5 ms·
Decoding the 90s: Cryptography in Early Software Development (2023)
- deleted 1y ago[deleted]
- fullstop 1y agoInteresting read, but none of the images will load for me. Throttled by wix? edit: I'm not sure why this is being downvoted. The website looks like this to me: https://i.imgur.com/q6846RF.png https://i.imgur.com/q6846RF.png edit2: not throttled by wix, although they are hosted with wix. There's some strange url parameters in the image src attribute, which I assume are supposed to do something fancy. That fancy bit isn't working.
- deleted 1y ago[deleted]
- abracadaniel 1y agoThey show like that for me briefly and then load. Maybe the decision to load the image is done dynamically in JS as a scraping countermeasure.
- fullstop 1y agoThey do not load for me, even after waiting for several minutes. I've tried in Chrome, Firefox, and Brave. No ad blockers, nothing unusual. edit: They work on my Android phone.
- fishgoesblub 1y agoI'm having the same issue, both Firefox and Vivaldi with or without a VPN the images are just low-res thumbnails. I tried to load the site in the Tor browser, but got 403'd.
- ipython 1y agoLove this article. Brings back memories of such a simpler time spending way too much time doing exactly this with IDA pro and Bochs (my favorite tool at the time for these sorts of projects). Bochs plus custom plugins equaled some amazing capabilities for real-time dynamic analysis of DOS, bootcode, and other low-level applications.
- anthk 1y agoAnd crazy OS debugging up tp i7 processors.
- kragen 1y agoI find it amusing that in 02023, after 77 years of software development, they referred to something like 01992 as "early software development", because people had only been developing software for 46 years at that time. But it's true that most software that has been written so far was written after that. Are we still in "early software development"? Presumably most software that will ever be written hasn't been written yet.
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- jagged-chisel 1y agoYour octal years aren’t coming out right
- unwind 1y agoSee https://longnow.org/ideas/long-now-years-five-digit-dates-and-10k-compliance-at-home/ https://longnow.org/ideas/long-now-years-five-digit-dates-an....
- jagged-chisel 1y agoSo a little silly, a little serious. On a practical note, we don’t tend to prefix zeroes to numbers because they are superfluous. If programmers are using strings to store a year and those strings are limited to four digits, your project likely has a host of other issues that will become problems long before Y10K. We already have a precedent, in programming, for prefixed zeroes having meaning: “an octal number follows.” Much like 0x indicates a hexadecimal number.
- xnorswap 1y agoI hope this is satire? Just in case it's serious or semi-serious: It's utterly ridiculous to worry about 10k date problems given we first have these: 2038 problem ( Signed unix time overflow ) 2069 problem ( strptime() parsing ) 2079 problem ( unsigned days since 1 January 1900 ) 2100 problem ( FAT/DOS ) 2106 problem ( Unsigned unix time overflow ) Further out but still way before 10k: 2262 ( signed nanoseconds since 1 January 1970 ) And that's just the bigger ones. ( See: https://en.wikipedia.org/wiki/Time_formatting_and_storage_bugs https://en.wikipedia.org/wiki/Time_formatting_and_storage_bu... ) What's the point of prefixing 0 to dates written forum posts? It just confuses contemporary human readers. Historians do a reasonable job at adequately translating dates from thousands of years ago across multiple calendar changes and societal collapses. Whatever future historian 10k+ years in the future is reading your post, should it survive, will be able to work out the date in the post, just from the language and other context clues alone. It'll be hard to confuse 12025 with 2025 in the same way it's hard to confuse 2025 with AD 25.
- mfro 1y agoVery cool that ScummVM was allowed to host IDA Pro 5.0 for free. I will be playing around with that tonight :)
- RKFADU_UOFCCLEL 1y ago90's crypto was interesting. They would just use naked RSA and block ciphers. Usually, the team would have one guy who was "smart about crypto" and he was just left to do his thing and after passing functional tests, it was accepted into the product. There was so much fun stuff to break as was it fun to try to prevent people from breaking your stuff.
