Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.system > #29056 > unrolled thread

iCloud Hacked Article

Started byFred Moore <fmoore@gcfn.org>
First post2012-08-06 17:46 -0400
Last post2012-08-08 04:31 +0000
Articles 15 on this page of 135 — 26 participants

Back to article view | Back to comp.sys.mac.system


Contents

  iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-06 17:46 -0400
    Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-06 21:54 +0000
      Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:33 -0400
        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:47 -0400
          Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:05 -0400
            Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:05 +0000
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:20 -0400
            Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 00:08 +0000
              Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 20:40 -0400
        Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-07 13:20 +1200
      Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-07 10:48 -0400
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 12:34 -0400
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 12:58 -0400
            Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-08 14:30 -0400
              Re: iCloud Hacked Article MC <copespaz@mapca.inter.net> - 2012-08-08 17:18 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:19 +0000
    Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-06 23:21 -0400
      Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:15 -0400
          Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:24 -0400
            Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:29 -0400
        Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 05:41 +0000
            Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:11 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:22 +0000
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:31 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 08:28 +0200
      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:19 -0400
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:30 -0400
        Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:15 +0000
        Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-08 08:11 -0400
      Re: iCloud Hacked Article David Lesher <wb8foz@panix.com> - 2012-08-07 18:26 +0000
    Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 00:26 -0400
      Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 00:31 -0400
        Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 20:16 -0400
          Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-08 12:28 +1200
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:13 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:16 +0200
              Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:56 -0400
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 09:46 -0400
                  Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 10:35 -0400
                    Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 12:41 -0400
                      Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 14:15 -0400
                Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 14:57 -0400
                  Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 16:25 -0400
                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:51 -0400
          Re: iCloud Hacked Article Larry Gusaas <larry.gusaas@gmail.com> - 2012-08-07 18:34 -0600
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 20:41 -0400
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
              Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-08 01:49 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:29 +0000
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:25 +0000
                Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:57 -0400
      Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
    Re: iCloud Hacked Article Jeff N <jeff+no.spam@jnadeau.com> - 2012-08-07 00:01 -0700
      Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 03:48 -0400
        Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:49 +0200
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 21:52 +0200
            Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 17:33 -0400
              Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 16:44 -0500
              Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 18:09 -0400
                Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 18:33 -0400
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 19:26 -0400
                    Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 19:19 -0500
                    Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 21:07 -0400
                      Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 11:14 -0400
                        Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-08 13:11 -0400
                          Re: iCloud Hacked Article me@home.spamsucks.ca (Király) - 2012-08-09 04:56 +0000
                    Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 21:48 +0000
                      Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:50 -0400
                        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:15 -0400
                          Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-08 20:16 -0500
                          Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:22 -0400
                      Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 07:03 -0400
                        Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 10:57 -0400
                          Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 12:29 -0400
                            Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:50 -0500
                              Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:53 -0400
                                Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-11 20:18 -0500
                                  Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-11 21:44 -0400
                                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 23:35 -0400
                          Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 19:00 -0400
                Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:19 +0200
            Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 23:06 -0400
              Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:26 +0200
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 10:59 +0000
                Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 16:27 -0400
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:29 -0400
                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:25 -0400
                    Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 13:30 -0400
                      Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 14:49 -0400
                        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 15:05 -0400
                          Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 15:55 -0400
                        Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:53 -0500
                          Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 20:30 -0400
                            Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-09 17:50 -0700
                              Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-10 09:15 -0400
                                Re: iCloud Hacked Article Warren Oates <warren.oates@gmail.com> - 2012-08-10 10:18 -0400
                                Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:49 -0700
                              Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 10:50 -0400
                                Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:48 -0700
                                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 12:21 -0400
                                    Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 10:00 -0700
                            Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-10 13:23 -0500
                      Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:54 -0400
                        Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-12 20:14 -0400
      Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 08:50 -0400
        Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:55 +0200
          Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 15:17 -0400
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:28 +0000
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:39 +0200
              Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 10:44 -0400
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 14:59 +0000
                  Re: iCloud Hacked Article Richard Kettlewell <rjk@greenend.org.uk> - 2012-08-09 10:50 +0100
                Re: iCloud Hacked Article Michael Vilain <vilain@NOspamcop.net> - 2012-08-08 17:40 -0700
                  Re: iCloud Hacked Article Jim Janney <jjanney@shell.xmission.com> - 2012-08-09 07:55 -0600
                    Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:40 -0400
              Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:15 -0400
                Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:42 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:19 +0000
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 15:44 +0000
                  Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 18:36 -0400
                    Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:21 -0400
                      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 21:09 -0400
                    Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 05:34 +0000
                      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:45 -0400
                        Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 17:39 +0000
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 11:12 -0400
                  Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 01:08 +0000
      Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 22:59 -0400
        Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:31 +0000

Page 7 of 7 — ← Prev page 1 2 3 4 5 6 [7]


#29240

FromDavoud <star@sky.net>
Date2012-08-09 10:40 -0400
Message-ID<090820121040352408%star@sky.net>
In reply to#29238
Jim Janney:
> And not everyone runs their cryptanalysis software on a desktop: 
> 
>     http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/
> 
> Maybe we should write to the NSA and advise them to pack a lunch? :-)

I don't have to /write/ to NSA. Wanna bet they're sitting un a passel
of unbreakable ciphers?

