* Bruce Schneier’s Crypto-Gram newsletter
Bruce Schneier, founder and chief technical officer of Counterpane Internet Security, is a celebrated cryptographer and writer about fundamental issues in information assurance. Two of his most famous popular books are _Beyond Fear_ and _Secrets and Lies: Digital Security in a Networked World_. He is also the author of _Applied Cryptography: Protocols, Algorithms, and Source Code in C_. He exemplifies the ideal of an active scientist: a contributor to new knowledge, a clarifier of confusing information and a vibrant mover of his entire field.
Since 1998, he has published the free Crypto-Gram newsletter, which is always packed with useful and interesting information and insights for everyone interested in security. The March 15, 2005, issue is available at:
https://www.schneier.com/crypto-gram-0503.html
It has so many hot topics I won’t list them all. Here are highlights:
* SHA-1 Broken
Schneier reports on the discovery of methods for finding collisions of the Secure Hash Algorithm 1 (SHA-1) faster than brute force. This finding allows one to locate different messages that have the same 160-bit hash some 2,000 times faster than searching the entire keyspace. The discovery does not mean that everyone using SHA-1 has to stop. Schneier writes, “For the average Internet user, this news is not a cause for panic. No one is going to be breaking digital signatures or reading encrypted messages anytime soon. The electronic world is no less secure after these announcements than it was before.” He suggests, however, that in the long run, we will see a shift towards longer hash functions and urges a concerted effort to develop even stronger functions.
* The Failure of Two-Factor Authentication
In his essay on two-factor authentication, Schneier warns that token-based, two-factor authentication using dynamically generated data from a token combined with a stable personal identification number cannot overcome man-in-the-middle attacks or Trojan attacks. In the former, “An attacker puts up a fake bank website and entices user to that website. User types in his password, and the attacker in turn uses it to access the bank’s real website. Done right, the user will never realize that he isn’t at the bank’s website. Then the attacker either disconnects the user and makes any fraudulent transactions he wants, or passes along the user’s banking transactions while making his own transactions at the same time.”
In the Trojan attack, “Attacker gets Trojan installed on user’s computer. When user logs on to his bank’s Web site, the attacker piggybacks on that session via the Trojan to make any fraudulent transaction he wants.”
The method is not useless, argues Schneier, but in the long run it will not significantly increase Internet security.
* ChoicePoint
Schneier launches a blistering attack on ChoicePoint management for concealing its breach of security: “ChoicePoint’s behavior is a textbook example of how to be a bad corporate citizen. The information leakage occurred in October, and it didn’t tell any victims until February. First, ChoicePoint notified 30,000 Californians and said that it would not notify anyone who lived outside California (since the law didn’t require it). Finally, after public outcry, it announced that it would notify everyone affected.” More important, Schneier analyses the situation to its roots and points out that the fundamental problem is that the people whose information is stored by credit bureaus are not viewed as customers and that there are no financial consequences for theft of identity. He makes a strong case for bringing the capitalist system to bear on these people by making them bear the costs of their malfeasance.
Well, that’s just a few of the interesting items in this month’s Crypto-Gram. I hope that those of you who have not yet subscribed will be moved to visit the archive at:
https://www.schneier.com/crypto-gram-back.html
Have fun browsing.
https://www.amazon.com/exec/obidos/ASIN/0387026207/fusion0e/ref%3Dnosim/102-9762002-1394528
Beyond Fear
Amazon.com
https://www.amazon.com/exec/obidos/ASIN/0471453803/fusion0e/ref%3Dnosim/102-9762002-1394528
Secrets and Lies: Digital Security in a Networked World
Amazon.com
https://www.amazon.com/exec/obidos/ASIN/0471117099/fusion0e/ref%3Dnosim/102-9762002-1394528
Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition
Amazon.com




