Live data from Hacker News

Practical bruteforce of military grade AES-1024 (2021) [video]

media.ccc.de

21–30 of 93 posts

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#21
post #10

I've yet to see a good definition of what constitutes "military grade encryption" vs. regular old encryption. It generally has the opposite effect, for me at least, in the sense that I avoid any product that advertises "military grade ". Edit: I'm not actually looking for definitions of "military grade encryption", thank-you everyone who tried to explain it though. I work in cybersec, and encryption is encryption. It…

For what it’s worth this is addressed in the linked video at the 6 minute mark. The presenter shows a slide with an online post saying: “cryptography marketed as military grade is often to crypto what military music is to music” The use in the title is almost certainly self aware and tongue in cheek.

The product website uses "military grade" all over the place in the marketing materials. Certainly not tongue-in-cheek. See https://www.encsecurity.com/solutions.php and search "military".

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#23
post #10

I've yet to see a good definition of what constitutes "military grade encryption" vs. regular old encryption. It generally has the opposite effect, for me at least, in the sense that I avoid any product that advertises "military grade ". Edit: I'm not actually looking for definitions of "military grade encryption", thank-you everyone who tried to explain it though. I work in cybersec, and encryption is encryption. It…

"Military grade encryption" means that the government has signed off on the algorithms use for information up to a specific classification level. Probably the NSA, but maybe the DOD has their own department. It's certainly a vote of confidence, probably by people more educated about cryptography than you specifically, although possibly less trusted by you (in terms of skill and/or ulterior motives) than other people.

A big, undisputed, downside is that newer algorithms take longer to be approved and it's possible that people keep using the term after algorithms get deprecated.

Encryption is more like "milspec", meeting military minimum quality guidelines than "military issue" which is the cheapest implementation of milspec in physical (or electronic for that matter) goods.

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#24
PSA: AES is not broken at all here. This is a break of a crap key derivation function that used MD5.

It shows that all components of a cryptosystem are important. Attacks seldom target things like actual ciphers unless it's one known to be weak like RC4 or single-DES. They target bad constructions (like this), implementation bugs, etc.

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#25
post #20
post #10

I've yet to see a good definition of what constitutes "military grade encryption" vs. regular old encryption. It generally has the opposite effect, for me at least, in the sense that I avoid any product that advertises "military grade ". Edit: I'm not actually looking for definitions of "military grade encryption", thank-you everyone who tried to explain it though. I work in cybersec, and encryption is encryption. It…

Well, there's NSA certified devices (Type 1, Type 2, etc) which are military grade. Something using AES correctly could be a Type 3 device.. "when appropriately keyed" :-)

To me, this would be "XYZ Compliant", not "XYZ Grade".

Grade implies something fundamentally changed/altered/adjusted in the underlying product to make it suitable for government/military/whatever use. Here, though, AES is AES whether it is used by my mother or by the military.

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#26
post #10

I've yet to see a good definition of what constitutes "military grade encryption" vs. regular old encryption. It generally has the opposite effect, for me at least, in the sense that I avoid any product that advertises "military grade ". Edit: I'm not actually looking for definitions of "military grade encryption", thank-you everyone who tried to explain it though. I work in cybersec, and encryption is encryption. It…

> I've yet to see a good definition of what constitutes "military grade encryption"

Done by the cheapest contractor :)

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#27
post #10

I've yet to see a good definition of what constitutes "military grade encryption" vs. regular old encryption. It generally has the opposite effect, for me at least, in the sense that I avoid any product that advertises "military grade ". Edit: I'm not actually looking for definitions of "military grade encryption", thank-you everyone who tried to explain it though. I work in cybersec, and encryption is encryption. It…

Bruce Schneier always used the term 'snake oil' for such unfounded buzzwords and frequently did naming and shaming on his blog. But military-grade is just a buzzword. Unlike something like MIL-SPEC there is no body that determines what is military grade. And even MIL-SPEC is not very specific, most of its standards have many components that don't apply unless the vendor specifically certifies for it. But yeah most ve…

Off topic, but please consider using the correct tense when talking about people. E.g ”Uses” instead of ”used”, otherwise you are implying that the person in question is dead…

(After reading your comment I went to wikipedia to check that Bruce Schneier hadn’t unexpectedly passed away.)

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#28
Considering the amount of free encryption software, a lot even opensource, where you just add your logo and a pdf with instructions, bundle the source in a zip file somewhere not to break GPL, and you're done, fuckups like these seem more and more intentional to me.

Tech-savy users will always use "the best" tools, but for "normal people", the police having the ability to decrypt their data, is a thing government wants. If the encryption is bundled, they'll use the broken one, because the alternative (googling the software) will usually show them only the software that actually works.

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#29
post #23
post #10

I've yet to see a good definition of what constitutes "military grade encryption" vs. regular old encryption. It generally has the opposite effect, for me at least, in the sense that I avoid any product that advertises "military grade ". Edit: I'm not actually looking for definitions of "military grade encryption", thank-you everyone who tried to explain it though. I work in cybersec, and encryption is encryption. It…

"Military grade encryption" means that the government has signed off on the algorithms use for information up to a specific classification level. Probably the NSA, but maybe the DOD has their own department. It's certainly a vote of confidence, probably by people more educated about cryptography than you specifically, although possibly less trusted by you (in terms of skill and/or ulterior motives) than other people.…

So, I understand what they intend it to mean (and maybe that wasn't clear from my original message; I work in cybersec). But what you have described is an encryption scheme which meets certain standards (i.e. it is XYZ compliant). I don't think it is justifiable to call that "military grade", and that saying so is a misrepresentation used by marketing folk.

Re: Practical bruteforce of military grade AES-1024 (2021) [video]

#30
post #27

Earlier quoted context omitted.

Bruce Schneier always used the term 'snake oil' for such unfounded buzzwords and frequently did naming and shaming on his blog. But military-grade is just a buzzword. Unlike something like MIL-SPEC there is no body that determines what is military grade. And even MIL-SPEC is not very specific, most of its standards have many components that don't apply unless the vendor specifically certifies for it. But yeah most ve…

Off topic, but please consider using the correct tense when talking about people. E.g ”Uses” instead of ”used”, otherwise you are implying that the person in question is dead… (After reading your comment I went to wikipedia to check that Bruce Schneier hadn’t unexpectedly passed away.)

That is not what the past tense means, and you should maybe take some responsibility for this. OC doesnt know what Bruce schneier currently does or endorses.
Post reply on HN