TechHui

Hawaii's Tech Community

Information

Crypto & Security

Nalbar vagrerfgrq va urycvat zr vzcyrzrag gur Ravtzn znpuvar'f pvcure va WninFpevcg? Yrnir n zrffntr sbe Oebbxr ba gur Pbzzrag Jnyy orybj...

Members: 13
Latest Activity: Nov. 15, 2008

Go on, try it...

Discussion Forum

Brooke Fujita

NSA History Documents on the National Security Archive

Started by Brooke Fujita Nov. 15, 2008.

Brooke Fujita

Key Duplication by Photograph? 3 Replies

Started by Brooke Fujita. Last reply by Jerry Nov. 9, 2008.

Brooke Fujita

NIST Contest to Find the New SHA-3

Started by Brooke Fujita Nov. 1, 2008.

Schneier on Security

The Best Capers of 2008

Good list....

Kip Hawley Is Starting to Sound Like Me

Good quote: "In the hurly-burly and the infinite variety of travel, you can end up with nonsensical results in which the T.S.A. person says, 'Well, I'm just following the rules,'" Mr. Hawley said. "But if you have an enemy who is going to study your technology and your process, and if you have something they can figure out a way...

FBI's New Cryptanalysis Contest

From their website....

Comment Wall (6 comments)

Add a Comment

You need to be a member of Crypto & Security to add comments!

6 Comments

Brooke Fujita Comment by Brooke Fujita on November 14, 2008 at 4:47pm
xkcd on Crypto

Daniel Leuck Comment by Daniel Leuck on September 18, 2008 at 11:13am
Brooke: Regarding writing the enigma machine in GWT, I wonder: are script tags allowed?
You can call in and out of Javascript from GWT using JSNI. We do this quite a bit on our current project.
Brooke Fujita Comment by Brooke Fujita on September 12, 2008 at 5:12am
Yo there, Dan:

Yeah, I do like the GWT, I would love to try out the 1.5 release. Regarding writing the enigma machine in GWT, I wonder: are <script> tags allowed? I would need to use that to load the entry point...
Daniel Leuck Comment by Daniel Leuck on September 9, 2008 at 1:00am
Hey Brooke - I love that the description of the group is encoded :-) I see from your ROT13 widget you are getting into Laszlo. Thats great!

Re: Writing the enigma machine's cipher in Javascript.

I just finished writing a wiki sytax -> html converter that runs on the client for ooi. I wrote it in Java and converted it to Javascript using GWT's compiler. You are limited to classes available in the JRE emulation environment, but it beats writing complex logic in Javascript (at least for me), and the compiler emits highly optimized code. You might want to try this approach.
Brooke Fujita Comment by Brooke Fujita on August 21, 2008 at 12:28pm
In case you didn't know, the image for this group is of a 3-rotor Enigma, the cipher machine created by Nazi Germany for use in World War II.

As luck would have it, I just watched that Matthew McConaughey movie U-571 on NHK Satellite TV the other night. Can't believe the tomatometer for this stinker is leaning towards the fresher side. History was re-written in order to sell this movie. Argh, I am only sorry that I tuned in too late to see Jon Bon Jovi get decapitated by flying debris. Seriously.

By the way, one of the major historical inaccuracies: the British Navy scored the first Enigma machine when they captured U-110 in May of 1941. But even before that, Polish mathematicians in Poland's cipher bureau had figured out the internal wirings of the Enigma machine, and at great risk, managed to pass this information along to the Allies in 1939 just before the German invasion.

The advanced encryption used by Germany led to the development of cryptanalysis at Britain's Bletchley Park, and of course paved the way for modern computing.
Brooke Fujita Comment by Brooke Fujita on August 6, 2008 at 6:26pm
Dan Kaminsky finally outlined the DNS vulnerability that was reported about 4 weeks ago (article on The Register). It appears to be a DNS forgery variant of DNS cache poisoning. If an attacker of a DNS server can quickly and correctly guess a 16-bit transaction ID, then the attacker will be able to replace DNS entries with their own spoofed ones. There has been one confirmed attack so far, where the attacker caused AT&T subscribers to be re-routed to fake Google pages.

For the curious, you might want to see how safe your ISP's DNS servers are. Try the "Check My DNS" button on Dan Kaminsky's site; or the "Test My DNS" link here. The key here is to see the amount of randomness of transaction IDs and query source ports in your ISP's DNS servers.
 

Members (13)

Brooke Fujita Jerry Daniel Leuck Sub Callnop Mika Leuck Cameron Souza Jon Rosebaugh Robert L. Koenig Adam Leszczynski Bill Stuart Malin John Atienza Rocco Blais
 
 
 

© 2009   Created by Daniel Leuck

Badges  |  Report an Issue  |  Privacy  |  Terms of Service