Bruce Schneier | |||||||||
Schneier on SecurityA blog covering security and security technology. « Psychoecology and the DHS | Main | Eavesdropping on a Fiber Optic Cable » September 24, 2007Idiotic Cryptography ReportingOh, this is funny: A team of researchers and engineers at a UK division of Franco-German aerospace giant EADS has developed what it believes is the world's first hacker-proof encryption technology for the internet. Snake oil, absolute snake oil. EDITED TO ADD (9/26): Steve Bellovin, who knows what he's talking about, writes: Actually, it's not snake oil, it's very solid -- till it got to Marketing. The folks at EADS built a high-assurance, Type I (or the British equivalent) IP encryptor -- a HAIPE, in NSA-speak. Their enemy isn't "hackers", it's the PLA and the KGB++. See this and this. David Lacey makes the same point here. Posted on September 24, 2007 at 01:58 PM • 56 Comments • View Blog Reactions To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. IIRC, SSH changes (session) keys several times a session...nothing new...nothing to see here...move along. Posted by: Phillip at September 24, 2007 02:10 PM So to get into the doghouse you actually have to sell it or....? Posted by: Jurgen at September 24, 2007 02:31 PM It's not so much snake oil but more like over-the-top marketing. They're talking about HAIPE (http://en.wikipedia.org/wiki/HAIPE) which basically is IPsec in a box with shiny management interfaces. Posted by: Henryk Plötz at September 24, 2007 02:51 PM But there's a photograph of a helicopter, so it must be good! Posted by: non sequitur at September 24, 2007 02:57 PM The actual devices seem to be not that bad, judging by what little documentation I found. Nothing groundbreaking, just your basic VPN appliance with some goverment/military certifications so they'll sell better. More a case of horrible marketing than of horrible products, I think. Posted by: Maik at September 24, 2007 03:01 PM "EADS is in talks with the Pentagon about supplying the US military with the system..." I assume some knowledgeable responsible person at NSA will have a good laugh, then deploy ye olde clue bat and ring the skull of the pentagon types who are thinking about buying into this. On the other hand, if I were a US official, I'd be very interested in having as many _other_ countries as possible buy this stuff... Posted by: Carlo Graziani at September 24, 2007 03:09 PM "hacker-proof" There is a probability of exactly 100% that their solution is NOT hacker-proof. I know that and I'm not even a cryptologist. Heck, I don't even play one on TV. Posted by: nzruss at September 24, 2007 03:13 PM Enigma designers must be rolling in their graves - so much for partnering with French instead of invading them .. somehow that bought out the best in the Germans :-) Posted by: sooth_sayer at September 24, 2007 03:24 PM Did anyone else notice how awful the 'journalism' of this article is? The heading starts with the company developing a hacker proof system. In the middle of the 'article' they have a blurb about Chinese hackers and at the end a bit about a fighter plane contract with Saudi Arabia. The decline of decent journalism is really scary. No wonder this snake oil is easy to peddle! On the other hand, I've really,really enjoyed your writing Bruce. Thanks for all your hard work. Posted by: chris at September 24, 2007 03:38 PM "Enigma designers must be rolling in their graves" Posted by: Erik W at September 24, 2007 03:41 PM So their implementation of HAIPE is nothing but a bunch of hype? ;) Posted by: Mike at September 24, 2007 03:56 PM
When I asked if they published a paper in Crypto, they said it's a secret and a patent. The algorithm. BTW, the method for decryption was a password of less than 10 letters... Snake-oil. Oh, I forgot to add that a credit-card company bought their algorithm for communication encryption. I'm serious. Posted by: Ishai Wertheimer at September 24, 2007 04:25 PM I Disagree - this kind of story is unsettling. Millions of honest, hard working but 'security clueless' people read these kinds of stories, whether it's about a new way of protecting their own data or a new way of safeguarding the planet, and *believe* them or at the very least become more confused about what to believe. Unfortunately, in the case of serious crypto, many who do take security seriously are still not skilled enough to aggressively critique a specific algorithm or implementation, but their b/s-ometer is often a good guide and alerts