Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.programming > #4616 > unrolled thread

On Risks and Vulnerabilities of Digital Signatures

Started byMok-Kong Shen <mok-kong.shen@t-online.de>
First post2014-06-15 10:38 +0200
Last post2014-09-21 11:41 +0200
Articles 6 — 2 participants

Back to article view | Back to comp.programming


Contents

  On Risks and Vulnerabilities of Digital Signatures Mok-Kong Shen <mok-kong.shen@t-online.de> - 2014-06-15 10:38 +0200
    Re: On Risks and Vulnerabilities of Digital Signatures "Chris Uppal" <chris.uppal@metagnostic.REMOVE-THIS.org> - 2014-06-15 13:02 +0100
      Re: On Risks and Vulnerabilities of Digital Signatures Mok-Kong Shen <mok-kong.shen@t-online.de> - 2014-06-15 20:44 +0200
    Re: On Risks and Vulnerabilities of Digital Signatures Mok-Kong Shen <mok-kong.shen@t-online.de> - 2014-06-15 20:34 +0200
    Re: On Risks and Vulnerabilities of Digital Signatures Mok-Kong Shen <mok-kong.shen@t-online.de> - 2014-06-21 07:48 +0200
    Re: On Risks and Vulnerabilities of Digital Signatures Mok-Kong Shen <mok-kong.shen@t-online.de> - 2014-09-21 11:41 +0200

#4616 — On Risks and Vulnerabilities of Digital Signatures

FromMok-Kong Shen <mok-kong.shen@t-online.de>
Date2014-06-15 10:38 +0200
SubjectOn Risks and Vulnerabilities of Digital Signatures
Message-ID<lnjm2p$cbf$3@news.albasani.net>
Recently I was asked by some acquaintances about the potential security
risks of digital signatures. The following is a sketch of what I
answered with my very humble knowledge. Hopefully experts in this group
would (eventually strongly) correct and augment my argumentation.

A. From the theoretical side (concerning math):

(1) There are assumptions in the underlying mathematical foundations
which till the present cannot yet be proved in the absolute exact
sense. These are hence liable to turn out to be false at any time in
the future. Example: Recently Lenstra et al. showed that the method of
discrete logarithms can be very much easier attacked than hitherto
commonly assumed.
(http://actu.epfl.ch/news/epfl-researchers-crack-unassailable-encryption-alg/).

(2) All methods have parameters which should be chosen to lie in
certain numerical ranges such that they may properly function as
desired. The determination of such ranges is apparently by necessity an
issue of more or less arbitrariness, whence the actual security
obtained in any given concrete case is not entirely unquestionable.

(3) Owing to the frequently very advanced math involved, high expertise
is required to be able to verify the correctness of the details. This
entails the risk that under circumstances the number of practically
available capable experts is insufficient to guarantee a neutral (the
opposite of biased/manipulated) examination and evaluation. Example:
The so-called "dual elliptic curve" is reported to contain a backdoor.
(http://www.reuters.com/article/2014/03/31/us-usa-security-nsa-rsa-idUSBREA2U0TY20140331) 

(The issue led to a revision of the procedure of processing
cryptological standards of the US national standradization body NIST
(http://fcw.com/articles/2014/02/25/nist-guidance.aspx)).

B. From the practical side (concerning software and CAs):

(1) In case within the entire processing of a digital signature there
is one single non-open-source (proprietary, blackbox) software
component, the risk of potential manipulations (due to possible
disloyality/dissatisfaction of employees of software firms, pressures
from authorities, hacking, etc.) is evidently already impossible to be
excluded.

(2) Also open-source software can contain grave errors, which due to
lack of persons in the public having interest, time and appropriate
knowledge to thoroughly examine them could remain undetected for a long
time. Example: the Heartbleed Bug of OpenSSL.
(https://www.schneier.com/crypto-gram-1404.html).

(3) CAs are organisations of humans and humans could not only commit
errors and mistakes but also be subjected to bribery, extortion,
ideological and other ways of influences. In any digital signature
processing there are in general a number of CAs involved which could be
located inland or overseas (thus beyond normal judicial reaches). How
well one could trust the results of a cooperation of such a group of
organisations (of which one as a rule knows nothing at all) is
apparently a large question mark from the very beginning.


M. K. Shen
-----------------------------------------------

P.S. It may be valuable in safeguarding one's privacy to constantly
keep in mind of the presence of certain quasi-omnipotent secret
agencies of the world, as has been convincingly revealed by Edward
Snowden (see G. Greenwald. No Place to Hide, New York, 2014).

This note is also available at:
http://s13.zetaboards.com/Crypto/topic/7204526/1/, where some other
crypto relevant publications of mine may also be found.

[toc] | [next] | [standalone]


#4617

From"Chris Uppal" <chris.uppal@metagnostic.REMOVE-THIS.org>
Date2014-06-15 13:02 +0100
Message-ID<UpmdnX8QerF-FgDOnZ2dnUVZ7o0AAAAA@bt.com>
In reply to#4616
Mok-Kong Shen wrote:

> (2) Also open-source software can contain grave errors, which due to
> lack of persons in the public having interest, time and appropriate
> knowledge to thoroughly examine them could remain undetected for a long
> time. Example: the Heartbleed Bug of OpenSSL.
> (https://www.schneier.com/crypto-gram-1404.html).

Not just bugs in the security code, but also missaplication of working (or at 
least not known-to-be-broken) code.

For instance these researches created /genuine/ a CA (in the sense that any 
working software would accept certs it signed) by exploiting weaknesses in the 
way upstream CAs worked.
    http://www.win.tue.nl/hashclash/rogue-ca/
(Which you probably know about already, but it's an interesting link for some 
who may not).

    -- chris

 

[toc] | [prev] | [next] | [standalone]


#4619

FromMok-Kong Shen <mok-kong.shen@t-online.de>
Date2014-06-15 20:44 +0200
Message-ID<lnkpii$n36$3@news.albasani.net>
In reply to#4617
Am 15.06.2014 14:02, schrieb Chris Uppal:

>      http://www.win.tue.nl/hashclash/rogue-ca/

Thanks for the link.

M. K. Shen

[toc] | [prev] | [next] | [standalone]


#4618

FromMok-Kong Shen <mok-kong.shen@t-online.de>
Date2014-06-15 20:34 +0200
Message-ID<lnkouv$mo9$1@news.albasani.net>
In reply to#4616
Concerning vulnerabilities as such,
https://www.schneier.com/crypto-gram-1406.html has an interesting
article entitled "Disclosing vs. Hoarding Vulnerabilities".

[toc] | [prev] | [next] | [standalone]


#4629

FromMok-Kong Shen <mok-kong.shen@t-online.de>
Date2014-06-21 07:48 +0200
Message-ID<lo36bg$ujq$1@news.albasani.net>
In reply to#4616
I just found an interesting article on digital signatures:

    D. Adamski et al.: Why Digital Signatures Fail - Legal Concepts
    for Long Term Validity in Austria, Germany and Poland, in
    A. U. Schmidt et al., Long-Term and Dynamical Aspects of
    Information, pp. 113-124, Nova Sci. Publ., 2007.

M. K. Shen

[toc] | [prev] | [next] | [standalone]


#4803

FromMok-Kong Shen <mok-kong.shen@t-online.de>
Date2014-09-21 11:41 +0200
Message-ID<lvm6fs$hug$2@news.albasani.net>
In reply to#4616
I have in the section Epilogue of my recent PROVABLEPRIME Version 1.0.1
(http://s13.zetaboards.com/Crypto/topic/7234475/1/) further argued a
tiny little bit and also quoted the following from a book of
R. Anderson of 2001 which very deplorably appears not yet to have
received the attention that it deserves:

"In short, while public key infrastructures can be useful in some
applications, they are unlikely to be the universal solution to
security problems as their advocates seem to believe. They don't
tackle most of the really important issues at all."

M. K. Shen

[toc] | [prev] | [standalone]


Back to top | Article view | comp.programming


csiph-web