Slashdot Mirror


Flaw Crippling Millions of Crypto Keys Is Worse Than First Disclosed (arstechnica.com)

An anonymous reader quotes a report from Ars Technica: A crippling flaw affecting millions -- and possibly hundreds of millions -- of encryption keys used in some of the highest-stakes security settings is considerably easier to exploit than originally reported, cryptographers declared over the weekend. The assessment came as Estonia abruptly suspended 760,000 national ID cards used for voting, filing taxes, and encrypting sensitive documents. The critical weakness allows attackers to calculate the private portion of any vulnerable key using nothing more than the corresponding public portion. Hackers can then use the private key to impersonate key owners, decrypt sensitive data, sneak malicious code into digitally signed software, and bypass protections that prevent accessing or tampering with stolen PCs. When researchers first disclosed the flaw three weeks ago, they estimated it would cost an attacker renting time on a commercial cloud service an average of $38 and 25 minutes to break a vulnerable 1024-bit key and $20,000 and nine days for a 2048-bit key. Organizations known to use keys vulnerable to ROCA—named for the Return of the Coppersmith Attack the factorization method is based on—have largely downplayed the severity of the weakness.

On Sunday, researchers Daniel J. Bernstein and Tanja Lange reported they developed an attack that was 25 percent more efficient than the one created by original ROCA researchers. The new attack was solely the result of Bernstein and Lange based only on the public disclosure information from October 16, which at the time omitted specifics of the factorization attack in an attempt to increase the time hackers would need to carry out real-world attacks. After creating their more efficient attack, they submitted it to the original researchers. The release last week of the original attack may help to improve attacks further and to stoke additional improvements from other researchers as well.

76 comments

  1. Organizations known to use keys vulnerable to ROCA by Anonymous Coward · · Score: 0

    List please? Or is this going to be another one of those things?

  2. encryption is overrated by Anonymous Coward · · Score: 1
    1. Re:encryption is overrated by Anonymous Coward · · Score: 0

      Do you want terrorist nerds? Because that's how you get terrorist nerds hitting us with bombs and chemicals and shit. Violence begets more violence.

  3. Effected Vendors? by Chrontius · · Score: 3, Interesting

    Anyone want to give me a list of whose smartcards to avoid?

    I know Yubikeys were recalled for this; if you have an effected key they'll ship you a new one for free. The old ones are fine, just so long as you don't use the internal key generator hardware EVER AGAIN. I plan on putting a red dot on mine with nail polish, and retiring them to emitting static passwords for my online games.

    1. Re:Effected Vendors? by Anonymous Coward · · Score: 3, Interesting

      "The issue weakens the strength of on-chip RSA key generation and affects some use cases for the Personal Identity Verification (PIV) smart card and OpenPGP functionality of the YubiKey 4 platform. Other functions of the YubiKey 4, including PIV Smart Cards with ECC keys, FIDO U2F, Yubico OTP, and OATH functions, are not affected. YubiKey NEO and FIDO U2F Security Key are not impacted."

      Quoted from Yubico's security advisory. I think you're over reacting if you're thinking of, "retiring them to emitting static passwords..."

    2. Re:Effected Vendors? by Anonymous Coward · · Score: 0

      Affected

    3. Re:Effected Vendors? by Anonymous Coward · · Score: 1

      Effected Vendors? Do you mean the vendors that are doing something about this?

      Effected key? Do you mean a key that is doing something?

      If that's what you mean, then your post makes no sense. If it's not what you mean then you're using the wrong word. Try this one instead: Affected.

      http://www.businessdictionary.com/article/967/affected-vs-effected-d1113/

    4. Re:Effected Vendors? by Anonymous Coward · · Score: 0

      You know I used to have no problem using the correct spelling. But now I have seen so many incorrect uses my built in filter of the right way and the wrong way has been so blurred and poisoned at the well that I have to really think about it hard each time I go to use it. And that really pisses me off.

      o/t this is Fox News's game - blur the truth enough and people can't tell the difference any more even if they once could. At that point they just go for the sugar hit.

