12 ms·
WTF is a KDF?
- wodenokoto 3y ago10.000 cloud GPUs running for a month is a lot of money. What was on that hard drive?
- unixhero 3y agoGovernments are formidable adversaries to have. They have amongst other virtually unlimited funds and resources.
- tgv 3y agoAn average police department, however, has very limited funds. Unless the guy is much more interesting that we know, nobody would spend that much money on cracking his address book.
- joseph_grobbles 3y ago[dead]
- thaumasiotes 3y agoMy guess would be contact information. He is apparently an anarchist imprisoned for setting fire to cars.
- t0mas88 3y agoEven with the smallest instance types that's around 8 million in compute cost. Doesn't sound like something you would spend on a small crime?
- WastingMyTime89 3y agoMultiple possible scenarios: - He actually gave his password himself as part of a deal with the police which includes this as a cover up. - The police got his password through another mean they don’t want to disclose and are using this as a cover up. - They really want a list of his contacts and what they were discussing because they are scared than one of them could be tempted to do more than burn a few cars. - France has a more computationally effective way to decrypt these drives which has yet to be released.
- jacquesm 3y agoI would bet on '1'. That's the one that requires the least imagination.
- Gasp0de 3y agoBitlocker also saves encryption backup keys in the Microsoft cloud where they can probably subpoenad? Then they might have found the password saved on the windows PC somewhere.
- deleted 3y ago[deleted]
- marginalia_nu 3y agoIf I wanted to get at an encrypted hard drive, I'd just tamper with the keyboard and record the password as it was being typed. Hardware keyloggers can be made very tiny with resources and determination.
- le-mark 3y agoDoes anyone have information or experience with this?
- marginalia_nu 3y agoThe USB HID protocol isn't encrypted. You can literally just add a pass through that logs (or transmits) the data. You'd have to check your USB connectors for a small extra dongle every time you boot up with just what is consumer-available[1]. There's also this type of stuff that can be wired into a keyboard[2], obviously harder to detect but a bit more involved to install as well. With a national R&D budget you can without a doubt do much better than both of these. [1] https://www.keelog.com/airdrive-keylogger/ https://www.keelog.com/airdrive-keylogger/ [2] https://www.keydemon.com/en/keydemon/28-1576-hardware-keylogger-module.html#/29-model-usb/54-memory-4mb https://www.keydemon.com/en/keydemon/28-1576-hardware-keylog...
- dist-epoch 3y agoEncrypting something well is so easy. If your encryption scheme fails at 8 million in compute cost something is horribly wrong.
- mr_mitm 3y agoThe number comes from this mastodon post, which is cited in the original article: https://kolektiva.social/@cedar/110214532879538171 https://kolektiva.social/@cedar/110214532879538171 > This enemy site talks about using up to 10,000 computers with GPU acceleration to attack a LUKS password: > https://blog.elcomsoft.com/2020/08/breaking-luks-encryption/ https://blog.elcomsoft.com/2020/08/breaking-luks-encryption/ There, it says: > Up to 10,000 computers and on-demand cloud instances can be used to attack a single password with Elcomsoft Distributed Password Recovery. So this is the theoretical maximum of some service. We should not be under the impression that the hard drive of the activist in question has been attacked with 10,000 GPUs.
- jwilk 3y agoRelated from 5 days ago: https://news.ycombinator.com/item?id=35611425 https://news.ycombinator.com/item?id=35611425 "PSA: Upgrade your LUKS key derivation function" (>180 comments)
- sam_goody 3y agoGeneral question, since I never before read up on why to use Argon: Why can't programs like Hashcat treat virtual memory (which is just disk space) as "on board memory", and then get 1000 attempts out of each TB? I would think the calculations themselves are relatively minor, if you are using that amount of RAM.
- Tuna-Fish 3y agoYou need to do random access to the memory buffer, and random access to virtual memory is slower than random access to actual ram, by enough to make it slow.
