foone, (edited )
@foone@digipres.club avatar

The 37C3 talk on TEA1 encryption (used by police and military units in europe) is hilarious.
The hackers announced they found a vulnerability in the encryption, and one of the ways the organization that standardized TEA1 downplayed the breach was by saying that it wasn't viable, because it required "high powered GPUs".

So they ported their algorithm to a Toshiba Satellite running Windows 95, and re-cracked the encryption there.

https://media.ccc.de/v/37c3-11761-all_cops_are_broadcasting

(or https://www.youtube.com/watch?v=8KhbJ4pqcOY )

LaF0rge,
@LaF0rge@chaos.social avatar

@foone yeah, it is hilarious - but has already been presented several times in summer 2023, including at the ccc camp.

foone,
@foone@digipres.club avatar

yeah it took 13 hours but still: this was hackable even when it was new, just /slowly/.

foone,
@foone@digipres.club avatar

but that's some hilarious pettiness. "oh, this isn't really a risk because it requires new hardware, and it was sensible when it was designed back in the 90s? Well, screw you, we'll hack your shit on a 90s laptop we bought off ebay!"

nblr,
@nblr@chaos.social avatar

@foone Same vibe as converting a voting computer into a chess computer after the manufacturer claimed that it is a trustworthy single purpose voting machine, not a computer, and that he doubts this could be done.

https://wijvertrouwenstemcomputersniet.nl/other/es3b-en.pdf

PeterKratz,
@PeterKratz@chaos.social avatar

@nblr @foone Has any of those Chess-ROMs survived?

nblr,
@nblr@chaos.social avatar

@PeterKratz @foone meepmeep* paging @erd

wiert,
@wiert@mastodon.social avatar

@nblr @PeterKratz @foone @erd

Paging @rop as well.

nblr,
@nblr@chaos.social avatar

@wiert @PeterKratz @foone @erd @rop
was specifically mentioning erdgeist because he and willem - who is not on mastodon to my konwledge - were adapting that chess solver to the micro controller as far as i remember. While I was gluing coins on the bottom parts of chess figures.

wiert,
@wiert@mastodon.social avatar

@nblr @PeterKratz @foone @erd @rop

Thanks. With all the aliases on social media it is hard to track who is who.

Thanks for making that possible in 2006. It finally opened some eyes to the public about stuff that was public knowledge with the geeks back then.

nblr,
@nblr@chaos.social avatar

@wiert I merely glued coins on chess pieces because I was at the same time in the same place. I too tip my hat. Fun times. Great impact.

argv_minus_one,
@argv_minus_one@mstdn.party avatar

@foone

Which, amazingly enough, apparently still works, rotating disk drive and all.

foone,
@foone@digipres.club avatar

@argv_minus_one nah, that's just how Toshiba Satellites are. I've got several, and other than the batteries, they'll just happily keep working for 25 years. They're some hardy machines.

foone,
@foone@digipres.club avatar

also that's a hilarious counter-argument. "it doesn't matter because it would require some high-end GPUs!"

you don't think an organized crime outfit couldn't justify a couple RTX 4090s in exchange for being able to listen to all the police's communications?

lanodan,
@lanodan@queer.hacktivis.me avatar

@foone Specially when you can rent those powerful machines.

foone,
@foone@digipres.club avatar

@lanodan sounds like something from a Charles Stross Halting State novel: the police figure out they're being spied on because they discover the AWS VM's get spun up at the same time as they use their radios.

madopal,
@madopal@mstdn.social avatar

@foone I've always wondered about this...do they even need to? Can't they just provision some GPUs for a few hours from a cloud provider of choice?

foone,
@foone@digipres.club avatar

@madopal absolutely!
You can just cloud-source as many GPUs you want and hack this shit relatively cheap, and that comes up later in the talk.

stilescrisis,
@stilescrisis@mastodon.gamedev.place avatar

@madopal @foone Yup, this works! I know someone who used GPUs on AWS to crack a private key.

foone,
@foone@digipres.club avatar

@stilescrisis @madopal someday I'm gonna raise the money to get enough AWS GPUs to crack a 3DES key.

I really, really want to watch a DIVX movie again.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ethstaker
  • DreamBathrooms
  • InstantRegret
  • tacticalgear
  • magazineikmin
  • Youngstown
  • thenastyranch
  • mdbf
  • slotface
  • rosin
  • modclub
  • kavyap
  • cubers
  • osvaldo12
  • JUstTest
  • khanakhh
  • cisconetworking
  • Durango
  • everett
  • ngwrru68w68
  • Leos
  • normalnudes
  • GTA5RPClips
  • tester
  • megavids
  • anitta
  • provamag3
  • lostlight
  • All magazines