<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>uncompiled.com &#187; Math</title>
	<atom:link href="http://www.uncompiled.com/category/math/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uncompiled.com</link>
	<description>Technology News That You Need</description>
	<lastBuildDate>Fri, 30 Jul 2010 01:19:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Send Secure Info Over the Internet</title>
		<link>http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/</link>
		<comments>http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 13:42:03 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Math]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1009</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Michael Spector (and yes, he&#8217;s my brother) asked how to safely email passwords, account numbers, and other sensitive information.</p>
<p>You can&#8217;t trust Internet email with potentially compromising information, such as your credit card or account numbers, social security numbers, or important passwords. As your message moves from one server to another, several people have the opportunity to read it.</p>
<p>o what should you do when you have to get sensitive information to someone, and snailmail just isn&#8217;t fast enough? I&#8217;ll give you several solutions.</p>
<p>Whatever option you pick, see What Is the Best Way to Create Strong Passwords? And if you have to share the password with the recipient, use the phone&#8211;just to be safe.</p>
<p>Public/Private Key Encryption: This elegant solution is supported by several programs, including Outlook 2007. The public key can encrypt but not decrypt, so you can safely share it with anyone. You keep the private key, which does the decrypting, to yourself.</p>
<p>Unfortunately, both the sender and the recipient must set up this type of encryption, and it&#8217;s not easy for the less technically inclined. That makes this a good choice in a business environment where everyone has an IT department, but not for occasional, personal communication.</p>
<p>Password-Protected .Zip Files: Depending on what software you use to create compressed .zip archives, you may or may not have an option to password-protect the files inside it. And that option may or may not support high-quality AES encryption.</p>
<p>And don&#8217;t go this route if it doesn&#8217;t support AES. The .zip format&#8217;s standard password protection is easy to hack.</p>
<p>Luckily, many third-party .zip programs support AES encryption, and they&#8217;re compatible with each other. These include industry leader WinZip, and the free, open-source 7-Zip. Whatever program you use, make sure you pick the AES option when you compress and encrypt your files.</p>
<p>Unfortunately, Windows&#8217; built-in .zip tool doesn&#8217;t support AES, so you can&#8217;t simply assume that your recipient will be able to open your archive. If they don&#8217;t have a compression program that supports AES .zips, don&#8217;t want to install one, or don&#8217;t know what you&#8217;re talking about, this isn&#8217;t your option.</p>
<p>Secure Message and File-Sending Services: You don&#8217;t have to actually email your private information. You can upload it to a secure web site, and let the recipient download.</p>
<p>I&#8217;m recommending one service in particular: Send. (the period is part of the company name). It&#8217;s free, and you don&#8217;t even have to share your password with the recipient. Each person has their own private password.</p>
<p>When you post a message on Send., the site emails a notice to the recipient, who will need their own free Send. account to access your message.</p>
<p>There&#8217;s a slight chance that a criminal will intercept that first email and create the account before the legitimate recipient does. To avoid this, send an initial message with nothing confidential in it. That way, the recipient will be safely signed up, with their own, hopefully strong password, before you send them something important.</p>
<p><a href="http://www.networkworld.com/news/2010/041210-send-secure-info-over-the.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;n=Send+Secure+Info+Over+the+Internet&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;t=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet&amp;srcUrl=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;srcTitle=Send+Secure+Info+Over+the+Internet&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Send%20Secure%20Info%20Over%20the%20Internet%22&amp;body=Link: http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;t=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Send+Secure+Info+Over+the+Internet+-+http://b2l.me/pb6sr&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;submitHeadline=Send+Secure+Info+Over+the+Internet&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Send+Secure+Info+Over+the+Internet&amp;body=Link: http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Medical records secured by code-changing algorithm</title>
		<link>http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/</link>
		<comments>http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 13:40:15 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Financial]]></category>
		<category><![CDATA[Math]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1007</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Medical records databases are a treasure trove for researchers &#8211; mapping trends in diseases and studying them to discover better treatment methods has never been easier. </p>