- CJefferson 3y agoThe algorithms are designed, at each step, to need a random memory location — the idea is you had some data, then use that data as the index into your memory. This means the speed of the algorithm is measured in random memory accesses, and that speed is much slower for discs than RAM, even with SSDs.
- dist-epoch 3y agoCompared to Windows+Bitlocker, using full disk encryption on Ubuntu (the most user friendly distro) is bizarrely difficult. By default the boot partition is not encrypted (so evil maid attacks are easier) and the KDF iteration counts are way too low, as can be seen here. When I setup FDE with LUKS on my Ubuntu laptop I had to go the manual route since I noticed that the default iteration counts don't make any sense, and it was so incredibly difficult to change them, pages upon pages of instructions. Anyone has any insight why the state of FDE is so bad on Linux? Nobody uses it?
- Gasp0de 3y agoI'm using it on Linux (Ubuntu and Arch Linux) and it wasn't so difficult. The default kdf settings are also sensible in Ubuntu 22.04. the biggest problem afaik is that the kdf isn't changed when there is a new default. E.g. when you installed your system in 2018 and upgraded all the way you still have the defaults from 2018.
- adriancr 3y agoEven if you encrypt boot partition someone could modify grub to grab password for boot partition used there. Then with that password they can evil maid again and change your boot partition. (unless you have same password on root/boot or password is embedded in boot partition in which case win for attacker) You could detect evil maid if you add a script that does a hash over grub used to load with a salt from boot sector, show on screen for user to decide against memorised hash... Prevent perhaps secure boot with custom keys?, but then that's one more layer. And you could probably use secure boot to avoid boot partition encryption entirely.
- vladvasiliu 3y agoYou can use an unencrypted /boot and have UEFI boot a unified kernel image with the kernel command line built in. And have secure boot verify the signature of that image. A TPM could possibly be helpful: you can't be sure that the PC you're booting up is actually yours and not a clone or has somehow had secure boot disabled that's booting a tampered kernel image. So if the TPM usually unlocks your drive (and a PIN, for added security) and it suddenly asks for your password, then something could be going on.
- mr_mitm 3y agoIt really annoys me how everyone takes that statement that a 20 character password has been cracked at face value. If it was randomly generated, it is physically impossible to crack even if it was hashed with MD5. It's also unlikely that somebody memorized 20 random characters. It is much more likely that the passphrase was weak because it's the title of a Wikipedia article or contained in some public word list. Also, by going with the original article (https://nantes.indymedia.org/posts/87395/une-lettre-divan-enferme-a-la-prison-de-villepinte-perquisitions-et-disques-durs-dechiffres/ https://nantes.indymedia.org/posts/87395/une-lettre-divan-en...), which I translated using DeepL, this is what we know: > As far as the investigation is concerned, in recent months new elements have been added to the file. The most significant is that the police managed to gain access to my computers, even though they were encrypted. The one at work, on which Windows is installed, is encrypted with BitLocker. _A previous report in the file says that they had already tried to access it while I was in police custody but had not succeeded._ But in September the Brigade d'appui en téléphonie, cyber-investigation et analyse criminelle (BATCIAC) sent a copy of the hard disk to the SDAT. In the PV, they only explain that they booted the computer with a bootable USB key and then used the software AccesData FTK imager 3.3.05 to copy the hard disk. But they don't talk about the decryption itself. > My personal computer, which runs Ubuntu 18, is encrypted with Luks (the password is more than twenty characters: letters, numbers, punctuation marks...). I couldn't find any indication in the file about how they decrypted it, but there too they made a copy of the hard disk. There are even files that had been deleted and emails that had been downloaded with Thunderbird (and then deleted). They didn't find anything that could be related to the fires I'm charged with. But I think the very fact that they were able to access hard drives encrypted with supposedly unbreakable software should be made as widely known as possible. This clearly hints at an evil maid attack, which we always knew were a real risk when it comes to full disk encryption.
