Wednesday, May 14, 2008

Debian and Ubuntu flaw - private SSL/SSH keys guessable


The Debian Security Advisory posted up DSA-1571-1 openssl -- predictable random number generator issue today and strongly advised its users to take steps to avoid possible compromising of any systems running on Debian, such as Ubuntu.

The researcher Luciano Bello discovered a security flaw in Debian's random number generator that allows to predict a random generated number. This is caused by an incorrect Debian change to the openssl package. As a result, cryptographic key material may be guessable.

This problem not only affects Debian, but also all its derivatives, such as Ubuntu.

It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on affected systems is recreated from scratch. Furthermore, all DSA keys ever used on affected systems for signing or authentication purposes should be considered compromised.

Via: debian.org

Wednesday, March 12, 2008

TrueCrypt 5.1


What's New in version 5.1:

New features:

  • Support for hibernation on computers where the system partition is encrypted (previous versions of TrueCrypt prevented the system from hibernating when the system partition was encrypted). (Windows Vista/XP/2008/2003)
  • Ability to mount a partition that is within the key scope of system encryption without pre-boot authentication (for example, a partition located on the encrypted system drive of another operating system that is not running). (Windows Vista/XP/2008/2003)

    Note: This can be useful e.g. when there is a need to back up or repair an operating system encrypted by TrueCrypt (from within another operating system).
  • Command line options for creating new volumes. (Linux and Mac OS X)
Improvements:
  • Increased speed of AES encryption/decryption (depending on the hardware platform, by 30-90%). (Windows)
  • Faster booting when the system partition is encrypted. (Windows Vista/XP/2008/2003)
  • When the system partition/drive is encrypted, the TrueCrypt Boot Loader is now stored in a compressed form and is, therefore, smaller. If a non-cascade encryption algorithm is used (i.e., AES, Serpent, or Twofish), the TrueCrypt Boot Loader is now small enough so that a backup of the TrueCrypt Boot Loader can be (and is) stored in first drive cylinder. Whenever the TrueCrypt Boot Loader is damaged, its backup copy is run automatically instead.

    As a result of this improvement, the following problem will no longer occur: Certain inappropriately designed activation software (used for activation of some third-party software) writes data to the first drive cylinder, thus damaging the TrueCrypt Boot Loader. The affected users had to use the TrueCrypt Rescue Disk to repair the TrueCrypt Boot Loader. This will no longer be necessary after upgrading to this version of TrueCrypt (provided that the system partition/drive is encrypted using a non-cascade encryption algorithm, i.e., AES, Serpent, or Twofish).

    Note: If your system partition/drive is currently encrypted using a non-cascade encryption algorithm (i.e., AES, Serpent, or Twofish), a backup copy of the TrueCrypt Boot Loader will be automatically stored in the first drive cylinder when you upgrade to this version of TrueCrypt.
  • The minimum memory requirements for the TrueCrypt Boot Loader have been reduced from 42 KB to 27 KB (twenty-seven kilobytes). This allows users to encrypt system partitions/drives on computers where the BIOS reserves a large amount of memory. (Windows Vista/XP/2008/2003)
  • Many other minor improvements. (Windows, Mac OS X, and Linux)
Resolved incompatibilities:
  • On some computers, when performing the system encryption pretest, Windows failed to display the log-on screen. This will no longer occur. (Windows Vista/XP/2008/2003)
Bug fixes:
  • On some systems, drive letters were not correctly assigned to newly mounted non-system volumes. This will no longer occur. (Windows)
  • Many other minor bug fixes. (Windows, Mac OS X, and Linux)
TrueCrypt.org

Wednesday, February 20, 2008

Reviews: LockCrypt 1.18

LockCrypt is a free account management program written in Java. It uses high strength AES encryption to encrypt your data, so only you can access it. 1.18 adds different views and a menu option to reset all settings (incase you forget the password).

Changes in LockCrypt 1.18
  • Added wizard which loads on first run to configure database and passwords.
  • Added different views: Large icons, Small icons, List or Tiles.
  • Added Split Pane to main window to allow resizing.(Thanks Mercury52)
  • Added created and last modified fields for accounts (Thanks Mercury52)
  • Added menu option to clear all preferences.
  • Changed: Scrolling behaviour when showing a group.

LockCrypt Mobile, a J2ME version is also available. It allows you to carry your account database with you on any Java enabled mobile device.

LockCrypt.com

Thursday, February 7, 2008

TrueCrypt 5.0

Free open-source disk encryption software for Windows Vista/XP , Mac OS X, and Linux
Main Features:

  • Creates a virtual encrypted disk within a file and mounts it as a real disk.
  • Encrypts an entire hard disk partition or a storage device such as USB flash drive.
  • Encryption is automatic, real-time (on-the-fly) and transparent.
  • Provides two levels of plausible deniability, in case an adversary forces you to reveal the password:
    • Hidden volume (steganography – more information may be found here).
    • No TrueCrypt volume can be identified (volumes cannot be distinguished from random data).
  • Encryption algorithms: AES-256, Serpent, and Twofish. Mode of operation: XTS.
Further information regarding features of the software may be found in the documentation.

New features:
  • Ability to encrypt a system partition/drive (i.e. a partition/drive where Windows is installed) with pre-boot authentication (anyone who wants to gain access and use the system, read and write files, etc., needs to enter the correct password each time before the system starts). For more information, see the chapter System Encryption in the documentation. (Windows Vista/XP/2003)
  • Pipelined operations increasing read/write speed by up to 100% (Windows)
  • Mac OS X version
  • Graphical user interface for the Linux version of TrueCrypt
  • XTS mode of operation, which was designed by Phillip Rogaway in 2003 and which was recently approved as the IEEE 1619 standard for cryptographic protection of data on block-oriented storage devices. XTS is faster and more secure than LRW mode (for more information on XTS mode, see the section Modes of Operation in the documentation).

    Note: New volumes created by this version of TrueCrypt can be encrypted only in XTS mode. However, volumes created by previous versions of TrueCrypt can still be mounted using this version of TrueCrypt.
  • SHA-512 hash algorithm (replacing SHA-1, which is no longer available when creating new volumes).

    Note: To re-encrypt the header of an existing volume with a header key derived using HMAC-SHA-512 (PRF), select 'Volumes' > 'Set Header Key Derivation Algorithm'.

    Improvements, bug fixes, and security enhancements:
  • The Linux version of TrueCrypt has been redesigned so that it will no longer be affected by changes to the Linux kernel (kernel upgrades/updates).
  • Many other minor improvements, bug fixes, and security enhancements. (Windows and Linux)

If you are using an older version of TrueCrypt, it is strongly recommended that you upgrade to this version.

TrueCrypt.org

Saturday, September 29, 2007

Thumb Drive - self-destruct in 10 seconds

Thumb drives are a convenient and cool way to carry around your data, and with drive sizes in the gigabytes, you can store a ton of photos, files, music, and video in a very tiny space. Unfortunately, due to their small sizes, they are targets for information thieves.

Think about it - all that personal data - your resume, email, password-files, and pictures of your girlfriend can be picked up and copied and returned before you even noticed it was missing. You want to have this data handy, but handy for you and not for that scumbag down the hall with the sticky fingers.

Like you, the US Military wanted portable but secure storage, and the guys at IronKey stepped up. They've developed the perfect solution that's one-part thumb-drive, and two parts Mission: Impossible. Their thumb drives hold up to 4 Gigabytes of data, but includes a hardware encryption chip that scrambles the data so as to be completely unreadable without a password.


Passwords can be hacked, but not the IronKey. It's built to withstand attacks both virtual and physical. 10 incorrect password attempts, and the encryption chip self-destructs, making the contents of the flash drive totally unreadable. The contents of the drive are filled with epoxy, so if a hacker tries to physically access the chips, he'd more likely damage them instead. Even if he did get access to the memory chips, they'd be worthless without the encryption chip. Electron-shielded, even a scanning electron microscope can't get inside.

Applications built right onto the IronKey help keep your personal data safe. For example, the password manager keeps your passwords safe. How? Your passwords are securely stored in a hidden hardware-encrypted area inside the device (and not in the drive's file system), being first locally encrypted with 256-bit AES, using randomly generated keys encrypted with a SHA-256 hash of your device password. All of this data is then doubly encrypted with 128-bit AES hardware encryption. Hack that.

A secure copy of Firefox included with your IronKey encrypts your browsing session through a VPN tunnel to IronKey's Secure Sessions Service. It works by tunneling your entire web browsing communications through the Tor-based Secure Sessions proxy on your IronKey. The Secure Sessions tunnel connects over an encrypted connection to their network routing servers, which in turn route your traffic between a number of servers, and then eventually out to your destination website. This approach protects your identity and your confidentiality, encrypting and anonymizing your Web surfing on almost any network or VPN (virtual private network).

These drives have already seen duty in Afghanistan, keeping US Military secrets safe from unsavory people. They're certainly good enough even for your most sensitive data.

All this goodness is demoed here. Go check it out!
* Fast 30MBPS Read, 20MBPS Write
* Drive contents encrypted with AES CBC-Mode Encryption
* Onboard IronKey Password-manager keeps all your internet passwords safe
* Secure version of Firefox included that encrypts all your web-surfing traffic
* Encased in a potted metal case, not plastic, making it one of the strongest USB keys around
* Exceeds MIL-STD-810F military waterproofing standards
* The encryption chip self-destructs if an invasive attack is detected
* If your Ironkey is lost, you can restore from a secure backup to a new Ironkey in minutes
* Dual channel SLC NAND Flash for high-quality and read/write speeds
* Windows XP and Windows Vista only, but Mac and Linux drivers are in development

Thursday, August 30, 2007

Decrypting and re-encoding DVD-Audio

DVD-Audio is a standard for storing high quality stereo or multi-channel audio content on a standard DVD disk. Supported sample rates range from 44.1KHz up to 192KHz, with bit depths of 16, 20 or 24 bits. A DVD-Audio contains both DVD-Audio content (in the AUDIO_TS folder) and DVD-Video content (in the VIDEO_TS folder) and has the DVD-Audio logo. The audio in the AUDIO_TS folder can be either Linear Pulse Compression Modification (abbreviated LPCM, which is uncompressed) or Meridian Lossless Packing (abbreviated MLP, which is losslessly compressed). Usually, a DVD-Audio contains 5.1ch MLP / 2.0ch MLP or 5.1ch MLP / 2.0ch LPCM. There is also audio present in the VIDEO_TS folder, but of lower quality (that is with a lower sample rate and a lower bit depth). More information can be found here.

