One-time pad prevent brute force attack

TechAdGetsdotcom | Security | Friday, July 18th, 2008

In cryptography, the one-time pad (OTP) is an encryption algorithm where the plaintext is combined with a random key or “pad” that is as long as the plaintext and used only once. A modular addition is used to combine the plaintext with the pad. (For binary data, the operation XOR amounts to the same thing.) It was invented in 1917 and patented a couple of years later.[citation needed] If the key is truly random, never reused, and kept secret, the one-time pad provides perfect secrecy. It has also been proven that any cipher with perfect secrecy must use keys with the same requirements as OTP keys. The key normally consists of a random stream of numbers, each of which indicates the number of places in the alphabet (or number stream, if the plaintext message is in numerical form) which the corresponding letter or number in the plaintext message should be shifted. For messages in the Latin alphabet, for example, the key will consist of a random string of numbers between 0 and 25; for binary messages the key will consist of a random string of 0s and 1s; and so on.

The “pad” part of the name comes from early implementations where the key material was distributed as a pad of paper, so the top sheet could be easily torn off and destroyed after use. For easy concealment, the pad was sometimes reduced to such a small size that a powerful magnifying glass was required to use it. Photos accessible on the Internet show captured KGB pads that fit in the palm of one’s hand [1], or in a walnut shell. [2]. To increase security, one-time-pads were sometimes printed onto sheets of highly flammable nitrocellulose.

The one-time pad is derived from the Vernam cipher, named after Gilbert Vernam, one of its inventors. Vernam’s system was a cipher that combined a message with a key read from a paper tape loop. In its original form, Vernam’s system was not unbreakable because the key could be reused. One-time use came a little later when Joseph Mauborgne recognized that if the key tape was totally random, cryptanalytic difficulty would be increased.

There is some term ambiguity due to the fact that some authors use the term “Vernam cipher” synonymously for the “one-time-pad”, while others refer to any additive stream cipher as a “Vernam cipher”, including those based on a cryptographically secure pseudorandom number generator (CSPRNG). [3]

Wikipedia




FireFox and Opera beta Remote Memory Information Leak

TechAdGetsdotcom | Security | Friday, February 29th, 2008

  Opera and FireFox contains vulnerable code for handling BMP files with partial palette. The code allows to craft a BMP file that leaks information from the heap. This information can be sent to remote server using canvas tag (HTML 5) and javascript.

Vulnerable Systems:
* Firefox version 2.0.0.11 and prior that support canvas.getImageData or any other method to acquire image data are affected
* Opera version 9.50 beta

Immune Systems:
* Firefox version 2.0.0.12
* Opera version 9.24
* Opera version 9.25

Download video here AVI file




Attacks on popular disk encryption systems BitLocker, FileVault, dm-crypt, and TrueCrypt

TechAdGetsdotcom | Security | Sunday, February 24th, 2008

Contrary to popular assumption, DRAMs used in most modern computers retain their contents for seconds to minutes after power is lost, even at operating temperatures and even if removed from a motherboard. Although DRAMs become less reliable when they are not refreshed, they are not immediately erased, and their contents persist sufficiently for malicious (or forensic) acquisition of usable full-system memory images. We show that this phenomenon limits the ability of an operating system to protect cryptographic key material from an attacker with physical access. We use cold reboots to mount attacks on popular disk encryption systems — BitLocker, FileVault, dm-crypt, and TrueCrypt — using no special devices or materials. We experimentally characterize the extent and predictability of memory remanence and report that remanence times can be increased dramatically with simple techniques. We offer new algorithms for finding cryptographic keys in memory images and for correcting errors caused by bit decay. Though we discuss several strategies for partially mitigating these risks, we know of no simple remedy that would eliminate them.

http://citp.princeton.edu/

Video here: http://techadgets.com/blog/?p=14




Cold Boot Attacks on Encryption Keys

TechAdGetsdotcom | Security | Sunday, February 24th, 2008













-

Accessoriesnotebook.com
Clean The Computer Of Spyware Entries With Reliable Spyware Removal Software by Arvind Singh
The Newest Work Hazard For Computer Users: CVS by Amy Thomas
Benefits Of Proper Computer Recycling & Disposal by Sam Brown
Dangers Of Illegal Computer Disposal by Sam Brown
How To Correct A Continually Rebooting Computer by Otis Cooper
Cellularmobile.info
Bulk SMS - a Revolution Of Mobile Phone Industry by ECS Technologies
Cell Phone Ring Tones; Personalize the music that you want to hear on your mobile phone by Daryl Plaza
Mobile Web Design and Development by Giovanni Gallucci
An Introduction to Mobile Psychiatric Rehabilitation by Megan Hazel
Beware of Hidden Costs When Purchasing Mobile Home Park Software by Jill Shaffer
Techadgets.com
Earn Money With Miss Upload and transfer paypal
South Korea First space rocket failed to reach proper orbit
Rockets with payloads into orbit successfully
Join freeautoresponse.com email marketing
UFO claim known as Britain's Roswell could be a "banana skin"
Digitaleditingsoftware.net
Hidden Secrets of Software by Jeffrey Colin Edwards
How To Copyright And Patent Your Software by Richard Cunningham
Hidden Secrets of Software by Jeffrey Colin Edwards
How To Copyright And Patent Your Software by Richard Cunningham
Hidden Secrets of Software by Jeffrey Colin Edwards
Freeeditingsoftware.net
Computer Fix It Software
A Review of Billing Software
User-Designed Applications. An Evolution in the Business Software Industry has Arrived.
Features And Benefits Of Anti-Spam Software
What Is Anti-Spam Software by Arvind Singh - ArticleCity.com