-- 
I agree with almost everything that you have said and almost everything that
you will say in your entire life.

usenet *at* davidillig dawt cawm

[toc] | [prev] | [next] | [standalone]


#29203

FromFred Moore <fmoore@gcfn.org>
Date2012-08-08 11:15 -0400
Message-ID<fmoore-8FEEBD.11151008082012@news.eternal-september.org>
In reply to#29196
In article <foo9f9-gs62.ln1@news1.chingola.ch>,
 Paul Sture <paul@sture.ch> wrote:

> On Wed, 08 Aug 2012 04:28:49 +0000, Lewis wrote:
> 
> > In message <8t48f9-7qh.ln1@news1.chingola.ch>
> >   Paul Sture <paul@sture.ch> wrote:
> >> On Tue, 07 Aug 2012 08:50:48 -0400, Tom Stiller wrote:
> > 
> >>> You can use something like 1Password to generate random answers to
> >>> such questions. Of course, you have to record the replies somewhere.
> >>> 
> >>> I use an encrypted diskimage saved in my Dropbox. Dropbox so I can
> >>> recover them if I lose a machine; encrypted for obvious reasons.
> > 
> >> That's what I was using until recently, but I shifted the encrypted
> >> image to SpiderOak, and in the light of the recent Dropbox compromise I
> >> am glad I did so.
> > 
> > How is that relevant? Dropbox getting hacked doesn't give anyone access
> > to your encrypted disk image, or to your 1Password data which is also
> > encrypted.
> 
> Once they have your encrypted disk image, they can attempt to crack it at 
> their leisure.

Except that if you encrypt it with AES256 and a good password, we will 
have long since turned to dust before HAL figures it out.

-- 
Microsoft has also provided the richest development environment for 
antivirus applications.

[toc] | [prev] | [next] | [standalone]


#29206

FromFred Moore <fmoore@gcfn.org>
Date2012-08-08 11:42 -0400
Message-ID<fmoore-90CE09.11423408082012@news.eternal-september.org>
In reply to#29203
A couple of updates:

Apple freezes AppleID password resets requested over the phone
<http://news.cnet.com/8301-13579_3-57488782-37/apple-freezes-appleid-pass
word-resets-requested-over-the-phone/>

Amazon addresses security exploit after journalist hack
<http://news.cnet.com/8301-1009_3-57488759-83/amazon-addresses-security-e
xploit-after-journalist-hack/>

-- 
* "Objects in Mirror Are Closer Than They Appear",
* "Do not use while sleeping or unconcious",
* "Do not use if you cannot see clearly to read the information in the 
information booklet."
* "Caution: Hot beverages are hot!"
* "Do not look into laser with remaining eye."

[toc] | [prev] | [next] | [standalone]


#29204

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-08 15:19 +0000
Message-ID<slrnk250rd.14pv.g.kreme@mbp55.local>
In reply to#29196
In message <foo9f9-gs62.ln1@news1.chingola.ch> 
  Paul Sture <paul@sture.ch> wrote:
> On Wed, 08 Aug 2012 04:28:49 +0000, Lewis wrote:

>> In message <8t48f9-7qh.ln1@news1.chingola.ch>
>>   Paul Sture <paul@sture.ch> wrote:
>>> On Tue, 07 Aug 2012 08:50:48 -0400, Tom Stiller wrote:
>> 
>>>> You can use something like 1Password to generate random answers to
>>>> such questions. Of course, you have to record the replies somewhere.
>>>> 
>>>> I use an encrypted diskimage saved in my Dropbox. Dropbox so I can
>>>> recover them if I lose a machine; encrypted for obvious reasons.
>> 
>>> That's what I was using until recently, but I shifted the encrypted
>>> image to SpiderOak, and in the light of the recent Dropbox compromise I
>>> am glad I did so.
>> 
>> How is that relevant? Dropbox getting hacked doesn't give anyone access
>> to your encrypted disk image, or to your 1Password data which is also
>> encrypted.

