A blog doesn't need a clever name
Cyberethics, Crypto, Community, Freedom, Privacy, Property, Philosophy, MP3, Online Ed, Copyright, Iran, other current topics and fun stuff
Last updated:
2/1/06; 6:18:50 AM


January 2006
Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31        
Dec   Feb



Subscribe to this blog in Radio:
Subscribe to "A blog doesn't need a clever name" in Radio UserLand.

Click to see the XML version of this web page.

Didn't find what you were looking for?




-
Listed on BlogShares

E-mail this blog's author, Bruce Umbaugh:
Click here to send an email to the editor of this weblog.
 

Monday, January 30, 2006

"Rainbows" (humongous look up tables) to crack passwords (from November).
Over the past two years, three security enthusiasts from the United States and Europe set a host of computers to the task of creating eleven enormous tables of data that can be used to look up common passwords. The tables - totaling 500GB - form the core data of a technique known as rainbow cracking, which uses vast dictionaries of data to let anyone reverse the process of creating hashes - the statistically unique codes that, among other duties, are used to obfuscate a user's password.

. . . . Called RainbowCrack Online, the site allows anyone to pay a subscription fee and submit password hashes for cracking.

"Usually people think that a complex, but short, password is very secure, something like $FT%_3^," said Travis, one of the founders of RainbowCrack Online, who asked that his last name not be used. "However, you will find that our tables handle that password quite easily."

. . .

The latest attack focuses on the hash functions used to verify passwords. Because operating systems cannot keep a copy of the password on the disk without weakening system security, the software instead saves a statistically unique code generated from the pasword. While the code, or hash, is computationally easy to create, reversing the process to recover the password is nearly impossible, given a correctly implemented hash function.

Rainbow tables side step the difficulty in cracking a single password by instead creating a large data set of hashes from nearly every possible password. To break a password, the attacker merely looks up the hash to find the password that produces that code.

"Creating the tables takes much more time than cracking a single hash, but then you can use the tables over and over again," said Philippe Oechslin, CEO of Swiss information-technology firm Objectif Sécurité and the inventor of rainbow tables. "The advantage of rainbow tables is that once you have the tables it is faster than a brute force (attack) and it needs less memory than a full dictionary (attack) of the function."


2:29:57 PM    comment []

Four from BNA News:
THE RISKS AND REWARDS OF DATA RETENTION
My weekly Law Bytes column examines the U.S. Department of Justice's demand for search data from the world's leading search engines. While much of the focus has been on the privacy implications of the request, I argue that the story highlights a much bigger issue - the significant risks and rewards that arise from data retention.
Toronto Star version
Freely available column

GATES SUPPORTS GOOGLE'S MOVE INTO CHINA
Bill Gates said on Friday the spectre of state censorship and the proliferation of illegal software should not deter technology companies from doing business in China. Microsoft, Google, and Yahoo have been criticized for acquiescing to Chinese government demands to block access to certain sites, a move critics contend suppresses free speech in the country. CNET coverage
SiliconValley.com coverage

GOOGLE ADDRESSES CHINA SEARCH RESULTS A day after Google's buggy censorship of sites for Chinese-users was revealed, the search giant responded by fixing its filters so topics such as beer and jokes are no longer deleted. An investigation published last Thursday by CNET News.com showed that Google's new China search engine not only censored criticisms of the Chinese government, but went further than similar services from Microsoft and Yahoo by targeting sites related to teen pregnancy, alcohol, dating and homosexuality.

HACKER WHO SELLS LEAKED WINDOWS CODE JAILED A hacker who sold a copy online of secret source code for parts of the Windows operating system that was leaked in 2004 was sentenced to two years in federal prison Friday. Like many others, the hacker downloaded a copy of the leaked code. Unlike others, he posted a note to his Web site offering it for sale.


11:29:28 AM    comment []

ebay wants you to learn how you can protect yourself from spoof (fake) emails.
9:29:08 AM    comment []

Carving out the Republicans: coverage of NSA vs. Lewinsky and Whitewater stories (Wilson). Jamison Foster of Media Matters has done a great job of compiling the stats on the differential treatment in the NYT and WaPo of stories (and related opinion-page calls for independent investigations) pertaining to Bush's authorizing NSA eavesdropping without a... [Leiter Reports: A Group Blog (Jan. 23-May 31 2006)]
6:34:10 AM    comment []

From the Value Subtraction frontier....