    5. Re:Effected Vendors? by Anonymous Coward · · Score: 1

      No. He's right. There's no fucking excuse for a grown ass adult to not know the difference between "affect" and "effect." It's laziness and willful ignorance.

    6. Re:Effected Vendors? by bluefoxlucid · · Score: 1

      Doesn't affect U2F, which is good because I leaned on U2F in my campaign and "the primary manufacture of X screwed it up somehow" creates annoyance. Conceptually, I designed my approach to handle this kind of thing: it's not a government-issue token, you can replace it with something else, and the whole thing is regulation-driven and should be based on NIST publications of what's latest-recommendation; politically, people like inflating flaws.

      Even if it did affect U2F, as you say, you can replace it with a non-flawed one. In the scheme I suggested, you'd just call your bank, voice-verify, and have your keys canceled with the CRAs; your accounts still work, but nobody can open a new credit account in your name until you show up to a bank with a real driver's ID or passport. Risk controls, you know? Even if we screw up that badly, we can just shrug it off with no harm done.

      Eh, maybe it would be more of an opportunity to have something this bad happen--especially right in the middle of deployment. Can always point and go, "See? This is a massive disaster, and a quick call to your bank, firmware update, and visit to your nearest branch at your convenience immediately protects you and lets you get back to opening new credit cards and mortgages when the need presents itself."

    7. Re:Effected Vendors? by Anonymous Coward · · Score: 0

      Since you can get a replacement you might as well, but you're correct - you can even use them as a smart card still as long as you generate the keys elsewhere and then import them onto the card.

    8. Re:Effected Vendors? by Chrontius · · Score: 1
      Actually, I'm pretty sure I'm right in my usage of "effect." Pardon the crappy Unicode support; the upside-down "e" probably won't render correctly.

      effect | fekt |

      noun

      1. a change which is a result or consequence of an action or other cause: the lethal effects of hard drugs | politicians really do have some effect on the lives of ordinary people.

      • the state of being or becoming operative.
      • the extent to which something succeeds or is operative: wind power can be used to great effect.
      • [with modifier] Physics a physical phenomenon, typically named after its discoverer: the Doppler effect.
      • an impression produced in the mind of a person: gentle music can have a soothing effect.

      2: (effects) the lighting, sound, or scenery used in a play, movie, or broadcast: the production relied too much on spectacular effects.

      3: (effects) personal belongings: the insurance covers personal effects.

      verb [with object] cause (something) to happen; bring about: nature always effected a cure | budget cuts that were quietly effected over four years.

      PHRASES

      come into effect

      become operative; start to apply: similar legislation came into effect in Wales on the same date | the Kyoto Protocol officially came into effect last week.

      for effect

      in order to impress people: I suspect he’s controversial for effect.

      in effect

      in operation; in force: a moratorium in effect since 1985 has been lifted.

      used to convey that something is the case in practice even if it is not formally acknowledged to be so: additional payments that are in effect an entrance tax.

      put (or bring or carry) something into effect

      cause something to apply or become operative: they succeeded in putting their strategies into effect.

      take effect

      become operative; start to apply: the ban is to take effect in six months.

      to the effect

      that used to refer to the general sense of something written or spoken: some comments to the effect that my essay was a little light on analysis.

      to that effect

      having that result, purpose, or meaning: she thought it a foolish rule and put a notice to that effect in a newspaper.

      ORIGIN

      late Middle English: from Old French, or from Latin effectus, from efficere ‘accomplish’, from ex- ‘out, thoroughly’ + facere ‘do, make’. effect (sense 3 of the noun) , ‘personal belongings’, arose from the obsolete sense ‘something acquired on completion of an action’.

      USAGE

      For the differences in use between effect and affect, see usage at affect.

      affect | fekt |

      verb [with object]

      have an effect on; make a difference to: the dampness began to affect my health | [with clause] : your attitude will affect how successful you are.

      touch the feelings of (someone); move emotionally: the atrocities he witnessed have affected him most deeply.

      ORIGIN

      late Middle English (in the sense ‘attack as a disease’): from French affecter or Latin affect- ‘influenced, affected’, from the verb afficere (see affect2).