<p>Information that was previously available to a restricted number of researchers is now digital and accessible to many, making the issue of patient privacy prominent in discussions regarding the handling of these records.</p>
<p>Electronic medical records consist of very detailed patient data, where every disease, symptom or injury has its own code, which makes analysis easier and faster. But, the problem is that these codes are available through public databases and electronic medical records, and with this knowledge, this anonymized data can be still tied to the persons to whom it belongs.</p>
<p>To prove that this is a realistic problem, a research team form the Vanderbilt University in Nashville has conducted an experiment which resulted in 96 percent of the 2,762 patients belonging to the test group identified through diagnosis codes.</p>
<p>Scientific American reports that &#8211; as a solution to this problem &#8211; they introduced an algorithm that generalizes clinical information, but doesn&#8217;t interfere with the medical and genetic inter-data connections needed for research. The algorithm exchanges the publicly known ICD codes with an other code system. </p>
<p>They tested it by simulating a hacker attack, with the premise that the hacker is privy to the patients&#8217; identity, their ICD codes and the fact that the patients&#8217; data is included in the database. The test was completely successful &#8211; the hacker couldn&#8217;t uncover the patient&#8217;s private information, and the information remained useful for research.</p>
<p><a href="http://www.net-security.org/secworld.php?id=9128">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;n=Medical+records+secured+by+code-changing+algorithm&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;t=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm&amp;srcUrl=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;srcTitle=Medical+records+secured+by+code-changing+algorithm&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Medical%20records%20secured%20by%20code-changing%20algorithm%22&amp;body=Link: http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;t=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Medical+records+secured+by+code-changing+algorithm+-+http://b2l.me/pb6fs&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;submitHeadline=Medical+records+secured+by+code-changing+algorithm&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Medical+records+secured+by+code-changing+algorithm&amp;body=Link: http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weak RNG in PHP session ID generation leads to session hijacking</title>
		<link>http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/</link>
		<comments>http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 19:15:29 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Math]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=957</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>PHP session ID generation uses RNG with weak properties<br />
=======================================================</p>
<p>Advisory (c) 2010 Andreas Bogk <andreas () andreas org></p>
<p>Product: PHP<br />
Version: 5.3.2 and before<br />
Type of vulnerability: Cryptographic weakness, session hijacking<br />
Severity: Medium</p>
<p>Summary<br />
=======</p>
<p>PHP utilizes a cryptographically weak random number generator to<br />
produce session ID information.  Additionally, not enough entropy is<br />
used for the initial seeding of the RNG, and some of the entropy can<br />
leak by careless use of the uniqid() PHP function.  Under certain<br />
circumstances, these individual weaknesses interact and reduce the<br />
number of possible values of a PHP session ID so much that exhaustive<br />
search for a valid session ID against the web server becomes feasible.</p>
<p><a href="http://seclists.org/fulldisclosure/2010/Mar/519">Source</a>      </andreas></p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;n=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;title=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;t=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;title=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;title=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking&amp;srcUrl=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;srcTitle=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;title=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Weak%20RNG%20in%20PHP%20session%20ID%20generation%20leads%20to%20session%20hijacking%22&amp;body=Link: http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;t=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;title=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;title=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;title=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking+-+http://b2l.me/mmjbz&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/&amp;submitHeadline=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Weak+RNG+in+PHP+session+ID+generation+leads+to+session+hijacking&amp;body=Link: http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/weak-rng-in-php-session-id-generation-leads-to-session-hijacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Theoretical Breakthrough For Quantum Cryptography</title>
		<link>http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/</link>
		<comments>http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 16:47:20 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Looking Ahead]]></category>
		<category><![CDATA[Math]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=868</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Quantum cryptography only works if Alice and Bob share their relative positions in advance. Now physicists have worked out how to do it without this information.</p>
<p>The world of cryptography is currently undergoing a quantum revolution. The weird laws of quantum mechanics allow cryptographers to create codes that guarantee perfect secrecy. Until recently, the best cryptographers could aim for was just pretty good secrecy with codes that were always compromised in some way or another. Quantum cryptography, on the other hand, is perfect: theoretically and practically secure.</p>
<p>A few companies have even sprung up to sell the gear that can send perfectly secure messages, mainly to banks and governments (although the gear itself creates some loopholes that eavesdroppers can attack).</p>
<p>But it&#8217;s still early days for this technology and naturally it suffers from several drawbacks. For example, one well known limitation is that quantum cryptography can only be used over point-to-point connections and not through networks where data has to be routed. That&#8217;s because the routing process destroys the quantum properties of the photons used to secure messages.</p>
<p>A lesser known limitation is that the sender and receiver of quantum encrypted messages&#8211;the famous Alice and Bob&#8211;must be perfectly aligned so that they can carry out well-defined polarisation measurements on the photons as they arrive. Physicists say that Alice and Bob must share the same reference frame.</p>
<p>That&#8217;s not so hard to do when Alice and Bob are both based in labs on the ground. But it&#8217;s much harder when one or the other is moving, in a satellite, for example, which would be both spinning and orbiting the Earth.</p>
<p>Today, Anthony Laing from the University of Bristol and a few pals show how to get round this. The trick is to use entangled triplets of photons, so-called qutrits, rather than entangled pairs.</p>
<p>This solves the problem by embedding it in an extra abstract dimension, which is independent of space. So as long as both Alice and Bob know the way in which all these abstract dimensions are related, the third provides a reference against which measurements of the other two can be made.</p>
<p>That allows Alice and Bob to make any measurements they need without having to agree ahead of time on a frame of reference. There is one proviso: Alice and Bob cannot move too quickly during the measurements since this changes their relative orientation and a new qutrit will be needed to establish a reference.</p>
<p>That&#8217;ll be useful for quantum encryption over satellite links, the kind of thing that government agencies and the military might want to do. But there&#8217;s another, more valuable application.</p>
<p>If quantum encryption is ever to be widely used, it&#8217;ll need to work between one microchip and another without the need to share a frame of reference in advance. That&#8217;s always been a problem because the chips inside computers are constantly on the move (relative the the wavelength of light) and because photon polarisations drift as they move through optical fibres, introducing another source of error.</p>
<p>That&#8217;s why quantum cryptography that is reference frame independent is an enabling technology and so potentially hugely valuable. It means that Laing and co may have made one of the key breakthroughs that will bring quantum cryptography to the masses.</p>
<p>Ref: arxiv.org/abs/1003.1050: Reference Frame Independent Quantum Key Distribution</p>
<p><a href="http://www.technologyreview.com/blog/arxiv/24899/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;n=Theoretical+Breakthrough+For+Quantum+Cryptography&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;title=Theoretical+Breakthrough+For+Quantum+Cryptography" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;t=Theoretical+Breakthrough+For+Quantum+Cryptography" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;title=Theoretical+Breakthrough+For+Quantum+Cryptography" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;title=Theoretical+Breakthrough+For+Quantum+Cryptography&amp;srcUrl=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;srcTitle=Theoretical+Breakthrough+For+Quantum+Cryptography&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;title=Theoretical+Breakthrough+For+Quantum+Cryptography&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Theoretical%20Breakthrough%20For%20Quantum%20Cryptography%22&amp;body=Link: http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;t=Theoretical+Breakthrough+For+Quantum+Cryptography" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;title=Theoretical+Breakthrough+For+Quantum+Cryptography&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;title=Theoretical+Breakthrough+For+Quantum+Cryptography" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;title=Theoretical+Breakthrough+For+Quantum+Cryptography" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Theoretical+Breakthrough+For+Quantum+Cryptography+-+http://b2l.me/jeyb9&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/&amp;submitHeadline=Theoretical+Breakthrough+For+Quantum+Cryptography&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Theoretical+Breakthrough+For+Quantum+Cryptography&amp;body=Link: http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/theoretical-breakthrough-for-quantum-cryptography/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA authentication weakness discovered</title>
		<link>http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/</link>
		<comments>http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 00:24:11 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Computer Science]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Math]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=841</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The most common digital security technique used to protect both media copyright and Internet communications has a major weakness, University of Michigan computer scientists have discovered.</p>
<p>RSA authentication is a popular encryption method used in media players, laptop computers, smartphones, servers and other devices. Retailers and banks also depend on it to ensure the safety of their customers&#8217; information online.</p>
<p>The scientists found they could foil the security system by varying the voltage supply to the holder of the &#8220;private key,&#8221; which would be the consumer&#8217;s device in the case of copy protection and the retailer or bank in the case of Internet communication. It is highly unlikely that a hacker could use this approach on a large institution, the researchers say. These findings would be more likely to concern media companies and mobile device manufacturers, as well as those who use them.</p>
<p>Andrea Pellegrini, a doctoral student in the Department of Electrical Engineering and Computer Science, will present a paper on the research at the upcoming Design, Automation and Test in Europe (DATE) conference in Dresden on March 10.</p>
<p>&#8220;The RSA algorithm gives security under the assumption that as long as the private key is private, you can&#8217;t break in unless you guess it. We&#8217;ve shown that that&#8217;s not true,&#8221; said Valeria Bertacco, an associate professor in the Department of Electrical Engineering and Computer Science.</p>
<p>These private keys contain more than 1,000 digits of binary code. To guess a number that large would take longer than the age of the universe, Pellegrini said. Using their voltage tweaking scheme, the U-M researchers were able to extract the private key in approximately 100 hours.</p>
<p>They carefully manipulated the voltage with an inexpensive device built for this purpose. Varying the electric current essentially stresses out the computer and causes it to make small mistakes in its communications with other clients. These faults reveal small pieces of the private key. Once the researchers caused enough faults, they were able to reconstruct the key offline.</p>
<p>This type of attack doesn&#8217;t damage the device, so no tamper evidence is left.</p>
<p>&#8220;RSA authentication is so popular because it was thought to be so secure,&#8221; said Todd Austin, a professor in the Department of Electrical Engineering and Computer Science. &#8220;Our work redefines the level of security it offers. It lowers the safety assurance by a significant amount.&#8221;</p>
<p>Although this paper only discusses the problem, the professors say they&#8217;ve identified a solution. It&#8217;s a common cryptographic technique called &#8220;salting&#8221; that changes the order of the digits in a random way every time the key is requested.</p>
<p>&#8220;We&#8217;ve demonstrated that a fault-based attack on the RSA algorithm is possible,&#8221; Austin said. &#8220;Hopefully, this will cause manufacturers to make a few small changes to their implementation of the algorithm. RSA is a good algorithm and I think, ultimately, it will survive this type of attack.&#8221;</p>
<p><a href="http://www.net-security.org/secworld.php?id=8969">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;n=RSA+authentication+weakness+discovered&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;title=RSA+authentication+weakness+discovered" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;t=RSA+authentication+weakness+discovered" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;title=RSA+authentication+weakness+discovered" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;title=RSA+authentication+weakness+discovered&amp;srcUrl=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;srcTitle=RSA+authentication+weakness+discovered&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;title=RSA+authentication+weakness+discovered&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22RSA%20authentication%20weakness%20discovered%22&amp;body=Link: http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;t=RSA+authentication+weakness+discovered" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;title=RSA+authentication+weakness+discovered&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;title=RSA+authentication+weakness+discovered" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;title=RSA+authentication+weakness+discovered" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=RSA+authentication+weakness+discovered+-+http://b2l.me/h34g5&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/&amp;submitHeadline=RSA+authentication+weakness+discovered&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=RSA+authentication+weakness+discovered&amp;body=Link: http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/rsa-authentication-weakness-discovered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA 2010: Experts Expect Several Ciphers to Be Cracked Soon</title>
