<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>CryptoBlog - Data Security and Information Theory</title>
	<atom:link href="http://cryptoblog.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://cryptoblog.wordpress.com</link>
	<description>Cryptography, Information Theory and Codes</description>
	<lastBuildDate>Sun, 15 Jan 2012 22:56:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='cryptoblog.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/b9a9581c450df89130f0cab713eb66cf?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>CryptoBlog - Data Security and Information Theory</title>
		<link>http://cryptoblog.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://cryptoblog.wordpress.com/osd.xml" title="CryptoBlog - Data Security and Information Theory" />
	<atom:link rel='hub' href='http://cryptoblog.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Seeing what stuxnet&#8230;</title>
		<link>http://cryptoblog.wordpress.com/2011/11/19/seeing-what-stuxnet/</link>
		<comments>http://cryptoblog.wordpress.com/2011/11/19/seeing-what-stuxnet/#comments</comments>
		<pubDate>Sat, 19 Nov 2011 17:57:03 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[in the News]]></category>
		<category><![CDATA[InSecurity]]></category>

		<guid isPermaLink="false">https://cryptoblog.wordpress.com/?p=641</guid>
		<description><![CDATA[&#8230; was capable of, it was just a matter of time until someone take a jab to the instalations of an utility company.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=641&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&#8230; was capable of, it was just a matter of time until someone take a <a href="http://www.washingtonpost.com/blogs/checkpoint-washington/post/foreign-hackers-broke-into-illinois-water-plant-control-system-industry-expert-says/2011/11/18/gIQAgmTZYN_blog.html">jab</a> to the instalations of an utility company.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/641/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/641/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/641/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/641/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/641/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/641/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/641/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/641/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/641/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/641/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/641/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/641/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/641/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/641/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=641&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/11/19/seeing-what-stuxnet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>
	</item>
		<item>
		<title>Hacking mechanical vibrations</title>
		<link>http://cryptoblog.wordpress.com/2011/10/27/hacking-mechanical-vibrations/</link>
		<comments>http://cryptoblog.wordpress.com/2011/10/27/hacking-mechanical-vibrations/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 16:20:53 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[in the News]]></category>
		<category><![CDATA[Misc.]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=638</guid>
		<description><![CDATA[These WIRED article described an interesting application of the side channel idea to key-log your typing by sensing mechanical vibrations.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=638&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>These <a href="http://www.wired.com/wiredscience/2011/10/iphone-keylogger-spying/" target="_blank">WIRED</a> article described an interesting application of the side channel idea to key-log your typing by sensing mechanical vibrations.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/638/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/638/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/638/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=638&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/10/27/hacking-mechanical-vibrations/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>
	</item>
		<item>
		<title>We need a &#8220;DO NOT TRACK&#8221; option for smart-phones!</title>
		<link>http://cryptoblog.wordpress.com/2011/04/22/we-need-a-do-not-track-option-for-smart-phones/</link>
