Path: csiph.com!v102.xanadu-bbs.net!xanadu-bbs.net!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Jim Janney Newsgroups: comp.sys.mac.system Subject: Re: iCloud Hacked Article Date: Thu, 09 Aug 2012 07:55:06 -0600 Organization: differences shown may not be optimal Lines: 77 Message-ID: References: <2012080700010178635-jeffnospam@jnadeaucom> <8t48f9-7qh.ln1@news1.chingola.ch> <080820121044084787%star@sky.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Injection-Info: mx04.eternal-september.org; posting-host="3e796541df3cd2e39d75fcba86cc47b9"; logging-data="16404"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/i5W4Vxvmn2iJVkAp+avhV" User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.1 (gnu/linux) Cancel-Lock: sha1:OGyLEMBEGSjH73ayEAoaqhKehtY= sha1:HMKcZ5VzMAm5ZnnivoDStby+dEI= Xref: csiph.com comp.sys.mac.system:29238 Michael Vilain writes: > In article <080820121044084787%star@sky.net>, Davoud > wrote: > >> Paul Sture: >> > Once they have your encrypted disk image, they can attempt to crack it at >> > their leisure. >> >> So encrypt with a strong password. >> >> They had better have lots of leisure time if they want to crack my >> encrypted disk image. I use passwords following a pattern that is >> vaguely typified by, but not the same as, this: *Jp4#aVia&TiOn-fUel! . >> The number of all possible passwords following this paradigm is >> 3,622,996,024,341,650,240,846,169,344,922,329,517,120 (3.62 x 10e39), >> which is greater than the number of particles in the observable >> Universe. >> >> Time to crack with the fastest conceivable attack (100 trillion guesses >> per second, which no hacker can do without a massively parallel >> supercomputer) is 11.52 thousand trillion centuries, a long enough >> period to be entirely meaningless in the context of any known or >> conceivable Universe, though one could be in the ballpark if one >> counted all of the fundamental particles in all the Universes in the >> Multiverse, if such exists. I do not have duplicate passwords for any >> log-ins. >> >> For some frequently-used log-ins I have weaker passwords. The weakest >> has a massive cracking array time of only 13.44 billion centuries. >> >> So is my password crackable? Theoretically, yes, practically no. A >> computer could hit it on the first guess, but divide 1 by the number >> above to find the likelihood of that. I trust my financial data and >> other important information to this PW without losing sleep. And >> persons wanting secure passwords should also note this: hackers, don't >> waste time looking for this password to be stored on any computer in >> any form, or on-line, or anywhere else you would look, no matter how >> clever you think you are; it is not stored in a strong, >> pressure-and-water-proof container at the bottom of Lake Vostok, or in >> a secret compartment in the Mars rover Curiosity, but those examples >> should give you some idea of your chances of finding it. BTW, I also do >> not keep a door key "hidden" on my property or in any of my cars, or on >> my person, though making such a key unfindable (as a practical matter) >> is easy enough if the owner is willing to put up with a little bit of >> inconvenience if s/he needs to access it. Yet I have easy access to a >> spare key if I need it. >> >> OK, now that I've written all of this nonsense it's time to change my >> password. I just noticed that if I were to use the exact number above, >> 3,622,996....120 the massive cracking array time would increase to 1.22 >> thousand trillion trillion trillion trillion centuries. A hacker would >> want to pack a lunch before launching that attack. > > Actually, someone asked about retrieving data from a FileVault encrypted > account recent. He posted interesting articles about the nature of > Apple's File Vault encryption and the encryption used on their disk > images. It's is much easier to crack that what you've laid out mostly > because there's 'leakage' with the key. It led me to doubt my original > position of "if you don't know that password, learn to live without the > data". The paper quoted showed how to break into these files. > > Check out the Google group archives for the article. Then wipe the smug > off your face. And not everyone runs their cryptanalysis software on a desktop: http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/ Maybe we should write to the NSA and advise them to pack a lunch? :-) In a possibly unrelated development, see also http://www.sltrib.com/sltrib/money/54651214-79/power-million-rate-mountain.html.csp -- Jim Janney