3 ms·
Did the individual donor have a three letter name? Or connected to an organisation with a three letter name?
by ampdepolymerase 6y ago
Did the individual donor have a three letter name? Or connected to an organisation with a three letter name?
- segfaultbuserr 6y agoYou have to realize the historical context of the award. The EFF describes the prize as > The EFF [...] is sponsoring cooperative computing awards [...] to encourage ordinary Internet users to contribute to solving huge scientific problems. What is "cooperative computing" and what does it mean by "encourage ordinary Internet users to contribute"? You must know a bit of history to see the context here. Back in the 1970s, the NSA drafted the Data Encryption Standard, or DES, as the national standard of data encryption for sensitive data, the NIST standardized it. However, Despite the decision by IBM to use a 64-bit key and the strong criticism from academic cryptographers (most prominently Diffie and Hellman [0]) that anything shorter than 128-bit is untrustworthy, a key length of 56-bit was selected by the NSA. D&H estimated that the NSA could theoretically construct a DES cracker for $20 million in 1976. Fast forward to the 1990s, the security of DES has become a serious problem. Just as predicted, its 56-bit key could not keep up with the progress in semiconductors and it could be broken even by a small organization at any moment. And after 1995, Internet access opened to the public, if the government mandated the use of DES (instead of replacing it by something stronger), it would create a serious threat to security and privacy to both ordinary citizens and businesses. However, the NIST refused to acknowledge DES's insecurity due to NSA and the FBI's effort to prevent the use of strong cryptography by the public, the FBI even described DES-encrypted data as a threat to national security. Around the same time, the U.S. government was also trying to suppress Phil Zimmermann for his PGP and was pushing a backdoored phone encryption system (sounds familiar?) known as the Clipper Chip. It was the First Crypto War. Because the insecurity of DES was both a threat to citizens and businesses interests, RSA Security, Inc cooperated with the civil libertarians in the crypto war to push the NSA back. One thing it did was launching an anti-DES campaign. To demonstrate that the claims of DES's security by the U.S. government was false, in 1997, RSA Security Inc started "The DES Challenge" - the company published an encrypted ciphertext, and anyone who can break DES and discover the plaintext would win $10,000. A group of computer scientists led by Rocke Verser, assisted by Justin Dolske and Matt Curtin, responded this challenge by started the DESCHALL Project. They created a distributed computing network - anyone who didn't like the NSA could help by contributing CPU time from a PC. It was truly an innovative idea. Later known as distributed.net, it's arguably the first volunteer-run distributed computing network, the predecessor of BONIC, SETI@Home or Folding@Home (the only competitor is GIMPS, which was established around the same time). The server was on a 486-based PS/2 PC with 56 MiB of memory, and they announced the project via Usenet towards the end of March. Client software was rapidly written for a large variety of home machines and eventually some more powerful 64 bit systems. About 10,000 people joined, and the DES Challenge was broken in 96 days, DES was demonstratively broken, a definite proof. Later, RSA launched another DES Challenge, the DES Challenge II-1. DES Challenge II-1 was cracked by distrbuted.net in 39 days in early 1998. The plaintext message being solved for was "The secret message is: Many hands make light work." It was the first significant demonstration of the distributed computing's power. Distributed.net celebrated this moment in an email, > Distributed.net is equivalent in processing power to: 11,264 DEC Alpha 21064 533s 15,316 Sun Ultra I 167s 22,393 Intel Pentium II 333s 68,859 Macintosh PowerPC 604e/200s. 41,712 Intel Pentium 166s 399,374 Intel 486DX2/66s 7,446,033 Intel 386SX/20s > (based solely on DES client performance) > Prospective: > If Keys were dollars, we could pay off the U.S. National Debt in 6.25 minutes > If Keys were pennies, we could buy 536249385 Mazda Miatas each day. > If Keys were pennies, we could buy 256728249 Jeep Cherokees each day! > If you printed a single page to represent each key block as it was checked and placed those pages in a stack, it would grow 12.83 inches taller every minute. > If blocks were liters of Dr. Pepper, we could produce 6381493 six-packs each day > If Key Blocks were cheeseburgers, fries, and a large Dr. Pepper, we could feed the entire city of Toronto, Ontario lunch each day. After this incident, the government still refused to acknowledge the insecurity of DES. FBI director Louis Freeh told Congress, > "If we hooked together thousands of computers and worked together for months we might, as was recently demonstrated, decrypt one message bit. That is not going to make a difference in a kidnapping case. It is not going to make a difference in a national security case. We don't have the technology or the brute force capability to get to this information." The RSA started yet another challenge, DES Challenge II-2. Meanwhile, the Electronic Frontier Foundation joined the game, thanks to its sponsors, the EFF spent $250,000 to build The EFF DES Cracker (nickname Deep Crack), a special purpose computer with 29 circuit boards and 1,856 ASIC chips. DES Challenge II-2 was solved in just 56 hours in July 1998. And the third challenge, DES Challenge II-3, was a cooperation between EFF and distributed.net, the key was found in just 22 hours 15 minutes in January 1999, and the plaintext was "See you in Rome (second AES Conference, March 22-23, 1999)". And the rest was history, DES was retired in late 1999s, the review of the Advanced Encryption Standard was performed in a highly transparent manner, later completed in 2001, Rijndael won, and became the most widely used cipher on the Internet. As you see, the First Crypto War was won largely due to > distributed computing. It was under this historical context that the EFF set up the cooperative computing award from an anonymous sponsor around 2000. Based on the history, it's persuadable to assume the intention by the anonymous donor was to encourage the applications of distributed computing, so the next Crypto War can be won. Finally, fun fact: After the First Crypto War, distributed.net is irrelevant, but it still exists, and the RC5-72 cracking project from the 2000s is still running, it's estimated that the brute-force search of the keyspace will complete within 150 years. [0] http://www.toad.com/des-stanford-meeting.html http://www.toad.com/des-stanford-meeting.html
- toomuchtodo 6y agoReally well written comment about the history of these challenges and distributed.net. “Cracking DES”, a book published by the EFF, contains the necessary information to build your own Deep Crack DES brute force appliance. It’s available in the Internet Archive: https://archive.org/details/crackingdes00elec https://archive.org/details/crackingdes00elec
- schoen 6y agoAlthough there are several generations of subsequent DES cracking hardware developed by other teams (albeit not with the level of open hardware detail as Deep Crack!). https://www.copacobana.org/docs.html https://www.copacobana.org/docs.html https://crack.sh/ https://crack.sh/ (I'm a little confused at why crack.sh had to spend roughly as much money per key per second as Copacobana, when it was being built with a more advanced model of the same manufacturer's FPGAs around a decade later. I wonder if the Virtex-6 has some high-end features that crack.sh doesn't really benefit from, but still had to pay for.)
- schoen 6y agoWhile I wasn't at EFF at the time the donation was made, I find it totally credible that the donor was an individual who wanted to highlight the Internet's ability to let people work together in new ways, and didn't have any hidden motive for encouraging this particular work. I believe primality testing was suggested as a topic for the prize by a panel of scientific advisors, who were mostly mathematicians. In that timeframe, the main technical advances that helped GIMPS get more efficient were being made by Richard E. Crandall (https://en.wikipedia.org/wiki/Richard_Crandall https://en.wikipedia.org/wiki/Richard_Crandall), who also wrote Prime Numbers: A Computational Perspective with Carl Pomerance (https://en.wikipedia.org/wiki/Carl_Pomerance https://en.wikipedia.org/wiki/Carl_Pomerance). If these folks are trying to help governments keep a monopoly on expertise about number theory and the difficulty of the RSA problem, they seem to be doing a pretty bad job of it.