Re: UBE '98 (was Re: Snake Oil)

New Message Reply About this list Date view Thread view Subject view Author view

Mike Stay (staym@accessdata.com)
Tue, 11 Aug 1998 16:22:39 -0600


Joe Peschel wrote:

>Mike,
>have you looked at the thing or are you speculating?

I downloaded the thing. It asks for a bunch of information (like e-mail
address, name, address, 25 random keystrokes). I wrote Peter about how
he created the key and he says it's MD5 and SHA plus some "random bytes
from various places in the computer." The key is stored somewhere and
protected with a password. It's always the same key. I encrypted a
file of zeros and another file, XORed the two and got the original. A
known plaintext attack will break every file you ever encrypt with this
(because it only generates one key, ever.)

-- 
Mike Stay
Cryptographer / Programmer
AccessData Corp.
mailto:staym@accessdata.com


New Message Reply About this list Date view Thread view Subject view Author view

 
All trademarks and copyrights are the property of their respective owners.

Other Directory Sites: SeekWonder | Directory Owners Forum

The following archive was created by hippie-mail 7.98617-22 on Sat Apr 10 1999 - 01:10:58