- st_goliath 3y agoThanks! Reading the article, I was already wondering myself: Do we already know any of this for fact, or is this just more wild mass guessing? The article doesn't seem to cite any new sources other than people speculating on twitter/mastodon. Following down the social media rabbit hole, I end up back at the article that sparked the debate 5 days ago. Some RFCs and product data sheets are cited to support the back-on-the-napkin calculations (also cited from social media), but do we have any credible source yet to confirm that's what really happened here?
- temptestfr 3y agoInteresting that this was generated on such an old version of Ubuntu. There were known implementation weaknesses in LUKS that would have surely cut the cracking time down to a manageable duration.
- TacticalCoder 3y agoWhat I find weird is that not many talk about one of the parameter to PBKDF2, c, the number of iterations desired. Someone here mentioned it a few days ago: just make decryption fast enough to be acceptable for you but still a big multiplier compared to the default. What do people care, when unlocking their SSD, if it takes 3ms or 300ms to unlock the SSD at boot? I mean: attacker shall have a bazillion RAM and a trizillion GPUs... Fine. I augment the number of iterations by 1024, there, it's brute-force attacking cost just rose by 1024. (I'm not sure that person was attacked by bruteforce but I'm surprised it's always left out... And now I've got friends sending me that picture with "time needed to brute-force a password if it has x, y or z characters" and I don't know what to answer except that "it's more complicated than that picture which circulates everywhere)
- doodlesdev 3y agoThe problem is PBKDF2 isn't as memory intensive, it's really easy to parallelize on a modern GPU thus making it a much worse PBKDF than Argon2id. Increasing iteration count is just a bandaid over this problem, you also need to have control over memory usage.
- zokier 3y agoSure argon2 is better, but high iteration count pbkdf2 is still a lot of work to crack, and afaik the work still scales linearly with iteration count. Lets do bit of reality check here. I checked my 14 year old laptop luks setup and it has iteration count set to 462093 and it unlocks near instantly. Looking at hashcat benchmark results for PBKDF2-HMAC-SHA1[1] I'd estimate that for that iteration count it'd do about 47 kH/s. Running a full year with 100000 gpus of that perf means about 2^47 hashes bruteforced (=log2(47e3×100e3×86400×365)). Considering that I'm using maybe 70ish bit secret there, I'm not exactly concerned. I still should upgrade to have better margin, but there is no reason to panic; I'd consider it still practically uncrackable with current level of tech. [1] https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb422222fd#file-rtx_4090_v6-2-6-benchmark-L1238 https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb4...
- 3y ago
- Gasp0de 3y agoI think the most likely situation is this: Bitlocker can save backup keys in the cloud where they can probably be subpoenad by the police. If the victim used a password manager without encryption (e.g. browser) and used or saved the same password somewhere else, they might have gotten it this way.
- hh3k0 3y agoI might be wrong, but something tells me that people who use LUKS to encrypt a hard drive would not use the password in question for an online service.
- dist-epoch 3y agoPeople are dumber than you think. Remember all the mistakes DPR did and commenters were like "a criminal mastermind creating the Amazon of drugs couldn't have possibly asked on StackOverflow using his real identity how to build that".
- jeroenhd 3y agoBitlocker saves the recovery key to the cloud, not the unlock PIN. Both can be used to recover access to the data, but the recovery key is not directly related to the password chosen. Furthermore, the article talks about LUKS, which is decidedly not related to Bitlocker. I doubt they would've spent the ridiculous amount of money you need to crack LUKS though. Most likely, the password was a phrase that could be brute forced through a dictionary attack, or it was reused somewhere else. That's not to say we shouldn't move to Argon2i as GPU performance increases over time. Argon is proven to be stronger and there's very little reason not to upgrade if you can get your bootloader to unlock the modern LUKS standard (i.e. not GRUB).
