Cryptography
Cryptography and encryption software, hardware, issues, articles and conferences.

 


















Subscribe to "Cryptography" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.

 

 

  Wednesday, February 14, 2007


Hacker cracks HD copy protection.

Years to develop; days to break

A lone hacker has unlocked the master key preventing the copying of high-definition DVDs in a development that is sure to get the entertainment industry's knickers wrapped tighter than a magnet's coil. What's more, the individual was able to defeat the technology with no cracking tools or reverse engineering, despite the millions of dollars and many years engineers put into developing the AACS (Advanced Access Content System) for locking down high-definition video.

[The Register - Music and Media]
7:51:01 PM    

miniLinks for 2007-02-13.
[EFF: Deep Links]
7:44:41 PM    

(IN)SECURE Magazine Issue 10. Articles in this issue include: Microsoft Windows Vista: significant security improvement?, Review: GFI Endpoint Security 3, Interview with Edward Gibson, Chief Security Advisor at Microsoft UK, Top 10 spyware of 2006, The spam problem and open source filtering solutions, Office 2007: new format and new protection/security policy, Wardriving in Paris, Interview with Joanna Rutkowska, security researcher, Climbing the security career mountain: how to get more than just a job, RSA Conference 2007 report, ROT13 is used in Windows? You're joking! and Data security beyond PCI compliance - protecting sensitive data in a distributed environment. [(IN)SECURE Magazine Notifications RSS]
7:35:00 PM    

TSA - Not Living Up to Its Middle Name.

The Transportation Security Administration is extending an olive branch to airline travelers who have been delayed or prevented from boarding a plane on account of their name matching an identical one on the agency's "no-fly" list. The TSA recently created a Web site designed to help disgruntled detainees clear their name. However, the would-be passenger must supply some personal data, including date and place of birth, as well as identifying numbers for a driver's license, birth certificate or passport.

This could be a useful service. But TSA is not living up to its middle name - Security. TSA and the contractor that built the site have overlooked a key piece of cyber protection. The site requests a lot of personal information. When a person clicks on "submit form," it transmits an individual's data to TSA without the benefit of the secure data transfer offered by secure sockets layer. In a site secured by SSL, a Web address begins with an "https://" rather than "http://".

Consider what this means for a passenger who is stewing in the airport terminal after missing his flight because a TSA screener confused him with that other Robert Johnson on the TSA's special list. The good Mr. Johnson is told he can try to prevent this misunderstanding from happening again if he submits data requested by the travel identity verification site. He pops open his laptop, hops on the airport terminal's wireless network, completes the form and clicks "submit." Meanwhile, a digital terrorist on the other side of the terminal has just captured the data Johnson submitted because it was sent without SSL.

A tip o' the hat to Chris Soghoian, the boarding pass hacker who spotted this latest transportation security foible.

Noted cryptologist and security expert Bruce Schneier is fond of saying that so much of the Homeland Security Department's protections are "security theater." He says they are constructs designed not necessarily to make us more secure but rather to make us feel more secure. I think that aptly captures much of what is sold to the public in the name of physical and Internet security. But a security device should at least adhere to the physician's motto -- to do no harm.

Update, 9:10 a.m.:Some folks have written in to say they've seen the site offer an SSL certificate but that it warns of a certificate error. If you navigate to the submission form from the main page by clicking on the Traveler Identity Verification form link, it takes you to this page, which offers two links to the same form -- one beginning in "https://" (the link at the top), and another one halfway down the page that does not offer the SSL certificate.

Those commenting so far were visiting the site in Firefox, but when I visit the SSL page in Internet Explorer 7, it gives me a warning page that says "There is a problem with this Web site's security certificate. We recommend that you close this webpage and do not continue to this website."

[Security Fix]
7:31:50 PM    

New Hack Simplifies HD Video Copying. Hacker claims to have discovered cryptographic key that can circumvent copy restrictions on HD DVD and Blu-ray movies. [PC World: Latest Technology News]
7:26:52 PM    


Click here to visit the Radio UserLand website. © Copyright 2007 Paul Hardwick.
Last update: 3/4/07; 3:02:57 AM.

February 2007
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28      
Jan   Mar