      USAGE

      Affect and effect are both verbs and nouns, but only effect is common as a noun, usually meaning ‘a result, consequence, impression, etc.’: my father’s warnings had no effect on my adventurousness. The noun affect is restricted almost entirely to psychology (see affect3). As verbs, they are used differently. Affect most commonly means ‘produce an effect on, influence’: smoking during

    9. Re:Effected Vendors? by Chrontius · · Score: 1

      This is true, and I'm not really "in production" with it - though I do manage IT assets for my extended family. Having said that, their certs all came from Comodo.

      It ain't exactly rocket surgery over here, and we're not the soft targets one hopes to avoid being, so. :-p

    10. Re:Effected Vendors? by Chrontius · · Score: 1

      Actually, I don't have much need for certificate-bearing smartcard emulators; on the contrary, I do need rather a lot of static-password emitting devices.

  4. Re:Organizations known to use keys vulnerable to R by thomst · · Score: 5, Informative

    List please? Or is this going to be another one of those things?

    Well, according to the authors' preprint version of the actual paper, there's quite a few software implementations of RSA-based encryption that are vulnerable - PGP among them.

    If you'd prefer the authors' summary version, you'll find it here.

    --
    Check out my novel.
  5. Online voting in Estonia by Anonymous Coward · · Score: 4, Informative

    Estonia has online voting using these ids. It's also been heavily cyber and social attacked by neighboring Russia. So the democracy is at risk as long as they continue to allow online voting using ids with unknown flaws:

    https://estoniaevoting.org/press-release/

    "Estonia is the only country in the world that relies on Internet voting in a significant way for national elections. The system is currently used for Estonia’s national parliamentary elections, municipal elections and is planned to be used for the May 2014 European Parliamentary elections. In recent polls, 20-25% of voters cast their ballots online."

    "In one [simulated by security experts critical of the system] attack, malware on the voter’s computer silently steals votes, despite the systems’ use of secure national ID cards and smartphone verification. A second kind of attack smuggles vote-stealing software into the tabulation server that produces the final official count. The team produced videos in which they carry out exactly the same configuration steps as election officials — but with the system under attack by a simulated state-level adversary. Everything appears normal, but the final count produces a dishonest result."

    The big wake up call for them was a cyber attack by Russia in 2007:
    https://en.wikipedia.org/wiki/2007_cyberattacks_on_Estonia

    BTW, Trump has ignored the deadline to impose sanctions against Russia for its cyber attack, and simply hasn't implemented them.

    1. Re:Online voting in Estonia by Anonymous Coward · · Score: 1

      Russia also kicked my dog.

    2. Re:Online voting in Estonia by Anonymous Coward · · Score: 0, Insightful

      All NSA cyber attacks are now routinely pushed through Russian servers in an effort to "implicate" Russia in ALL cyber attacks that they carry out.
      But it wasn't RUSSIA that created Stuxnet, nor the base code for a STRING of recent hacking tools.

    3. Re:Online voting in Estonia by Anonymous Coward · · Score: 0

      Russia made my milk spoil.

    4. Re: Online voting in Estonia by Anonymous Coward · · Score: 0

      Russia made me fail my first drivers license test when I was in high school.

    5. Re:Online voting in Estonia by Anonymous Coward · · Score: 0

      The above comment is apparently spam, and a copy of this one.

    6. Re:Online voting in Estonia by Anonymous Coward · · Score: 5, Funny

      And all USA military attacks are launched from Russian soil, that's how USA invaded Ukraine and Georgia secretly without anyone noticing! All they had to do was sneak onto Russian soil first!

      And NSA wanted Trump in power, which is why they cyber attacked their own election to selectively release emails on his competitors. The devils!

      NSA is soooo cunning, they even hired dodgy Russian businessmen to buy up Trump condos shortly after the property crash, using Russian cash laundered through Cyprus, giving his buildings a fake inflated value that he could over-leverage against and keep his ponzi property empire afloat. Just so two election cycles later it could pretend he was heavily indebted to his Russian friends!

      Damn cunning NSA, always blaming sweet sweet innocent Putin for everything.

    7. Re:Online voting in Estonia by Anonymous Coward · · Score: 0

      #55511631> #55511519, Parent seems to be the original, with the lower message id, with the copy being a link correct one by someone call 'Beau'.

      Either way, the idea of having online voting, connecting your voting system to every attacker in the world, specifically when you have been repeatedly attacked by your neighbor/former invader. EXPOSING YOUR VOTING SYSTEM TO THAT ATTACKER is insanely dumb. That's what they've done with online voting.

      Their democracy is one hack away from being taken from them.

      Estonia should walk back their online voting system. Even a bad actor in the software development, or voting machine configuration, or voting machine QA, could rig that election silently. They've simply made it trivial to hijack the vote.

      They need to walk it back to a verifiable paper voting system that anyone/everyone participating in the vote can check for themselves and thus have confidence in.

    8. Re:Online voting in Estonia by butzwonker · · Score: 1

      That may be one and the same person but it's also possible that someone does that to troll the original poster (PopeRatzo?), and/or to collect karma for nefarious purposes.

    9. Re:Online voting in Estonia by Anonymous Coward · · Score: 2, Insightful

      Count yourself lucky. The Chinese would have eaten it!

    10. Re:Online voting in Estonia by DNS-and-BIND · · Score: 0

      Why does Estonia need voter ID to ensure the integrity of its elections? That shit is a racist dog whistle. We just had a successful election in Virginia yesterday with no voter ID. How does this get modded up? (baffled)

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    11. Re:Online voting in Estonia by Anonymous Coward · · Score: 0

      Exactly. It's all about preventing people from voting.

    12. Re:Online voting in Estonia by Anonymous Coward · · Score: 0

      Without voter ID, how do you ensure people don't vote twice?

    13. Re:Online voting in Estonia by Anonymous Coward · · Score: 1

      There's absolutely no way to accurately measure whether it's happening or not.

      So obviously, any solution to ensure there's a way to accurately measure it is "a racist dogwhistle."

      If you say anything else on the matter, you're a racist too. Wait, people might think I'm racist as well, since we share a similar name. Please shut up.

    14. Re:Online voting in Estonia by Anonymous Coward · · Score: 0

      They work together. First the Russians 'tenderize' the dog, then the Chinese eat it. The Chinese then build a military airstrip on the doghouse in your yard and claim that they have always been there.

    15. Re:Online voting in Estonia by Anonymous Coward · · Score: 1

      So Hillary was really selling US uranium to the NSA?

    16. Re:Online voting in Estonia by Anonymous Coward · · Score: 0

      Can we mod parent -1, Just Plain Wrong?

      Virginia has a voter ID requirement.

      From https://www.elections.virginia.gov/registration/photo-ids-required-to-vote/

      About Virginia Voter Photo Identification
      Virginia law requires all voters to provide an acceptable form of photo identification (photo ID) when voting in person at their polling place.

    17. Re:Online voting in Estonia by DCFusor · · Score: 1

      No, they paid Hillary's pals to kill Seth Rich so they could take the credit for hacking the DNC. Couldn't have it known that a disgusted insider leaked.

      --
      Why guess when you can know? Measure!
    18. Re: Online voting in Estonia by Anonymous Coward · · Score: 0

      For reference, Estonian e-voting documentation can be read at:
      https://www.valimised.ee/en/internet-voting/documents-about-internet-voting
      The design principles, system architecture, source code, audit procedures, etc are there for public scrutiny.

  6. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 0, Insightful

    That's not what I'm asking. I want a list of vendors to see who I might be using, but we always get the runaround on this.

  7. Re:Organizations known to use keys vulnerable to R by plover · · Score: 5, Informative

    What you can do is submit your public key to an online checker, like https://keytester.cryptosense.... and see if it's vulnerable.

    --
    John
  8. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 0

    HA! Neat trick!

  9. So, you're saying by Anonymous Coward · · Score: 0

    now's a bad time to renounce my US citizenship and emmigrate to Estonia? Just want to be clear on this.

    1. Re: So, you're saying by Anonymous Coward · · Score: 0

      Wrong, never has there been a better time. You get to choose who you want to be in Estonia!

  10. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 2, Interesting

    Estonia has online voting using these ids. It's also been heavily cyber and social attacked by neighboring Russia. So the democracy is at risk as long as they continue to allow online voting using ids with unknown flaws:

    estoniavoting link

    "Estonia is the only country in the world that relies on Internet voting in a significant way for national elections. The system is currently used for Estonia’s national parliamentary elections, municipal elections and is planned to be used for the May 2014 European Parliamentary elections. In recent polls, 20-25% of voters cast their ballots online."

    "In one [simulated by security experts critical of the system] attack, malware on the voter’s computer silently steals votes, despite the systems’ use of secure national ID cards and smartphone verification. A second kind of attack smuggles vote-stealing software into the tabulation server that produces the final official count. The team produced videos in which they carry out exactly the same configuration steps as election officials — but with the system under attack by a simulated state-level adversary. Everything appears normal, but the final count produces a dishonest result."

    The big wake up call for them was a cyber attack by Russia in 2007:

    (wiki link)

    BTW, Trump has ignored the deadline to impose sanctions against Russia for its cyber attack, and simply hasn't implemented them.
     
    Post corected by:
    -=Beau=-

  11. Hohoho by Anonymous Coward · · Score: 0

    HAHAHA

  12. All FIPS certified models. by Anonymous Coward · · Score: 0

    Which probably means ALL OF THEM.

    Only models with a non-FIPS PRNG/cipher configs MIGHT be safe, although they still need to go through rigorous testing and their entropy failures may be different than the FIPS exploits.

    The Clipper Chip concept is alive and well, eh?

  13. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 1

    Online voting in Estonia is inherently more secure than paper ballots, which are much easier to manipulate.

    Furthermore, this form of voting is a lot unlike this black-box electronic voting sham in the U.S., which has outdated and vulnerable machines with old operating systems spread around far and wide. In many respects, Estonia has electronic voting done right.

  14. Software designed for this specific hardware by raymorris · · Score: 3, Interesting

    From my understanding, the error was made by a hardware vendor who makes an encryption chip, and is present in the specialized library used with their chip. It can be loaded from software, but it's not what I'd call a "software implementation", the software is just an interface to this one vendor's hardware chip.

    The list of products using this hardware chip is quite long, and I haven't seen a comprehensive list published. We can say that it's hardware-based systems, smartcards and the like, that are affected.

    Of course it's also possible that developers of some pure software systems independently made the same error, separately from the reported flaw.

    1. Re:Software designed for this specific hardware by Anonymous Coward · · Score: 0

      YubiKey (version 4) is one of them, their response has been good. First, they updated the firmware months ago so new keys are no longer affected, they have also posted workarounds and are offering to replace affected keys.

      With the Yubikey and many other smart cards, you can either have the built-in chip generate the keys, or you can generate the keys elsewhere and import them onto the chip. This flaw affects keys generated on the card itself. I prefer generating keys in gpg and then importing (because backups...) which is unaffected by this flaw, however using the built-in function is generally considered "more secure" because the private keys have only ever existed on the card, where nothing ever has direct access to them.

    2. Re:Software designed for this specific hardware by arglebargle_xiv · · Score: 1

      In any case there's nothing to worry about, both NIST and the EU Common Criteria guys have certified it as being completely secure, so the vulnerability is all just a figment of our imagination.

  15. Re:National ID cards used for voting? by Anonymous Coward · · Score: 2, Insightful

    4M+ illegal voters on 11/8/16.

    (In a very tired voice)

    Evidence, please?

  16. Stop putting those backdoors in by Anonymous Coward · · Score: 0

    If you don't, you will pay for compromised security. Literally.
    Nobody can believe this was an accident. Weaken the cryptography just enough that someone who is in the know can break it with some effort?

  17. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 1

    As much as I welcome Estonia's leading role in the development of democratic governance, your claim is unfortunately very, very untrue. We know that it's possible to store persistent viruses in the firmware of hard drives, let alone the possible exploits of UEFI, and the Intel ME and AMD PSP. Online voting systems are much easier to tamper on a massive scale than paper ballots, because of a lack of reliable endpoint security. All PCs are insecure, whether used with card readers or not.

  18. Re:Organizations known to use keys vulnerable to R by paavo512 · · Score: 3, Informative

    All PCs are insecure, whether used with card readers or not.

    That's why in Estonia you can double-check via a physically independent channel (smartphone app) that your vote reached the server correctly. Worked fine for me at the recent elections.

  19. Dan Bernstein... that guy again... by Anonymous Coward · · Score: 5, Interesting

    Full disclosure: I am in the academic crypto community, I have met Dan Bernstein and Tanja Lange countless times at seminars, conferences, etc. Posting as AC for obvious reasons.

    Just to put it into perspective for the readers who don't know: Dan and Tanja are longtime partners, they have most of their work done together. Tanja is cool. Dan Bernstein, however, is totally not. He is smart, but not *that* smart, not as much as he wants people to believe anyway. And that's totally fine, at the end you have to do your best to advertise yourself and sell your expertise, everybody does it, and Dan is not one of the worst ones in this respect.

    What I can't stand about this guy though is the aggressive, obsessive, and self-glorifying way he uses when discussing any possible little thing. Like, he needs to show you that he's ALWAYS right, that he's THE BEST on every possible discussion topics. You can clearly see that this poor guy was bullied hardcore as a child, and now he feels like he has to compensate his insecurities through this aggressive behavior.

    Typical thing he does, as this slashdot story shows, is taking credit for any big crypto-related breakthrough, even if it does not originally come from himself. Some researcher with less PR skills than Dan come up with a clever attack that makes it into the news? Dan comes up with a *minor* improvement on that work, downplaying the importance of the first attack, and hitting all the tech news websites with glorifying headlines. Like in the case of this slashdot story. Or like when, after Marc Steven's collision attack on SHA-1, he made some minor improvements and changed his twitter handle to @hashbreaker (that was ridiculous, and I really liked Marc's response of changing his handle to @realhashbreaker lol! Dan is indeed, in a certain sense, the academic equivalent of The Donald).

    There are many other examples of Dan's claiming expertise he dose not have and bashing other researchers on topic he's not an expert of. Just have a look at the IACR (almost unused) forum, or GoogleGroups related to lattice-based crypto, or Twitter, and much more. In any case, he'd NEVER admit he was wrong.

    I do not comment on his involvement in the Jacob Applebaum case, because I'm not really informed, and I'm not a vigilante.

    Seriously Dan, if you're reading this: take a hint! You're fine, really, you don't have to behave like this. This is not just my opinion, mind you, I have talked with many and many crypto people who think the same, and they just don't tell you because they do not want to be involved in pointless discussions with you. Can you please be nicer to people? I'm sure your career would also benefit from it.

    1. Re:Dan Bernstein... that guy again... by Anonymous Coward · · Score: 0

      He came up with a faster way to crack it . So what. You sound a bit jealous if you ask me.

    2. Re:Dan Bernstein... that guy again... by Anonymous Coward · · Score: 0

      Tanja is that you?

    3. Re:Dan Bernstein... that guy again... by mesterha · · Score: 2

      When I read the summary, I didn't understand the importance of a 25% improvement. It seemed trivial. Going from impossible to 25 minutes is big. Going from 25 minutes to 18 minutes is minor. (A student in the area could probably optimize the original code to get this kind of improvement.) Maybe I'm missing something, but perhaps the GP has the right explanation...

      --

      Chris Mesterharm
    4. Re:Dan Bernstein... that guy again... by Ungrounded+Lightning · · Score: 2

      When I read the summary, I didn't understand the importance of a 25% improvement. It seemed trivial. Going from impossible to 25 minutes is big. Going from 25 minutes to 18 minutes is minor.