- hangonhn 1y agoEven companies as well resourced as Microsoft made these mistakes well into the 2000s. Remember when they used plain old AES to encrypt the Viewstate for ASP.Net? It was vulnerable to padding oracle attacks: https://en.wikipedia.org/wiki/Padding_oracle_attack#Attacks_using_padding_oracles https://en.wikipedia.org/wiki/Padding_oracle_attack#Attacks_... Cryptography is such an esoteric and deep field that it's easy for a fairly smart but inexperience engineer to misjudge the security of a particular implementation or usage of a cryptographic primitive.
- susam 1y ago> Even companies as well resourced as Microsoft made these mistakes well into the 2000s. Indeed! As I just wrote in another comment on this page, Microsoft Outlook 2003 used CRC32 to "hash" the personal folder (.PST) passwords. Since CRC32 isn't a cryptographic hash, it was trivial to generate a collision and access someone else's Outlook personal folder. This flaw persisted until at least 2006! More details here: <https://www.nirsoft.net/articles/pst_password_bug.html https://www.nirsoft.net/articles/pst_password_bug.html>.
- asveikau 1y agoI guess the thing about these examples is that cryptography can "visibly work" while being broken. The vast majority of people looking at the product will observe it to work "fine", in that nothing blows up.
- tptacek 1y agoI mean, they were implementing straight out of Applied Cryptography. How good a job could they possibly have done? A fun thing to look at today is `deslogin`, the predecessor to SSH.
- susam 1y agoI have encountered my fair share of in-house RC4 implementations from the 90s. Every single one of them was vulnerable in some way. They suffered from all kinds of issues: improper IV initialisation, predictable keystreams, and even partial leakage of plaintext into ciphertext. RC4's deceptively simple specification made it enticing to implement, giving developers a false sense of confidence and security. As another example, Microsoft Outlook 2003 infamously used CRC32 to "hash" the personal folder (.PST) passwords: <https://www.nirsoft.net/articles/pst_password_bug.html https://www.nirsoft.net/articles/pst_password_bug.html>. Naturally, it was trivial to find a CRC32 checksum collision and open someone else's PST. Thankfully, the industry has come a long way since then. These days, rolling your own cipher is, quite rightly, considered a red flag!
- xnorswap 1y agoI've seen far too many IVs statically declared as "<Product>IV" in my lifetime. Bonus marks for when the key was also "<Product>Key".
- notarealllama 1y agoNirsoft saved my ass so many times on different things. I remember when I lived somewhere without (reliable or consistent) internet access, I scraped all the tools to take with me. They still are in my tools folder to this day!
- giancarlostoro 1y ago> RC4's deceptively simple specification made it enticing to implement, giving developers a false sense of confidence and security. I never like the idea of hand implementing crypto, ever. Why would I not just use existing libraries?
- 01HNNWZ0MV43FF 1y agoSome languages like c++ don't have popular package managers, so adding even one dependency can be very difficult. Learning an unpopular package manager and asking your team to rely on it introduces the burden of teaching everyone how to use it, if the manager even allows it In this hostile environment, many wheels are reinvented C programmers actually consider this a point of pride
- blintz 1y agoI know this would be less fun, but given that the key space was only 36^4, why not just run the actual decryption functionality in QText? Like, even if it takes 1 second to decrypt, spin up 32 cores and wait a day. They allude to the idea that checking the key derivation is faster, but I wonder by how much. (of course, it’s still interesting to read about 90s encryption, so I appreciate that they did it the fun way)
- unscaled 1y agoI assume the hard part would have been automating this or extracting the key derivation and check code out of QText so you can run it separately in a loop. I'm pretty sure you can automate DOSBox input, but if you're more comfortable with reversing algorithms than writing reliable UI automation script then what they did isn't necessarily an overkill.
- gizajob 1y agoWhy waste 2 seconds of my time making your website have a splash screen?
- coldcity 1y agoWho would have thought that in 2025 I'd be hyper alert to cute ASCII art splashes where one row is mysteriously misaligned? It's the details that are the giveaway.