Looks like your crypto-facist fantasies have been answered.

http://phys.org/news/2013-09-nsa-tor-keys.html

Also looks like I was exactly right when I said:
Unless you can implement Elliptic curve cypto, openssl does support it, but on 
redhat/centos you need to recompile openssl for ECDSA and ECDH support, 
debian/ubuntu comes with it by default now. 

Thanks for being dismissive! Because obviously that is how these things will 
get fixed.


----- Original Message -----
From: "Brad Knowles" <[email protected]>
To: "Todd Freeman" <[email protected]>
Cc: "Brad Knowles" <[email protected]>
Sent: Wednesday, August 14, 2013 11:01:19 AM
Subject: Re: [OpenWireless Tech] ANYFI IS PROPRIETARY!

On Aug 14, 2013, at 10:27 AM, Todd Freeman <[email protected]> wrote:

> I think looking at the way its currently done practically, 
> http://www.aircrack-ng.org/doku.php?id=cracking_wpa
> is what would go on, the govt simply uses much larger and faster distributed 
> hash DBs and brute forces the preshared key out of the handshake.

If that page and <http://lastbit.com/pswcalc.asp> is correct, then assuming 
they have hardware equivalent to 
<https://products.butterflylabs.com/homepage/500-gh-s-bitcoin-miner.html>, and 
you try to scale up the math, then 500TH/s would still theoretically take 
14519386921195274 years to crack a 20 character random alphanumeric password 
(~120 bits of entropy).  By that math, a fourteen character password would fall 
in 88422 years, and twelve characters would fall in seventeen years.

Personally, with massive multi-petabyte rainbow tables in RAM and improved 
hardware, I don't think it would take anywhere near that long.  My guess is 
that NSA already has quantum cryptography equipment that measures on the scale 
of dozens or hundreds of square miles of computer room floor space, and with 
quantum crypto all the sort of stuff we have been talking about so far would 
fall in linear time.


But maybe that's just my paranoid crypto-fascist conspiracy theorist side 
talking.

--
Brad Knowles <[email protected]>
LinkedIn Profile: <http://tinyurl.com/y8kpxu>
_______________________________________________
Tech mailing list
[email protected]
https://srv1.openwireless.org/mailman/listinfo/tech

Reply via email to