10 ms·
Practical bruteforce of military grade AES-1024 (2021) [video]
- WhitneyLand 4y agoSummary: AES was not really broken or brute forced at all. The title is clickbait, and also is factually wrong. What really happened: Yet another random company simply implemented the password code wrong. This has nothing to do with the integrity of AES which remains unbroken in principle. Nothing to see here.
- PeterWhittaker 4y ago> multiple encryptions Correct me if I am wrong, but isn't AES a group, like DES? If so, encrypting twice under keys of the same strength is the same as encrypting once, with a different key. This is why, e.g., 3-DES uses encryption-decryption-encryption, under different keys.
- Reubensson 4y agoIsn't key derivation function completely separate from aes implementation. I mean you could have used the same broken key derivation with some other aes implementation. Also aes-1024 sounds like some proprietary thingy, not something people should probably trust anyway...
- nfreising 4y agoAgreed: 'Breaking the DataVault encryption software' would be a better title
- NovemberWhiskey 4y agoAs far as I can see: yes and yes. Clickbait title.
- upofadown 4y agoThe complaint is that the user supplied password is easier to guess than it could be. A fast hash is used and not very many times. So you might have to, say, use 5 words rather than, say, 3 words in your diceware generated passphrase if you want to be secure against brute force attacks. This ends up being a common usability issue whenever a user is asked to provide a passphrase for some sort of symmetrical encryption scheme. The user is almost never given any guidance to allow them to chose a passphrase strong enough for the system in use. So they end up with a dictionary word with a digit on the end and have no way to know that they have not actually protected anything. It ends up being sort of a con in practice. The user is allowed to believe that the system is much more convenient to use than it actually is. The system under consideration is not really any worse than other things in this.
- mistrial9 4y ago> So they end up with a dictionary word with a digit on the end and have no way to know that they have not actually protected anything a dictionary word with common letters substituted with a number, case-sensitive, and one or two punctuation.. that is "not protected anything" ? .. almost any two dictionary words put together, not even case sensitive also "not protected anything" ? the out-of-breath security analysis is bothersome and lead us to mandatory ten characters of garble and other extreme anti-user patterns.. I am looking at a stack of forty accounts with passwords as an ordinary library user.. not convinced of this expert analysis today
- gamacodre 4y agoIf your threat model is "someone cloned the database and can now perform unlimited attacks against the stored passwords", then yeah, word + digit protects just about nothing. Assuming a lexicon of 5,000 words, word+digit gives you about 50,000 variations to try. Say that L337 substitutions give you another 10x factor, so now you have 500,000 candidates for what the password might be. Now lets assume that instead of the stupid crap they did in this video, the folks storing your password did everything right and used bcrypt with a work factor of 12. A cracking rig from a couple years ago can run something like 10,000 hashes per second under these conditions, so it might take a whole minute to discover your password. (Remember this is if they did it right, most other password storage schemes would yield your password in a fraction of a second.) Or, we could look at the two-words-separated-by-punctuation case. Same 5,000 word lexicon, maybe 10 different symbols likely to show up between the words. Call that ~250,000,000 possibilities for your password. That'll take up to a day to crack. A day is a long time to spend on one password, but maybe they don't have anything better to do. Maybe they hate you personally. Add another word, suddenly the hackers need years per password, which is obviously uneconomical. These guidelines don't come out of nowhere, and there isn't really a tower of experts somewhere giggling at the unwashed idiots around them (well, there might be, but I wasn't invited). This is just one of many problems in computing that live around the intersection of math and psychology, where the "natural" thing to do is (unintuitively) quite dangerous.
- 4y ago
- dvaun 4y agoIt's definitely proprietary. In the summary below the video, it states: > It turned out that the key derivation function was PBKDF2 using 1000 iteration of MD5 to derive the encryption key. The salt used to derive the keys is constant and hardcoded in all the solutions and all the vendors. This makes it easier for an attacker to guess the user password of a vault using time/memory tradeoff attack techniques such as rainbow tables and to re-use the tables to retrieve passwords for all users using the software. The implementation itself was incorrect and even with a randomly generated unique salt, it would be effortless to recover the password of a user. I'd stick with veracrypt for now.
- spzb 4y agoAny time I see encryption described as "military grade" it usually sets of my bullshit detector.
- twic 4y agoMaybe it was Russian military grade.
- albntomat0 4y agoTo be clear, this isn’t a break of AES itself, but the implementation of a whole system, of which AES is a part.
- deleted 4y ago[deleted]
- zinekeller 4y agoThe software in question: https://www.encsecurity.com/solutions.php https://www.encsecurity.com/solutions.php (Technically, the actual software in the USB is white-labeled with the USB flash drive brand, but apart from that this is it.)
