Earlier quoted context omitted.
This is Sweet32, an attack on any block cipher with an 8-byte block size. We don't consider those ciphers "broken"; they just can't be used safely in some common modes. You shouldn't use 3DES or IDEA or Blowfish, of course, but I don't think they're considered "broken", not in the same sense that, say, RC4 is.
to any non-cryptographer, i think that's a distinction without a difference. it's disallowed from use by the major standards institute due to a vulnerability where people can recover the plain text. that sounds "broken" to me, but i'm not a cryptographer. so, i'll defer to you when you say it's not broken. (i dont know what the cryptographer-specific definition of broken is -- it'd be great if you would shed some lig…
Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
31–40 of 46 posts
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#32Earlier quoted context omitted.
It's true that 64 bits was known not to be enough when DES shipped decades ago, but there is some difference between "We know that's a bad idea" and a demo showing why, and so I think I'm OK with the word "broken" in that context. There's a reason POCs matter right? Why you feel comfortable (even though I don't agree) saying multi-threaded Go doesn't have a memory safety problem and yet you wouldn't feel comfortable…
I'm not a cryptographer but to me "broken" seems to imply that the core algorithm itself can be attacked. If merely applying it in certain ways as part of some larger system can fail then aren't most (possibly all) ciphers broken? It's entirely possible to do all sorts of stupid things. Granted, a 2^32 block limit is pretty severe by modern standards.
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#33Earlier quoted context omitted.
to any non-cryptographer, i think that's a distinction without a difference. it's disallowed from use by the major standards institute due to a vulnerability where people can recover the plain text. that sounds "broken" to me, but i'm not a cryptographer. so, i'll defer to you when you say it's not broken. (i dont know what the cryptographer-specific definition of broken is -- it'd be great if you would shed some lig…
Again: not a vulnerability in the cipher.
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#34Earlier quoted context omitted.
Surely someone who has been here as long as you have understands that this type of behavior is not compatible with the guidelines. > Converse curiously; don't cross-examine. You could have just corrected them and not goaded them into further revealing their ignorance. Yes, they underestimated how difficult it is to crack 3DES. You could have simply told them that.
this is a very common pattern in tptacek's comments, but it's not worth calling out as he absolutely refuses to recognize it, always falling back to a similar response you see here. with a quick google of "3des broken" and reading the first paragraph of wikipedia on 3des, i was able to guess (correctly!) what they original commenter was referring to.
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#35Earlier quoted context omitted.
You could never, in a million years, have guessed by "broken" they meant "it can be decrypted by the public with little effort?" I doubt that. I see no evidence they are talking about a password hash. Here's what they actually cited: > The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, ... They're clearly talking about it's use as a cipher. Again, someone wh…
Do we have conflicting premises about what Hashcat is? I'm pretty sure you're just wrong here.
They were clearly suggesting that there exists a publicly available tool to attack this algorithm. They clearly didn't care one way or the other about whether it was used in passwords. What they actually cited was vulnerabilities in network services.
You are being disingenuous. Cut it out.
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#36Earlier quoted context omitted.
Do we have conflicting premises about what Hashcat is? I'm pretty sure you're just wrong here.
Do we have conflicting premises about what SSH is? I'm pretty sure you're dodging and deflecting from the actual issues here. They were clearly suggesting that there exists a publicly available tool to attack this algorithm. They clearly didn't care one way or the other about whether it was used in passwords. What they actually cited was vulnerabilities in network services. You are being disingenuous. Cut it out.
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#37Earlier quoted context omitted.
Do we have conflicting premises about what SSH is? I'm pretty sure you're dodging and deflecting from the actual issues here. They were clearly suggesting that there exists a publicly available tool to attack this algorithm. They clearly didn't care one way or the other about whether it was used in passwords. What they actually cited was vulnerabilities in network services. You are being disingenuous. Cut it out.
What are you talking about? No there isn't. There is no "publicly available tool to attack 3DES". Hashcat is a password cracker. You know what else it supports? AES. Is AES broken?
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#38Earlier quoted context omitted.
What are you talking about? No there isn't. There is no "publicly available tool to attack 3DES". Hashcat is a password cracker. You know what else it supports? AES. Is AES broken?
It's very difficult for me to imagine a way you could have read my remarks in good faith and come to that conclusion. I hope someday you figure this out, I guess I have no hope of explaining it.
They were clearly suggesting that there exists a publicly available tool to attack this algorithm.
What were you referring to? If it was Hashcat, then I have just one more question:
Is Hashcat a publicly available tool that attacks AES?
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#39Earlier quoted context omitted.
It's very difficult for me to imagine a way you could have read my remarks in good faith and come to that conclusion. I hope someday you figure this out, I guess I have no hope of explaining it.
Here's a simple question. When you said: They were clearly suggesting that there exists a publicly available tool to attack this algorithm. What were you referring to? If it was Hashcat, then I have just one more question: Is Hashcat a publicly available tool that attacks AES?
Re: Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
#40Earlier quoted context omitted.
Here's a simple question. When you said: They were clearly suggesting that there exists a publicly available tool to attack this algorithm. What were you referring to? If it was Hashcat, then I have just one more question: Is Hashcat a publicly available tool that attacks AES?
I'm not going back and forth with you if you're not going to discuss the thrust of our disagreement. I am not wading into this minutia with you. I see the game you are playing to evade the subject I am trying to discuss; I'm not interested in playing.