		<link>http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/</link>
		<comments>http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 20:56:47 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Computer Science]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Math]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=833</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Cryptographers are expecting several of the major cryptographic systems in use today to be broken in the near future.</p>
<p>In the Cryptographers Panel session at the RSA Conference Tuesday, Adi Shamir said that he is working with a team of researchers who have put together a paper that describes an attack that will break AES 128 within 10 rounds.</p>
<p>&#8220;And if you go to AES 256, we can break the entire cryptosystem,&#8221; Shamir said. </p>
<p>Shamir, one of the inventors of the RSA algorithm, was speaking on the panel with Ron Rivest, Brian Snow of the National Security Agency, Martin Hellman of Stanford University, Whit Diffie, and Ari Juels of RSA Security. The panel, which is an annual event at the RSA Conference, usually provides some of the more interesting anecdotes of the conference, and this year&#8217;s was no exception.</p>
<p>In addition to the work against AES, which is the encryption standard used in many cryptosystems today, Rivest said that he expects 1024-bit RSA encryption to be broken relatively soon.</p>
<p>&#8220;I expect that RSA 1024 will be broken within a decade,&#8221; Rivest said. &#8220;People should start moving to 2048 soon.&#8221;</p>
<p>Rivest, a professor at MIT who worked with Shamir and Len Adleman to design the original RSA algorithm, also said that he still gets email and calls from people wanting to use the MD5 hash function, which he designed in 1991. MD5 was widely used, but has been shown to have several weaknesses in recent years.</p>
<p>&#8220;I always say to them, &#8216;Don&#8217;t you understand that MD5 is an extinct hash function? It&#8217;s dead,&#8217;&#8221; Rivest said.</p>
<p>Juels, chief scientist at RSA Labs, moderated the panel and asked all of the speakers whether they had ever done anything foolish.</p>
<p>&#8220;I&#8217;ve rarely done anything else,&#8221; Diffie said, which got a nice laugh from the crowd.</p>
<p>Hellman took the question a bit more seriously, but essentially echoed Diffie&#8217;s answer, saying that his original research with Diffie in the 1970s that led to the invention of public-key cryptography was looked at as a black hole when they started it.</p>
<p>&#8220;I was told by all of my colleagues that cryptography was a waste of time. The NSA had a massive budget, we didn&#8217;t know how big at the time, and they had been working on the problem for decades. We were told there&#8217;s no way we&#8217;d discover anything that they hadn&#8217;t already found, and if we did, they&#8217;d classify it,&#8221; Hellman said. </p>
<p><a href="http://threatpost.com/en_us/blogs/experts-expect-several-ciphers-be-cracked-soon-030210">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;n=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;title=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;t=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;title=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;title=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon&amp;srcUrl=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;srcTitle=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;title=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22RSA%202010%3A%20Experts%20Expect%20Several%20Ciphers%20to%20Be%20Cracked%20Soon%22&amp;body=Link: http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;t=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;title=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;title=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;title=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon+-+http://b2l.me/huyr2&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/&amp;submitHeadline=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=RSA+2010%3A+Experts+Expect+Several+Ciphers+to+Be+Cracked+Soon&amp;body=Link: http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/rsa-2010-experts-expect-several-ciphers-to-be-cracked-soon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PGP Key Management Server</title>
		<link>http://www.uncompiled.com/2010/02/pgp-key-management-server/</link>
		<comments>http://www.uncompiled.com/2010/02/pgp-key-management-server/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 16:20:22 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Math]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=772</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Encryption is an essential element of any data protection plan. It applies from the employee desktop to the data center and the cloud, and all points in between. IT organizations are adding cryptographic measures to maintain consumer privacy, preserve data integrity, avoid data loss, prevent intrusions, and address compliance demands. Each new data protection technology contributes to a growing volume of keys that need to be managed, and fractures the hope of maintaining control.</p>