		<comments>http://cryptoblog.wordpress.com/2011/04/22/we-need-a-do-not-track-option-for-smart-phones/#comments</comments>
		<pubDate>Fri, 22 Apr 2011 15:40:14 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[in the News]]></category>
		<category><![CDATA[Misc.]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[wi-fi]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[smartphone]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=605</guid>
		<description><![CDATA[Hey Apple, Google, when are you going to have a DO NOT TRACK option on your smartphones&#8217; operating systems? This is another idea, maybe RIM engineers can come up with a feature like that to give the BlackBerrys a fighting chance. The fact that most of us carry (voluntarily) a tracking device should not be [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=605&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_611" class="wp-caption alignleft" style="width: 310px"><a href="http://online.wsj.com/video/news-hub-apple-google-know-exactly-where-you-are/AB53BE18-B81A-4ED7-A5FD-AB67AFDAC67E.html"><img src="http://cryptoblog.files.wordpress.com/2011/04/i_phone_track.jpg?w=300&#038;h=167" alt="smartphones tracking users" title="i-Track-U" width="300" height="167" class="size-medium wp-image-611" /></a><p class="wp-caption-text">smartphones tracking users</p></div>Hey Apple, Google, when are you going to have a <a href="http://donottrack.us/" target="_blank">DO NOT TRACK</a> option on your smartphones&#8217; operating systems?<br />
This is another idea, maybe RIM engineers can come up with a feature like that to <a href="http://www.stockhouse.com/News/CanadianReleasesDetail.aspx?n=8134613" target="_blank">give the BlackBerrys a fighting chance</a>. </p>
<p>The fact that most of us carry (voluntarily) a tracking device should not be news for anybody.  I guess the news-worthy part is that somebody expossed what Apple and Google where doing. I am not sure it is illegal, have you checked the small font bits of the contract you signed? Me neither.<br />
Believe me, that Apple and Google know where you are and where you have been is not the biggest of our problems with privacy as <a href='http://www.cato.org/event.php?eventid=7706' target="_blank">discussed in here</a>.</p>
<p>Related:</p>
<ul>
<li><a href="http://www.cato.org/pubs/pas/pa520.pdf" target="_blank">A good reference to understand privacy</a>.  </li>
<li><a href="http://www.cato-at-liberty.org/the-government-can-monitor-your-location-all-day-every-day-without-implicating-your-fourth-amendment-rights/" target="_blank">We know where you are, and there is nothing you can do about it.</a></li>
</ul>
<p>(h/t) Raymond who sent <a href="http://www.ctv.ca/CTVNews/TopStories/20110421/iphone-ipad-locations-110421/" target="_blank">this link</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/605/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=605&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/04/22/we-need-a-do-not-track-option-for-smart-phones/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>

		<media:content url="http://cryptoblog.files.wordpress.com/2011/04/i_phone_track.jpg?w=300" medium="image">
			<media:title type="html">i-Track-U</media:title>
		</media:content>
	</item>
		<item>
		<title>More on Cyberwar</title>
		<link>http://cryptoblog.wordpress.com/2011/04/07/more-on-cyberwar/</link>
		<comments>http://cryptoblog.wordpress.com/2011/04/07/more-on-cyberwar/#comments</comments>
		<pubDate>Thu, 07 Apr 2011 06:31:39 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[in the News]]></category>
		<category><![CDATA[InSecurity]]></category>
		<category><![CDATA[networks]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Stuxnet]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=596</guid>
		<description><![CDATA[Short Video from PJTV featuring an interview with Paul Rosenzweig.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=596&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.pjtv.com/?cmd=mpg&amp;mpid=101&amp;load=5190"><img src="http://cryptoblog.files.wordpress.com/2011/04/cyberwarpjtv.jpg?w=600&#038;h=336" alt="Cyber War: Is the Ultimate WMD For Sale at Best Buy? " title="CyberWarPJTV" width="600" height="336" class="alignleft size-medium wp-image-597" /></a></p>
<p>Short Video from PJTV featuring an interview with Paul Rosenzweig.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/596/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=596&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/04/07/more-on-cyberwar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>