- Gasp0de 3y agoI'm sorry if my comment was unclear. The person whose laptops were confiscated by the police stated that his bitlocker encrypted windows pc was also cracked by the police. My point was: They could have gotten the bitlocker recovery key, then found his password somewhere on the windows pc and used that to "crack" the LUKS encrypted partition.
- daneel_w 3y agoThis isn't a PBKDF2 problem. It's a password problem with roots in practicality and psychology. His password has absolutely not been 20 random characters, but instead something easy to remember and type in, quite likely just 3 or 4 common words.
- bob1029 3y agoPbkdf2 is designed to protect the users from their own bad choices more than anything else. In fact if you think about it, pbkdf2 with a high number of iterations could become quite costly at scale. How much are you willing to pay to protect a given user from themselves? If someone uses a proper password, one iteration is all you need.
- CyberDildonics 3y agoKey derivation functions (KDFs) are tools that allow us to improve the entropy derived from the types of passwords people typically use.
- vasco 3y agoIn a way it'd actually be great if police was frequently cracking encrypted communications of old algorithms. It'd both increase the pressure on better standards as well as remove the need for shitty laws banning encryption outright.
- upofadown 3y agoAn interesting bit from the linked ElcomSoft article: >Brute force attacks became not just faster, but much smarter as well. The user’s existing passwords are an excellent starting point. These passwords can be pulled from the user’s Google Account, macOS, iOS or iCloud keychain, Microsoft Account, or simply extracted from the user’s computer. The user’s existing passwords give a hint at what character groups are likely used: So if the victim used portions of that "longer than 20 characters" password in their other passwords, the amount of work required to crack the LUKS password would be much reduced.
- Brian_K_White 3y agoNot just subsets/supersets, but similar concepts and patterns.
- swapfile 3y agoThis is why you let a computer choose. By doing that you end up forcing the attacker to brute force, which we all know is mathematically unfeasible given enough entropy.
- Closi 3y ago"An activist imprisoned in France" makes this sound like some sort of locked up protestor, rather than someone that set fire to a load of vehicles and a warehouse. It should really read "An arsonist imprisoned in France".
- flangola7 3y agoThose aren't mutually exclusive. France isn't known for having neutered nonviolent protests like those in the US and UK.
- Closi 3y agoIt's true, but if a murderer that donated to charity was imprisoned I would probably go with "a murderer imprisoned in France" rather than "a philanthropist imprisoned in France".
- aquariusDue 3y agoHow about a "murderous philanthropist"?
- shakow 3y ago> France isn't known for having neutered nonviolent protests It definitely is.
- CoastalCoder 3y agoInteresting point. One word seems to bias us toward sympathetic assumptions, and the other away from them. I'm struggling to think of a good neutral term for this case.
- justinclift 3y agoAren't they just "accused of arson" at this point?
- kebman 3y agoIf you look into Koba's life before he came Stalin; even if you try to give what he did neutral descriptions, the words "mafia racket" still comes to mind.
- upofadown 3y agoThe use of a memory hard KDF like Argon2 is hardly a panacea for something like disk encryption. If your passphrase is compute time hard already, the advantage of using something memory hard is unlikely to be more than a factor of a thousand or so. Adding even a single diceware generated word to a passphrase increases the difficulty by a factor of 7776. So passphrase length is by far the dominant factor. There is a faction out there that claims that Argon2 is not as good as cache hard functions for the case where the user is only going to be willing to wait second or less. That's a reasonable assumption so it would probably be a good idea to evaluate more than just Argon2 for any particular application. Yes I know that Argon2 won a contest, but such contests are followed by a much longer evaluation period.
