UA-9726592-1
Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Saturday, June 2, 2012

Blackberry Playbook review

Wirehead's son wanted a bigger tablet. He had been using an IPad for about two years but wanted a larger unit.

The Samsung Genesis one of the better units but it is pricey. Most of the tabelts are 7 and 10 inch models and sometimes a 9 inch.

A lot of the units use Android 4.0 also called Ice Cream Sandwich.


The current tablet processor is a CORTEX A10 which has 1.5 GHz CPU. Many units have internal RAM for the OS and external SD RAM for storage.

Every unit we looked at used an 802.11B/G/N wireless connection. Some units also offer Blue Tooth and have both an audio and USB port.

The 7 inch model will be large enough for most people. Rightardia looked at a lot of tablet reviews and narrowed our search down to Le Pan and Coby because the even the 10 inch models were around $200. the amazon user reviews were four star on both models


After all of that research, Wirehead's son bought a Blackberry Playbook. OS2.0 that uses the RIM OS built by recently acquired QNX.


RIM intends to also offer 3G and 4G models in the future. 


Everything worked but the wireless. Rightrdia's  wireess router was set for G/N mixed mode with AES/TKIP eycryption enabled. The router was also configured for WPA-2 pre-shared key (PSK).


After two or three hours of experimentation and reading Blackberry forums on the "wireless problem" we got the wireless connection to work flawlessly.


The biggest problem was playing YouTube videos. The videos would often time-out and the wireless connection was bursty according to ping tests.

Here's how we fixed the Playbook wireless:
  • Use the older 802.11G protocal
  • set AES encryption only.
We cannot understate the importance of using WPA-2. Do not use the older WEP or WPA protocols. Only WPA-2 is secure. If you want to keep the government out of your network, use a 16-digit password which will take years to break. 

At minimum use  12-digit password that uses a mix of both upper case and lower case letters, numbers and special characters

See http://www.engadget.com/2010/09/27/rim-introduces-playbook-the-blackberry-tablet/

Subscribe to the Rightardia feed: http://feeds.feedburner.com/blogspot/UFPYA

Creative Commons License


Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.

Permissions beyond the scope of this license may be available at rightardia@gmail.com.

Saturday, January 7, 2012

Did the RBN break RSA encryption to steal the RQ-170 drone?


Rightardia noticed this email posted on Cryptome today.

Date: Thu, 05 Jan 2012 16:35:31 -0800
From: "J. Oquendo" <joquendo[at]e-fensive.net>
Subject: RSA - Hackers and Predator Drones


A few months ago, I did a down and dirty reverse analysis of the RSA compromise and posted a video of it. In my video, after dissecting, scouring through many lists (some private) that deal with malicious networks (think lists like Shadowserve, BadIP.info, etc), I concluded that the RSA attack was somehow connected more to the "Russian Business Network" than to China. Many scoffed at it. Lo and behold, the predator drone incident...

http://www.infiltrated.net/rsa-comp-analysis/ (My original RSA reverse malware analysis)

Quoting from Cryptome's iran-rsa-cipher.htm:
"There was a report today that the Russians helped Iran intercept the drone:

http://www.intelligenceonline.com/north-america/government-intelligence

The Russian claim could be a cover-up of an RSA decrypt"

More from Cryptome:

"Have you heard anything additional about Iran's spoofing of GPS to misdirect the stealth drone to land it where they wanted?

Military-band GPS (M-code) is protected against spoofing by the RSA cipher.

In admitting that they spoofed military GPS are they admitting to the world that they've cracked RSA?

ComodoHacker claimed he had also broken into EMC's RSA servers, and he claimed to be in pursuit of a cryptanalytic attack against RSA.

Just wondering if you'd heard anybody else mention RSA in regards to Iran's GPS spoofing.

If they really did spoof GPS to misdirect the drone they would have had to have broken red-key mode M-code GPS, which is the military GPS signal used in classified hardware (black-key mode is used in unclassified hardware).


They could have done this in two ways: 
  1. by fast-factoring large semiprimes that are the basis of RSA
  2.  by stealing the secret red key.
If the Russians have access to Red key M-code GPS data, this has other implications. M-code GPS data can be used for accurate targeting of battlefield or even military or government installations in the US.

Donate for the Cryptome archive of files from June 1996 to the present 

--
Subscribe to the Rightardia feed: http://feeds.feedburner.com/blogspot/UFPYA  

Creative Commons License
Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.

Permissions beyond the scope of this license may be available at rightardia@gmail.com.

Cryotlogon: Which Encryption Software Do I Use?


Reader Question: Which Encryption Software Do I Use?
A Cryptlogon reader recently asked about the encryption software: 
For full disk encryption, I use TrueCrypt. Whether or not you believe that TrueCrypt can protect your data from all attackers, when used properly, it can definitely protect your data from attackers that you are likely to encounter; for example, your children, thieves, your local and national police forces, etc.
For more about Truecrypt, see http://en.wikipedia.org/wiki/TrueCrypt
For email, I use the outstanding Enigmail frontend to GPG, which is fully integrated with Thunderbird.
I’m not going to get into the of the ifs-ands-and-buts related to this, but let it suffice to say that there are many. In general, though, it’s like I said above: If the attacker is the kid down the street or the pigs, this stuff can make your data relatively secure.

In a related story form Wired: 
Federal prosecutors want a judge to order a Colorado woman to provide the password to decrypt her laptop. The government seized the laptop with a search warrant, but is unable to break the encryption.

With backup from a digital rights groups, the woman is arguing that being forced to provide her password violates the Fifth Amendment’s protection against forced self-incrimination.

Rightardia hopes that the woman prevails in court. We cannot think of a legal basis for the government to force you to reveal your password.

If the police come into your home or business with a search warrant, they will tell you that your cooperation will limit the time of their stay.

Eventually they will ask you for your passwords. Rightardia's advice is to remain silent. Any information you provide to the police will be used against you.

Most attorneys would give you the same advice.



Subscribe to the Rightardia feed: http://feeds.feedburner.com/blogspot/UFPYA   

Creative Commons License


Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.
Permissions beyond the scope of this license may be available at rightardia@gmail.com.