like Bruce's are extremely helpful. Posted by: Rob Mayfield at September 24, 2007 04:31 PM There you have it: "...has developed what it thinks is..." Posted by: Flado at September 24, 2007 04:46 PM Smells like marketing speak for dedicated hardware to implement a DH key exchange very frequently, like every 512bits =D Posted by: Chris Gragsone at September 24, 2007 05:03 PM Quote: That is the funniest thing that I have read all week. Posted by: Harrkev at September 24, 2007 05:09 PM The problem is that these scientists and engineers have not studied cryptography; it is not their area of expertise. Even so, it would be one thing for them to claim to have found something useful in the field. It is quite another thing for them to claimt to have out-done everyone in the field. Posted by: RC at September 24, 2007 05:17 PM And the super-duper hacker-proof version has 5 Enigma designers rolling in their graves. Posted by: Anonymous at September 24, 2007 05:26 PM I don't know about other countries, but in the US, it's impossible to patent a secret. The patent has to DISCLOSE what you're patenting. That discrepancy alone should set off at least as many warning bells as the "million-bit key". Posted by: Anonymous at September 24, 2007 05:28 PM @Carlo Graziani: "I assume some knowledgeable responsible person at NSA will have a good laugh, then deploy ye olde clue bat and ring the skull of the pentagon types who are thinking about buying into this." Actually, I think it depends on how much the units cost. If the cost is reasonable (despite the over-the-top hype), the Pentagon might just be interested in several thousand easily-deployed internet-appliances that support some kind of SSL. Of course, if they change the keys *too* frequently, your bandwidth is going to be eaten alive by continual protocol-handshaking... Posted by: X-the-Unknown at September 24, 2007 06:09 PM Better than Virtual Matrix Encryption? "Virtual Matrix Encryption, or VME, is the industry's only commercially available, unbreakable encryption engine. Utilizing a combination of Virtual Matrices and a 1,048,576 bit symmetric key, VME is impervious to brute force attacks." Posted by: Jim at September 24, 2007 06:11 PM Virtual Matrix Encryption Selling security by selling stuff to break it? Sounds like Bart Simpson planning. Posted by: Anonymous at September 24, 2007 06:19 PM Note: (VME Spy Phone™) Pursuant to Federal law at 47 U.S.C. 302a, this product is available only for use by the Government of the United States or any agency thereof. Other interested parties are urged to contact appropriate regulatory oversight entities to determine whether any additional exceptions or arrangements have been authorized and implemented to permit use of this product consistent with controlling law. Don't try getting one. It's for us dubious secret agents with a phone in our shoe. Posted by: 007 at September 24, 2007 06:25 PM The first indication of this was the fact that it was reported. Even as technology permeates every facet of our lives, there are plenty of people who are utterly clueless about it. Cryptography and related fields are even more esoteric for most people. Some of those technologically-challenged people are also journalists whose qualifications are on the order of "I know how to use computers - hell, I've typed this here article on one! I must, therefore, be qualified...". It must be said that the PR folks at a given company also know up whose ass they can blow smoke to get their message out. This is not unlike the spam emails - people know this is BS, but some will get interested, might get roped into a sales pitch, and presto-sello, there be orders. "EADS is in talks with the Pentagon about supplying the US military with the system..." -- "We've sent them the PR packet. The purchasing officer showed it to the crypto people. They can't return our calls because they are not done laughing yet" Posted by: Pavel at September 24, 2007 06:27 PM Off topic: TV station runs competition with $30,000 wedding as prize, winner to be determined by e-mail voting. Then they are surprised when cheating happens. I'm only surprised that they noticed. Posted by: Filias Cupio at September 24, 2007 08:14 PM Just noticed more vitriol than I would expect for this story. Be sure to pay attention to the people mentioning HAIPE (http://en.wikipedia.org/wiki/HAIPE). I think some of the ingredients of this snake oil are "dubious" algorithms such as AES and SHA. Also of note is that the company's website is remarkably absent of the usual snake oil pitch. Posted by: peri at September 24, 2007 08:24 PM peri: Any article claiming an encryption algorithm is "hacker proof" deserves whatever amount of vitriol we can safely throw at it. Posted by: Eam at September 24, 2007 08:56 PM eam: your unqualified claim suggests articles are "hacker proof,"-- when some random employee (Sales Manager) is possibly misquoted then I say unbounded virtriol might be excessive. Posted by: peri at September 24, 2007 09:13 PM Strangely, most commenters have missed the point that it is about an idiotic reporting, not a product. Based on available documents, I would say that Ectocryp seems to be a fairly decent HAIPE. Although I tend to agree that they are using a pretty strange 'A' in the product's name. Posted by: Ilya Levin at September 24, 2007 09:23 PM Grandiose claims? Check. I'd buy that for a dollar! Seriously though, I think the hype can be blamed both on the quoted sales manager and the quote-unquote journalist. Between product-hype and news-sensationalism, there's no room for any incentive to have grounded, objective reporting. Posted by: Albert Sweigart at September 25, 2007 01:44 AM
Posted by: Nick Lancaster at September 25, 2007 03:56 AM Hu, sometimes it's so embarrassing to be european.... First read about this on www.heise.de (german newsticker) and immediatly thought about Bruce and his definition of snake oil. Still remember the good old MAGENTA algorithm by the german TELEKOM. ...embarrassing Posted by: TheDoctor at September 25, 2007 04:12 AM "Hacker-proof" is a claim I can at least entertain. Depends on your definition of "hacker", of course, and I confidently predict that any definition of "hacker-proof" which this algorithm meets, is also met by existing standard crypto algorithms. "Fool-proof" is the give-away: no system in existence is proof against even the average fool. Posted by: SteveJ at September 25, 2007 04:38 AM ....after thinking a while...it was clear...these people MUST be nuts ! Posted by: ikaros at September 25, 2007 04:39 AM Nothing to it- Snakeoiler:"[ring]Hello, Pentagon? We'd like to sell you our stuff!" Snakeoiler:"[ring]Hello, Pentagon? We'd like to sell you our stuff!" Press release:"We are in talks with the pentagon about buying our product" Posted by: bob at September 25, 2007 06:35 AM I have spotted the Hitch hikers guide to the galaxy reference and I claim my £5! Posted by: Tim the Enchanter at September 25, 2007 07:11 AM It'll never beat a rot13 done twice. Doing it twice makes it 2X as hard to break Posted by: DanC at September 25, 2007 07:34 AM There needs to be a Godwin's type law for rot13 done twice. Something along the lines of "Whenever you see a 'rot13 done twice' reference, the jokes are all made and it's time to move on" Posted by: JustSomeGuy at September 25, 2007 08:12 AM Of course the reporting is bad, it's the Torygraph.
Posted by: Colossal Squid at September 25, 2007 08:27 AM In defense of the defnese contactor. EADS are one of the biggest defense contractors in the world. They ar a conglomeration of various British and German arms companies. Greatest hits include breach loading artilery (Armstrong Whitworth), the steam turbine (Vickers Thorneycroft) , both the Hawker Hurricane and the Messerchmit 109, some crap tanks (from Vickers) and some superb armored vehicles (from Panther descended from the WWII Tiger tank), the worlds first second and third military jets and the worlds first two commercial jet airliners. So they do have some sort of track record. Applying a filter to remove the marketing speak the article really says "we are the first defense company to get our HAIPE equipment certified". Posted by: supersnail at September 25, 2007 08:51 AM The people this "article" really makes me feel bad for are the actual engineers and cryptographers who made the product. Somewhere, a bunch of people at EADS are crying into their beer. Posted by: Kadin2048 at September 25, 2007 10:49 AM Anonymous who thinks it's impossible to patent a secret in the USA: that's normally true, but the NSA has an exemption. They can have a patent issued and hold it unpublished until someone else tries to patent the same idea. Of course the clowns we're talking about today are not the NSA and don't have that power. Posted by: Matthew Skala at September 25, 2007 11:01 AM peri: I would never suggest an article is hacker-proof, and if the "journalists" are misquoting staff from the company, that's even more reason to start being vitriolic. Posted by: Eam at September 25, 2007 11:06 AM @Matthew Skala Exactly. Also, remember the patent tribulations of the inventor of the LASER, Gordon Gould (http://en.wikipedia.org/wiki/Gordon_Gould). Posted by: X the Unknown at September 25, 2007 01:02 PM EADS is a modern arm of the British empire apparatus, and a very good friends of hedge funds, mercenary units and other fine bits of poison. Posted by: ForReal at September 25, 2007 02:11 PM "Something along the lines of "Whenever you see a 'rot13 done twice' reference, the jokes are all made and it's time to move on"" I think that should be when you see the rot13 joke done twice... Posted by: G at September 25, 2007 04:44 PM I wonder what other topics the Telegraph understands, and describes, this poorly. Posted by: Joseph Adler at September 25, 2007 05:29 PM The NSA and Pentagon may have a few of their "front line" folks that have to deal with sales pitches like this, but the guys in the backend data centers running the mainframes that really run the government comm systems, and the cryptographers working on new codes or breaking current codes probably won't even be bothered with "news" of it. And any nation foolish enough to implement any of this stuff in any of their systems probably will be conquered at some point or another anyway if the builders of their infrastructures fall for this. Good reporting, Bruce! Posted by: The Wanderer at September 25, 2007 11:11 PM If you're going to put out a press release containing the words "hacker proof" then you're going to earn the scorn of Schneier and others like him. There's no such thing as "hacker proof". Now, if they can explain what they're doing and why it's sufficiently secure (this presumably means it not being filtered through a journalist!), they might have a claim. Posted by: Andy Cunningham at September 26, 2007 06:29 AM Google took me to http://www.eadsdsuk.com/ectocryp/ from where you can download an info PDF. Looks to me like a VPN endpoint with expensive governmental certification; it claims support for UK Eyes and Suite A (do they mean NSA Suite A?), so I doubt that any more details will become public. Posted by: Ross Younger at September 26, 2007 09:52 AM @ Matthew Skala, Anonymous, Ishai Wertheimer "Anonymous who thinks it's impossible to patent a secret in the USA" Outside of the USA you are required to keep the "methods" in your patent application secret untill after it is granted otherwise you have "disclosed" and therefore no patent granted or you lose it when challenged (the result of a quaint old aspect of English law). Due to the length of time it takes to get a patent you often have to go "commercial" prior to patent grant (for other quaint reasons), which as you can guess gives rise to quite a few messy complications (which is why legal bods specialising in IP can get very very rich without realy trying ;). Ishai Wertheimer's comments about the specifics of the system he was talking about may well be true but.... He did include, "(patent-pending!!! :) )" Posted by: Clive Robinson at September 27, 2007 05:04 AM As far as I can tell, this is a decent device; 'ECTOCRYP' looks like an FPGA-based high-grade assurable platform, on top of which the product that they're pushing is a network encrypter using standard algorithms. It's likely to be hacker-proof in the reasonably strong sense that no input packet can change the functionality of the hardware, since the packets are touched only by hardware which, because of the way FPGA programming works, can't be reprogrammed by their contents. It's has a completely separate management interface, which will be attached to an internal secure network in the government communications centre in which these things will be installed. I suspect the press release is to announce that the product is CAPS certified; CAPS certification is a slow-moving bureaucratic nightmare of a process, but a device being CAPS-certified to Top Secret UK Eyes is an indication that a lot of very good engineers at CESG have gone over it with very fine-tooth combs and pronounced it adequate. Posted by: Tom Womack at September 27, 2007 06:10 AM Thank god, yet another great and well documented article by Bruce. If it was not for Bruce I might have used another snake oil product by this shaddy EADS company: http://www.airbus.com Posted by: John at September 28, 2007 01:37 PM Post a comment
Powered by Movable Type 3.2. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT Counterpane. |
|
Comments