- motohagiography 3y agoWhile I haven't worked on LUKS, if you put aside using several millions of dollars in raw compute, the options are in order of likelihood: - recovering the key from a deleted file, ram, or other caches. - obtained key or bytes thereof by prior surveillance. (so many ways) - a forensics company could be sitting on a LUKS zero-day the way certain companies sit on Signal and iPhone vulns and use them on behalf of state actors. - exploited a deprecated version themselves with an implementation error. - prisoner had a short key because he used it so often - brute force using generated wordlists from surveillance and data transcripts. - trained a GPT model on all the books, music and online forum posts the prisoner had ever bought and used and produced a weighted wordlist. (I just made that one up.) - Happen to have "millions of dollars in gpu time" because they already had racks of seized mining rigs from other investigations so the main cost was electricity. Being an anarchist or secret police in France just seems like participation in their national traditions of riot sports, intrigue, and feats of mysterious intellectual prowess. There are so many unanswered questions in the story, I will wait for the Wes Anderson adaptation before thinking about it again.
- wood_spirit 3y agoAlso, I would expect the government can crack passwords more cheaply than hiring normal commercial cloud compute. Everything from negotiating good prices, to having their own or reserved cloud so the cost is having the ability to do it more than actually doing each crack, to asking an ally for help. Would be kinda shocking if they pay the sticker price for this stuff.
- ipython 3y agoYou’re right. They probably pay a premium on the sticker price, after you include all of the necessary professional services and us gov only personnel with security clearances.
- chaxor 3y ago... you definitely don't need "GPT" to make a word list... C'mon guys.
- 3y ago
- Snawoot 3y agoBruteforce of such random password is just not plausible and talks about KDF "weakness" is just a distraction. I think most likely it was evil maid attack. Here are projects which try to mitigate some of evil maid attack risks: https://github.com/noahbliss/mortar https://github.com/noahbliss/mortar https://safeboot.dev/ https://safeboot.dev/
- kazinator 3y ago> Earlier this week a letter from an activist imprisoned in France was posted to the Internet. And this letter's authenticity was verified how? Even if authentic, it could be the result of coercion, to create a bluff and spook some other activists. Or it could be that the cops fooled the activist into believing that they cracked his hard drive, so that he then wrote the letter. Do not believe everything "posted to the Internet". The letter says (DeepL translation) that "There are even files that had been deleted and emails that had been downloaded with Thunderbird (and then deleted)." Files and e-mails come from somewhere. If I know that you downloaded certain files or e-mails from a mail server to your encrypted hard drive, I could claim that I decrypted them from your drive and spook you.
- dmix 3y agoThis sounds a bit paranoid. You give the police too much credit. Lying to the public to scare off people from using Linux encryption?
- kazinator 3y agoMight you be confusing skepticism with paranoia? They are almost opposite: the paranoiac is too willing to believe; a skeptic can be too unwilling. Police perpetrating bluffs on people they have in custody is standard operating procedure. I wouldn't weave the "scare people from using Linux encryption" narrative into it, though; I don't think that would be their motivation. (Though it could be a counterproductive unintended effect. The last thing authorities want it spooking people into finding better encryption.) Anyway, I suspect that in situations in which cops really crack someone's hard drive at great expense, it mostly behooves them to take advantage of whatever they learn, while keeping secret how they got it. If you have someone in custody who thinks their hard drive is safe, while you have secretly cracked it, that gives you an information advantage you can use at a strategic time.
- aspectmin 3y agoRecognizing the ability of these entities to hire great cryptographers, what’s the possibility they found a shortcut or vulnerability in the algorithm (or set thereof) itself?
- tptacek 3y agoFor whatever it's worth --- probably not much if you don't do any cryptography engineering --- the definition provided here is of a password KDF. There are other important kinds of KDF, and they don't necessarily have the goal of stretching an untenably low-entropy secret into a facsimile of an actual key. HKDF, for instance, is often the way you extract keys from a Diffie-Hellman exchange.
- nullagent 3y agoThanks for the feedback, I was worried people may take it that way. I've clarified that KDFs are broader than just passwords.
- schwede 3y agoWhat was the password length? How many iterations were used?