<p>PGP® Key Management Server provides organizations with the infrastructure and tools to manage large scale deployments of encryption keys and certificates. Instead of using proprietary standalone key repositories or custom single purpose tools, PGP Key Management Server delivers a better approach to managing encryption keys by starting with a design core around supporting different types of keys, trust models and applications.</p>
<p>    * Pare down operational cost and complexity &#8211; Maintaining multiple key repositories requires extensive labor, resources, and expertise. PGP Key Management Server simplifies the environment with a consistent administrative interface.<br />
    * Reduce risk of unrecoverable data &#8211; Ensure that dependable key recovery methods are in place before the need arises.<br />
    * Prevent unexpected downtime &#8211; Unanticipated certificate expirations can bring business to a standstill. Automate certification updates and eliminate certificate accidents that lead to system outages.<br />
    * Stay in control &#8211; IT leaders need to know if their security policy matches reality. Key management helps organizations account for encryption keys throughout their environment and demonstrate proof of compliance.</p>
<p>PGP Key Management Server provides a versatile foundation to centralize management of encryption throughout the enterprise to help organizations take control over their encryption keys, strengthen security, and reduce operational cost.</p>
<p><a href="http://www.pgp.com/products/key_management_server/index.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;n=PGP+Key+Management+Server&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/02/pgp-key-management-server/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;title=PGP+Key+Management+Server" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;t=PGP+Key+Management+Server" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;title=PGP+Key+Management+Server" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;title=PGP+Key+Management+Server&amp;srcUrl=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;srcTitle=PGP+Key+Management+Server&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;title=PGP+Key+Management+Server&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22PGP%20Key%20Management%20Server%22&amp;body=Link: http://www.uncompiled.com/2010/02/pgp-key-management-server/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;t=PGP+Key+Management+Server" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;title=PGP+Key+Management+Server&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;title=PGP+Key+Management+Server" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;title=PGP+Key+Management+Server" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/02/pgp-key-management-server/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=PGP+Key+Management+Server+-+http://b2l.me/g3mr7&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/02/pgp-key-management-server/&amp;submitHeadline=PGP+Key+Management+Server&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=PGP+Key+Management+Server&amp;body=Link: http://www.uncompiled.com/2010/02/pgp-key-management-server/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/02/pgp-key-management-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microscope-wielding boffins crack cordless phone crypto</title>
		<link>http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/</link>
		<comments>http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 20:02:20 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Attack]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Math]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=738</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Cryptographers have broken the proprietary encryption used to prevent eavesdropping on more than 800 million cordless phones worldwide, demonstrating once again the risks of relying on obscure technologies to remain secure.</p>
<p>The attack is the first to crack the cipher at the heart of the DECT, or Digital Enhanced Cordless Telecommunications, standard, which encrypts radio signals as they travel between cordless phones in homes and businesses and corresponding base stations. A previous hack, by contrast, merely exploited weaknesses in the way the algorithm was implemented.</p>
<p>The fatal flaw in the DECT Standard Cipher is its insufficient amount of &#8220;pre-ciphering,&#8221; which is the encryption equivalent of shaking a cup of dice to make sure they generate unpredictable results. Because the algorithm discards only the first 40 or 80 bits during the encryption process, it&#8217;s possible to deduce the secret key after collecting and analyzing enough of the protected conversation.</p>
<p>&#8220;This standard, as with everything else we have broken, has been designed some 20 years ago, and it is proprietary encryption,&#8221; said Karsten Nohl, one of the cryptographers who helped devise the attack. &#8220;It relied on the fact that the encryption was unknown and hence could not be broken. This is a case where something that has some potential for being strong is broken by just this one design decision that in any public review would have been spotted immediately.&#8221;</p>