- ziddoap 4y agoI've yet to see a good definition of what constitutes "military grade encryption" vs. regular old encryption. It generally has the opposite effect, for me at least, in the sense that I avoid any product that advertises "military grade <something>". Edit: I'm not actually looking for definitions of "military grade encryption", thank-you everyone who tried to explain it though. I work in cybersec, and encryption is encryption. It is either compliant with standards or it is not. But "military grade" is pure marketing fluff, hence why I avoid it.
- vengefulduck 4y agoTo me being FIPS compliment would be a good definition of something being “Military Grade” because that would be the actual standards the US military would use. However, that still doesn’t mean it has the best security because really good algorithms like Ed25519 aren’t FIPS compliant dispute being much better than their FIPS counterparts IMO.
- OskarS 4y agoYep, totally, it's a big red flag. Another term like that when it comes to software is "patented technology" (or "algorithm", or "software", or whatever). Instant turn-off.
- kevin_thibedeau 4y agoNowadays it means outdated, bare minimum security so we can still certify 3DES.
- lazide 4y agoFrankly it doesn’t even guarantee THAT. If they could certify it, they could list the mil-spec certification. It’s pure weasel wording.
- fl0wenol 4y agoOnly for grandfathered-in systems that are critical to keep operating that can't be replaced. New systems and lower-impact existing systems cannot use 3DES at all, unless it's only to decrypt stuff previously encrypted with it.
- RcouF1uZ4gsC 4y ago>However, it turned out after the analysis that all these modes offer only a security level of 128-bit. >A plugin in John the ripper software to allow everyone to "practically brute force military grade AES-1024" will be released at the time of the presentation. My understanding was that even 128-bit security is safe from brute forcing at the present. Am I missing something?
- zinekeller 4y agoThe proprietary "AES-1024" is actually AES-128 encrypted four times (like Triple DES which is an actual standard). The actual problem is that the key derivation is literally MD5 and the "salt" is static (making brute-force laughable). So, no, AES is not broken, just this weird one that happens to be the encryption program you've get free with the purchase of certain brands of USB drives.
- bawolff 4y agoThey are bruteforcing pbkdf2 with too low number of iterations (people are talking about md5, but md5 isn't really the problem here. A memory hard hash would be better [albeit maybe impractical in context], but if you are using pbkdf2, md5 isn't any different from sha256 or whatever else)
- NovemberWhiskey 4y agoIf your password is 22 randomly generated characters chosen from the alphabet of upper and lower case letters plus numbers (which implies ever-so-slightly-less than six bits of entropy per character) then you will get 128 bit security from one of these devices - meaning that an attacker will just as well have to brute-force the cipher as attack the password. And, as you said, that is currently believed infeasible. If you are a human being, your password is more likely to be a single English word or name with some arbitrary capitalization, some swapping out of o/0 a/@ s/$ t/+ or some such, and then a number tacked on the beginning or end. At this point, brute-forcing your password is going to be a much simpler proposition; you're reliant on a key-derivation function being sufficiently expensive to compute to slow down that brute-force attack. The attack in this case was of the latter kind; the KDF was so poor that it could be attacked very quickly. No 128-bit encryption was harmed in the filming of that presentation.
- GekkePrutser 4y agoIn this case it's surely a military grade. Grade F to be precise :)
- crest 4y agoNobody will notice a little red line to turn `F` into `A` it worked from them in high school after all ;).
- api 4y agoPSA: AES is not broken at all here. This is a break of a crap key derivation function that used MD5. It shows that all components of a cryptosystem are important. Attacks seldom target things like actual ciphers unless it's one known to be weak like RC4 or single-DES. They target bad constructions (like this), implementation bugs, etc.
- spydum 4y agoActually the AES encryption they implemented is ALSO broken. The premium instances of AES-256, "512" and "1024" were totally broken and based on zero-content blocks, the security gets reduced to 128-bit in all scenarios. So yeah, AES itself not broken, but.. the places it implements AES-256, 512, and 1024, were broken by implementation.
- ajsnigrutin 4y agoConsidering the amount of free encryption software, a lot even opensource, where you just add your logo and a pdf with instructions, bundle the source in a zip file somewhere not to break GPL, and you're done, fuckups like these seem more and more intentional to me. Tech-savy users will always use "the best" tools, but for "normal people", the police having the ability to decrypt their data, is a thing government wants. If the encryption is bundled, they'll use the broken one, because the alternative (googling the software) will usually show them only the software that actually works.