      If I'm (speed) reading the postings correctly, (BIG caveat) ...

      what he did was:
        * Look at the open postings, which didn't reveal the details of the attack or publish its code.
        * Figure out (from this and his crypto-related math knowledge) enough to, independently, come up with both a variant attack (that ran faster) and an explanation that's accessible to people with just some background and access to wikipedia to fill in the blanks.
        * and publish "here's what I did and here's how it works".

      So the big deal is not the speed improvement, but (being able and choosing to) bringing the guts of the crack out to where it's accessible to people without connections to the crypto-community's internal deliberations.

      Also: He may have found additional, or different, attacks (or pieces of them) than the original authors - and he fed that back to them and received acknowledgement that his input improved their code as well.

      --
      Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  20. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 1

    Online voting in Estonia is inherently more secure than paper ballots, which are much easier to manipulate.

    ...

    WUT?!?!?

    "It's not the people who vote that count, it's the people who count the votes." - Josef Stalin

    Get control of the counting software and you control the country, with no evidence to the contrary.

    At least with paper ballots, the ballots themselves exist.

  21. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 0

    So they need to hack the app/the server talking with the app in addition.
    Seriously, that's all it takes to convince you?
    How would you even know if the server added the votes up correctly? Doesn't even have to be malicious.
    Not to mention that the idea of checking one single vote in itself is ludicrous. What's the point of your vote being counted correctly if the remaining 99.99999% aren't? Even if he system was working and secure (and it almost certainly isn't) you'd need maybe 80% to actually do the checking for it to really be effective. And what if you have a group that secretly decides to claim their vote was miscounted? Do you just ignore any such claims (then what's the point?). Or do you intend to let any minority invalidate the election whenever they feel like it?
    With paper voting, the votes are counted locally, under the eyes of anyone interested. They take notes of the results. These local results, and the results on level higher etc. are then printed in the paper. As long as you assume that the local results are checked well enough by the local people in charge you can verify the whole thing. Checking your single vote is utterly useless. The step from personally identifiable votes (which must be kept secret and thus cannot be allowed to be verified by the general public) to a reasonable aggregate (that can be published and thus secures the processing from there on up by making it publicly verifiable) is what needs to be protected, and with systems that we understand how to secure. Anything involving the word "smartphone" doesn't even qualify. If someone claims irregularities, it's either in the counting and can be addressed right there, or the claim is about the very simple step from getting the tally results from a paper there to the newspapers/main office somewhere else and is easy enough to verify as right or wrong.

  22. On the brightside by Anonymous Coward · · Score: 0

    Does this mean DIY free topups hacks for public transport cards, Tollway Transponder, BluRays, CableTV and more is up for grabs. Mexico cartels will be so thankful for the USA passport smartchip - now they have more options.
    More stuff hat hotspot WiFi locations, people using old Ipads and the like. WooHoo.

    I bet Skype is not in a hurry to fix any weaknesses,

  23. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 0

    But at least we know that Bitcoin software is not vulnerable to such errors

  24. Did he come up with the headlines? by Anonymous Coward · · Score: 1

    I got the link first through some other venue so I did read it, and he clearly states right up front what he's done, that his work was not independent, and so on. So the meat of the matter was not dishonest.

    I took it as was described, as an exercise in seeing what he could come up with given the few hints the original researchers let drop, which is quite a bit, in fact. That datum is interesting (if to me not surprising), when taken as such. The breathless headline and non-story from the "copy/paste-press" (that I didn't read) notwithstanding. And yeah, I'm ignoring the tweeter shenanigans and whatnots, too.

    I'm willing to ignore the shenanigans as long as he sticks to cryptography. Haven't forgiven him for qmail, djbdns, and especially not daemontools. And let's be honest here: Most of the "security" headlines are full of self-glorifying bullshitting; he manages to come up with well-argued substance moreso than the rest of the bunch, including the big name corps. Which is not to say he couldn't do better. Something to try next time, eh.

  25. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 0

    All PCs are insecure, whether used with card readers or not.

    That's why in Estonia you can double-check via a physically independent channel (smartphone app) that your vote reached the server correctly. Worked fine for me at the recent elections.

    Only for very loose definitions of "worked fine".

