About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Privacy
100 Ways to Disappear and Live Free
A Guide to Intelligence Collection Methods
A Study of Criminal History Records, as Maintained by the RCMP
A Theory of Information Warfare: Preparing for 2020
An Appraisal of the Technology of Political Control
Anonymity on the Web
Antisurveillance
Appeal Filed in Teenager vs. FBI Case
Beating The FBI
Big Brother's Little Helpers: Private Intelligence Networks
Biometric ID Cards
Bugs, Taps And Infiltrators: What To Do About Political Spying
Carnival Booth: Defeating Computer-Assisted Passenger Screening System
Carnivore FAQ
China's Golden Shield: Corporations and the Development of Surveillance Technology in China
Civil Liberties Under Threat
Cooperation of Telecommunications Providers with Law Enforcement
Cryptography: Policy and Technology Trends
Disabling CCTV / Video Cameras
Disabling Surveillence Video Cameras
EPIC Analysis of Draft Guidelines on Searching and Seizing Computers
EU Lawful Interception of Telecommunications
Eavesdropping On the Electromagnetic Emanations of Digital Equipment
Electronic Surveillance in a Digital Age
Email Privacy Law Review
European Union and FBI Launch Global Surveillance System
Executive Guide to the Protection of Information
Exposing The Global Surveillance System
Exposing the Global Surveillance System
FBI Investigates Domestic Activities to Identify Terrorists
Fingerprints
General Counterdrug Intelligence Plan
Gmail Bedfellows
Hiding Yourself
Homeless Tracking Fact Sheet
How COINTELPRO Helped Destroy the Movements of the 1960s
How Private Is My Credit Report?
How Tax Returns are Selected for Audit
How To Create A New Indentity
How To Get Lost
How to Get Anything on Anyone
IRS Cups It's Ear to Cordless Phones
IRS and Terrorist-Related Information Sharing
Identification, Anonymity and Pseudonymity in Consumer Transactions
Identification: A Move Towards the Future
Identity Cards: Frequently Asked Questions
Interception Capabilities 2000
Internet Security and Privacy for Activists and Citizens
Internet Security and Privacy for Activists and Citizens
Investigators Guide to Sources of Information
Is the NSA Sniffing Your Email?
Mail Surveillance
New Communications Technologies and Traditional Civil Liberties
Participating With Safety
Privacy Rights of BBS Users
Privacy or Service: Must We Be Forced to Choose?
Proof of Echelon?
Rebirth Methods In Post 9/11 USA
Recieve Your FBI File
Report of the Interception of Communications Commissioner for 2001
Schengen Information System: SIS II
Smart Cards: Opportunities for Public Sector Applications
Spook Words
Spy Secrets
Statements by the DCI and the NSA Director on Economic Spying
Surveillance Conference Overview
Testimony of Mark M. Ishikawa CEO BayTSP.com
The "Enemy Within": EU Plans the Surveillance of Protestors
The Group Trap
The Joy of Handles
The Libertarian Party Represents You
The Shocking Menace of Satellite Surveillance
The TEMPEST Method of Computer Data Interception!
The World of Surveillance
They Were Spying on Us: Detroit Police Red Squad
Touching Big Brother: How Biometric Technology will Fuse Flesh and Machine
U.S. Military Spying on Web Sites
UK ID Cards: Majority in Favor
UK National ID Cards - A Consultation
Using the Freedom of Information Act: Revised Edition
Watching the Watcher Watching You
Watching the Watchers: The Spanish Police
What To Do When They Ask For Your Social Security Number
Who's Afraid of Carnivore? Not Me!
Why Legal Action Should Be Taken for Installation of Surveillance Cameras in Public Places
Will We Be Under Total Surveillance?
Your Papers Please
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it

Cracking PGP Myth Banishment Notes

by Route

PGP is a hybrid cryptosystem. It contains 4 crytpographic elements, each of which is subject to a different type of cryptographic attack. It contains a symmetric cipher, an asymmetric cipher, a one-way hash, and a random number generator.

-- The symmetric cipher --

IDEA, finalized in 1992 by Lai and Massey is strong. It is the toughest block cipher known of today. There have be no advances in the cryptanalysis of standard IDEA that are publically known. (I know nothing of what the NSA has done, nor does most anyone.)

The best method of attack, therefore, is brute force. As we all know the keyspace of IDEA is 128-bits. To recover a particular key, one must, on average, search half the keyspace. That is 127 bits. Fine. If you, for the sake of argument, had 1 billion machines that could try 1 billion keys/sec. It would still take all these machines longer than the universe as we know has existed and then some, to find the key. Not a likely event. IDEA, as far as present technology goes, not vulnerable to attack, pure and simple.

-- The asymmetric cipher --

RSA, the first *full fledged* public key cryptosystem was designed by Rivest, Shamir, and Adleman. It has withstood *years* of *intense* cryptographic scrutiny. RSA gets it's security from the apparent difficulty in factoring very large composites. However, nothing has been proven with RSA. It is not *proven* that factoring the public modulous is the only (best) way to factor RSA. It is also not proven that factoring *has* to be as hard as it is. There exists the possiblity that an advance in number theory may lead to the discovery of polynomial time factoring algorithm. But, none of these things has happened, and nothing points in that direction. However, 3 things that *are* happening and *will* continue to happen are the advances in: factoring technique and computing power, and the decrease in the cost of computing hardware. These things, esp. the first one, work against the security of RSA. However, as computing power increases, so does the ability to generate larger keys. It is *much* easier to multiply very large primes than it is to factor the resulting composite.

So, as it stands now, the best way to crack RSA is through factoring the public modulus. This, as far as we know, is not an easy task, if the public modulous is large enough (there are numerous examples of smaller keys falling to concerted effort). Using the General Number Field Sieve, a 1024-bit key would likely require 3E11 MIPS years to factor. 20 years from now (assuming no breakthoughs in factoring technology) this keyspace will likely be insecure. Today, it is not. But, the ultra-conservative will opt for 2048-bit keys, which is not a bad idea in my opinion.

It is very difficult to make predictions in this area of computing/ cryptography. Arjen Lenstra the most succesful factorer will not make predictions oast 10 years.

To sum it up: RSA is vulnerable to factoring. --DON'T LET ANYONE WITHOUT A PHD IN THEORECTICAL MATH TELL YOU OTHERWISE-- If you use a large enough public key, all the worlds computers cannot factor your key (using present factoring technology). RSA would not have lastest this long if it was as fallible as some crackpots would like you to believe.

-- The one-way hash --

MD5 is the hash used to hash the passphrase into the IDEA key and to sign documents. Message Digest 5 was designed by Rivest. It's output is four 32-bit blocks, which form a 128-bit hash of the input. MD5 has no known practical security weaknesses. It has a weakness in the compression function, allowing for collisions, but this does not allow for any practical attack. There are two attacks against MD5 (or any hash function). The first is to find a another input that will hash to same value. Not very practical or likely.

Remember the output is 128-bits. That's a BIG number. The other attack, the birthday attack, trys to find two random messages that hash to the value. This is also impractical (although not as much as the first one).

Since English has 1.3 bits of information per character, and IDEA uses a 128-bit key, a passphrase of about 100 characters will maximize the randomness of the resulting hash. How many of you use 100 character passphrases?

-- The PRNG --

I do not have enough info on the PSNG used by PGP as of yet. This section under construction.

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics