Slashdot Mirror


Encrypted Images Vulnerable To New Attack

rifles only writes "A German techie has found a remarkably simple way to discern some of the content of encrypted volumes containing images. The encrypted images don't reveal themselves totally, but in many cases do let an attacker see the outline of a high-contrast image. The attack works regardless of the encryption algorithm used (the widely-used AES for instance), and affects all utilities that use single symmetric keys. More significant to police around the world struggling with criminal and terrorist use of encryption, the attack also breaks the ability of users to 'hide' separate encrypted volumes inside already encrypted volumes, whose existence can now for the first time be revealed." The discoverer of this attack works for a company making full-disk encryption software; their product, TurboCrypt, has already been enhanced to defeat the attack. Other on-the-fly encryption products will probably be similarly enhanced, as the discoverer asserts: "To our knowledge is the described method free of patents and the author can confirm that he hasn't applied for protection."

6 of 155 comments (clear)

  1. aw4jthpa by Anonymous Coward · · Score: 1, Funny

    naivjdae4ovhnrBuAbrf!AbjLbhPnaFrrZlPbzzrag!;wfqudnwrenfyihltred

    1. Re:aw4jthpa by martinw89 · · Score: 4, Funny

      Oh god, thanks for the outline of Goatse.

      Jerk.

    2. Re:aw4jthpa by mrsteveman1 · · Score: 4, Funny

      You didn't look close enough, there was a hidden volume inside!

  2. Re:Confusing by mikesd81 · · Score: 3, Funny

    In fact I had to read the fine article (I know, unheard of) to figure it out. Maybe that's the new thing to get us to RTFA. Use even more confusing summaries?

    --
    That which does not kill me only postpones the inevitable.
  3. Re:Only works on uncompressed bitmaps by clarkkent09 · · Score: 4, Funny

    Whew, thanks for pointing that out. Most of my encrypted porn is jpgs

    --
    Negative moral value of force outweighs the positive value of good intentions.
  4. Re:Confusing by Anonymous Coward · · Score: 3, Funny

    Can you tell us what you figured out so we can RYFC instead of TFA?