Japanese Researchers Crack Supposedly Hack-Proof Cryptography
June 19, 2012 3:54 PM
comment(s) - last by
Researchers who developed standard claimed it would take "thousands of years to crack", but it took only 148 days
We're living in either a dark, dysmal time for cryptographers or a golden,
glorious age for hackers
depending on how you look at it. Casual hackers are making short work of supposedly
modestly-secure older hashing
, and even supposedly-super-secure "strong" encryption techniques are falling to novel attacks.
I. Pair-Based Cryptography Continues to Fall in Security
The latest victim in the march of progress is pairing-based cryptography, an approach that was thought to hold the key to super-secure future communications. Japanese electronics giant Fujitsu Ltd. (
, and Japan’s
National Institute of Information and Communications Technology
a 278-digit (923-bit) cryptogram, easily besting the previous world record of 204 digits (676 bits).
Researchers who worked with pair-based cryptography have in the past expressed confidence that 900+ bit cryptograms would take hundreds of thousands of years to crack. But Fujitsu,
. achieved the feat in a mere 148.2 days -- less than half a year -- running on a 21-computer cluster with 252 cores.
Fujitsu has cracked an encryption that was previously estimated to take "hundreds of thousands of years" to break. [Image Source: Fujitsu]
By employing parallel programming methods and other novel techniques to the attack, the research team was able to cut the time that would have been required by a less state-of-the-art brute force attack with previous methods.
II. Cat and Mouse -- No System is Unbreakable
Fujitsu warns that the shocking success should serve as a warning to security firms that what seems like reliable standards may be crackable sooner than they think, and unsafe not too long after that. Writes the company:
As cryptanalytic techniques and computers become more advanced, cryptanalytic speed accelerates, and conversely, cryptographic security decreases. Therefore, it is important to evaluate how long the cryptographic technology can be securely used.
We were able to overcome this problem by making good use of various new technologies, that is, a technique optimising parameter setting that uses computer algebra, a two dimensional search algorithm extended from the linear search, and by using our efficient programing techniques to calculate a solution of an equation from a huge number of data, as well as the parallel programming technology that maximises computer power.
Cryptography today is facing a two-side assault. On the one side are the crackers, looking to employ novel methodology to reverse advance encryption. On the other side are the exploiters, looking to identify and leverage fundamental
flaws in the implementation
, flaws which sabotage the reliability of the underlying methods.
Unbreakable security is a fantasy. [Office Hackery]
Some public keys encrypted by
the RSA standard
were recently found to have "no security at all". The culprit, said Swiss researchers who published their findings in February, was improper generation. Likewise in 2010 Norwegian researchers
[abstract] results indicating
could be cracked via attacking the photon detectors that implemented the encryption via quantum mechanical effect. Here, the quantum cryptography itself was likely strong enought to stand up to any direct assault, but the glaring weak spot was the encoders/decoders in the system, which could be hijacked with traditional attacks.
Of course security researchers will surely scramble on to new and safer protection schemes. But it's more clear than ever that uncrackable encryption is anything but.
This article is over a month old, voting and posting comments is disabled
6/19/2012 9:26:02 PM
Well, not really...
Imagine that in 1 years 1024 bits can be cracked in 6 months with that computer...
1 - Any document you "legally" sign, after those 6 months of having the keys being used are actually worthless - anything can be signed with your both public keys now!
2 - That computer seemed like a week one, for anyone wanting to go in strength to get potentially zillions of dollars (as being able to sign documents for other people is worth that), so put a really good supercomputer and it would maybe be done in 1 week or even 1 day... and now 1024 bits is unusable.
In security, you must adequate what is being secured to the security employed, so...
1024b can only be used for stuff that u don't mind as having as public, like having a normal wooden door at your house.
2048b can be used safely for a few years (to be confirmed every year with new methods like this one), like installing a great safe at home or even at a bank (the probability of being taken is low)
4096b can be used safely for several/lots of years (to be confirmed every few years), like having something at the safe where money gets printed (security measures are really huge)
So don't trust public key crypto with 1024b for anything you really can't have it made public!
Same thing for symmetric-key algorithms (AES, ...) 128b maybe considered fine, but if you really want it safe, use 256b... that way when 128b gets cracked you'll hear about it and have time to move to 512b :)
“We do believe we have a moral responsibility to keep porn off the iPhone.” -- Steve Jobs
Secure Wi-Fi? Not so Much -- Gaping Hole Found in WPS Pin System
December 29, 2011, 12:42 PM
Inside the Mega-Hack of Bitcoin: the Full Story
June 19, 2011, 6:40 PM
RSA Offers New SecurIDs in the Wake of Lockheed Martin Cyberattack
June 7, 2011, 6:36 PM
MD5 Is Officially Insecure: Hackers Break SSL Certificates, Impersonate CA
January 4, 2009, 5:04 PM
Researchers Crack WPA, No Brute Force Needed
November 7, 2008, 8:50 AM
Breaking Bad: How to Crash Google's Chrome Browser With Just 8 Characters
September 23, 2015, 11:08 AM
Quick Note: Amazon UK Offers £10 Back on Any Order £50 or Over
August 3, 2015, 12:05 PM
Editorial: Reddit Allows Itself to be Hijacked as a Hate Platform For Racist Bigots
July 21, 2015, 6:32 PM
Mozilla and Facebook to Adobe: It's Time to Kill Flash
July 20, 2015, 6:30 PM
Instagram Bans "Curvy" From Hashtag Searches, Provokes "Plus Sized" Outrage
July 16, 2015, 1:20 PM
Mozilla Promise Punctual Windows 10 Firefox Release, Teases at iOS Arrival
July 7, 2015, 3:08 PM
Most Popular Articles
Why the U.S. Won't be Able to Ban Google's New Huawei Marshmallow Flagship Phone
October 3, 2015, 5:27 PM
Microsoft Band 2 Stays Focused on Fitness, Debuts Oct. 30, Priced at $249
October 6, 2015, 9:16 PM
Microsoft's HD-500 ("Display Dock"), the Magic Sauce Behind Continuum
October 6, 2015, 5:30 PM
Apple's First Fixes to iOS 9 Land w/ iOS 9.0.1 Release
September 23, 2015, 6:11 PM
Microsoft Lumia 950 and 950 XL Finally Launch, w/ Windows 10, Liquid Cooling
October 6, 2015, 3:35 PM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2015 DailyTech LLC. -
Terms, Conditions & Privacy Information