> Once they have your encrypted disk image, they can attempt to crack it at 
> their leisure.

Yeah? And? How many centuries will that take?

http://howsecureismypassword.net says it would take a desktop PC about a
million years to crack my 1password password. The password for my
encrypted disk image is even more secure, at 12 trillion years.

By adding one character to my 1Password I could bump it up to 16 billion
years, and by changing one character to another I could bump it to 157
billion years.

Despite what you see in movies, people do not 'crack' encryption.

-- 
So here's us, on the raggedy edge. Don't push me. And I won't push you.

[toc] | [prev] | [next] | [standalone]


#29207

From"Geoffrey S. Mendelson" <gsm@mendelson.com>
Date2012-08-08 15:44 +0000
Message-ID<slrnk2522b.398.gsm@cable.mendelson.com>
In reply to#29204
Lewis wrote:
>
> By adding one character to my 1Password I could bump it up to 16 billion
> years, and by changing one character to another I could bump it to 157
> billion years.
>
> Despite what you see in movies, people do not 'crack' encryption.
>

Of course they do. Most people don't use such secure encryption, and even if
they did there always is a way to crack it.

Those numbers assume that someone is going to start out with all zeros in the
key, add one and try to use it until it works. 

A much faster approach is to try to decrypt it with some standard keys and
see the result. Based upon the result, you can determine the encryption
method and with that you can use the data to figure out a working key.

Not usually the key used to encrypt the data, but one that still works.

This is not something you are going to find programs to do it with a web
search, but google "large number theory" for a taste of it.

This is not new, it was how the Enigma encryption was broken in WWII.

Geoff.


-- 
Geoffrey S. Mendelson,  N3OWJ/4X1GM/KBUH7245/KBUW5379


[toc] | [prev] | [next] | [standalone]


#29216

FromDavoud <star@sky.net>
Date2012-08-08 18:36 -0400
Message-ID<080820121836328532%star@sky.net>
In reply to#29207
Lewis:
> > By adding one character to my 1Password I could bump it up to 16 billion
> > years, and by changing one character to another I could bump it to 157
> > billion years.

> > Despite what you see in movies, people do not 'crack' encryption.

Geoffrey S. Mendelson:
> Of course they do. Most people don't use such secure encryption, and even if
> they did there always is a way to crack it.
> 
> Those numbers assume that someone is going to start out with all zeros in the
> key, add one and try to use it until it works. 
> 
> A much faster approach is to try to decrypt it with some standard keys and
> see the result. Based upon the result, you can determine the encryption
> method and with that you can use the data to figure out a working key.
> 
> Not usually the key used to encrypt the data, but one that still works.
> 
> This is not something you are going to find programs to do it with a web
> search, but google "large number theory" for a taste of it.
> 
> This is not new, it was how the Enigma encryption was broken in WWII.

But we know that there are encryption systems that have been in use for
years that have not been broken. You can't beat HUMINT when it comes to
learning how successful the enemy's SIGINT service is.

The attack on Enigma was aided by misuse of keys, captured keys, and
re-used keys, and intimate knowledge of the workings of the machine. In
the same vein, we read certain Soviet messages in what came to be known
as the Venona project. If those OTP's had been used properly the
ciphers would never have been broken. As it was, it required years of
painstaking work.

-- 
I agree with almost everything that you have said and almost everything that
you will say in your entire life.

usenet *at* davidillig dawt cawm

[toc] | [prev] | [next] | [standalone]


#29218

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2012-08-08 19:21 -0400
Message-ID<5022f46f$0$1534$c3e8da3$12bcf670@news.astraweb.com>
In reply to#29216
Davoud wrote:

> But we know that there are encryption systems that have been in use for
> years that have not been broken. You can't beat HUMINT when it comes to
> learning how successful the enemy's SIGINT service is.

It all depends on the value of the encrypted data. Some data loses its
value after a day or two. (such as location of troups). Some data may
not lose much value over time, but is of insufficient value to assign
resources to decrypt. (such as what underwear I buy).


If there are frequent communications between high value
criminals/targets, then intelligence agency(ies) may spend the time to
find how to decrypt them so that eventually they can be listened to in
near real time.


[toc] | [prev] | [next] | [standalone]


#29220

FromDavoud <star@sky.net>
Date2012-08-08 21:09 -0400
Message-ID<080820122109596231%star@sky.net>
In reply to#29218
Davoud:
> > But we know that there are encryption systems that have been in use for
> > years that have not been broken. You can't beat HUMINT when it comes to
> > learning how successful the enemy's SIGINT service is.

