Affichage des articles dont le libellé est Cryptography. Afficher tous les articles
Affichage des articles dont le libellé est Cryptography. Afficher tous les articles

Importance Of Cryptography And Security Experts In Society.

ABSTRACT

It is well known that philosophy hacker alters every decade, year, time, and your value. Currently the involvement of these citizens who assists the process of innovation, strengthens the technological knowledge base, the hacker culture has a fundamental relationship with the Brazilian and multinational corporate entities that dominate the IT industry.

Clearly, this scenario suffers the effects of information security, the more people involved in a project, more innovation and evolution is computer generated. Simple versions to illustrate how this concept is described are some open source projects and independent Linux distributions have been excellent.


INTRODUCTION

Due to the advancement of technology  emerged the cypherpunks (the name derives from 'cipher', cipher code and punk) defend the right to freedom and privacy, making use of and contributing to the future of encryption and similar techniques in order to establish political revolutions and even social. Started in the early 1990s, the movement led to its peak during cyberwars and also in the period of Internet censorship better known as the Arab Spring in 2011.

The term can be used to refer to any individual activist,security groups or for a general philosophy. First, cypherpunks advocate the use of encryption as a tool for data protection and personal privacy or corporate in a universe where information is increasingly available on the network.

The movement began with groups of information security in the late 1980s and early 90s who communicated primarily through mailing lists online, was strongly influenced by the hacker culture, concerns with the government, your personal data, civil law and the implications for supervision of superpowers. The hackers were the first to recognize the growing problem of online privacy.
To paraphrase Richard Stallman, “The use of hacker to mean security breaker is a confusion on the part of the mass media. We hackers refuse to recognize that meaning, and continue using the word to mean, someone who loves to program and enjoys being clever about it".

CONTEXT

To answer this, hackers revolutionary or  “Cypherpunks” put themselves in front of a major challenge in coding and implementation of the technology required supporting the objective of the advent of encrypting files, data, and documents for secure anonymous networks, email, web browsing and financial transactions.
From the beginning, a number of groups of experts aimed at protecting the data and ensure privacy online.

They have been responsible for the creation and dispersion of the software used to promote anonymity online. Heavily involved in political debates and issues that involve the use encryption.
The cypherpunks are a strong influence on the data encryption, they are generally well educated and professionally made, using the use of cryptography and computer programming, despite the implications of the term "punk", they cover a wide range of incomes, and ethnicities social classes. At a critical point in history where our data are drifting like garbage in the ocean, there was the awakening of the hacker culture creating and innovating techniques of privacy and anonymity.

PROCEEDINGS OF THOUGHT

Readers in mind various dimensions and critical thinking, stopped to watch through the eyes and mind of a hacker? Have you ever wondered how they act, how much need and responsibility affects their daily life, how to apply your strength or support any movement, as to base their ethics and politics, which made it so?

Well, we're hackers, and like everyone else we want to do our part to contribute to a more just and egalitarian society, defend the right of freedom and expression.

Currently, encryption has evolved such that we think that we are vulnerable, we are just targets, there is the goal of obtaining unique security solutions for citizens, governments, military, health agencies and multinational companies, and finance departments legal, actually became essential to establish equilibrium.

SAFETY FIRST WORLD

There is only one encryption system known perfectly safe; all encryption methods ever conceived,only one was mathematically proven to be completely safe.

It's called "Vernam cipher or one-time pad“, the value of all other figures are based on computer security, this code is mathematically calculated to ensure autonomy and privacy. This means that the probability of breaking the encryption key using computer technology and algorithms currently available within a reasonable time, is not supposed to be extremely small, but impossible. Each cryptographic algorithm except the “One-Time Pad” can be broken given certain space of time, even though it may delay. Example, systems of public key encryption such as PGP, RSA is based on the following:

The security of these systems is simply based on the computational difficulty of calculation, to break this number N such methods should be followed, and by the time these systems are designed the best publicly available algorithms for factoring would take millions of years to factor a 200-digit number.
This does not logically exclude the possibility of technological invention capable of running at high speed factoring algorithms.

How do you know that the encryption system you use is really safe? Do you understand how it works?

Do you think if a government institution or military intelligence had a method of breaking cryptosystems that would advertise this fact?

Systems security is a matter of utmost importance for anyone with a natural distrust and those attracted to positions of power. The interception and decoding of personal communications can be literally a matter of life or death for some individuals.

CONCLUSION

The result of the work of a new and innovative computer technology known as the quantum computer, an algorithm for factoring now exists for factoring integers in linear time giants. It was created in 1994 by Peter Shor of AT & T Bell Laboratories. An engine to process quantum Shor's algorithm could factor a hundred digit integers in a few arithmetic operations in a matter of time fast.

Quantum computers are functioning prototypes exist information on the implementation of a scalable matrix inversion in the time optimized(SMITH).

In 1917,during the First World War,the American scientist Gilbert Vernam was given the task of inventing a method of encryption that the Germans could not break through by AT & T.

What was planned was the only proven unbreakable encryption scheme known to date. In comparison with most encryption systems is a very simple way. To use a one-time pad, you need 2 copies of the "pad” (also known as the key), which is a source of random data to the message you want to encode.

If the data on the ' pad' is not truly random, the security of the block is committed.
The 'pad' should never be reused, are unique and not reused. The decisive factor is that the 'pad' may be used only once, the purpose is “OneTime”, that is the point of this model. Its engine is based on the VOC technology (Virtual Cascade OTP) and fully resistant crypto analysis and is much safer as “Acid Cryptofiler”, used by NATO. This algorithm is designed for citizens who desire freedom and privacy, secret agents, agencies that operate in foreign countries, can be used by journalists, lawyers, doctors, police...
Random data to ' pad' should never be generated only by software.

It should be developed through processes, access to the hardware of a truly non-deterministic nature. If you intend to provide or secure highly confidential information through insecure channels, a telephone, and you need absolute certainty that there will be decrypted ciphertext is intercepted then there is no choice but to use the Vernam algorithm.

About The Author

This is a guest post written by , RAFAEL FONTES SOUZA. He is the maintainer of the “Project Backtrack Team Brazilian”, He is also a member of the "French Backtrack Team" and made partnerships with groups from Indonesia and Algeria, was prepared a collection of video lessons and made available on the website. He is also Founder of the "Wikileaks and Intelligence, Cypherpunks". Good communication in groups and the general public, attended college projects with a focus on business organization, he currently seeks work experience outside of brazil”.

~ vendredi 8 novembre 2013 0 commentaires

Encryption In Times Of Espionage


ABSTRACT

Everyone knows that encryption is essential in modern times, among the main aims and objectives of this method are some functions such as protecting the financial networks that interconnect the banks in the world, does not allow mobile phone calls are heard, keep records of documents confidential, safe keeping sensitive information from military officers, doctors, lawyers and protect credit card and financial transactions.

CONCEPT

Encryption algorithms also depend called "trapdoor functions", pieces of mathematics that are theoretically easy to perform encryption in one direction, but very difficult to reverse. A common method is based on the assumed difficulty of finding the prime factors of large numbers, but many security researchers were touting new codes based on a different and innovative math involving elliptic curves, but what if some entity or someone with great skill and can pick these constants so as to make the codes vulnerable to decoding result, this could be a global threat.

INTRODUCTION

Most encryption systems utilize generating pseudo-random numbers as part of a complex mathematical codes in the creation of virtually unbreakable sequences were generated numbers can be predicted, this would make the code was broken attacked given power sufficient processing and a certain amount of time.
According to documents revealed by Edward Snowden (systems administrator fugitive from NSA who now lives in Russia and was considered a spy) the National Security Agency is three steps ahead in secret cyber war, using his favor supercomputers, techniques evolved and hitherto unknown to crack encrypted data, court orders, persuasion and agreement with major companies, to corrupt the main tools that protect the privacy of Internet communications usual.

CONTEXT

Supposedly the NSA can break the codes that allow for private communication over the internet and also sabotage them. The strategy includes undermine the supposed official standards bodies and major IT companies bribe. The goal would be to insert  "backdoors" , The New York Times cites a document  "GCHQ" which says that the NSA has large amounts of encrypted data that used to be discarded and are now exploitable , and that was an aggressive effort toward breaking technologies encryption considered safe.