<p>Nohl, 28, is the same University of Virginia microscope-wielding reverse engineer to crack the encryption in the world&#8217;s most widely used smartcard. In December, he struck again after devising a practical attack for eavesdropping on cellphone calls.</p>
<p>He and fellow researchers Erik Tews of the Darmstadt University of Technology and Ralf-Philipp Weinmann of the University of Luxembourg, plan to present their findings Monday at the 2010 Fast Software Encryption workshop in Korea.</p>
<p>Like several of Nohl&#8217;s previous hacks, it began with nitric acid and an electron microscope. After dissolving away the epoxy on the silicon chip and then shaving down and magnifying the section dedicated to the DECT encryption, he was able to glean key insights into the underlying algorithm. He then compared the findings against details selectively laid out in a patent and exposed during a debug process.</p>
<p>The results of all three probe methods revealed the fatally insufficient amount of pre-ciphering in the DECT Standard Cipher.</p>
<p>In practical terms, the attack works by collecting bits of the encrypted data stream with known unencrypted contents. In cordless phones, this often comes from a device&#8217;s control channel, which broadcasts a variety of predictable data, including call duration and button responses. Sniffing an encrypted conversation with a USRP antenna and the average PC, an attacker would need to collect about four hours of data to break the key in typical scenarios.</p>
<p>In others &#8211; such as where DECT is used in restaurants and bars to wirelessly zap payment card details &#8211; the time needed to crack the key could be dramatically shorter, Nohl said. The time can also be sped up in a variety of other ways, including by adding certain types of graphics cards to beef up the power of the attacking PC. In some cases, the attack can retrieve the secret key in 10 minutes.</p>
<p>&#8220;We expect that some smarter cryptographers than ourselves will find better attacks, of course,&#8221; Nohl told El Reg. &#8220;We found the algorithm and then implemented the first attack. It&#8217;s almost guaranteed that this is not the best attack.&#8221;</p>
<p>The DECT Forum, the international body that oversees the standard, said it takes the attack scenarios laid out in the paper seriously and &#8220;continues to investigate their applicability.&#8221;</p>
<p>The crack of DECT is only the latest time Nohl has defeated the proprietary encryption of a device with critical mass. His 2008 attack on the Mifare Classic smartcard used similar techniques of filing down a silicon chip and then tracing the connections between transistors. His proposed attack of GSM encryption affects cellphones used by more than 800 carriers in 219 countries. ®</p>
<p><a href="http://www.theregister.co.uk/2010/02/08/dect_phone_encryption_cracked/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;n=Microscope-wielding+boffins+crack+cordless+phone+crypto&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;title=Microscope-wielding+boffins+crack+cordless+phone+crypto" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;t=Microscope-wielding+boffins+crack+cordless+phone+crypto" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;title=Microscope-wielding+boffins+crack+cordless+phone+crypto" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;title=Microscope-wielding+boffins+crack+cordless+phone+crypto&amp;srcUrl=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;srcTitle=Microscope-wielding+boffins+crack+cordless+phone+crypto&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;title=Microscope-wielding+boffins+crack+cordless+phone+crypto&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Microscope-wielding%20boffins%20crack%20cordless%20phone%20crypto%22&amp;body=Link: http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;t=Microscope-wielding+boffins+crack+cordless+phone+crypto" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;title=Microscope-wielding+boffins+crack+cordless+phone+crypto&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;title=Microscope-wielding+boffins+crack+cordless+phone+crypto" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;title=Microscope-wielding+boffins+crack+cordless+phone+crypto" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Microscope-wielding+boffins+crack+cordless+phone+crypto+-+http://b2l.me/fyfqy&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/&amp;submitHeadline=Microscope-wielding+boffins+crack+cordless+phone+crypto&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Microscope-wielding+boffins+crack+cordless+phone+crypto&amp;body=Link: http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/02/microscope-wielding-boffins-crack-cordless-phone-crypto/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>768-bit RSA cracked</title>
		<link>http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/</link>
		<comments>http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 14:49:51 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Computer Science]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Math]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=643</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Researchers have decomposed a 768-bit number with 232 decimal places into its two prime factors and published a paper with their results. The number is the string released as &#8220;RSA-768&#8243; under the now defunct RSA Challenge. As a result, RSA encryptions with 768-bit keys must, from now on, be considered cracked.</p>
