Talk About Network

Google


Register and Login
Nick
Password
Register create new account Sign up is FREE and you can post replies, new topics, bookmark posts and more!
Recover lost password


Government > Crypto > Re: ** Anyone c...
Latest [ Topics | Posts ] Archive Post A New Topic Post a Reply
<< Topic < Post Post 7 of 15 Topic 370 of 474
Post > Topic >>

Re: ** Anyone cracked CryptoSMS yet ? **

by David Eather <eather@[EMAIL PROTECTED] > Apr 12, 2007 at 09:43 PM

° Shanghai Lil ° wrote:
> A year or so ago there was much discussion about
> CryptoSMS with some self-proclaimed experts claiming
> it would be trivially easy to crack.
> 
> Has anyone cracked it yet?
> 
> 
> 
> 
A non biased account of CryptoSMS would look like this.

This does not imply any sort of meaningful security statement at all - 
It has not been cracked by anyone at sci.crypt.  And repeat; This does 
not imply any sort of meaningful security statement at all.  If you 
think it does then consider this -

The resources that an individual sci.crypter could bring to the job - 
very limited time, very limited budget and very limited computing power. 
  Compare this to a TLA, Large time with numbers of people working in 
consultation, large budget, massive computing power.

But there were (are?) deficiencies in the implementations of some 
elements of the software, such as not salting the password list combined 
with a possibly inadequate hash function MD5 (and IIRC there were also 
no multiple iterations of the hash function to generate the key - I 
could be wrong about that).

A competent security person would have avoided these problems and not 
used a damaged hash function in a new product.

So, if you would trust your secrets to a programmer who makes simple 
mistakes and thinks that beating a guy with a PC and a few spare hours 
is enough to claim his software is "unbreakable" then go ahead.

There is not much more to be said for that product.
 




 15 Posts in Topic:
** Anyone cracked CryptoSMS yet ? **
"° Shanghai Lil °&qu  2007-04-11 15:16:48 
Re: ** Anyone cracked CryptoSMS yet ? **
Bryan Olson <fakeaddre  2007-04-12 00:05:47 
Re: ** Anyone cracked CryptoSMS yet ? **
William Hugh Murray <w  2007-04-25 23:31:52 
Re: ** Anyone cracked CryptoSMS yet ? **
clark <clark@[EMAIL PR  2007-04-11 23:38:50 
Re: ** Anyone cracked CryptoSMS yet ? **
"Dave -Turner"   2007-04-12 16:28:17 
Re: ** Anyone cracked CryptoSMS yet ? **
Ignacio aecbi <literac  2007-04-12 07:43:35 
Re: ** Anyone cracked CryptoSMS yet ? **
David Eather <eather@[  2007-04-12 21:43:24 
Re: ** Anyone cracked CryptoSMS yet ? **
Ertugrul Soeylemez <do  2007-04-13 21:22:55 
Re: ** Anyone cracked CryptoSMS yet ? **
"Dave -Turner"   2007-04-14 12:34:06 
Re: ** Anyone cracked CryptoSMS yet ? **
Ertugrul Soeylemez <do  2007-04-14 16:25:11 
Re: ** Anyone cracked CryptoSMS yet ? **
Unruh <unruh-spam@[EMA  2007-04-14 17:02:29 
Re: ** Anyone cracked CryptoSMS yet ? **
"Joseph Ashwood"  2007-04-14 14:02:56 
Re: ** Anyone cracked CryptoSMS yet ? **
Ertugrul Soeylemez <do  2007-04-17 00:35:55 
Re: ** Anyone cracked CryptoSMS yet ? **
David Eather <eather@[  2007-04-18 01:21:28 
Re: ** Anyone cracked CryptoSMS yet ? **
Unruh <unruh-spam@[EMA  2007-04-17 18:04:15 

Post A Reply:
  Go here to Signup

AddThis Feed Button


About - Advertising - Contact - Frequently Asked Questions - Privacy Policy - Terms of Use - Signup

Contact
tan12V112 Fri Dec 5 6:00:25 CST 2008.