At 09:42 AM 4/26/2004, bruce wrote:
with regards to razor/cloudmark, are there any docs/white papaers/analysis
that discuss the underlying algorithms/approaches used by the overall
process???? if there are, can anybody provide information as to where they
might be located...

There's not much out there in terms of papers, etc. However, some bits and pieces of the algorithms are described in the "what's new for v2" readme:


http://razor.sourceforge.net/docs/whatsnew.php

There's a bit more you can get by reading the source, and the rest (ie: TeS and everything else server-side) is completely closed with no public details available.

Note: please RTA before making arguments about TeS being closed. It's been argued dozens of times. The most popular augment is to compare TeS to a crypto algorithm, an argument which is fundamentally flawed since TeS doesn't have any separable "keys" to keep secret like crypto algorithms do.

While security through obscurity does suck, in this case there's little other option. The behaviors of the algorithm are the key to attacking it, anyone who understands the algorithm can abuse TeS.

If you can suggest a way of doing a public algorithm for the TeS application that isn't abusable by understanding the code, I for one would love to hear your ideas. However, keep in mind this is a rather hard problem is at least as hard as good crypto is. Here you must write an anonymous, secure authentication and trust evaluation system with no secrets and no prior knowledge of which users are trustworthy or not. The algorithm must resist tampering by determined attackers who have studied all publicly available information and can sign up as an anonymous user.




------------------------------------------------------- This SF.net email is sponsored by: The Robotic Monkeys at ThinkGeek For a limited time only, get FREE Ground shipping on all orders of $35 or more. Hurry up and shop folks, this offer expires April 30th! http://www.thinkgeek.com/freeshipping/?cpg=12297 _______________________________________________ Razor-users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/razor-users

Reply via email to