<p>It took the team of researchers from Switzerland, Japan, Germany, France, the US and the Netherlands about two and a half years to perform the factorisation. The first step of the calculation, polynomial selection, required half a year on a cluster consisting of 80 PCs, while the second and considerably more labour-intensive sieving step took about two years on a cluster of several hundred computers. According to the researchers, a single Opteron processor with 2 Gbytes of RAM would have needed about 1,500 years to complete the sieving step.</p>
<p>As RSA-512 was cracked about a decade ago, the researchers assume that the computing power required to master RSA-1024 is likely to become available in about ten years. They therefore recommend that all 1024-bit RSA keys be decommissioned by 2014 at the latest.</p>
<p><a href="http://www.h-online.com/security/news/item/768-bit-RSA-cracked-898986.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;n=768-bit+RSA+cracked&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;title=768-bit+RSA+cracked" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;t=768-bit+RSA+cracked" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;title=768-bit+RSA+cracked" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;title=768-bit+RSA+cracked&amp;srcUrl=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;srcTitle=768-bit+RSA+cracked&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;title=768-bit+RSA+cracked&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22768-bit%20RSA%20cracked%22&amp;body=Link: http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;t=768-bit+RSA+cracked" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;title=768-bit+RSA+cracked&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;title=768-bit+RSA+cracked" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;title=768-bit+RSA+cracked" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=768-bit+RSA+cracked+-+http://b2l.me/c9xqb&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/&amp;submitHeadline=768-bit+RSA+cracked&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=768-bit+RSA+cracked&amp;body=Link: http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/01/768-bit-rsa-cracked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Encryption Can Get Board&#8217;s Attention</title>
		<link>http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/</link>
		<comments>http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 12:54:01 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Looking Ahead]]></category>
		<category><![CDATA[Math]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=490</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>There are lots of good reasons for IT leaders to pay attention to even the finest details of encryption policies. One of the more practical is that encryption&#8217;s a board-level concept. As in, the board of directors will feel no hesitation in second guessing decisions not to encrypt data that ends up exposed.Which makes the findings in this week&#8217;s cover story on encryption all the more surprising.</p>
<p>Based on exclusive InformationWeek Analytics research, it finds nearly all companies use some encryption, but only 14% says it&#8217;s pervasive at their companies. A fourth have database table-level encryption. And about 3 out of 5 companies don&#8217;t encrypt mobile devices, despite their habit of disappearing loaded with confidential data. </p>
<p><a href="http://www.informationweek.com/blog/main/archives/2009/11/encryption_can.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;n=Encryption+Can+Get+Board%27s+Attention&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;title=Encryption+Can+Get+Board%27s+Attention" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;t=Encryption+Can+Get+Board%27s+Attention" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;title=Encryption+Can+Get+Board%27s+Attention" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;title=Encryption+Can+Get+Board%27s+Attention&amp;srcUrl=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;srcTitle=Encryption+Can+Get+Board%27s+Attention&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;title=Encryption+Can+Get+Board%27s+Attention&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Encryption%20Can%20Get%20Board%27s%20Attention%22&amp;body=Link: http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;t=Encryption+Can+Get+Board%27s+Attention" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;title=Encryption+Can+Get+Board%27s+Attention&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;title=Encryption+Can+Get+Board%27s+Attention" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;title=Encryption+Can+Get+Board%27s+Attention" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Encryption+Can+Get+Board%27s+Attention+-+http://b2l.me/aqmuh&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/&amp;submitHeadline=Encryption+Can+Get+Board%27s+Attention&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Encryption+Can+Get+Board%27s+Attention&amp;body=Link: http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2009/11/encryption-can-get-boards-attention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
