guess who likes anonymous Web surfing...

2001-02-14 Thread Steve Bellovin
s to cloak cyberwar activities, or they want to learn the flaws of the product so they can penetrate anonymity. (Why not -- according to CNN, the NSA claims that Osama bin Laden has better communications technology than we do) --Steve Bellovin, http://www.research.att.com/~smb

Bleichenbacher finds flaw in DSA

2001-02-11 Thread Steve Bellovin
available. The attack is quite expensive; it requires O(2^64) operations, several terabytes of memory, and 2^22 signed messages. --Steve Bellovin, http://www.research.att.com/~smb

Carnivore transformed

2001-02-11 Thread Steve Bellovin
Today's Wall Street Journal reports that the FBI is changing the name of Carnivore. It will now be known as the DCS1000 -- the "DCS" stands for "Data Collection System". Clearly, that resolves all of the problems with it. --Steve Bellovin, http://www.research.att.com/~smb

it's not the crypto

2001-02-05 Thread Steve Bellovin
, not the transmission! --Steve Bellovin, http://www.research.att.com/~smb

Update on NIST crypto standards (fwd)

2001-01-09 Thread Steve Bellovin
PROTECTED] *** --- End of Forwarded Message --Steve Bellovin

Carnivore draft report released

2000-11-21 Thread Steve Bellovin
The draft Carnivore report is at http://www.usdoj.gov/jmd/publications/carniv_entry.htm I haven't checked yet to see if any of the redactions are reversible... --Steve Bellovin

software patents in Europe

2000-09-13 Thread Steve Bellovin
glut of litigation." A final decision will be made in November. --Steve Bellovin

Free speech and the DeCSS case

2000-07-26 Thread Steve Bellovin
According to today's Wall Street Journal, the judge in the DeCSS case against 2600 publisher Eric Corley (better known as Emmanuel Goldstein) has asked both sides to submit briefs on whether or not software is speech, and hence protected by the First Amendment. --Steve

Forwarded: Cable modems [and 3 other issues]

2000-07-18 Thread Steve Bellovin
do under CALEA. I don't see extending it at this point. --- End of Forwarded Message --Steve Bellovin

More one-time pads cracked?

2000-06-18 Thread Steve Bellovin
not heard of GEE, and as far as I knew the ministry used online machines. Does anyone have any details on either this system or its solution? --Steve Bellovin

legal status of digital signatures

2000-06-09 Thread Steve Bellovin
--Steve Bellovin

nothing major at AES-3...

2000-04-15 Thread Steve Bellovin
I spent the week at the Fast Software Encryption and AES-3 conferences in New York. The big news is that there was no big news. All five candidates still look solid, and there were at least as many papers on performance as on cryptanalytic results. Not only that, the former were more

book by Sarah Flannery

2000-04-11 Thread Steve Bellovin
s on order... --Steve Bellovin

secret-sharing code

2000-03-28 Thread Steve Bellovin
Are there any freely-available secret-sharing packages around? Specifically, I need to be able to set up modestly complex policies to protect a sensitive signature key. While source code would be best, I'd also be interested in smart card-based products. --Steve Bellovin

The Zimmerman Telegram

2000-02-07 Thread Steve Bellovin
about this? I know that Zimmerman (ab)used U.S. facilities to transmit the message, but it was encrypted in 0075 code, as I recall. --Steve Bellovin

Internet lobbying group

1999-07-12 Thread Steve Bellovin
According to the Wall Street Journal, nine Internet firms (AOL, Amazon.com, Yahoo, eBay, Excite@Home, DoubleClick, Inktomi, theglobe.com, and Lycos) have formed a Washington lobbying group. The purpose is to focus on issues of concern to Internet companies. The article does list privacy

Shamir's factoring machine

1999-05-05 Thread Steve Bellovin
Shamir's paper describing his design for a factoring machine is now available (with permission) at http://www.research.att.com/~smb/twinkle.ps -- I'll leave it there for a few weeks.

tapping the nte

1999-04-29 Thread Steve Bellovin
To: [EMAIL PROTECTED] From: Dave Farber [EMAIL PROTECTED] Subject: IP: "Intercepting the Internet" Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Sender: [EMAIL PROTECTED] Precedence: list Reply-To: [EMAIL PROTECTED] From: "Caspar Bowden" [EMAIL PROTECTED] To: "Dave Farber

McCain and 64-bit crypto

1999-04-02 Thread Steve Bellovin
Before cheering too much about McCain's apparent change of heart, it's worth doing some arithmetic. 64-bit ciphers are vulnerable to a brute force attack that costs 256 times what an attack on the same 56-bit cipher would cost. Plug in EFF's 250K and you see that a similar design would cost

Re: PGP compromised on Windows 9x?

1999-02-08 Thread Steve Bellovin
But what you imply, that PGP (and other programs that request passwords and passphrases from the user) should be more picky in what it accepts, is an excellent idea. Of course, it's impossible to force the user to choose a good passphrase, but requiring no fewer than, say, 12 characters that

Re: Intel announcements at RSA '99

1999-01-27 Thread Steve Bellovin
In message [EMAIL PROTECTED], Colin Plumb writes: Well, as I mentioned, I said so in fairly emphatic terms once already, although I don't know whether such access was planned or if my comments had any effect. I'm having another, more detailed discussion with the responsible designers on

Intel announcements at RSA '99

1999-01-20 Thread Steve Bellovin
Intel has announced a number of interesting things at the RSA conference. The most important, to me, is the inclusion of a hardware random number generator (based on thermal noise) in the Pentium III instruction set. They also announced hardware support for IPSEC.

publishing inventions

1999-01-19 Thread Steve Bellovin
I asked a friendly patent attorney. The Patent Office accepts what are called "statutory invention registrations" that serve this purpose. I don't know how to file one, or what they cost.

Re: Wassenaar vs. CipherSaber

1998-12-04 Thread Steve Bellovin
In message [EMAIL PROTECTED], Jim Gillogly writes: "Arnold G. Reinhold" [EMAIL PROTECTED] writes: ... descriptions on the CipherSaber web site http://ciphersaber.gurus.com . .. Any comments, suggestions, endorsements and publicity are welcome. I'll endorse it -- the pages give a good