JF Mezei:
> It all depends on the value of the encrypted data....

If my context didn't make it clear, I wasn't talking about encrypting
your porn collection. In referring to HUMINT and SIGINT was talking in
particular about U.S. Government Intelligence, National Defense, and
Diplomatic secrets, some of which need to be kept secure for a very
long time, and some of which may be declassified after a period of
years according to a statutory schedule.

-- 
I agree with almost everything that you have said and almost everything that
you will say in your entire life.

usenet *at* davidillig dawt cawm

[toc] | [prev] | [next] | [standalone]


#29230

From"Geoffrey S. Mendelson" <gsm@mendelson.com>
Date2012-08-09 05:34 +0000
Message-ID<slrnk26ipt.cm.gsm@cable.mendelson.com>
In reply to#29216
Davoud wrote:
> The attack on Enigma was aided by misuse of keys, captured keys, and
> re-used keys, and intimate knowledge of the workings of the machine. In
> the same vein, we read certain Soviet messages in what came to be known
> as the Venona project. If those OTP's had been used properly the
> ciphers would never have been broken. As it was, it required years of
> painstaking work.
>


True. However it started out because someone sitting at a desk looking
at encrypted messages noticed there was a pattern, and that was used
to exploit the errors, etc.

Geoff.

-- 
Geoffrey S. Mendelson,  N3OWJ/4X1GM/KBUH7245/KBUW5379


[toc] | [prev] | [next] | [standalone]


#29241

FromDavoud <star@sky.net>
Date2012-08-09 10:45 -0400
Message-ID<090820121045320232%star@sky.net>
In reply to#29230
Davoud:
> > The attack on Enigma was aided by misuse of keys, captured keys, and
> > re-used keys, and intimate knowledge of the workings of the machine. In
> > the same vein, we read certain Soviet messages in what came to be known
> > as the Venona project. If those OTP's had been used properly the
> > ciphers would never have been broken. As it was, it required years of
> > painstaking work.

Geoffrey S. Mendelson:
> True. However it started out because someone sitting at a desk looking
> at encrypted messages noticed there was a pattern, and that was used
> to exploit the errors, etc.

Yes, of course. But until and unless quantum computers become reality,
you are overly pessimistic about INFOSEC. Various cryptologic agencies
around the world know a number of ways to generate a cipher key that
cannot be recovered by a person sitting at a desk or by all of the
computers extant.

-- 
I agree with almost everything that you have said and almost everything that
you will say in your entire life.

usenet *at* davidillig dawt cawm

[toc] | [prev] | [next] | [standalone]


#29248

From"Geoffrey S. Mendelson" <gsm@mendelson.com>
Date2012-08-09 17:39 +0000
Message-ID<slrnk27tba.p61.gsm@cable.mendelson.com>
In reply to#29241
Davoud wrote:
> Yes, of course. But until and unless quantum computers become reality,
> you are overly pessimistic about INFOSEC. Various cryptologic agencies
> around the world know a number of ways to generate a cipher key that
> cannot be recovered by a person sitting at a desk or by all of the
> computers extant.
>

I don't think so. I think it is reasonable to say that in the foreseeable
future no one can "break" our files in a cost effective manner.

However, I disagree with the billions, or millions, thousands, and even 
hundreds of years.

This, of course, assumes that the creator of the files is not a target of
investigation by one of the intelligence/security agencies. It also assumes
that a vulnerability will NOT be found, and no "backdoor" exists.

As for the keys created by those agencies, I doubt that any of us on this
group would have access to them.

Geoff.





-- 
Geoffrey S. Mendelson,  N3OWJ/4X1GM/KBUH7245/KBUW5379


[toc] | [prev] | [next] | [standalone]


#29243

FromAlan Browne <alan.browne@FreelunchVideotron.ca>
Date2012-08-09 11:12 -0400
Message-ID<4rqdnX5GZo36Tr7NnZ2dnUVZ_sadnZ2d@giganews.com>
In reply to#29207
On 2012-08-08 11:44 , Geoffrey S. Mendelson wrote:
> Lewis wrote:
>>
>> By adding one character to my 1Password I could bump it up to 16 billion
>> years, and by changing one character to another I could bump it to 157
>> billion years.
>>
>> Despite what you see in movies, people do not 'crack' encryption.
>>
>
> Of course they do. Most people don't use such secure encryption, and even if
> they did there always is a way to crack it.
>
> Those numbers assume that someone is going to start out with all zeros in the
> key, add one and try to use it until it works.
>
> A much faster approach is to try to decrypt it with some standard keys and
> see the result. Based upon the result, you can determine the encryption
> method and with that you can use the data to figure out a working key.
>
> Not usually the key used to encrypt the data, but one that still works.
>
> This is not something you are going to find programs to do it with a web
> search, but google "large number theory" for a taste of it.
>
> This is not new, it was how the Enigma encryption was broken in WWII.