		<media:content url="http://cryptoblog.files.wordpress.com/2011/04/cyberwarpjtv.jpg?w=300" medium="image">
			<media:title type="html">CyberWarPJTV</media:title>
		</media:content>
	</item>
		<item>
		<title>Attacks on Cryptographic Systems (Part I)</title>
		<link>http://cryptoblog.wordpress.com/2011/03/22/attack-on-cryptographic-systems-part-i/</link>
		<comments>http://cryptoblog.wordpress.com/2011/03/22/attack-on-cryptographic-systems-part-i/#comments</comments>
		<pubDate>Tue, 22 Mar 2011 05:27:55 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[Cryptanalysis]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=592</guid>
		<description><![CDATA[Soft Attacks No matter how sophisticated the attack techniques become, one must not forget that when the ultimate goal is to obtain the secret message, coercion or social engineering are often the most effective attack techniques. These attacks are based on using physical or psychological threats, robbery, bribery, embezzlement, etc. The attacks are mostly directed [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=592&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<ul>
<li><strong>Soft Attacks</strong><br />
No matter how sophisticated the attack techniques become, one must not forget that when the ultimate goal is to obtain the secret message, <em>coercion</em> or <em>social engineering</em> are often the most effective attack techniques. These attacks are based on using physical or psychological threats, robbery, bribery, embezzlement, etc. The attacks are mostly directed to human links of the data security chain.<br />
Social Networks have become a launching pad for these kind of attacks. In a typical soft attack such as the so-called spear-phishing, e-mail addresses and information about the victims social circle is harvested from social networks and then used to send targeted e-mail with malware that cause to reveal secret information for access to secured systems.</li>
<li><strong>Brute Force Attacks</strong><br />
Assuming, as <em>Kerchoff&#8217;s principle</em> recommends, that the algorithm used for encryption and the general context of the message are known to the cryptanalyst, the brute-force attack involves the determination of the specific key being used to encrypt a particular text. When successful, the attacker will also be able to decipher all future messages until the keys are changed. One way to determine the key entails exhaustive search of the <em>key-space</em> (defined as the set of all possible valid keys for the particular crypto-system).<br />
Brute force is a passive, off-line attack in which the attacker Eve passively eavesdrops the communication channel and records cipher text exchanges for further analysis, without interacting with either Alice or Bob.<br />
To estimate the time that a successful brute-force attack will take we need to know the size of the key-space and the speed at which each key can be tested. If <img src='http://s0.wp.com/latex.php?latex=N_k&amp;bg=f0f0f0&amp;fg=555555&amp;s=0' alt='N_k' title='N_k' class='latex' /> is the number of valid keys and we can test <img src='http://s0.wp.com/latex.php?latex=N_s&amp;bg=f0f0f0&amp;fg=555555&amp;s=0' alt='N_s' title='N_s' class='latex' /> keys per second, it will take, on average <img src='http://s0.wp.com/latex.php?latex=%5Cfrac%7B1%7D%7B2%7D%28%5Cfrac%7BN_k%7D%7BN_s%7D%29&amp;bg=f0f0f0&amp;fg=555555&amp;s=0' alt='&#92;frac{1}{2}(&#92;frac{N_k}{N_s})' title='&#92;frac{1}{2}(&#92;frac{N_k}{N_s})' class='latex' /> seconds to find the proper key by brute-force.<br />
The threat that a brute-force attack poses cannot be underestimated in the real world. Most financial institutions use cipher-systems based on DES.  Keys of length 56-bits, such as the one used by the<br />
standard implementation of DES, can be obtained by brute-force using computer hardware and software available since the late 1990&#8242;s. Indeed, to counter this possibility, most contemporary implementations of DES use a derivative known as Triple-DES (or 3-DES) which uses three different 56-bit keys instead of one. The effective key length for the combined 3-DES key is a more secure 168 bits.<br />
Brute force analysis have been used in combination with other attacks as was the case for the deciphering of the Enigma. The famous <em>bombes</em> were an example of the brute-force approach working in combination with a mathematical method that provided an important reduction of the key-space.
</li>
</ul>
<p>To be continued&#8230;..</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/592/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=592&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/03/22/attack-on-cryptographic-systems-part-i/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>
	</item>
		<item>
		<title>Securing the Human</title>
		<link>http://cryptoblog.wordpress.com/2011/03/17/securing-the-human/</link>
		<comments>http://cryptoblog.wordpress.com/2011/03/17/securing-the-human/#comments</comments>
		<pubDate>Thu, 17 Mar 2011 04:39:08 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[in the News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=588</guid>
		<description><![CDATA[SANS Institute set up an excellent resource for those interested in computer security issues (who is not these days?). OUCH! and other newsletters carry current information on the security issues and they are published now in several languages. I&#8217;ve put a permanent link with the badge in the right column.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=588&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>SANS Institute set up <a href="http://www.securingthehuman.org/resources" target="_blank">an excellent resource</a> for those interested in computer security issues (who is not these days?).<br />
OUCH! and other newsletters carry current information on the security issues and they are published now in several languages. I&#8217;ve put a permanent link with the badge in the right column.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/588/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=588&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/03/17/securing-the-human/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>
	</item>
		<item>
		<title>Good News for InterNet Freedom</title>
		<link>http://cryptoblog.wordpress.com/2011/03/12/good-news-for-internet-freedom/</link>
		<comments>http://cryptoblog.wordpress.com/2011/03/12/good-news-for-internet-freedom/#comments</comments>
		<pubDate>Sat, 12 Mar 2011 07:18:48 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[in the News]]></category>
		<category><![CDATA[networks]]></category>
		<category><![CDATA[CRTC]]></category>
		<category><![CDATA[net neutrality]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=572</guid>
		<description><![CDATA[As reported by the National Post Canada’s telecom regulator said Friday it will not expand its probe into Internet pricing to look at the billing practices of retail Internet services because market forces are working just fine for consumers. A related editorial, explains why this is the right approach. A &#8220;Free&#8221; internet does not mean [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=572&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As reported by the <a href="http://www.nationalpost.com/news/CRTC+refuses+widen+probe+into+Internet+pricing/4426761/story.html" target="_blank">National Post</a> </p>
<blockquote><p>Canada’s telecom regulator said Friday it will not expand its probe into Internet pricing to look at the billing practices of retail Internet services because market forces are working just fine for consumers.</p></blockquote>
<p>A related editorial, <a href="http://opinion.financialpost.com/2011/03/10/net-pricing-means-service-flexibility/" target="_blank">explains why</a> this is the right approach. </p>
<p>A &#8220;Free&#8221; internet does not mean that users should not be paying market prices for connectivity or services. </p>
<p>See my <a href="http://cryptoblog.wordpress.com/2011/03/03/net-neutrality-another-bad-idea/">previous post</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/572/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=572&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/03/12/good-news-for-internet-freedom/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>
	</item>
		<item>
		<title>Fingerprinting Computers &#8211; Part II &#8211; Hardware</title>
		<link>http://cryptoblog.wordpress.com/2011/03/07/fingerprinting-computers-part-ii-hardware/</link>
		<comments>http://cryptoblog.wordpress.com/2011/03/07/fingerprinting-computers-part-ii-hardware/#comments</comments>
		<pubDate>Mon, 07 Mar 2011 03:49:47 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[Anti-tamper]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[Fingerprint]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=536</guid>
		<description><![CDATA[The fingerprinting of a computer using data accessible or generated by software is subjected to a Replay attack or could be easily disrupted by malware. This method should not be used to authenticate the machine. In order to defeat Replay attacks, the fingerprinting algorithm needs to generate a one time string, based on some unique [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=536&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://cryptoblog.files.wordpress.com/2011/03/id_card_laptop.jpg"><img src="http://cryptoblog.files.wordpress.com/2011/03/id_card_laptop.jpg?w=300&#038;h=183" alt="" title="ID_Card_Laptop" width="300" height="183" class="alignleft size-medium wp-image-566" /></a><br />
The fingerprinting of a computer using data accessible or generated by software is subjected to a Replay attack or could be easily disrupted by malware. This method should not be used to authenticate the machine.<br />
In order to defeat Replay attacks, the fingerprinting algorithm needs to generate a one time string, based on some unique property of the hardware and that can be used by the verifier to check the identity of the computer.<br />
One example of such technology is the <a href="http://ipt.intel.com/welcome.aspx" target="_blank">Intel IPT</a> (Identity Protection Technology) that works by generating a unique 6 digit number every 30 seconds. This number is generated by a section of the chip that is inaccessible to the Operating system and holds some secret key shared with the validator/server. Once a particular processor is linked to a server, the server will be able to identify the CPU and validate the computer. Of course this does not imply user authentication and the intended use of this technology is as an additional factor on a multi-factor authentication scheme.<br />
A Public Key infrastructure (Certificate Authority) is still needed to defeat the Man in the Middle attack.<br />
Technologies that can identify hardware to the chip level are being developed <a href="http://www.sciencedaily.com/releases/2011/02/110208091719.htm" target="_blank">to prevent counterfeiting</a>. These are based on the PUF (Physically Unclonable Functions) that use physical variations of the circuit to extract certain parameters that are unique to each chip and cannot be reproduced nor manipulated without physically tampering with the circuit.<br />
Related:<br />
<a href="http://cryptoblog.wordpress.com/2009/06/01/power-up-of-a-sram-as-a-source-of-entropy-and-identification/" target="_blank">Power-up of a SRAM as a source of Entropy and Identification</a><br />
<a href="http://cryptoblog.wordpress.com/2009/04/18/secure-processors-the-ultimate-battlefield/" target="_blank">Secure Processors, the ultimate battlefield</a><br />
<a href="http://www.eecg.utoronto.ca/~janders/aspdac2010.pdf" target="_blank">  A PUF Design for Secure FPGA-Based Embedded Systems</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/536/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=536&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/03/07/fingerprinting-computers-part-ii-hardware/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>

		<media:content url="http://cryptoblog.files.wordpress.com/2011/03/id_card_laptop.jpg?w=300" medium="image">
			<media:title type="html">ID_Card_Laptop</media:title>
		</media:content>
	</item>
		<item>
		<title>Net Neutrality, another bad idea [Updated]</title>
		<link>http://cryptoblog.wordpress.com/2011/03/03/net-neutrality-another-bad-idea/</link>
		<comments>http://cryptoblog.wordpress.com/2011/03/03/net-neutrality-another-bad-idea/#comments</comments>
		<pubDate>Thu, 03 Mar 2011 18:39:58 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[in the News]]></category>
		<category><![CDATA[networks]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[net neutrality]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=531</guid>
		<description><![CDATA[What can go wrong with the government dictating how much companies can charge for bandwidth on the internet? They certainly have a very good track record regulating it. Regulators are congenitally incapable of grasping that they create more problems than they solve This is why I am always wary of attempts at regulation.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=531&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>What can go wrong with the government dictating how much companies can charge for bandwidth on the internet?<br />
They certainly have a very good track record <a href="http://cryptoblog.wordpress.com/2011/02/21/it-didnt-took-very-long/" target="_blank">regulating</a> it. </p>
<blockquote><p>
<a href="http://opinion.financialpost.com/2011/03/03/peter-foster-one-flew-over-the-regulator%E2%80%99s-nest/" target="_blank">Regulators are congenitally incapable</a> of grasping that they create more problems than they solve</p></blockquote>
<p>This is why I am always wary of attempts at regulation.</p>
<span style="text-align:center; display: block;"><a href="http://cryptoblog.wordpress.com/2011/03/03/net-neutrality-another-bad-idea/"><img src="http://img.youtube.com/vi/oTshrURtcjU/2.jpg" alt="" /></a></span>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/531/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/531/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/531/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/531/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/531/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/531/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/531/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/531/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/531/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/531/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/531/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/531/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/531/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/531/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=531&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/03/03/net-neutrality-another-bad-idea/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>
	</item>
		<item>
		<title>Fingerprinting Computers &#8211; Part I &#8211; Your browser.</title>
		<link>http://cryptoblog.wordpress.com/2011/02/27/fingerprinting-computers-part-i-your-browser/</link>
		<comments>http://cryptoblog.wordpress.com/2011/02/27/fingerprinting-computers-part-i-your-browser/#comments</comments>
		<pubDate>Sun, 27 Feb 2011 17:32:27 +0000</pubDate>
		<dc:creator>Mario</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[DRM]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[Fingerprint]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cryptoblog.wordpress.com/?p=476</guid>
