.comment-link {margin-left:.6em;}

filling the void

Friday, August 01, 2008

Cryptonomicon

Several years ago, I read a wonderful book by Neal Stephenson called Cryptonomicon. It is a book about the things I absolutely love to read about, WWII and cryptography. I consider this to be one of, if not the best books I have ever read. Quite frankly, if I could read only one book ever for the rest of my life, this would be it.
Now, the copy I read was my brothers. It looks like this, The Wrong Book and has the following ISBN number: 0099410672. This book has long been out of print. It was first printed in 1999 or 2000, and the best thing about it is that it has an incredibly soft spine. It is a paper back, and yet I can bend it to extreme angles without the cracking or breaking that you get with most cheaper paperbacks. In short, it's the perfect binding. Now, I've been looking for this particular edition of this book for a while, and I finally found the proper edition with the right ISBN, and a dealer that actually seemed to have it in stock (the picture even matched).
So I go to this dealer (bokus.com) and I order this book. I make damn sure that the ISBN is the right one, so that I wont get the other edition that most stores have. I shall refer to this as the "wrong" edition. It looks like this, The Right Book and it has the following ISBN number: 0099410676. As you can see, the ISBN numbers are terrible similar. This, possibly along with some stocking error or ISBN merging (having multiple ISBNs pointing to the latest edition of the book you have in store), bokus.com sent me the wrong book. I was a bit disappointed, as I was looking forward to getting my hands on the good edition once more, and reading it. So I email bokus and tell them about my predicament. They say they're sorry, and since they don't actually have they don't have the real book in stock, and neither does their supplier. Fair enough I think, it is a fairly rare book this long after the original publication. So, they tell me, we've clearly sent you the wrong book, would you like to return it for a complete refund? I say yes, unfortunately this isn't the book I want, how do we solve the return issue. It should be noted that I ordered this book from a Swedish retailer, and I currently live in the Netherlands, so they had to ship it for more than the book was worth. So, I've told them that I want to return it, and could they please instruct me as to how. The next email I get from them says something like "lets do this, it's probably going to cost us more to ship the book back than the book is actually worth, so you can just keep the book and I've already refunded your money".
Lets let that sink in for a minute, they were not only nice and had a swift response, but they were also apologetic about their mistake and they GAVE ME THE BOOK FOR FREE in the end! How cool is that! That's not something you see every day. Needless to say I was very pleased with this evolution of the matter so I wrote them a nice thank you letter, and now I actually have a free copy of the cryptonomicon. Wrong edition as it may be, they were so nice to me, and it was free in the end, so I really can't complain that much. Now if the rest of my problems could solve them selves with such ease I would be a happy man.

Labels: , , , , ,

Friday, November 23, 2007

Skype Crypto Unbreakable by German Police

Slashdot is running this article today. It's about how the German police is having difficulty breaking the cryptography used by the popular voice communication software Skype.

Germany's top police officer, Joerg Ziercke, said. "The encryption with Skype telephone software ... creates grave difficulties for us... We can't decipher it. That's why we're talking about source telecommunication surveillance — that is, getting to the source before encryption or after it's been decrypted."
My first reaction to this was "so, any and all other forms of encryption are easily breakable to you then?". This is, hopefully, not true, but it was phrased in such a way.
There was an especially good comment, with a really good finisher, and it was this one by hanssprudel:

This is a good thing. Having to install monitoring at the source or destination means an operation that requires effort and, hopefully, a court order. This means that their is judicial oversight, and that to catch criminals police have to do, you know, police work rather than just sitting around spying on us.

Ubiquitous encryption does not make law enforcement impossible. It just makes indiscriminate law enforcement impossible.
The bold face is mine. (If hanssprudel doesn't like me reprinting this, he's welcome to talk to me about it, and I'll fix it).
I think it's a good thing that the police should have to earn their keep. Sure, the beat cops are out there getting shot at, and they earn their paycheck, but in the age of digital surveillance, it has become to easy for organizations (governmental or otherwise) with clandestine agendas to spy on what other people do.
Granted, it has become easier to hide what we do as well (we as in normal people, not clandestine organizations), but that doesn't mean that the intelligence community should get carte blanche for spying on us.
Regardless of what technology you use, there should be checks and balances in place to make sure that the rights of the individual are not being violated. We should not regulate technology. That is useless, because it changes faster than the laws do. We need to regulate what can be done to people rather than how.

Labels: , , , , , ,

Friday, October 12, 2007

Bruce Schneier Talks at Defcon 15

From Bruce's blog we get a link to the talk he gave at Defcon 15. It's actually just a Q&A session, but it's quite insightful and interesting. Besides, Bruce is an awesome speaker, he's funny, he's charismatic, and he has a great voice. If this man was selling volcano insurance, I'd buy it in a second.
He takes some questions about the flying withing an ID, and the TSA, and why they have one of the shittiest jobs in the world. He goes on to talk about crypto and hash functions and how NIST is going to do for hash functions what they did for the AES, namely have a competition to get the next successor to SHA-1.
He also gets a question about privacy which he answers brilliantly and at length. This, for me, was the highlight of the show.
He then talks about side channel attacks on crypto and electronic voting and some more crypto.
All in all a very good way to spend 49 minutes and 20 seconds. It's available from google video here.

Labels: , , ,

Sunday, April 08, 2007

Bruce Schneier Facts

This won't amuse you unless you're a crypto geek, or at least reasonably interested in computer science and cryptography. Bruce Schneier is something of a guru and icon is the cryptography society.

Much like the facts known about Chuck Norris, there are also facts about Bruce Schneier.
Maybe not as hilarious as the Chuck Norris Facts, I found them pretty entertaining.

Bruce also has a blog here.

(Hah, I already had a tag created for Bruce Schneier! Imagine that!)

Labels: ,

Thursday, February 08, 2007

Hash

A couple of months ago, I took a class called "Introduction to Computer Security". For this class, we were asked to, in pairs, write a small small paper on any topic in computer security. It wasn't a research paper, but rather we were supposed to write something about someone else's research, or a topic that we found interesting. The best of these papers were to be presented at a mini "conference" at the end of the class.

Me and a friend wrote a paper called "Hash Collisions - Impact on Modern Cryptography".
Not surprisingly it deals with the problems we face should the widely used hashing algorithms be broken. Since we were limited to 6 pages, the paper is extremely condensed, but in the end concludes that, because of recent breakthroughs in cryptanalysis, algorithms like MD5 and SHA1 shouldn't be used any more, and more secure alternatives should be found.
Now, I don't claim that we came up with this conclusion, smarter people did, and we agreed, but now it seems like someone is actually doing something about it.

NIST, the National Institute of Standards and Technology has initiated a contest for candidates for what will probably become the worlds new hashing function. Bruce Schneier has written an excellent article about the competition in Wired, and he has also previously reached the same conclusions as we did. I feel like I'm in the company of greater minds whenever this happens, even though it's all re-iteration of what other people have said, to a large degree.

Even if you don't read the paper, I suggest you read the article.

(No, we didn't get one of the spots at the mini conference, but I still like our subject)

Labels: , , , ,