- vmoore 4y ago> SanDisk, and Lexar provide encryption software for their USB keys, hard drives, and other storage products. I'm someone who bought several Sandisk devices over the years. The first thing I do after buying and unboxing is setup LUKS[0] on the device with the Disks utility in Ubuntu. These USB flash drives usually ship with an `.exe` piece of 'security software' written to the disk, which I never execute because I don't trust their claims. I prefer battle-hardened and trusted things like LUKS, instead of proprietary products that use snake-oil terms like 'Military Grade'. [0] https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup
- SAI_Peregrinus 4y agoThere is no such thing as AES-1024 specified by NIST. AES is a NIST standard, it has three (and only three) variants: AES-128, AES-192, and AES-256. If you see something other than those three, it's almost certainly proprietary junk. Note that AES is always used in a "mode of operation" to provide any sort of secure encryption. AE-secure modes are AES-SIV, AES-GCM-SIV, AES-OCB, and AES-GCM in decreasing order of safety/performance (possibly others, but those are the most well reviewed and most used). Those sometimes get noted with the key length, eg AES-256-GCM-SIV, sometimes not.
- _8j50 4y agoI must disagree with the "proprietary junk" assertion you made. While Your statement about AES is correct, Rijndael cipher of which AES is a subset can have bigger keys and block sizes. For marketing reasons they interchange Rijndael with AES since many have never heard of it.
- tgsovlerkhgsel 4y agoWhile it is possible to do that, companies that understand what they're doing will generally stick to well-proven, standardized versions and companies that don't tend to also do other dangerous mistakes. It's not a 100% guarantee that it's proprietary junk, but it's a very good indicator.
- gray_charger 4y agoIs AES-XTS a secure mode? Or is that something else?
- Nursie 4y agoXTS is often used in disk encryption (or it was a few years ago when I worked on at-rest data encryption for a storage product at a major vendor). It uses the sector number and block offset within the sector as input, a little like a counter mode. Its major advantage is zero overhead, so you don't lose disk capacity, or need to map blocks around, you can just sorta use it as a filter layer in your disk reads/writes. It's not properly authenticated though, as data tampering can result in altered or scrambled plaintext rather than detectable errors, so you need other mechanisms for error detection, which then have to be secure against attacks.
- bawolff 4y agoIn case anyone else was confused wtf aes-1024 was. The tl;dr is they were chaining aes-128 multiple times. The bruteforcing is about bruteforcing pbkdf2 w/ only 1000 iterations being used with user passwords, and doesn't have anything to do with aes
- bob1029 4y ago> PBKDF2 using 1000 iteration of MD5 to derive the encryption key. The salt used to derive the keys is constant and hardcoded in all the solutions and all the vendors. I feel like this is being bad on purpose.
- staticassertion 4y ago> . It turned out that the key derivation function was PBKDF2 using 1000 iteration of MD5 to derive the encryption key. The salt used to derive the keys is constant and hardcoded in all the solutions and all the vendors. This makes it easier for an attacker to guess the user password of a vault using time/memory tradeoff attack techniques such as rainbow tables and to re-use the tables to retrieve passwords for all users using the software. The implementation itself was incorrect and even with a randomly generated unique salt, it would be effortless to recover the password of a user. Other flaws of the key derivation function will be discussed and compared with nowadays good practices. Yikes
- moonbug 4y agostopped reading at "military-grade"
- aaron_m04 4y agoThe cracking script he wrote is at https://github.com/openwall/john/blob/bleeding-jumbo/run/encdatavault2john.py https://github.com/openwall/john/blob/bleeding-jumbo/run/enc...
- spydum 4y agoI was watching this just because it's fun to see bad implementations. I was totally caught offguard when the vendor presented their own view of the problem! Did not see that coming. Makes for a more interesting presentation IMHO (both sides of the issue, no finger pointing)! often we hear about how broken something is, very RARELY do you get to see the remediation action and decision making. Hats off to the guys at EncSecurity for stepping up to fix their issues AND sharing the lesson with the industry.
- benlivengood 4y agoIt's also a pretty strong indictment of any sort of add-on file encryption software. HMACing files is out of scope and not the intention of the software and too difficult to implement to boot? Waiting for enough PBKDF2 rounds will annoy customers, when Microsoft office products take multiple seconds in a splash screen to load? I am probably just spoiled by OSS/free software offerings. It would be great if exFAT was not patent-encumbered and supported native encryption+integrity. ZIP archives at least provide cross-platform encryption+integrity with AES-256 but without block-level hmacs or encrypted file names. Maybe Windows will add support for ZFS someday?