-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/962/adam-bozanovich-did-not-uncover-an-nsa-ipsec-conspiracy-diffie-hellman-parameter-validation-explained/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
Ferguson and Schneier's paper on IPSec, including IKE, from a protocol design standpoint:
http://schneier.com/paper-ipsec.html
I also know from first-hand experience that a couple of the existing implementations have disastrously scary codebases.
That we should be more careful about blog titles? :)
I found and reported this problem to the security contacts of the ipsec-tools and openswan people last May, neither bothered to fix it. Some more details at: http://article.gmane.org/gmane.comp.encryption....
Of course I was being very web 1.0 about it, I guess I should have just blogged it.
MD5("barfing bunions" || secret)
Then rainbow tables cannot be used to attack it. Also, in addition to 1970's Unix crypt being a new discovery, apparently the 1980's chroot break code is also new:
http://kerneltrap.org/Linux/Abusing_chroot
Rainbow tables visualized:
http://ourworld.compuserve.com/homepages/citygl...
Well, p is always going to be zero mod p!