		<description><![CDATA[Authentication is about the only big open problem in the practice of internet security. The existing encryption and hashing algorithms as well as the key generation/management protocols offer a high degree of security, barring programming/implementation errors. Authentication technologies face serious challenges mainly because identity is difficult to establish with a 100% certainty even using physical [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=476&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://cryptoblog.files.wordpress.com/2011/02/chip_and_finger.jpg"><img src="http://cryptoblog.files.wordpress.com/2011/02/chip_and_finger.jpg?w=300&#038;h=280" alt="" title="Chip_and_finger" width="300" height="280" class="alignleft size-thumbnail wp-image-503" /></a>  <a href="http://wp.me/P31ZG-7I" target="_blank"><strong>Authentication</strong></a> is about the only big open problem in the practice of internet security. The existing encryption and hashing algorithms as well as the key generation/management protocols offer a high degree of security, barring programming/implementation errors.<br />
Authentication technologies face serious challenges mainly because identity is difficult to establish with a 100% certainty even using physical characteristics, i.e., signatures and credentials can be forged, the physical appearance of people can be manipulated, etc.<br />
<span id="more-476"></span><br />
In some applications, the availability of a technology able to establish the identity of the computer with a 100% certainty, is enough to establish identity (or at least a very important factor). Such technologies could be particularly useful for Digital Right Management applications and for communications between servers.<br />
One way to establish the ID of a computer in the network is through the cataloging of the public information that is available to your browser. For example, if you need to establish the identity of your computer on the Internet for the purposes of an e-commerce transaction, the <strong>Verificator</strong> may use a script running in your browser that requests and catalog the information about installed drivers, fonts, software and plug-ins, such that the particular setup of your computer can be used as its ID. The <a href="http://www.eff.org" target="_blank">Electronic Frontier Foundation</a> has made an enormous contribution to the practical aspects of this issue through the project <a href="http://panopticlick.eff.org" target="_blank">Panopticlik</a>. Focusing on what this information leak does to privacy, they setup a website that runs a script looking at the information that is &#8220;leaked&#8221; by the browser in your computer. From that they calculated that on average browsers leak about 18 bits of information, that means your particular computer can be picked up from a set of <img src='http://s0.wp.com/latex.php?latex=2%5E%7B18%7D+%3D+262%2C144+++%5E%7B%5B1%5D%7D&amp;bg=f0f0f0&amp;fg=555555&amp;s=0' alt='2^{18} = 262,144   ^{[1]}' title='2^{18} = 262,144   ^{[1]}' class='latex' /> computers that visit the site. Moreover, the evolution of this fingerprint can be tracked over time with a good degree of accuracy.<br />
For identification purposes, this will need to be complemented with additional information readily available to a piece of software that has access to the OS. Therefore, it is in principle possible to have a &#8216;software&#8217; based ID method. The problem with this approach is that as the computer administrator has full control over the OS, these parameters can be faked and therefore such system will be subjected to a Man in the Middle attack. </p>
<p><strong>[To be contibued...]</strong></p>
<ol>
<li>To uniquely identify a person out of the total population of the globe will take less than 33 bits <img src='http://s0.wp.com/latex.php?latex=2%5E%7B33%7D+%3D+8%2C589%2C934%2C594&amp;bg=f0f0f0&amp;fg=555555&amp;s=0' alt='2^{33} = 8,589,934,594' title='2^{33} = 8,589,934,594' class='latex' /></li>
<li>A very good introduction to the probabilistic concepts behind this can be found <a href="https://www.eff.org/deeplinks/2010/01/primer-information-theory-and-privacy" target="_blank">here</a>.</li>
</ol>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptoblog.wordpress.com/476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptoblog.wordpress.com/476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptoblog.wordpress.com/476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptoblog.wordpress.com/476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptoblog.wordpress.com/476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptoblog.wordpress.com/476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptoblog.wordpress.com/476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptoblog.wordpress.com/476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptoblog.wordpress.com/476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptoblog.wordpress.com/476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptoblog.wordpress.com/476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptoblog.wordpress.com/476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptoblog.wordpress.com/476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptoblog.wordpress.com/476/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptoblog.wordpress.com&amp;blog=722652&amp;post=476&amp;subd=cryptoblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptoblog.wordpress.com/2011/02/27/fingerprinting-computers-part-i-your-browser/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3de944a0999f975a2a6c8dbb07a20bc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mario</media:title>
		</media:content>

		<media:content url="http://cryptoblog.files.wordpress.com/2011/02/chip_and_finger.jpg?w=150" medium="image">
			<media:title type="html">Chip_and_finger</media:title>
		</media:content>
	</item>
	</channel>
</rss>
