mersenneforum.org  

Go Back   mersenneforum.org > Extra Stuff > Soap Box

Reply
 
Thread Tools
Old 2013-09-07, 10:05   #265
xilman
Bamboozled!
 
xilman's Avatar
 
"๐’‰บ๐’ŒŒ๐’‡ท๐’†ท๐’€ญ"
May 2003
Down not across

2·5,393 Posts
Default

Quote:
Originally Posted by ewmayer View Post
New Snowden documents say NSA can break common Internet encryption: (Reuters) - The U.S. National Security Agency has secretly developed the ability to crack or circumvent commonplace Internet encryption used to protect everything from email to financial transactions, according to media reports citing documents obtained by former NSA contractor Edward Snowden.
Suspicions are mounting that one of the alleged backdoors may be in a widely used cryptographic random number generator called Dual_EC_DRBG

The article suggests how such a backdoor might be implemented in practice.
xilman is offline   Reply With Quote
Old 2013-09-07, 17:28   #266
cheesehead
 
cheesehead's Avatar
 
"Richard B. Woods"
Aug 2002
Wisconsin USA

170148 Posts
Default [OT]

[OT]

Bring back the lava lamp RNG!
cheesehead is offline   Reply With Quote
Old 2013-09-07, 18:31   #267
xilman
Bamboozled!
 
xilman's Avatar
 
"๐’‰บ๐’ŒŒ๐’‡ท๐’†ท๐’€ญ"
May 2003
Down not across

2·5,393 Posts
Default

Quote:
Originally Posted by cheesehead View Post
[OT]

Bring back the lava lamp RNG!
Nice in theory. A real pig to put into practice.

Incidentally I have a USB "lava-lamp". It consist of a container of liquid, probably water, and some flakes of aluminized plastic foil. The liquid is heated by three LEDs which are cycled by a PIC. Unfortunately the green LED stopped working about a year ago. I took the contraption to bits but was unable to repair it.
xilman is offline   Reply With Quote
Old 2013-09-07, 20:21   #268
ewmayer
2ω=0
 
ewmayer's Avatar
 
Sep 2002
Repรบblica de California

19×613 Posts
Default

Quote:
Originally Posted by xilman View Post
Nice in theory. A real pig to put into practice.
I wonder how difficult it would be to implement a tiny RNG based on decays of a smoke-detector-style radioactive-material module. Safely encapsulated, obviously, and using a tiny amount of stuff which need have a half-life only around that of a typical computer.

Edit: It just occurs to me that the above is alas incompatible with applications requiring "repeatably random" number sequences.

Quote:
Incidentally I have a USB "lava-lamp". It consist of a container of liquid, probably water, and some flakes of aluminized plastic foil. The liquid is heated by three LEDs which are cycled by a PIC. Unfortunately the green LED stopped working about a year ago. I took the contraption to bits but was unable to repair it.
Replacements available for < $10 at your local online retailer.

Last fiddled with by ewmayer on 2013-09-07 at 20:35
ewmayer is online now   Reply With Quote
Old 2013-09-07, 20:37   #269
fivemack
(loop (#_fork))
 
fivemack's Avatar
 
Feb 2006
Cambridge, England

23×11×73 Posts
Default

Quote:
Originally Posted by xilman View Post
Nice in theory. A real pig to put into practice.
This very iPad has front and back-mounted 2D arrays of decent-quality Poisson noise sources: even assuming very horrible correlations and per-pixel variable dark current, md5sum(take-a-photo) should be entropic enough, whether the lens cap be on or no.
fivemack is offline   Reply With Quote
Old 2013-09-08, 07:30   #270
xilman
Bamboozled!
 
xilman's Avatar
 
"๐’‰บ๐’ŒŒ๐’‡ท๐’†ท๐’€ญ"
May 2003
Down not across

2·5,393 Posts
Default

Quote:
Originally Posted by ewmayer View Post
Replacements available for < $10 at your local online retailer.
Oh, I know that, that's not the point. The original was a present and I've no great desire to replace it. The interest was in finding out how it was constructed and whether something as simple as a re-soldered joint might be sufficient to repair it
xilman is offline   Reply With Quote
Old 2013-09-10, 20:00   #271
ewmayer
2ω=0
 
ewmayer's Avatar
 
Sep 2002
Repรบblica de California

2D7F16 Posts
Default

NSA unveils its brand new fingerprint database ... oh wait, did the ZHers actually write that title? They meant, of course, "New iPhone 5S includes 'touch id' fingerprint-sensor technology". I'm sure they are very sorry about the typo.