They didn't even have Apple II level computing ability in WW II.  And 
such would have been sufficient for one-time pad ciphers that would have 
been perfectly unbreakable assuming a merely good random number 
generator for the pads.

Since, at the time, "code books" were necessary to encrypt a message 
(and the corresponding codes to decrypt), ciphers of the time were 
poorly implemented.  The "break" coming from the fact that the pseudo 
randomness of the encryption machine was simply not long enough. 
Patterns eventually emerged from machines of a given model.

Today's public key codes (assuming no mathematical backdoors have been 
put in) are unbreakable over the course of several ages of the universe 
even anticipating higher speed, bigger, faster computers.

(Though a quantum computer (if ever realized) is said to be able break 
any code near instantly if there is a little bit of known information in 
the file.  A single word of 5 letters would probably suffice to get it 
on track).

-- 
"Civilization is the limitless multiplication of unnecessary necessities."
             -Samuel Clemens

[toc] | [prev] | [next] | [standalone]


#29267

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-10 01:08 +0000
Message-ID<slrnk28np9.985.g.kreme@mbp55.local>
In reply to#29207
In message <slrnk2522b.398.gsm@cable.mendelson.com> 
  Geoffrey S. Mendelson <gsm@mendelson.com> wrote:
> Lewis wrote:
>>
>> By adding one character to my 1Password I could bump it up to 16 billion
>> years, and by changing one character to another I could bump it to 157
>> billion years.
>>
>> Despite what you see in movies, people do not 'crack' encryption.
>>

> Of course they do. Most people don't use such secure encryption, and even if
> they did there always is a way to crack it.

> Those numbers assume that someone is going to start out with all zeros in the
> key, add one and try to use it until it works. 

> A much faster approach is to try to decrypt it with some standard keys and
> see the result. Based upon the result, you can determine the encryption
> method and with that you can use the data to figure out a working key.

> Not usually the key used to encrypt the data, but one that still works.

Your knowledge of encryption is a decade or more out of date.

> This is not new, it was how the Enigma encryption was broken in WWII.

Maybe read something published this millenium for a change.

-- 
'What shall we do?' said Twoflower.  'Panic?' said Rincewind hopefully.

[toc] | [prev] | [next] | [standalone]


#29177

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-08-07 22:59 -0400
Message-ID<jvskng$7ua$1@dont-email.me>
In reply to#29117
On 08-07-2012 03:01, Jeff N wrote:
> I also think that "security questions" which consist of easily
> discoverable information (mother's maiden name, street you grew up on,
> city you were born in) are outstandingly stupid gatekeepers to a process
> for resetting my password. Never ever give honest answers to those.

It is so rare for me to have to use "security questions" that I 
generally can't remember the fake answers I gave way back when.

-- 
Wes Groleau

     ASCII stupid question, get a stupid ANSI

[toc] | [prev] | [next] | [standalone]


#29184

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-08 04:31 +0000
Message-ID<slrnk23qsv.vfq.g.kreme@mbp55.local>
In reply to#29177
In message <jvskng$7ua$1@dont-email.me> 
  Wes Groleau <Groleau+news@FreeShell.org> wrote:
> On 08-07-2012 03:01, Jeff N wrote:
>> I also think that "security questions" which consist of easily
>> discoverable information (mother's maiden name, street you grew up on,
>> city you were born in) are outstandingly stupid gatekeepers to a process
>> for resetting my password. Never ever give honest answers to those.

> It is so rare for me to have to use "security questions" that I 
> generally can't remember the fake answers I gave way back when.

Right. This is why I decided to treat them as really long free-form
password fields and just put them into the password manager.

-- 
The new Death raised his cowl.  There was no face there. There was not
even a skull. Smoke curled formlessly between the robe and a golden
crown.  Bill Door raised himself on his elbows.  A CROWN? His voice
shook with rage. I NEVER WORE A CROWN!  You never wanted to rule.

[toc] | [prev] | [standalone]


Page 7 of 7 — ← Prev page 1 2 3 4 5 6 [7]

Back to top | Article view | comp.sys.mac.system


csiph-web