    You really trust the system that counted your vote to tell you if it's lying?

  26. You mean Dilberts third party ..... by Anonymous Coward · · Score: 0

    It's no surprise. Dilbert's company has been farming work out to that country for years with poor results.

  27. Re:Organizations known to use keys vulnerable to R by paavo512 · · Score: 2

    If the servers get compromised then it's game over. That's the same with paper ballots, if the central office is corrupt then there is no trust in the results. It is true that there needs to be some trust in the state officials; electronic voting would probably not work in some other countries where 146% voter turnout or 99% single party wins are common. But that's not the problem with paper or technology, it's the problem with the state.

    For detecting that there is something fishy happening you don't need 80% coverage. Even a handful of mismatches would create a huge media storm (assuming free press) and a detailed investigation would be started. The same would happen if the election results would not resemble any pre-election predictions or polls.

    Paper ballots regularly get miscounted, intentionally or unintentionally. In totalitarian countries it's also easy to fake the paper ballots, any reports would be just ignored or silenced (see e.g. http://www.nytimes.com/2012/03... ). But this would require silenced press.

    Estonia is currently at the 12-th place in the press freedom index (out of 180), which is a very different situation from e.g. Russia (place 148) or even US (place 46). What works in one country may not work in another.

  28. so by Anonymous Coward · · Score: 0

    hacker uses a bot net not to ddos you but break keys

    think 1000 bots as pcs of 1000 times less time.....think about the nsa with 1 million or 10 million less time

  29. Re: National ID cards used for voting? by spongman · · Score: 1

    And he world is _flat_, damnit!

  30. Re:Organizations known to use keys vulnerable to R by 93+Escort+Wagon · · Score: 1

    Interesting. The story states that PGP may be vulnerable, but when I put my (known good) public gpg key into the crypto sense tester it says "Sorry, this doesn't look like a valid or supported key".

    So it would seem either the story is incorrect in claiming PGP keys are vulnerable, or else the tester is badly written.

    --
    #DeleteChrome
  31. Lets see... by Anonymous Coward · · Score: 0

    I wonder how long it's going to be until the U.S. Government or world bank, or IMF, or United Nations or Federal Reserve, etc. offer their own "solution".

  32. Re:Organizations known to use keys vulnerable to R by rthille · · Score: 1

    Russian bot?

    --
    Awesome furniture, accessories and cabinetry in Santa Rosa, CA: http://humanity-home.com/
  33. Security thru obscurity by Anonymous Coward · · Score: 0

    is the root cause of this.

    The widely used implementation's prime picker picked from a subset of primes governed by a cleverly crafted equation.
    p = k*M + (65537**a mod M), where M is known, special, and sized so that a and k are about 100 bits.
    Allowed the conversion of a 512 RSA key from 256 bits of entropy to 99 bits.

    And worse, the converted entropy did not increase as expected with the key size.
    It almost appears optimized for easy opening of the popular key sizes of 512, 1k, 2k, 4k.

    One with a tin foil hat would wonder how such a 'feature' could get into something so important.
    Also, what 'features' are in other PKI's?

  34. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 0

    Ya, right. Our local Estonian Reformierakond used the ID card to cheat in elections.
    No way a 90 or 103 year old people in "old peoples homes" can vote online in 30 seconds as the "official logs" show ...

  35. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 0

    No way a 90 or 103 year old people in "old peoples homes" can vote online in 30 seconds as the "official logs" show

    That's an issue not with the Reform party, but with the managers of those old people's homes. And the managers of these homes are usually Soviet people (lat. homo sovieticus)

    By the way, if a 93-year-old lady can drive a Tesla car, then 90-year-old people can vote online, too. So long their minds are sharp, and as long as their PIN codes are not in anyone's wrong hands.

    The reason that online voting in Estona is more secure, is that votes actually cannot be manipulated by anyone, which is one of the things about i-voting that really ticks off the pro-Russia Center party.

  36. Re:Organizations known to use keys vulnerable to R by Anonymous Coward · · Score: 0

    At least with paper ballots, the ballots themselves exist.

    Do they?