1996-03-12 - Re: Remailer passphrases

Header Data

From: frantz@netcom.com (Bill Frantz)
To: cypherpunks@toad.com
Message Hash: 85be4b78c54719f18c6c95fe7af3ff5329e7cf839fc4e58b718be06d596b26f8
Message ID: <199603121853.KAA28808@netcom8.netcom.com>
Reply To: N/A
UTC Datetime: 1996-03-12 20:58:48 UTC
Raw Date: Wed, 13 Mar 1996 04:58:48 +0800

Raw message

From: frantz@netcom.com (Bill Frantz)
Date: Wed, 13 Mar 1996 04:58:48 +0800
To: cypherpunks@toad.com
Subject: Re: Remailer passphrases
Message-ID: <199603121853.KAA28808@netcom8.netcom.com>
MIME-Version: 1.0
Content-Type: text/plain


At  5:43 AM 3/12/96 -0500, Gary Howland wrote:
>On Mon, 11 Mar 1996, Gary Howland wrote:
>> root access to the system, something like "strings /dev/kmem" could narrow
>> the search for the passphrase down significantly.  Of course one could
>> obfuscate the passphrase by XOR'ing it with 0x80, but that's only security
>> through obscrurity.
>
>Sure, _if_ they were able to gain root access without rebooting the machine,
>but the usual scenario is that the filth turn up with black bin liners, not
>men from the NSA.

The bottom line of all cryptography is that there is something that must be
kept secret.  Since it must be kept secret, there is always a significant
level of paranoia about the means to keep the secret.  For example, one
could imagine an attacker attaching a logic analyzer to the CPU chip,
unloading the on-chip caches and then rummaging thru the system memory for
the secret.

One of the reasons classical (government) crypto users change keys
frequently is to minimize the amount of data compromised by a broken key. 
We keep hearing about NSA decrypting 20 year old cyphertext and showing
more of the workings of the atomic spy rings operating in the 40s and 50s. 
If an opponent can rubber hose the key, her job is easy.  If she has to
perform cryptoanalysis, it is much harder.  Remailers should regularly
change their keys to avoid compromising previously recorded traffic.  (They
can have a long lived key for signing their traffic keys.)

Regards - Bill


------------------------------------------------------------------------
Bill Frantz       | The CDA means  | Periwinkle  --  Computer Consulting
(408)356-8506     | lost jobs and  | 16345 Englewood Ave.
frantz@netcom.com | dead teenagers | Los Gatos, CA 95032, USA







Thread