The recent leak suggests that not only was spying from foreign adversaries , but also commercial rivals of American businesses , something that other foreign companies and governments are worrying for years , there are those who are suspicious of Mr. Snowden and his allies , and contest the references taken from the leaked documents , and defend the role of the NSA , on the other hand can now put protectionist as privacy advocates and national dignity , German politicians have asked that people avoid American web companies if they want to keep their data insurance, the Indian government is considering a ban on the use of Google's Gmail service to send official communications and technology companies in places like Russia and Switzerland has seen a considerable increase in inquiries from companies seeking a haven for their data order to keep them protected.

CURIOSITY

The largest technology companies , with its global horizons spread around the world , have more to lose (reputation) , including Facebook , Microsoft , Google and Yahoo , may be requested through actions by the Court of the Foreign Intelligence Surveillance America that is requested permission to reveal more detailed information on the types of orders and requests they receive from U.S. government agencies , an information document "Bullrun" says the NSA had developed innovative capabilities against encrypted Web chats and phone calls and also performed successfully attack techniques against Secure Sockets Layer (SSL) and virtual private networks (VPN).

At this present time where we are vulnerable as rabbits return to the wolf pack, there is ways to get around this use tools that employ open-source and the best strategies , in the case of open source encryption the advantage is that the algorithm can be examined freely to potential security vulnerabilities that can arise throughout the tests.

SOLUTION

Workarounds and useful tools:

GPG an open-source implementation of the OpenPGP protocol used to encrypt e-mail communications.
TrueCrypt (encryption on-the -fly OTFE) to confidential files , folders and entire drives on your PC , encryption, it can create a virtual encrypted disk or encrypt a partition , individual algorithms supported by TrueCrypt are AES , Serpent and Twofish, additionally , five different combinations of cascaded algorithms are available : AES - Twofish , AES - Twofish - Serpent , Serpent - AES , Serpent - Twofish - AES and Twofish - Serpent . Uses RIPEMD - 160, SHA - 512 and Whirlpool as hashing functions .

TAILS, a Linux distribution built for safety and anonymity, comes with numerous tools privacy and encryption, which lets you surf the web (mostly) in an almost anonymous .

Messages off- the-record, or OTR , an encryption protocol to encrypt and authenticate communications and instant messaging also use others as TLS and IPsec ,remember also apply to other software such as Silent Circle and BleachBit .

CONCLUSION

Regarding PRIVACY is important to know how to control the availability and exposure of your data , the AES algorithm was proposed to replace DES, NIST ("National Institute of Standards and Technology U.S.") held a competition (The selection process began in 1997 and ended in 2000 with the victory of the Rijndael algorithm written by Joan Daemen and Vincent Rijmen) for it to be made an algorithm that would be called "Advanced Encryption Standard " that meets the following specifications: algorithm publicly defined;

Being a symmetric cipher block; Designed for the key size can be increased; Deployable in both hardware and software; Powered freely, this algorithm Encrypt and Decrypt using an encrypted key and blocks, both sizes of 128,192 or 256 bits.

Concluding , I will address the most advanced technique for encryption , we got the "One Time Pad" (OTP) or "Vernam Cypher" single key cipher is an encryption algorithm where the plaintext is combined with a random key or " pad " that is as large as the plaintext and used only once , if the key is truly random , never reused , and kept secret , the one- time pad is unbreakable!

About the Author, RAFAEL FONTES SOUZA.

Over the years, acquiring knowledge of Webmaster Programmer (HTML5,CSS,XML,ActionScript), developer in languages like Python, Shell Script, Perl, Pascal, Ruby, Object Pascal, C and Java. I started studying with thirteen (SQL database), i have extensive experience in operating systems such as Linux, UNIX, and Windows.  I am maintainer of the “Project Backtrack Team Brazilian”, I am also a member of the "French Backtrack Team" and made partnerships with groups from Indonesia and Algeria, was prepared a collection of video lessons and made available on the website.

I am Founder of the "Wikileaks and Intelligence, Cypherpunks". Good communication in groups and the general public, attended college projects with a focus on business organization, I currently seek work experience outside of brazil”.

http://sourceforge.net/projects/cypherpunks/

Contact: fontes_rafael@hotmail.com

~ vendredi 11 octobre 2013 0 commentaires

Steganography Tutorial - Image & Concept

Steganography is a good replica of Cryptography and in some situation steganography is seems to be a best idea than cryptography, we have already discussed the basis of them and their advantages from the point of Information security. In this article I will discuss the working mechanism of steganography.




How steganography is smart and strong than cryptography?

I think most of the point of this question has been discussed above that steganography is smart than cryptography because:
  • It does not need any key distributor
  • It seems to be a simple communication

What is the working mechanism of steganography?

There is no need of a key in steganography this is the general way to explain or this is the pure steganography but we have different sort of steganography and some of them need a key, means:

  • Public and private key based steganography

The general working mechanism has been discussed above but there are different sort and different way to implement steganography and each way (method) has different working mechanism.
Digital and modern steganography can be implemented on:

  • Text file
  • Images
  • Audio
  • Video
  • Web content (protocols)

Text based steganography is the most famous method of steganography, the rule is to hide the secret message into to redundant of nth word, same as the compression method. Secret data means the message that you want to hide while the covered data means a carrier or a container that convey the secret data. The final data can be called stego data. There are mainly three types of steganography:

  • Pure steganography (no key)
  • Public key steganography
  • Private key steganography

Key has been involved in steganography to increase the level of security, in pure steganography both parties has to understand that the message could contain a secret data. There are different sort of steganography techniques and algorithms has been developed but the most famous and applicable rule is to hide the message into LSB (least significant bit), images seems to be best way to use as steganography because they contain more redundant bits, images are more popular in steganography subject.
Web content and protocol steganography means to hide the data into some protocols of OSI layer model, for example hide your data into TCP/IP stream.

Image Based Steganography

To understand the image based steganography we need to understand the concept of a digital image. Images are the combination of width and hight (W*H) that becomes pixel images are based on 8-bit or 24-bit color combination, if we discuss about 8-bit color than there would 256 colors formed an image because of the basic binary calculation (2^8= 256). A 24-bit color pattern is more complex and provide more colors in this case each pixel represent 3 bytes remember 1 byte contain 8-bits and each byte represent a combination of color that is RGB (Red, Green and Blue). Let suppose an image has a size of 1200 * 800 pixel than 1200 x 800= 960,000 pixel so for 24-bit scheme that contain 3 bytes it would become 960,000 x 3 =28,80000 bytes and 1 byte consist of 8 bits so 2880000 x 8 = 23040000 bits

Now we have calculated that an image of 1200 * 800 pixel is based on 23040000 bits, remember this number is in decimal form we need to convert it on binary for the depth analysis. So the binary of this bits would be 0001010111111001000000000000

So what is the method to hide a message into an image? By using the above calculation method we can easily get the binary of an image right side of the binary is called least significant bit (LSB) because it contain less information while the left side top most is called most significant bit (MSB) because it contains most of the information. So the point is that if we replace the LSB (Least significant bit ) with some other bit that contain some other information this method does not affect the shape of the image because we replace LSB that does not contain much information. Lets consider an example:

Suppose we have a 16 byte of data:

00110101 00101100 11001001 10010111
00001110 11001011 10011111 00010001

10010111 00000000 11001001 01010110
10101010 01001010 10010100 10000101

Now we want to hide Hi in this bytes, method is simple first of all we need to get the binary equivalent of word Hi we can get the binary by using ASCII to binary conversion and binary of Hi is

0100100001101001
Put each bits on the LSB of above bytes:

00110100001011011100100010010110
00001111110010101001111000010000

10010110000000011100100101010110
10101011010010101001010010000101

We have successfully hide the word Hi into this bytes.

Steganography Tutorial

There has been numerous development made by different researcher and programmer in steganography, now there are so many tools are available for image based and audio/video based steganography some tools are commercial and some are open source means free of cost. Stepicis among those tools that are available free of cost, stepic is a script that is based on python or stepic is python image steganography.

If you are using Debian or Ubuntu than you can get stepic by using your terminal, on the terminal type:
sudo aptitude install python-stepic

The alternate way to get stepic is to download from official website, let suppose we have an image and a text file and we want to hide this text into the image so that we can send this secret message to its destination. Stepic can easily hide the text into image.

Image before process



stepic -e -i real-image.png -t secretmsg.txt -o stego-image.png

 


Image after process

At the receiver side we need to retrieve the secret message from this image, stepic also give you an option to decode an image. The command will like this:


stepic -d -i stego-image.png

 



The next part of this article will be publish soon, do not forget to share it.
 

Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mercredi 5 septembre 2012 0 commentaires

Steganography VS Cryptography

Cryptography is the most common method to protect important information, cryptography techniques are very useful to protect and secure the perimeter. Steganography is an art of hidden communication and in this article we will discuss about steganography with the background and we will have a deepest look. Secret communication is not a new term and human have being using this term from ages infect animals has their own way of communication. 

Secret communication is very important because if your message is important and if you do not want others know about your message than you use different techniques to hide your message from third person, there are many ways to do this. In computing and in computer science we use a term called cryptography, in short cryptography is the science of secret communication. There are so many algorithms are available to make the cryptography process strong so that an intruder or cracker does not able to crack it. Cryptography has been implemented on different services even you are using one algorithm on your smart card (it may be your credit card, SIM card and others), the famous cryptography algorithm is DES (data encryption standard) and we have different variant of DES like triple DES to make the process and the secret key strong and unbreakable. So if we have a strong and smart system for secret communication than:

  • Why there is a need to introduce a new technique?
  • What is Steganography?
  • How steganography is smart and strong than cryptography?
  • What is the working mechanism of steganography?
These are the most important question that you might be thinking about steganography and I will discuss each and everything about steganography in detail.



Why There Is a Need to Introduce a New Technique?


If cryptography is a strong way to encrypt and secure a communication than why we need a new technique? Answer is very simple when we are using any cryptography technique we need to send a secret key and third person can easily judge that some secret communication is going on. Lets consider an example simple communication, we need two entities one is the sender and the other is receiver sender send the message and receiver receive it, a simple communication but consider an encrypt way of communication. Entities like this:

  • A sender
  • A receiver
  • A third person (might be machine and other way)

Sender encrypt the message by using a pre-define algorithm and generate a secret key and a cipher message than send it to receiver, receiver needs a key to decrypt it generally a third system carry this key and provide it to the receiver than receiver decrypt it. So in this case anyone can understand that something unusual is going on. In some cases like an military agent (secret agent) wants to send some message to the command station but he/she does not want to do this cryptanalysis because enemies can easily judge the process than the simple way to send a normal message and hide your secret message into this normal message.



What is Steganography?

Steganography has been discovered from a Greek term and it means “Covered writing”, Cryptography has also discovered from a Greek term and it means “Secret writing”. So you can easily understand that both techniques has been discovered from Greek and both are the methods of secret communication. In steganography you don't need any key or a key distributor (pure steganography). The basic idea of steganography is to covered writing means hide your secret message into a simple/regular message so that other parties does not aware about the communication. 

These are the most important question that you might be thinking about steganography and I will discuss each and everything about steganography in detail.



Why There Is a Need to Introduce a New Technique?



If cryptography is a strong way to encrypt and secure a communication than why we need a new technique? Answer is very simple when we are using any cryptography technique we need to send a secret key and third person can easily judge that some secret communication is going on. Lets consider an example simple communication, we need two entities one is the sender and the other is receiver sender send the message and receiver receive it, a simple communication but consider an encrypt way of communication. Entities like this:



  • A sender
  • A receiver
  • A third person (might be machine and other way)



Sender encrypt the message by using a pre-define algorithm and generate a secret key and a cipher message than send it to receiver, receiver needs a key to decrypt it generally a third system carry this key and provide it to the receiver than receiver decrypt it. So in this case anyone can understand that something unusual is going on. In some cases like an military agent (secret agent) wants to send some message to the command station but he/she does not want to do this cryptanalysis because enemies can easily judge the process than the simple way to send a normal message and hide your secret message into this normal message.



What is Steganography?



Steganography has been discovered from a Greek term and it means “Covered writing”, Cryptography has also discovered from a Greek term and it means “Secret writing”. So you can easily understand that both techniques has been discovered from Greek and both are the methods of secret communication. In steganography you don't need any key or a key distributor (pure steganography). The basic idea of steganography is to covered writing means hide your secret message into a simple/regular message so that other parties does not aware about the communication.
  
The next article of this series will be publish soon!


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ vendredi 17 août 2012 0 commentaires