6 ms·
When AES(☢) = ☠ – a crypto-binary trick
- drdaeman 12y agoThere's also a word play in the title. "AES" transliterates to "АЭС" (acronym for "Атомная Электростанция") in Russian (and some other Slavic languages), which means "nuclear power plant". Thus, the "☢" sign.
- ange4771_ 12y agothat's totally unintended: I just looked for some interesting unicode characters and chose these 2 for the video game references ;)
- mooism2 12y agoActual link: https://speakerdeck.com/ange/when-aes-equals-episode-v https://speakerdeck.com/ange/when-aes-equals-episode-v
- BrokenPipe 12y agoimpressive! a very cool hack!
- JoachimS 12y agoA good example of why a MAC after encryption is also needed. And blocking length extension attacks.
- tptacek 12y agoWhere do length extension attacks come into play with angecrypt?
- dikei 12y agoCool trick, I have encountered something like this in a steganography wargame before, the only difference is they used Base64 encoding on the original picture instead of AES :)
- yiedyie 12y agoBase64 is not true encryption, it doesn't require a key it is merely obfuscation.
- georgemcbay 12y agoIn the general usage case base64 is not even obfuscation, really (though it does make it non-human-readable... for most humans), just an encoding for dealing with situations where you need to store or transmit 8-bit or multibyte character data into a system that may otherwise be incapable of dealing with it reliably.
- dikei 12y agoOf course it's not, but the method is the same, you append a different picture to the end and modify the original image header to point to it. The encoding or encryption is not relevant.
- silsha 12y agoRecording of the talk: http://podcast.raumzeitlabor.de/#wbHkVZfCNuE http://podcast.raumzeitlabor.de/#wbHkVZfCNuE
- frik 12y agoImpressive. That's also the reason why one should limit the max-length of a password field (something reasonable), if one is using the salted-password in db approach. Otherwise someone could enter a very long password to do the trick (MD5/SHA1), see http://en.wikipedia.org/wiki/MD5#Security http://en.wikipedia.org/wiki/MD5#Security .
- jimktrains2 12y agoI guess I'm not following your logic. If there is a salted, hashed password in a db, allowing arbitrary length passwords shouldn't matter? HMACs and KDFs work very differently from symetric-crypto primatives.
- michaelmior 12y agoThe point is that it makes it easier for an attacker to find a hash collision. It's much easier to construct data which hashes to a given value if it can be of arbitrary length. I don't immediately see the connection with this article however.
- tptacek 12y agoThe attacker doesn't need a hash collision in the case you're describing; they need a preimage.
- asdfaoeu 12y agoI don't follow. Breaking a password hash your not trying to find a hash collision you need to break the preimage attack. Sure are some stage in the future there might be a preimage attack that requires a large amount of data to use. But really if your worried about theoretical preimage attack you aren't using md5.
- aidos 12y agoThat was a great read. I saw the title and figured it would quickly go over my head but it's all pretty understandable. Does anyone know where I can download the src to have a look through? Edit: found it https://code.google.com/p/corkami/source/browse/#svn%2Ftrunk%2Fsrc%2Fangecryption https://code.google.com/p/corkami/source/browse/#svn%2Ftrunk...
- thristian 12y agoI love the "HexII" hex-dump format he links to, it's so much less cluttered than the traditional one. I'm definitely going to have to try that out the next time I'm picking apart some binary file.
- ange4771_ 12y agothanks - HexII is in very early development for now.
- reblochon 12y agoDoes any one know the name of the hex editor used in these slides, the one showing the PNG chunks and JPEG information?
- ange4771_ 12y agothat's https://bitbucket.org/haypo/hachoir/wiki/Home https://bitbucket.org/haypo/hachoir/wiki/Home
- glial 12y agoWhat's the benefit of AES using such small blocks?
- AnthonyMouse 12y agoThe block size of a symmetric cipher will generally be in the neighborhood of the key length. You can imagine the problem if you had a 128-bit key but an 8-bit block size -- for each of the 256 possible inputs you would have only 256 possible outputs. There would be multiple keys that produced the same mapping and you could produce every possible mapping with only 65536 keys. So the block size needs to be near the key size. Making it larger than that wouldn't make it any more secure but would make it slower.
- tzs 12y agoThis doesn't sound right to me. There are 256! permutations of the set {0, 1, 2, 3, ..., 255}. 256! is much bigger than 2^128, so I see no reason that each key cannot produce a unique mapping. > So the block size needs to be near the key size Note that AES-256 has a 256 bit key, but the block size is 128 bits, which is not near the key size. I believe that the main constraint on block size is that a small block limits the length of messages you can safely encrypt with a given key. If the bad guys see a lot of cipher text encrypted with the same key, they have a better chance of a successful attack. What "a lot of cipher text" means depends on the block size. The bigger the block size, the more cipher text is needed to constitute "a lot of cipher text".
- deleted 12y ago[deleted]
- AnthonyMouse 12y agoWow, that was stupid of me. Yes of course, the number of possible mappings is 256! rather than the square of 256. I don't know what I was thinking.
- tptacek 12y agoA smaller block also gives you less room to maneuver when designing modes of operation; for instance, it can be tricky to implement CTR with a 64 bit block --- the convention is to split the block into "counter" and "nonce", and you need enough space for the counter that it can't conceivably wrap.
- ShowNectar 12y agoWhere do you store the IV? Do you just append it at the end of the file?
- mzs 12y agoYou have to supply that, see the python script, at the end it prints what to run to decrypt, the determined IV is passed as a param: http://corkami.googlecode.com/svn/trunk/src/angecryption/angecrypt.py http://corkami.googlecode.com/svn/trunk/src/angecryption/ang...
- hzc 12y agothis is awesome. now I hide secret information in a seemingly innocent image. no one would want to use AES to decrypt it if the image looks fine.
- krick 12y agoThat's amazing. Didn't think it's even possible, however it turns out to be surprisingly simple. Also, laughed out loud because of that guy's twitter nickname on the 3rd slide.