John Palfrey: Want to see what Google is blocking in China? Coming soon to the OpenNet Initiative. I suspect we'll see it soon here.

[The Doc Searls Weblog]
6:25:18 AM    comment []

Google’s Dual View of World.

From Dave Farber’s Interesting People mail list:

Here’s what censorship does.

Compare

Google China:
http://images.google.cn/images?q=tiananmen

Google the rest of the world:
http://images.google.com/images?q=tiananmen

[Center for Citizen Media: Blog]
6:25:18 AM    comment []

Should you bother or not? Relevant commentary in: Finding out who your "ancestors" were via DNA. [Gene Expression]
6:24:18 AM    comment []

Bubbling up.

Read this L.A. Times piece about the new Steven Soderbergh movie Bubble, before it scrolls behind the paywall. (Note: that last link goes to HDNet Films' all-Flash website, where it appears that no direct link to any item is possible. Hey, Mark, can you get your guys to fix that?)

Here's the imdb page on the movie.

Here's the LA Times editorial today on the matter.

Here's an SFChrnonicle piece about the movie. This one won't scroll behind a paywall.

 . . .

Here's the part of the story that matters:

"Bubble" clearly hews to the more esoteric side of Soderbergh's sensibility. In fact, if the casting for the movie is any indication, the future of digital cinema may rely more on the kindness of strangers like Kentucky Fried Chicken employee Debbie Doebereiner than on the largesse of superstar Julia Roberts, Hollywood's highest-paid actress, who won an Oscar for "Erin Brockovich" and has since appeared in three more Soderbergh films.

In April, Soderbergh found himself an unlikely new muse when he became fixated by Doebereiner, a pale, plump, middle-aged woman who makes her acting debut in "Bubble." Doebereiner was discovered behind the counter of a fast-food joint in rural West Virginia.

"It's pretty hilarious," Soderbergh says. "Our casting director Carmen Cuba heard Debbie from the drive-through lane yelling at these teenagers for not doing something right. Carmen leaned her head out the window and saw Debbie, pulled her car over, went right into the KFC and said to her, 'You've got to come in and interview for this movie.' Everything sort of flowed from Debbie. She has this amazing face and was even better than what I'd imagined her to be."

Likewise, Doebereiner's "Bubble" co-stars are ordinary civilians trying to scratch out a living in the Ohio River Valley. Shy high school dropout Dustin James Ashley plays shy high school dropout Kyle. He's studying to be a computer technician. Misty Dawn Wilkins appears as his romantic interest, Rose. She lives in Belpre, Ohio, with her fiance and four children and works as a receptionist at the Regis Salon in Vienna, W.Va.

Doebereiner, Ashley, Wilkins and the rest of the entirely nonprofessional cast were selected after Soderbergh and a lean crew of 11 arrived with a van, three digital video cameras, no lights and one cube truck in Parkersburg, W.Va. The director conducted auditions, then spent hours conversing with his three stars while writer Coleman Hough folded their experiences into a story outline. Cast members then made up their own dialogue for each scene on the day of shooting.

See what Soderbergh is doing here? He's showing the rest of us how to start making movies.

 . . .

[The Doc Searls Weblog]
6:23:25 AM    comment []

Looking back when today was the future: Knowledge Navigator.

(Via SentientWave)

Take a look at the way today was supposed to look, as envisioned nearly twenty years ago by John Sculley, a former Pepsico executive who actually ran Apple, for a time:

Quicktime movie.

Apple Computer • 'Knowledge Navigator'

Producer: Jane Hernandez

Director: Randy Field
Director of Photography: Bill Zarchy
Filmed on location in San Francisco
AC: Rod Williams
Gaffer: Jani Vournas

[Smart Mobs]
6:23:20 AM    comment []



© Copyright 2006 Bruce Umbaugh. Click here to send an email to the editor of this weblog.
Last update: 2/1/06; 6:18:58 AM.
Powered by
(-- £ Salon Bloggers & --)