A DVD-Audio can be encrypted. The encryption is called Content Protection for Prerecorded Media (CPPM), which uses a media key block (MKB) to authenticate DVD-Audio players. In order to decrypt the audio, players must obtain a media key from the MKB, which also is encrypted. The player must use its own unique key to decrypt the MKB. If a DVD-Audio player's decryption key is compromised, that key can be rendered useless for decrypting future DVD-Audio discs. DVD-Audio discs can also contain digital watermarking technology, typically embedded into the audio once every thirty seconds. If a DVD-Audio player encounters a watermark on a disc without a valid MKB, it will halt playback. quoted from wikipedia As of today, the encryption is broken, but it is not possible to remove the watermarks yet.

The purpose of this guide is the following:

  • It explains how to decrypt and re-encode the audio of your DVD-Audio to FLAC (which is an open source lossless audio codec). This enables you to play your re-encondings on your PC without any hassle (using open source tools).
  • The above will be done retaining higher quality than the audio counterpart that is located on the video section of the disc.

As of today, it is not possible to decode the MLP tracks of your DVD-Audio using open source (or even free) tools. So you need to get one of the following two tools:

  • The Sonic filters "Sonic HD Demuxer" and "Sonic Cinemaster@Audio Decoder 4.3.0". They are directshow filters contained in the package "Sonic.CinePlayer.HD.DVD.Decoder.v4.3.rar".
  • Surcode MLP.

If you want to use AviSynth (without creating intermediate WAV files) then you need to get the Sonic filters somewhere. As of today, 192kHz 24bit MLP tracks are not supported by the Sonic filters, so you are forced to use Surcode MLP in that case. The Sonic filters which support MLP decoding are the following:

  1. CinemasterAudio.dll v4.2.0.840, SonicHDDemuxer.dll v4.2.0.59
  2. CinemasterAudio.dll v4.3.0.151, SonicHDDemuxer.dll v4.3.0.73
  3. CinemasterAudio.dll v4.3.0.169, SonicHDDemuxer.dll v4.3.0.89

Monday, August 27, 2007

DivX 6.7 Beta 1

The DivX Codec takes the power of advanced digital video compression to the next level, encoding video at resolutions up to high-definition 1920 x 1080. That's right, you heard it straight: 1080i and 1080p, at a fraction of the file size. What more can we say? Wait, we almost forgot, there is more. Read on, dear friend, for a list of DivX Codec features.

Features

* Compress digital video 5 to 10 times more than MPEG-2/DVD format and hundreds of times over raw digital video
* Encode high-definition (HD) video at resolutions up to 1080p
* Maximized performance for all HyperThreaded, dual core and dual CPU (SMP) systems
* Improved support for interlaced video
* Six carefully optimized encoding modes for balancing visual quality and performance
* Automated noise reduction reduces grain and low-light noise (common with DV cameras) without significantly degrading the video

DivX 6.7 Beta 1

Friday, April 13, 2007

Encrypt Files - File encryption utility

Encrypt Files is a file encryption utility that enables you to encrypt the content of file, using a variety of secure algorithms including Blowfish, AES, Twofish, RC6 and others. Simply select the files from the integrated file browser and encrypt them, with the algorithm of your choice. The program does not change the extension or name of the file but highlights encrypted files in the file browser, so they can be identified later. Encrypt Files also includes a file shredder to permanently delete sensitive files.

Encrypt Files HomePage

Tuesday, March 13, 2007

Laptop hard drive with on-board encryption!

ASI Computer Technologies of Markham, Ontario, Canada will be the first to sell laptop computers using Seagate Technology LLC's computer hard drives with built-in encryption technology. The Scotts Valley, California-based company has included a chip that automatically encrypts all data written to the Momentus 5400 FDE (Full Disk Encryption) hard drive on the fly, rendering it unreadable without a digital key or password and allowing all data stored on it to be instantly erased.

Seagate says its hardware-based technology has an advantage over software-based encryption (example: Microsoft’s BitLocker, include in Ultimate and Enterprise editions of Vista), in part because it would make it impossible to even start a computer without proper authentication. The 2.5-inch 160 gigabyte-capacity hard drive is to include security management software by Wave Systems Corporation of Lee, Massachusetts, to help companies use the encryption technology.

Source: CBC News