall is configured to block P2P sharing on the LAN side of a network;

click to enlarge

Rightardia would recommend that you contact you cable provider and have them put the cable modem into bridge mode. Try to get the SMCD3GN cable modem and wireless router replaced if you have one. Brighthouse has disabled many of the advanced feature of this cable modem.

Once your cable modem is in bridge mode he cable company will no longer be able to intrude into your home network, but you will have to configure a firewall and/or wireless router that you now control.

This is necessary because the major cable providers are cooperating with both the MPAA and the RIAA. When Rightardia installed Peerblock software, Wirehead noticed that trackers were showing up on TCP ports that the Brighthouse SMCD3GN firewall should have been blocking.
BrightHouse has crippled the SMCD3GN router 

However, the ports weren't being blocked and the firewall did not allow any TCP ports to be blocked on the incoming WAN side of the network. According to BrightHouse, it is not necessary to block incoming WAN port because all of these ports are already blocked.

Peerblock indicated otherwise after we started a file sharing program. All we can assume is that BrightHouse has opened these TCP ports because it has been co-opted by the MPAA and the RIAA to avoid lawsuits and allow corporate and government trackers into home networks.

Wireless is now a dicey proposition because hackers have been able to break into WPA2 wireless routers that use the Advanced Encryption Standard (AES) encryption. This means wireless routers that are correctly configured are no longer secure. Hackers are using video card graphic processing units (GPU) to break the AES encryption.

In the past, a hacker could sit nearby outside your home with a Pringle can antenna to break into your home's wireless network. They can now break into home with advanced antenna from more than a mile away.

If you aren't using wireless in your home, it is best to disable it.

Subscribe to the Rightardia feed: http://feeds.feedburner.com/blogspot/UFPYA   Netcraft rank: 6627 http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com Creative Commons License
Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.
Permissions beyond the scope of this license may be available at rightardia@gmail.com.

Tuesday, May 3, 2011

Police using Universal Forensic Extraction Device for illegal searches


Multisource political news, world news, and entertainment news analysis by Newsy.com


BY JESSICA HORD

Tech News: Michigan Police Use UFED


Next time you’re pulled over for a moving violation -- you may be asked to hand over your license, registration, insurance, and … cell phone?

It’s all because of a gadget called the Universal Forensic Extraction Device or UFED. The device can capture data such as text messages, photos, and contacts once connected to a cell phone.

But can police use the device without a search warrant?  A legal analyst for WJBK says that would violate a person’s Fourth Amendment rights.

Rightardia first heard about this device on Cryptome. There is both a fixed and mobile version of this device which was initially used by police for forensics and allows technicians to clone a cell phone and copy the GPS data, phone records and operating system of the cell phone.

The police would also be able to monitor any new phone calls to your cell phone as well with this technology.

Do the police have any right to stop you on the highway and ask you for your cell phone? Rightardia suggest they do not without a search warrant. If you hand over you phone, you have surrendered your right to privacy.

Likewise, if the police search your home and have a  search warrant, do not give them any of your computer or network passwords. If you do, you have surrendered your right to privacy.




rhttp://feeds.feedburner.com/blogspot/UFPYA  


Netcraft rank: 5841 http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com
Creative Commons License
Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.

Permissions beyond the scope of this license may be available at rightardia@gmail.com.

Monday, November 22, 2010

SNL: TSA Public Service Announcement



Is the TSA harassing American travellers? The TSA provides its position.

Subscribe to the Rightardia feed: feeds.feedburner.com/blogspot/IGiu 

Netcraft rank: 8515 http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com

Wednesday, November 4, 2009

Ubnuntu 9.10 Security Upgrades

Rigtardia updated its workstations to Ubuntu 9.10 over the weekend. It took about 5 hours per workstation because people all over the world were doing upgrades at the same time which stressed the FTP servers.



However, when Wirehead upgraded his wife's PC at home last Tuesday with Ubuntu 9.10,  it only took about 1 hour and 20 minutes for more than 1200 files to be downloaded and installed.

Today 56 new upgrades, most of which were security related, showed up when Wirehead ran the Update Manager in Administration.

All users are advised to run the Upgrade Manager to check for the Karmic Koala security upgrades. 

Subscribe to the Rightardia feed: feeds.feedburner.com/blogspot/IGiu

Netcraft rank: 5953 http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com

Sunday, August 9, 2009

How to get your kids cell phones and PCs under control

This video provides a great overview of security measures you can implement on your children's cell phones and PCs. It is now easier than ever to monitor cell phones and PCs and your children cannot do much to get around it.


Get 30 days of free traffic analysis simply by going to Web-Stat: http://www.web-stat.com/?id=2955

Subscribe to the Rightardia feed: feeds.feedburner.com/blogspot/IGiu

Improve blog traffic with TrafficG http://trafficg.com/splash/splash01.php?uid=eelder1

Netcraft rank: 19798 http://toolbar.netcraft.com/stats/topsites?s=BE281D838226A4DAC11D0E201A0E#19798