ELECTION 2008 | The Pub | The Field Mess | The Staff College | Bookmark WAB



Go Back   World Affairs Board > General Forums > World Affairs Board Pub > Science & Tech
Register FAQ WAB RSS Feed Forum GuidelinesMembers List Search Today's Posts Mark Forums Read

Greetings, and welcome to the World Affairs Board!

The World Affairs Board is one of the premier forums for the discussion of the pressing geopolitical issues of our time. Topics include foreign & defense policy, international security, military developments, weapons proliferation, terrorism, international strategic affairs, and politics. Our membership includes many from military, defense industry, and government backgrounds with expert knowledge on a wide range of topics. Registration is fast, simple and absolutely free so why not register a World Affairs Board account and join our community today?
Reply
 
LinkBack Thread Tools Display Modes
Old 11-28-2007, 15:16 PM   #1 (permalink)
Dwarven Pirate
Contributor
 
Join Date: 08-20-07
Posts: 325
OOPS? (cryptography)

Schneier on Security: The Strange Story of Dual_EC_DRBG

Backdoor in NSA encryption standard.
Dwarven Pirate is offline   Reply With Quote
Old 11-28-2007, 18:43 PM   #2 (permalink)
Ryan Bailey
Military Professional
 
Ryan Bailey's Avatar
 
Join Date: 09-25-07
Location: Megalopolis, US
Posts: 140
Country:
From Greg Alexander:
"...More details.... The previous post was about the "Analysis of the Linux Random Number Generator." I decided to read "Cryptanalysis of the Random Number Generator of the Windows Operating System" from Dorrendorf/Gutterman/Pinkas, for contrast. I find it odd that the flaws in the Windows generator are described as "a flaw" while the FUD about the Linux generator is described as "flaws". Let me compare and contrast:

* Entropy:
+ Linux: maybe predictable, if the moon lines up just right and you squint
+ Windows: only used every 128kB, not used for seed, and therefore mostly irrelevant
* forward-security attack:
+ Linux: possible to go back one value if there is no intervening entropy and if you have full access to kernel, O(2^64) or harder
+ Windows: possible to go back up to 128kB values with just access to user memory, O(2^23)
* backward-security attack:
+ Linux: O(1) iff there are *no* entropy events occurring whatsoever
+ Windows: O(1) for 128kB no matter what

The vulnerabilities are not even in the same realm. The Windows vulnerabilities are the sort of things that can and will be exploited in The Real World we all Know And Love. The Linux vulnerabilities are grasping at straws"

Friends, Is he not correct that the work shows prejudice ?
__________________
"If we will not be governed by God then we will be ruled by tyrants" -William Penn
Ryan Bailey is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Oops! – Swedish Style Amled Political Discussions 2 10-17-2006 02:25 AM
Oops.... Jay World Affairs Board Pub 4 12-11-2005 13:25 PM
oops we miscalculated something here. Brad Pics & Videos 4 02-03-2005 13:19 PM


All times are GMT -4. The time now is 15:08 PM.


Rochen is the business hosting sponsor of World Affairs Board and a provider of reseller web hosting services.

Powered by vBulletin® Version 3.6.9
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC8