3 ms·
Matthew Green:I’ve never seen so many broken things in one simple piece of code
- NotSwift 5y agoThis is a post by Matthew Green who is a respected cryptographer about Kasperky's password manager. This is the original post by Bruce Schneier that helped me find it: https://www.schneier.com/blog/archives/2021/07/vulnerability-in-the-kaspersky-password-manager.html https://www.schneier.com/blog/archives/2021/07/vulnerability...
- schoen 5y agoThe time-based seed was also a fatal flaw in Netscape's implementation of SSL (not TLS!) back in 1996. https://people.eecs.berkeley.edu/~daw/papers/ddj-netscape.html https://people.eecs.berkeley.edu/~daw/papers/ddj-netscape.ht... Kaspersky re-implemented a famous cryptographic vulnerability from that era in a modern product. :-(
- andrewmcwatters 5y agoThis is a very bad article even if it’s from someone reputable because they don’t explain why not at each step. It reads as someone smug just saying, “No, you idiot.” And they literally use “WTF,” as if it’s some statement of authority. Further, that’s not even the right application of “don’t roll your own crypto,” reducing the credibility of the article. “Don’t roll your own crypto” comes from people suggesting that you don’t implement your own copy of, say Diffie–Hellman key exchange, not making some calls to a RNG, which is ridiculously far more trivial. Why always use X? Why never use Y? If you can’t articulate it, you’re not teaching anything. And this guy supposedly teaches, too. What a shame. Tell me: if you read this article and took away not to ever use floats in cryptography, can you tell me why? No? Interesting.
- craftinator 5y ago> This is a very bad article even if it’s from someone reputable because they don’t explain why not at each step. Based on the context and how it's written, I get the feeling he never intended it to be a full fledged article, just some tweets, then it grew organically from there. This was never an instructional piece of work.
- andrewmcwatters 5y agoI ended up tracking down the tweet thread and every single subthread I read had nothing meaningful to share. There were no insights to glean. I get this sense from a lot of people in security: smart enough to follow conventional advice, too uneducated to explain why. This password manager will almost certainly generate basically anything that will get hashed and salted in the end, so it’s all irrelevant as long as it’s basically not outputting passwords from exposed lists, and even then it’s still mostly irrelevant. I have never once heard of particular passwords being an issue in the industry outside of social engineering or common password lists. Completely irrelevant. It’s almost always data breaches. Never does it hit the news that 3.5 million password were cracked due to hackers reverse engineering the time the accounts were created against popular password managers. What nonsense. If you simply generated a password from /dev/urandom, it would have almost as much consequence as whatever they’re doing here. Edit: The source article referenced is the only thing meaningful, which explains the severity, everyone else commenting on it was a dope.
- duskwuff 5y agoYou have completely missed one of the the key points of the thread. Seeding the random number generator with the current time, measured in seconds, removes any element of randomness from the password generator. It makes it straightforward to produce a list of every password that this software has ever generated, or will generate in the future.
- andrewmcwatters 5y agoYeah, you’re right, I did, because the tweets were worse than worthless. Just link to the source article.
- jnwatson 5y agoThis isn't an article. This is a computer-generated roll-up of a series of tweets, hence the brevity.
- andrewmcwatters 5y agoAnd the quality, apparently. The source article is worth reading, but none of the tweets are.