Archive for February, 2005

Still with you, carry on….

February 21st, 2005

For various reasons I’m subscribed to the bugtraq mailing list in work and at home, mainly to spot what’s about to become a problem in terms of cracking systems, and also to make myself feel informed.

homer_small_brain.jpeg

Sometimes, though, I get so lost in the jargon I have no clue whatsoever of what’s being discussed. Example: Last week, the security world was abuzz with news of SHA-1 being ‘broken’ by a team of Chinese cryptographers. It probably means nothing to the average punter for the next few years, but it’s still big news. Lots of discussion about what could replace the broken hash function.

Today, this appeared. I’m the first to admit that I’m a bit thick, but I’d like to think that understanding of this email marks you out as being, errrmm, ‘gifted’

On Sat, 19 Feb 2005, John Richard Moser wrote:

> Yeah I noticed that on the wikipedia :)
>
> http://en.wikipedia.org/wiki/Secret_sharing

I would like to add that both schemes described there are essentially
equal as both make use of the fact that a T dimensional subspace U of an N
dimensional vector space V (for example a vector space of polynomials) is
encoded by giving T linearly independent vectors in U.

Data can now be encoded by thinking of it as a functional

f: T —> F

that is a linear function that maps T into the field F over which T is a
vector space.

Now for each bearer i of a part of the secret give him a vector b_i in U
(in terms of T coordinates) and his share of the data is e_i = f(b_i).

If T bearers come together, they can combine their T vectors b_i into a
TxT matrix M and compute M^(-1) (if they are linearly independent).
Finally, acting with M^(-1) on the vector of the T e_i’s recovers the
original functional f.

Note that if you want to share more data f1…fk you need to compute the
b_i and thus M^(-1) only once and then you pass on the f_n(b_i).

For a practical implementation you could for example use the unique field
F_256 of dimension 256 and do arithmetic using look up tables. See for
example the perl scripts

http://www.damtp.cam.ac.uk/user/rch47/split.pl

for the sharing/combining of the data and

http://www.damtp.cam.ac.uk/user/rch47/gf2.pl

for the finite field arithmetic.

Robert

Piece of piss. Problem solved and all that. (!) Now can we get back to breaking into IIS webservers? I can follow that.

British TV to Show ‘Guantanamo-Style’ Stress Techniques

February 9th, 2005

This will prove to be illuminating…


British TV to Show ‘Guantanamo-Style’ Stress Techniques

The program, due to air in mid-March, will examine the effects of the interrogation techniques over 48 hours in a London warehouse. It is part of a four-part series on torture hosted by news presenter Jon Snow.

It could be a useful way of showing viewers that seemingly innocuous techniques like sleep deprivation can have a devastating effect, said Steve Crawshaw, director of Human Rights Watch’s London office.

After all the ‘justification’ I’ve heard about it ‘not really being torture’ since it’s just a bit of sleep deprivation, some stress positions and a bit of playing with dogs, this will probably change a few minds in the UK. Doubtless it won’t be shown in the US but it’s the kind of thing that will enflame moderate, enrage left-leaning folks and cause the apologists for war to cough and look around. If they had the decency, that is.

Nothing serious, right?

Just to bring it home

February 6th, 2005

This is a perspective post, mainly for me. Get your head back together Pete!

I’ve actually met a neocon colleague, one of those that reads Michelle Malkin and thinks she’s ‘funny’ (she’s the author of the door-stopper yawnfest ‘In Defense of Internment: The Case for Racial Profiling in World War II and the War on Terror’). Lovely woman, pity she can’t seem to remember her family history past 1980, bless. Too busy posing for pictures for her blog. Tip for you love, less backcombing and porn star, mouth open photos. You could look classy without the second-rate pic. In fact, you could write classy and lose the pic, but I don’t see that happening – presentation seems to be a big thing in this womans’s world.

Anyway, I read her blog again for the first time in a while and as per usual, it came across as vacuous, a bit whiny (she wants to be a google news source, it seems!), and mostly devoid of anything actually interesting. I contast her writings with this list and wonder if she’d ever link to it or write about the names listed. Probably not, it’s a bit too REAL for her sort of writing, not enough fluff, flannel and wittering. I mean, how can you bang on about the democracy and the liberty and the voting and the democracy and the voting, with the purple fingers and the liberty and the democracy and all that stuff when people are dying?

Shit, all that trickle, trickle, drip, drip dying troop stuff just gets in the way of the 27 freedoms and the 15 liberties that good old Georgie promised to the world.

Wrong end of the stick

February 3rd, 2005

This is excellent. The Sunday Times wrote an article outlining how Mark Thatcher and his cohorts were going to run Equatorial Guinea as a private colony managed by an old style colonial company.


Insight: Coup plotters wanted colony of their own

THE FAILED coup attempt involving Sir Mark Thatcher was to have made Equatorial Guinea a private colony run for the benefit of the British plotters, leaked documents reveal.

The papers, passed to The Sunday Times by South African intelligence sources, reveal that the plotters had created a trading company to control the oil-rich West African state.

The Bight of Benin Company (BBC), named after the bay on the state’s coastline, was to have grabbed control of the country’s economy, its oil reserves, army and police.

The company would have controlled the country as a private fiefdom, modelled on the British East India Company, which ran vast swathes of India before it formally became part of the empire.

Not to be confused by facts, a British BBC (as in the broadcasting folks) bashing blogger has decided that this should should be brought to the attention of the world.

Surely some mistake? :)

Bad Behavior has blocked 442 access attempts in the last 7 days.

peteconnolly.co.uk is Digg proof thanks to caching by WP Super Cache