U.S. tapped into networks of Google, Petrobras, others: report: (Reuters) - The U.S. government tapped into computer networks of companies including Google Inc. and Brazilian state-run oil firm Petroleo Brasileiro SA, according to leaked U.S. documents aired by Globo, Brazil's biggest television network.
Quote:
A week after it broadcast a report that the U.S. National Security Agency spied on the presidents of Brazil and Mexico, Globo said the agency had also spied on major companies.

It showed slides from an NSA presentation, dated May 2012, that it said was used to show new agents how to spy on private computer networks.

In addition to Google and Petrobras the presentation suggested the NSA had tapped into systems operated by France's foreign ministry and the Society for Worldwide Interbank Financial Telecommunication, an international bank cooperative known as Swift, through which many international financial transactions take place.
Hey, man, It's not industrial espionage if it's done in the name of the Holy War on Terror.
ewmayer is online now   Reply With Quote
Old 2013-09-11, 07:30   #272
Nick
 
Nick's Avatar
 
Dec 2012
The Netherlands

29×59 Posts
Default

The NSA's next move: silencing university professors?
Quote:
This actually happened yesterday:
A professor in the computer science department at Johns Hopkins, a leading American university, had written a post on his blog, hosted on the university's servers, focused on his area of expertise, which is cryptography. The post was highly critical of the government, specifically the National Security Agency, whose reckless behavior in attacking online security astonished him.
The post was widely circulated online because it is about the sense of betrayal within a community of technical people who had often collaborated with the government. (I linked to it myself.) On Monday, he gets a note from the acting dean of the engineering school asking him to take the post down and stop using the NSA logo as clip art in his posts. The email also informs him that if he resists he will need a lawyer.
Full article:
http://www.theguardian.com/commentis...-johns-hopkins
The university later backed down.

The computer science department of Cambridge University in the UK also receives pressure, such as in this example from a year or two ago where an ex-government minister writes on behalf of bankers:
http://www.cl.cam.ac.uk/~rja14/Papers/2011_10_11_16_00_32.pdf

Ross Anderson's response was typically robust:
http://www.cl.cam.ac.uk/~rja14/Papers/ukca2.pdf

Quote:
For my part I believe that the UK Cards Association owes us a clarification and an apology, plus an undertaking to cease and desist from harassing security researchers.
Nick is offline   Reply With Quote
Old 2013-09-11, 17:22   #273
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

100110001101102 Posts
Default

Are the NIST Standard Elliptic Curves Back-doored?
chalsall is online now   Reply With Quote
Old 2013-09-11, 19:32   #274
garo
 
garo's Avatar
 
Aug 2002
Termonfeckin, IE

22×691 Posts
Default Who is the real boss?

http://www.theguardian.com/world/201...rael-documents

Quote:
The National Security Agency routinely shares raw intelligence data with Israel without first sifting it to remove information about US citizens, a top-secret document provided to the Guardian by whistleblower Edward Snowden reveals.
Details of the intelligence-sharing agreement are laid out in a memorandum of understanding between the NSA and its Israeli counterpart that shows the US government handed over intercepted communications likely to contain phone calls and emails of American citizens. The agreement places no legally binding limits on the use of the data by the Israelis.
garo is offline   Reply With Quote
Old 2013-09-11, 20:41   #275
chalsall
If I May
 
chalsall's Avatar
 
"Chris Halsall"
Sep 2002
Barbados

2·67·73 Posts
Default

Quote:
Originally Posted by garo View Post
Who is the real boss?
An excellent question.

Imagine the deafening silence in response....
chalsall is online now   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
I'm rich AND on a government check. jasong jasong 18 2013-08-12 18:21
How does proper government manifest in regulation? cheesehead Soap Box 10 2011-04-17 02:29

All times are UTC. The time now is 22:21.


Fri Aug 6 22:21:17 UTC 2021 up 14 days, 16:50, 1 user, load averages: 3.03, 3.34, 3.18

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2021, Jelsoft Enterprises Ltd.

This forum has received and complied with 0 (zero) government requests for information.

Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.
A copy of the license is included in the FAQ.