Re: Status of the Java Port?
Wolfgang Keller <[email protected]>
| Newsgroups | gmane.comp.security.passwordsafe.devel |
|---|---|
| Message-ID | <[email protected]> |
It is rather simple what I mean by this. Statement A.: "PWS uses outdated security technology" I am referring here to both security functions, namely the encryption algorithm Blowfish and the cryptological hash function SHA-1. a) Blowfish falls into the category of 8 byte block modification schemes. This feature it has in common with the late DES standard which now is practically an open book for crypt-analysts. Although it is granted that Blowfish has a better reputation than DES, obviousely some American official came to the conclusion that 8 byte block modification is considered a security hazard in respect to ever growing capabilities of modern cryptanalysis and fast computers. Hence the new standard AES was developed which has a minimum of 16 byte block modification. As speaking of the same fathers, Twofish is the successor of Blowfish with considerably increased security and hence, just by this fact and in this sense, Blowfish is outdated. - This is of course nothing new to you. b) SHA-1 has recently been identified as a possible security risk as some people found a way to trace collisions. Tracing collisions may be used for cryptanalytical methods on the ciphertext. For the moment it may not seem likely to happen, but who knows? Things are changing and SHA-1 is marked for substitution even by the NIST. Outdated No. 2. Statement B.: ".. implementation is partly resting on doubtful and erroneous quality" While basically true, I like to revoke this. I came to the conclusion after having seen that the SHA-1 code has been tampered with in some way that seemed to render propriatory (hence doubtful) results. At a closer look today, however, it showed that the basic security function of the SHA-1 implementation is alive and only in a small substep there exists an erroneous result in the sense that this result it is not a SHA-1 digest but something different. As this step is a secondary step based on a well-formed SHA-1 value, the "doubtful" result should not be expected to cause a security damage (under the assumption the SHA-1 does the job). So please take my apologies for statement B; I will weaken it to " ... implementation partly rests on a propriatory HMAC function." My basic conclusion on PWS is however unchanged. Cheers! - Wolfgang J. Wren Hunt wrote: >-----BEGIN PGP SIGNED MESSAGE----- >Hash: RIPEMD160 > > > >Wolfgang Keller wrote: ><snip!> > > >>work, and it ripened to almost a first release, but I have given up on >>it after considering a few facts about passwordsafe in general which >>have brought me to the conclusion that its security technology is >>basically outdated and its implementation is partly resting on doubtful >>and erroneous quality. - I have plans to use my developments for a >>different project, at an indeterminate time. >> >> >> >So I just gotta ask - can you elaborate on what you mean by this and >possibily provide examples? Thx! > > >- -- > >Cheers! > >J. Wren Hunt >Cambridge, MA. USA > >- ------------ >"The difference between the right word and the almost right word is the >difference between lightning and the lightning bug." > -- Mark Twain > >+------------------------------------------------------------------+ >| v-card http://wrenhunt.homelinux.org/data/wren.vcf | >| x.509 http://wrenhunt.homelinux.org/data/thawte_wren_hunt.cer | >| OpenPGP ADF5 1432 A59E 8F4D 4AE7 4DFE 03FA 91E1 4A24 D6F4 | >+------------------------------------------------------------------+ > > >-----BEGIN PGP SIGNATURE----- >Version: GnuPG v1.4.1 (Darwin) > >iD8DBQFCbqiMA/qR4Uok1vQRA1JgAKD+uLTpt7BWGUu0xPyjimaPi2VpBACfXqq1 >IuQdofeQjbtOJs/8HJtoRUU= >=QnOT >-----END PGP SIGNATURE----- > > >------------------------------------------------------- >SF.Net email is sponsored by: Tell us your software development plans! >Take this survey and enter to win a one-year sub to SourceForge.net >Plus IDC's 2005 look-ahead and a copy of this survey >Click here to start! http://www.idcswdc.com/cgi-bin/survey?id=105hix >_______________________________________________ >Passwordsafe-devel mailing list >[email protected] >https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel > > > >