<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>infosecurity.ch – Playhouse of privacy, security, hacking, encryption, intelligence and some business stuff</title>
<link>https://infosecurity.ch/</link>
<atom:link href="https://infosecurity.ch/feed.xml" rel="self" type="application/rss+xml"/>
<description>Blog of Fabio Pietrosanti (naif) on privacy, security, hacking, encryption and intelligence (2007–2017), restored in 2026.</description>
<language>en</language>
<lastBuildDate>Tue, 06 Oct 2026 10:55:05 +0000</lastBuildDate>
<item>
<title>infosecurity.ch is back online: the blog has been restored</title>
<link>https://infosecurity.ch/20260917/infosecurity-ch-restored/</link>
<guid isPermaLink="true">https://infosecurity.ch/20260917/infosecurity-ch-restored/</guid>
<pubDate>Thu, 17 Sep 2026 12:00:00 +0200</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<description>After years offline, infosecurity.ch is back. On 17 September 2026 I restored this blog from its Internet Archive copy and republished it as a static site at…</description>
<content:encoded><![CDATA[<p>After years offline, <strong>infosecurity.ch</strong> is back. On <strong>17 September 2026</strong> I restored this blog from its Internet Archive copy and republished it as a static site at <a href="https://infosecurity.ch/">https://infosecurity.ch</a>.</p>
<p>Everything is as it was: the posts I wrote between 2007 and 2017 on privacy, security, hacking, encryption, interception and intelligence, the comments, tags and categories, and every original URL, including the automatic translations of the time. This is a historical archive: comments are closed and nothing has been rewritten, so some links point to a web that no longer exists.</p>
<p>What changed is under the hood: HTTPS, an up-to-date sitemap with language alternates, structured data, an <a href="https://infosecurity.ch/feed.xml">RSS feed</a> and machine-readable versions of the posts for search engines and AI assistants (<a href="https://infosecurity.ch/llms.txt">llms.txt</a>).</p>
<p>One 2010 post that had vanished from the blog before 2017 is back, recovered from a 2016 snapshot: <a href="https://infosecurity.ch/20100129/licensed-by-israel-ministry-of-defense-how-things-really-works/">Licensed by Israel Ministry of Defense? How things really works!</a>, together with the automatic translations that were archived with it. A second one, published on 24 September 2010 about SIP/VoIP firewalls, was never archived and is lost.</p>
<h3>Where to find me today</h3>
<ul>
<li>Home page: <a href="https://fabio.pietrosanti.it/" rel="me">fabio.pietrosanti.it</a></li>
<li>LinkedIn: <a href="https://www.linkedin.com/in/secret/" rel="me">linkedin.com/in/secret</a></li>
<li>X (Twitter): <a href="https://x.com/fpietrosanti" rel="me">@fpietrosanti</a></li>
<li>GitHub: <a href="https://github.com/fpietrosanti" rel="me">github.com/fpietrosanti</a></li>
<li>SlideShare, talks from those years: <a href="https://www.slideshare.net/fpietrosanti" rel="me">slideshare.net/fpietrosanti</a></li>
</ul>
<h3>Contacts</h3>
<p>The quickest way to reach me is a message on <a href="https://www.linkedin.com/in/secret/">LinkedIn</a>; more details are on my <a href="https://fabio.pietrosanti.it/">home page</a>.</p>
<p>&mdash; Fabio (naif) Pietrosanti</p>
]]></content:encoded>
</item>
<item>
<title>Low Liability - Reduced Abuses Tor Exit Nodes</title>
<link>https://infosecurity.ch/20170610/low-liability-reduced-abuses-tor-exit-nodes/</link>
<guid isPermaLink="true">https://infosecurity.ch/20170610/low-liability-reduced-abuses-tor-exit-nodes/</guid>
<pubDate>Sat, 10 Jun 2017 17:00:30 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>privacy</category>
<description>In 2011 i’ve experimented running a Tor Exit by reducing my liability , by reducing the source of abuses. During those years I’ve been looking at different…</description>
<content:encoded><![CDATA[<p>In 2011 i’ve <a href="https://infosecurity.ch/20110124/my-tor-exit-node-experience-trying-to-filter-out-noisy-traffic/">experimented running a Tor Exit by reducing my liability</a>, by reducing the source of abuses.</p>
<p>During those years I’ve been looking at different scenarios, I’ve to admit not always in-line with the <a href="https://blog.torproject.org/blog/ethical-tor-research-guidelines">Tor Ethical Research Guidelines</a>, posting various ideas on tor-talk mailing list, irc channel and opening up single trac ticketing features.</p>
<p>In particular the following tickets has been opened for this specific purposes:</p>
<ul>
<li><a href="https://trac.torproject.org/projects/tor/ticket/17975">Introduce OutboundExitAddress to enable exit-only traffic to go via a different IP address</a> (IMPLEMENTED!)</li>
<li><a href="https://trac.torproject.org/projects/tor/ticket/18267">Enable Exit Policy by Autonomous System Numbers</a></li>
<li><a href="https://trac.torproject.org/projects/tor/ticket/18269">Enable Tor Browser users to become &#8220;easy to be run&#8221; Tor Exit relay</a></li>
<li><a href="https://trac.torproject.org/projects/tor/ticket/18268">Make Tor aware of the top-30 destinations of Tor Exit traffic</a></li>
</ul>
<p>So the proposed policy to reduce the liability and abuses is following those steps::</p>
<ol>
<li>Block most outgoing web attacks without causing harms to regular traffic <b>- Reduce automated abuses sent because of hacking attempt</b></li>
<li>Block most outgoing peer to peer traffic that’s highly likely generating <b>- Reduce automated abuses sent because of DMCA and Copyright Infrigment</b></li>
<li>Block traffic going to the countries of origin of your residences <b>- Improve your personal legal resiliency against simple mistake done by local law enforcement agencies</b></li>
<li>Block most outgoing portscan without causing harms to regular traffic <b>- Reduce automated abuses sent because of hacking attempt</b></li>
</ol>
<p>It would also be possibile to follow a whitelisting approach, rather than a blacklisting one:</p>
<ol>
<li>Route whitelisted traffic going trough major internet company directly (let’s assume represent top tor destination, being normally top internet destination of traffic)</li>
<li>Divert non-whitelisted traffic back into Tor network with 1-hop link trough a high speed gateway</li>
</ol>
<p>Those methods could enable volunteers to run Tor Exit Relay rather than just Tor Relay with no-exit policy also on budget VPS. Budget VPSs usually provide a tons of bandwidth but disconnect and block your account after the very first abuses related to your IP touch their ticketing system, and for that reason it’s nearly impossible to run Tor Exit Relay on it.</p>
<p>Each of the steps previously defined can now be technically experimented thanks to the new <a href="https://blog.viraptor.info/tag/dns.html" title="Some testing of this directive by Own automatic phishing list and Tor-to-Tor tunneling">OutboundBindAddressExit</a> settings that would enable to “manipulate” (but with a good intention) Tor Exit Traffic easily.</p>
<p>Very particular care should be taken by defining in advance how to avoid disrupting Tor Exit traffic and determining if it effectively happened and why.</p>
<p>That experimenting should be done by publishing transparently what’s being done and where, because <b><i><u>manipulating Tor Exit Traffic is against any Tor Community Standards or Ethics Research Guideline</u></i></b>.</p>
<p>The effective willingness to do that experiments means accepting critics and incorporating each of the critics back into the hacking of the methodology being tested.</p>
<p>It also means accepting that the Tor Directory Authority operators may just find this behaviour unacceptable and by majority of consensus promote to block and kick-out that Tor Exit Relay from the Tor Network.</p>
<p>I’d love that people would pick it up the various challenges posed by those kind of setup and start testing it. Otherwise with enough Sundays, I’ll do that and document success and failures! :-)</p>
<p>Ah, that’s a blog post done in 2017 with my last blog post being from 2011…. maybe I’m getting back writing thoughts on blog rather than spending those time on social media?</p>]]></content:encoded>
</item>
<item>
<title>RFC 6189: ZRTP is finally a standard!</title>
<link>https://infosecurity.ch/20110411/rfc-6189-zrtp-is-finally-a-standard/</link>
<guid isPermaLink="true">https://infosecurity.ch/20110411/rfc-6189-zrtp-is-finally-a-standard/</guid>
<pubDate>Mon, 11 Apr 2011 22:54:11 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>privacy</category>
<category>voicesecurity</category>
<category>zrtp</category>
<description>Finally ZRTP has been assigned an official RFC assignment, RFC6189 ZRTP: Media Path Key Agreement for Unicast Secure RTP. It had as a dependency the SRTP…</description>
<content:encoded><![CDATA[<p>Finally <a href="http://en.wikipedia.org/wiki/ZRTP">ZRTP</a> has been assigned an official RFC assignment, <a href="http://tools.ietf.org/html/rfc6189">RFC6189</a> ZRTP: Media Path Key Agreement for Unicast Secure RTP.</p>
<p>It had as a dependency the <a href="http://en.wikipedia.org/wiki/Secure_Real-time_Transport_Protocol">SRTP</a> with AES key size of 256bit that now has been defined as <a href="http://tools.ietf.org/html/rfc6188">RFC6188</a>.</p>
<p>It’s exciting to see the RFC finally released, as it’s an important milestone to set ZRTP as the official standard for end-to-end encryption much like <a href="http://tools.ietf.org/html/rfc4880">PGP</a> has been for emails.</p>
<p>Now any organization in the world will be officially able to implement ZRTP for end-to-end protocol voice encryption</p>
<p>Currently 3 different public implementations of ZRTP protocol exists:</p>
<ul>
<li><a href="http://www.philipzimmermann.com/">Philip Zimmermann’s</a> <a href="http://zfoneproject.com/">LibZRTP</a> (c code)</li>
<li><a href="http://www.zrtp.org/">PrivateWave’s ZORG</a> (c++ code / Java code)</li>
<li><a href="http://www.gnutelephony.org/index.php/GNU_ZRTP">GNU Telephony ZRTP</a> (c++ code / Java code)</li>
</ul>
<p>Each of them provide different features of the protocol, but most important are known to be interoperable.</p>
<p>A new wave is coming to the voice encryption world, irrupting into a gray area where most of the companies doing phone encryption systems has been implementing custom encryption.</p>
<p>Now a standard has been setup and there are few reasons left to implementing something different.</p>
<p>Hurra <a href="http://www.philzimmermann.com/">Mr. Zimmermann</a> and all the community of companies (like <a href="http://www.privatewave.com/security/security-protocols/zrtp.html">PrivateWave</a>) and individuals (like <a href="http://programm.froscon.org/2008/events/169.en.html">Werner Dittmann</a>) that worked on it!</p>
<p>Today it’s a great day, such kind of technology is now official and also with multiple existing implementation!</p>
<p>Philip, you did it again, my compliments to your pure spirit and determination :-)</p>]]></content:encoded>
</item>
<item>
<title>Progress for GSM cracking in Freiburg university</title>
<link>https://infosecurity.ch/20110223/progress-for-gsm-cracking-in-freiburg-university/</link>
<guid isPermaLink="true">https://infosecurity.ch/20110223/progress-for-gsm-cracking-in-freiburg-university/</guid>
<pubDate>Wed, 23 Feb 2011 13:32:47 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>hacking</category>
<category>mobile</category>
<category>privacy</category>
<category>voicesecurity</category>
<description>The exciting world of mobile protocols (GSM, GSM-R, TETRA, UMTS, etc) hacking is getting official research activities from universities. The investment to…</description>
<content:encoded><![CDATA[<p>The exciting world of mobile protocols (GSM, GSM-R, TETRA, UMTS, etc) hacking is getting official research activities from universities.</p>
<p>The investment to make opensource code releases of cracking software is giving the opportunity to students of university to work on it, improve it and do strong research.</p>
<p>The University of Freiburg just released the paper <b><a href="http://www.ks.uni-freiburg.de/download/misc/practical_exercise_a51.pdf">Practical exercise on the GSM Encryption A5/1</a></b> along with a <a href="http://www.ks.uni-freiburg.de/download/misc/gsmframecoder.tar.gz">gsmframencoder</a> support tool to improve the sniffing, decoding and cracking process.</p>
<p>Opening hardware, opening software, opening protocol demonstrate the weakness of any kind of proprietary method or process to build-up communication and security technologies.</p>
<p>It should be the goal of any scientists to try to open-up and crack any kind of proprietary and closed technology to force the industry to goes on only with interoperable and open approach while designing telecommunication protocols.</p>]]></content:encoded>
</item>
<item>
<title>My TOR exit node experience trying to filter out noisy traffic</title>
<link>https://infosecurity.ch/20110124/my-tor-exit-node-experience-trying-to-filter-out-noisy-traffic/</link>
<guid isPermaLink="true">https://infosecurity.ch/20110124/my-tor-exit-node-experience-trying-to-filter-out-noisy-traffic/</guid>
<pubDate>Mon, 24 Jan 2011 22:14:19 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>privacy</category>
<description>Early this year i decided that’s time to run a TOR exit node so i brought a VPS at hetzner.de (because they are listed as a Good TOR ISP )and setup the…</description>
<content:encoded><![CDATA[<p>Early this year i decided that’s time to run a TOR exit node so i brought a VPS at <a href="http://hetzner.de/">hetzner.de</a> (because they are listed as a <a href="https://trac.torproject.org/projects/tor/wiki/TheOnionRouter/GoodBadISPs">Good TOR ISP</a>)and setup the exit-node with nickname <a href="http://88.198.109.35/">privacyresearch.infosecurity.ch</a> with a 100Mbit/s connection for first 1TB of monthly data, then 10MBit/s flat.</p>
<p>It also run <a href="http://www.tor2web.org/">TOR2WEB</a> software on <a href="http://tor.infosecurity.ch">http://tor.infosecurity.ch</a> .</p>
<p>I setup the <a href="http://88.198.109.35/exitpolicy.txt">exit-policy</a> as suggested by running <a href="https://blog.torproject.org/blog/tips-running-exit-node-minimal-harassment">exit-node with minimal harassment</a> and prepared an <a href="https://trac.torproject.org/projects/tor/wiki/TheOnionRouter/TorAbuseTemplates">abuse response template</a>.</p>
<p>In the first day i’ve been running the node i received immediately DMCA complain due to peer to peer traffic.</p>
<p>So i decided to filter-out some P2P traffic by using <a href="http://www.opendpi.org/">OpenDPI</a> iptables module and DMCA complain automatically disappeared:</p>
<p><b>iptables -A OUTPUT -m opendpi -edonkey -gadugadu -fasttrack -gnutella -directconnect -bittorrent -winmx -soulseek -j REJECT</b></p>
<p>Then, because i am italian, i decided to avoid my TOR node to connect to the Italian internet address space in order to reduce the chance that a stupid prosecutor would wake me up at morning because did not understand that i am running a TOR node.</p>
<p>I tried, with the help of <a href="http://twitter.com/hellais">hellais</a> that wrote a <a href="https://github.com/hellais/blockfinder/blob/master/torexit.py">script to make Exit Policy reject statement</a>, to reject all Italian netblocks based on <a href="http://www.appelbaum.net/">ioerror’s</a> <a href="https://github.com/ioerror/blockfinder">blockfinder</a> but we found that the <a href="https://www.torproject.org/docs/tor-manual.html">torrc configuration</a> files with +1000 lines was making TOR crash.</p>
<p>We went to open a ticket to report the crash about our attempt to block TOR exit policy by country and <a href="https://trac.torproject.org/projects/tor/ticket/993">found a similar attempt</a> where we contributed, but it still seems to be an open-issue.</p>
<p>The conclusion is that it’s not possible to make a Country Exit Policy for TOR exit node in a clean and polite way so i decided to go the dirty way by using <a href="http://www.ducea.com/2009/03/18/iptables-geoip-match-on-debian-lenny/">iptables/geoip</a> . After fighting to make it compile properly, it was one line of iptables to block traffic going to italy:</p>
<p><b>iptables -A OUTPUT -p tcp -m state -state NEW -m geoip -dst-cc IT -j REJECT</b></p>
<p>Now from my exit-node no connection to italian networks will be done and i am safe against possibly stupid prosecutors not understanding TOR (i have an exception for all TOR node ip address applied before).</p>
<p>After some other days i started to receive complains due to portscan activities originated from my tor nodes.</p>
<p>
From my own point of view i want to support anonymity network, not anonymous hacking attempt and so i want to filter-out portscan and attacks from originating from my node.That’s a complex matter that require some study, so in the meantime i installed <a href="http://www.openwall.com/scanlogd/">scanlogd</a> and <a href="http://www.snort.org/">snort</a> because i want to evaluate how many attacks, which kind of attacks are getting out from my TOR exit node.<br/>
Later i will try to arrange some kind of filtering to be sure to be able to filter out major attacks.<br/>
For what’s related to portscan it seems that there are no public tools to detect and filter <b>outgoing portscan</b> but only to filter <b>incoming portscan</b> so probably will need to write something ad-hoc.<br/>
I will refer how things are going and if there will be some nice way to implement in a lightwave way <a href="http://seclab.pl/pdf/Snort-Inline_and_IPTABLES.pdf">snort-inline</a> to selectively filter-out major attack attempt originating from my exit-node.</p>
<p>
My goal is to keep an exit node running in long-term (at least 1TB of traffic per months donated to TOR), reducing the effort related to ISP complain and trying to do my best to run the exit-node with a reasonable liability.</p>]]></content:encoded>
</item>
<item>
<title>TETRA hacking is coming: OsmocomTETRA</title>
<link>https://infosecurity.ch/20110123/tetra-hacking-is-coming-osmocomtetra/</link>
<guid isPermaLink="true">https://infosecurity.ch/20110123/tetra-hacking-is-coming-osmocomtetra/</guid>
<pubDate>Sun, 23 Jan 2011 10:27:44 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>hacking</category>
<category>mobile</category>
<category>voicesecurity</category>
<description>It’s very exciting to see the release of OsmocomTETRA , the first opensource SDR ( Software Defined Radio ) implementation of TETRA demodulator, PHY and…</description>
<content:encoded><![CDATA[<p>It’s very exciting to see the release of <a href="http://tetra.osmocom.org/">OsmocomTETRA</a>, the first opensource SDR (<a href="http://en.wikipedia.org/wiki/Software-defined_radio">Software Defined Radio</a>) implementation of TETRA demodulator, PHY and lower MAC layers.</p>
<p>It’s the TETRA version of <a href="http://www.airprobe.org/">GSM airprobe</a> that unlock access to the data and frame of TETRA communication protocol, thus giving great hacking opportunity!</p>
<p>Now that also TETRA technology has been opened we should expect, during this 2011, to see opensource TETRA sniffers and most probably also TEA encryption (the Tetra Encryption Algorithm) cracked!</p>
<p>TETRA is used by Police, Emergency Services and Militaries as an alternative mobile communication network that can works even without the availability of network coverage (only mobile-to-mobile without a base station) and provide some special high availability services.</p>
<p>I wrote about TETRA in my slide <a href="http://www.slideshare.net/fpietrosanti/voice-securityprotocol-review">Major Voice Security Protocol Review</a> .</p>
<p>In OsmocomBB mailing lists there was already discussion about some TETRA network status:</p>
<ul>
<li>Belgium Police TETRA ASTRID network: unencrypted</li>
<li>German Police test TETRA network in Aachen: unencrypted</li>
<li>Some ex-jugoslawia TETRA network: unencrypted</li>
<li>Netherland C200 TETRA network: TEA2 encrypted with static keys</li>
<li>UK Airwave TETRA network: TEA2 encrypted with TEA2</li>
</ul>
<p>It will be really fun to see that new Police and rescue service hacking coming back from old analog ages to the new digital radios :-)</p>]]></content:encoded>
</item>
<item>
<title>Government 2.0, Open Data and WikiLeaks</title>
<link>https://infosecurity.ch/20110115/government-2-0-open-data-and-wikileaks/</link>
<guid isPermaLink="true">https://infosecurity.ch/20110115/government-2-0-open-data-and-wikileaks/</guid>
<pubDate>Sat, 15 Jan 2011 20:05:26 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>civilrights</category>
<description>The concepts behind WikiLeaks, OpenLeaks, GlobalLeaks, BalkanLeaks is much more than just revealing secrets to the public. It’s part of a revolution that’s…</description>
<content:encoded><![CDATA[<p>The concepts behind WikiLeaks, OpenLeaks, GlobalLeaks, BalkanLeaks is much more than just revealing secrets to the public.</p>
<p>It’s part of a revolution that’s coming in government’s organization, transparency and cooperation with so called &#8216;web 2.0 / wiki’ collaborative systems.</p>
<p>Have a look at those <a href="http://www.slideshare.net/AnkeDomscheitBerg/2010-09-23-gov-20-pep-net-summit-ankedomscheitberg">Government 2.0 - Introduction</a> by Anke Domscheit Berg, Innovative Government Program Leads of Microsoft Germany and wife of Daniel Berg, co-founder of <a href="http://wikileaks.ch/">WikiLeaks</a> and now founder of <a href="http://www.openleaks.org/">OpenLeaks</a>.</p>
<p>Have a look at <a href="http://www.slideshare.net/jkonga/gov-20-and-open-data-sustainability">Open Data government 2.0</a> initiative to enforce government transparency, reducing corruption and improving performance of government organization.</p>
<p>That revolution it’s just more than a group of anarco-libertarian funky guys that want to create chaos by spreading secrets, it’s just the start of the rush to achieve new organization model of governments by leveraging complete transparency and strong cooperation with citizens.</p>]]></content:encoded>
</item>
<item>
<title>ZORG, new C++ and Java ZRTP implementation public release</title>
<link>https://infosecurity.ch/20110112/zorg-new-c-and-java-zrtp-implementation-public-release/</link>
<guid isPermaLink="true">https://infosecurity.ch/20110112/zorg-new-c-and-java-zrtp-implementation-public-release/</guid>
<pubDate>Wed, 12 Jan 2011 14:01:17 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>mobile</category>
<category>privacy</category>
<category>voicesecurity</category>
<category>zrtp</category>
<description>Hi all, today at PrivateWave Italia S.p.A, italian company engaged in developing technologies for privacy protection and information security in voice…</description>
<content:encoded><![CDATA[<p><span style="font-family: Times; font-size: medium;"><span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">Hi all, today at</span></span> <span style="font-family: Times; font-size: medium;"><span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">PrivateWave Italia S.p.A, italian company</span> <span style="font-size: 11pt; font-family: Arial; color: #333333; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">engaged in developing technologies for privacy protection and information security in voice telecommunications where i am CTO, we</span> <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">release ZORG, a new open source ZRTP protocol implementation available for download from <a href="http://www.zrtp.org/">http://www.zrtp.org</a> .</span></span></p>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; background-color: transparent; font-family: Times; font-size: medium;">
  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">ZRTP [1] provides end-to-end key exchange with Elliptic Curve Diffie-Hellmann 384bit and AES-256 SRTP encryption .</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">ZORG has been originally developed and implemented in PrivateWave’s PrivateGSM voice encryption products available for the following platforms: Blackberry, Nokia and iOS (iPhone) .</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">Zorg C++ has been integrated with PJSIP open source VoIP SDK [2] and it’s provided as integration patch against PJSIP 1.8.5. It has been tested on iPhone, Symbian, Windows, Linux and Mac OS X.</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">Zorg Java has been integrated within a custom version of MJSIP [3] open source SDK on Blackberry platform and it includes memory usage optimizations required to reduce at minimum garbage collector activity.</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">Both platforms have separated and modular cryptographic back-ends so that the cryptographic algorithms implementation could be easily swapped with other ones.</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">ZORG is licensed under GNU AGPL and source code is available on github at</span> <a href="https://github.com/privatewave/ZORG"><span style="font-size: 11pt; font-family: Arial; color: #000099; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap;">https://github.com/privatewave/ZORG</span></a> <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">.</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">We are releasing it under open source and in coherence with our approach to security [4] as we really hope that it can be useful for the open source ecosystem to create new voice encryption systems in support of freedom of speech.</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">More than 20 pjsip-based open source VoIP encryption software and several written in Java could directly benefit from ZORG release.</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">We would be happy to receive proposal of cooperation, new integration, new cryptographic back-ends, bug scouting and whatever useful to improve and let ZRTP affirm as voice encryption standard.</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">Zorg is available from <a href="http://www.zrtp.org/">http://www.zrtp.org</a> .</span></p>
<p>  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">[1] ZRTP:</span> <a href="http://en.wikipedia.org/wiki/ZRTP"></a><a href="http://en.wikipedia.org/wiki/ZRTP">http://en.wikipedia.org/wiki/ZRTP</a><br/>
  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">[2] PJSIP: <a href="http://www.pjsip.org/">http://www.pjsip.org</a></span><br/>
  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">[3] MJSIP: <a href="http://www.mjsip.org/">http://www.mjsip.org</a></span><br/>
  <span style="font-size: 11pt; font-family: Arial; color: #000000; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;">[4] Security approach:</span> <a href="http://www.privatewave.com/security/approch.html"><span style="font-size: 11pt; font-family: Arial; color: #000099; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: underline; vertical-align: baseline; white-space: pre-wrap;">http://www.privatewave.com/security/approch.html</span></a>
</div>]]></content:encoded>
</item>
<item>
<title>Encrypted mobile to landline phone calls with Asterisk 1.8</title>
<link>https://infosecurity.ch/20101025/encrypted-mobile-to-landline-phone-calls-with-asterisk-1-8/</link>
<guid isPermaLink="true">https://infosecurity.ch/20101025/encrypted-mobile-to-landline-phone-calls-with-asterisk-1-8/</guid>
<pubDate>Mon, 25 Oct 2010 12:15:05 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>mobile</category>
<category>privacy</category>
<category>voicesecurity</category>
<description>We just released a technical howto on how to build up Secured mobile to landline VoIP infrastructure with: Asterisk 1.8 (just released, support SIP/TLS +…</description>
<content:encoded><![CDATA[<p>We just released a technical howto on <a href="http://www.venturevoip.com/news.php?rssid=2464">how to build up Secured mobile to landline VoIP infrastructure</a> with:</p>
<ul>
<li><a href="http://www.asterisk.org/">Asterisk 1.8</a> (just released, support SIP/TLS + SDES key exchange for SRTP)</li>
<li><a href="http://www.privatewave.com/security/security-protocols/srtp-sdes.html">PrivateGSM Enterprise</a> (Nokia / iPhone / Blackberry)</li>
<li><a href="http://www.snom.com/">SNOM 300 Desktop phone</a></li>
</ul>
<p>In next weeks others howto like this one will come out by using other server platforms such as FreeSWITCH, all in the spirit of transparency and leverage of opensource security technologies.</p>]]></content:encoded>
</item>
<item>
<title>Eight Epic Failure of Regulating Cryptography</title>
<link>https://infosecurity.ch/20101021/eight-epic-failure-of-regulating-cryptography/</link>
<guid isPermaLink="true">https://infosecurity.ch/20101021/eight-epic-failure-of-regulating-cryptography/</guid>
<pubDate>Thu, 21 Oct 2010 14:59:57 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>policy</category>
<description>A very illuminating article on Eight Epic Failure of Regulating Cryptography and common misunderstanding by government regulators that doesn’t have a wide…</description>
<content:encoded><![CDATA[<p>A very illuminating article on <a href="http://www.privacydigest.com/2010/10/21/eight%20epic%20failures%20regulating%20cryptography">Eight Epic Failure of Regulating Cryptography</a> and common misunderstanding by government regulators that doesn’t have a wide view on how technology works.</p>
<p>Ignorant government regulators does not understood that strict regulation would have the following drawbacks:</p>
<ol>
<li>It will create security risk</li>
<li>It won’t stop the bad guys</li>
<li>It will harm innovation</li>
<li>It will harm US business</li>
<li>It will cost consumers</li>
<li>It will be unconstitutional</li>
<li>It will be a huge outlay of tax dollars</li>
</ol>
<p></p>]]></content:encoded>
</item>
<item>
<title>PrivateGSM: Blackberry/iPhone/Nokia mobile voice encryption with ZRTP or SRTP/SDES</title>
<link>https://infosecurity.ch/20101019/privategsm-blackberryiphonenokia-mobile-voice-encryption-with-zrtp-or-srtpsdes/</link>
<guid isPermaLink="true">https://infosecurity.ch/20101019/privategsm-blackberryiphonenokia-mobile-voice-encryption-with-zrtp-or-srtpsdes/</guid>
<pubDate>Tue, 19 Oct 2010 09:10:33 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>mobile</category>
<category>privacy</category>
<category>voicesecurity</category>
<category>zrtp</category>
<description>I absolutely avoid to use my own personal blog to make promotion of any kind of product. That time it’s not different, but i want to tell you facts about…</description>
<content:encoded><![CDATA[<p>I absolutely avoid to use my own personal blog to make promotion of any kind of product.</p>
<p>That time it’s not different, but i want to tell you facts about products i work on without fancy marketing, but staying technical.</p>
<p>Today, at <a href="http://www.privatewave.com/">PrivateWave</a> where i am <a href="http://linkedin.com/in/secret">CTO and co-founder</a>, we released publicly mobile VoIP encryption products for Blackberry, iPhone and Nokia:</p>
<ul>
<li>The 1st ever Blackberry encrypted VoIP with <a href="http://www.privatewave.com/security/security-protocols/zrtp.html">ZRTP</a> - <b>PrivateGSM VoIP Professional</b></li>
<li>The 1st ever iPhone encrypted VoIP with <a href="http://www.privatewave.com/security/security-protocols/zrtp.html">ZRTP</a> - <b>PrivateGSM VoIP Professional</b></li>
<li><b><span style="font-weight: normal;">The 1st ever Blackberry encrypted VoIP client with <a href="http://www.privatewave.com/security/security-protocols/srtp-sdes.html">SRTP with SDES key exchange over SIP/TLS</a> -</span> PrivateGSM VoIP Enterprise</b></li>
</ul>
<p style="text-align: center;"><a href="http://www.privatewave.com/"><img src="https://infosecurity.ch/wp-content/uploads/2010/10/logo-privatewave-colore.png" width="229" height="47" alt="logo-privatewave-colore.png"/></a></p>
<p>At PrivateWave we use a different approach respect to most voice encryption company out there, read our <a href="http://www.privatewave.com/security/approch.html">approach to security</a> .</p>
<p>The relevance of this products in the technology and industry landscape can be summarized as follow:</p>
<ul>
<li>It’s the first voice encryption company using only standards security protocols (and we expect the market will react, as it’s clear that proprietary tech coming from the heritage of CSD cannot provide same value)</li>
<li>It’s the first approach in voice encryption to use only open source & standard encryption engine</li>
<li>It’s the first voice encryption approach to provide different security model using different technologies (end-to-end for <a href="http://www.privatewave.com/security/security-protocols/zrtp.html">ZRTP</a> and <a href="http://www.privatewave.com/security/security-model/end-to-site.html">end-to-site</a> for <a href="http://www.privatewave.com/security/security-protocols/srtp-sdes.html">SRTP</a>)</li>
</ul>
<p>Those suite of Mobile Secure Clients, designed for professional security use only using best telecommunication and security technologies, provide a high degree of protection along with good performance also in bad network conditions:</p>
<ul>
<li>Multiple security model: <a href="http://www.privatewave.com/security/security-model/end-to-end.html">end-to-end</a> encryption with <a href="http://www.privatewave.com/security/security-protocols/zrtp.html">ZRTP</a> and <a href="http://www.privatewave.com/security/security-model/end-to-site.html">end-to-site</a> encryption with SRTP</li>
<li>Voice encryption</li>
<li><a href="http://www.privatewave.com/security/security-protocols/sip-tls.html">Signaling encryption</a></li>
<li><a href="http://www.privatewave.com/security/security-protocols/sip-tls.html"></a>Digital certificate strict checking of <a href="http://www.privatewave.com/security/security-protocols/sip-tls.html">SIP/TLS</a> (99% of voip clients does not do in-depth strict <a href="http://en.wikipedia.org/wiki/Transport_Layer_Security">TLS</a> checking)</li>
<li><a href="http://en.wikipedia.org/wiki/Adaptive_Multi-Rate_audio_codec">AMR 4.75kbit codec</a> (same technology and audio codec of standard GSM phone calls)</li>
<li>Extremely optimized <a href="http://en.wikipedia.org/wiki/Jitter">jitter buffering</a> (It works even in GPRS and via WiFi over Satellite)</li>
<li>Automatic always-on reconnection using <a href="https://docs.google.com/viewer?url=http://research.nokia.com/files/NRCTR2008002.pdf">Nokia Standby Techniques</a> for <b>strong battery saving</b></li>
</ul>
<p>The applications are:</p>
<ul>
<li><a href="http://www.privatewave.com/products-services/private-gsm/versions-platforms.html">PrivateGSM Professional</a> <b>- It does <a href="http://www.privatewave.com/security/security-model/end-to-end.html">end-to-end</a> encryption with <a href="http://www.privatewave.com/security/security-protocols/zrtp.html">ZRTP with ECDH384</a>, strict cache verification and addressbook integration</b></li>
<li><a href="http://www.privatewave.com/products-services/private-gsm/versions-platforms.html">PrivateGSM Enterprise</a> - <b>It does <a href="http://www.privatewave.com/security/security-model/end-to-site.html">end-to-site</a> encryption with <a href="http://www.privatewave.com/security/security-protocols/srtp-sdes.html">SRTP with SDES key exchange over SIP/TLS</a></b></li>
<li><a href="http://www.privatewave.com/enterprise-voip-security-suite/enterprise-solution.html">Enterprise VoIP Security Suite</a> - <a href="http://www.privatewave.com/security/pbx-security.html">Secure PBX System</a> based on Asterisk with added VoIP Firewalls</li>
</ul>
<p style="text-align: center;"><a href="http://www.privatewave.com/"><img src="https://infosecurity.ch/wp-content/uploads/2010/10/icona-pgsm.png" width="118" height="141" alt="icona-pgsm.png"/></a></p>
<p>The supported mobile devices are:</p>
<ul>
<li><a href="http://www.privatewave.com/support/mobile-devices/nokia.html">Nokia S60</a></li>
<li><a href="http://www.privatewave.com/support/mobile-devices/iphone.html">iPhone</a> 3GS/4G with iOS 4.x</li>
<li><a href="http://www.privatewave.com/support/mobile-devices/blackberry.html">Blackberry</a> with RIMOS 5 (several GSM models)</li>
</ul>
<p>Regarding <b><a href="http://www.privatewave.com/security/security-protocols/zrtp.html">ZRTP</a></b> we decided to stress and stretch all the security and paranoid feature of the protocol with some little addition:</p>
<ul>
<li>Use only <a href="http://en.wikipedia.org/wiki/Elliptic_curve_cryptography">Elliptic Curve Diffie Hellmann</a> (ECDH) 384bit that are part of <a href="http://en.wikipedia.org/wiki/NSA_Suite_B_Cryptography">NSA Suite-B</a> (<a href="https://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/">No Koblitz ECDH-571 curves!</a>)</li>
<li>Use <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard">AES256</a> in CTR mode</li>
<li>Does cache verification and key continuity</li>
<li>Strict addressbook integration extended respect to RFC with additional paranoid checking</li>
<li>All security warning and security error cause the call to be hangup, cache cleared and user warned to re-check ZRTP security</li>
<li>Use <a href="http://en.wikipedia.org/wiki/Random_number_generation">Random Number Generator</a> in strict compliance with <a href="http://www.privatewave.com/security/security-protocols/random-number-generation.html">FIPS security requirements</a> by using Phisical Source of Entropy (Microphone)</li>
</ul>
<p>Our strict address book integration, goes beyond <b><a href="http://tools.ietf.org/html/draft-zimmermann-avt-zrtp-22">ZRTP RFC</a> <span style="font-weight: normal;">specification</span>,</b> that could be vulnerable to certain attacks when used on mobile phones because of user behavior of not to look at mobile screen.</p>
<p>Our paranoy way of using ZRTP mitigate such conditions, we will write about this later and/or will add specific details for RFC inclusion.</p>
<p><b><span style="font-weight: normal;">Some words on</span> PrivateGSM Professional</b> with end-to-end encryption with ZRTP</p>
<ul>
<li>User does not need to use the application: It’s i<a href="http://www.privatewave.com/products-services/private-gsm/blackberry-usage-mode.html">ntegrated in the phone for dialing with a secure prefix</a> putting +801 in front of the number to call</li>
<li><b>It’s</b> <a href="http://m.privategsm.com/new-webdownload/">downloadable from the internet</a> for self trial for 15 days (most voice encryption company does not provide free download)</li>
<li><b>Receiver is FREE</b> that means that only who make calls have to buy the application, receiver does not need to pay anything</li>
<li>it does <b><a href="http://www.privatewave.com/security/security-protocols/rtp-traffic-obfuscation.html">Traffic Obfuscation</a></b> to <b>Bypass <a href="http://www.voip-sol.com/10-isps-and-countries-known-to-have-blocked-voip/">VoIP blocks over 2G/3G</a></b></li>
<li>It’s <a href="http://www.privatewave.com/support/network-requirements/voip.html">very narrowband:</a> Use as little as 100Kbyte/minutes</li>
</ul>
<p>Read <a href="https://docs.google.com/viewer?url=http://www.privatewave.com/media/0/29101080972386/privategsm_voip_techsheet_en.pdf">technical sheet</a> there!</p>
<p style="text-align: left;">To <a href="http://www.privatewave.com/products-services/private-gsm/try-privategsm.html">download it</a> click here and just put your phone number</p>
<p>Those are the results of hard work of all my very skilled staff (16 persons worked on this 6 projects for 3 different platforms) on challenging technologies (voice encryption) in a difficult operating environment (dirty mobile networks and dirty mobile operating systems) for more than 2 years.</p>
<p>I am very proud of our staff!</p>
<p><b>What next?</b></p>
<p>In next weeks you will see releasing of major set of documentations such as integration with asterisks, freeswitch and other Security Enabled PBX, along with some exciting other security technology news that i am sure will be noticed ;)</p>
<p>It has been an hard work and more have to be done but i am confident that the security and opensource community will like such products and our transparent approach also with open important releases and open source integration that make a very politically neutral (backdoor free) technology.</p>]]></content:encoded>
</item>
<item>
<title>A couple of nice VPN provider</title>
<link>https://infosecurity.ch/20101017/a-couple-of-nice-vpn-provider/</link>
<guid isPermaLink="true">https://infosecurity.ch/20101017/a-couple-of-nice-vpn-provider/</guid>
<pubDate>Sun, 17 Oct 2010 12:39:54 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>privacy</category>
<description>There are a lot of reason why one would need to access internet trough a VPN. For example if you live in a country blocking certain contents (like…</description>
<content:encoded><![CDATA[<p>There are a lot of reason why one would need to access internet trough a VPN.</p>
<p>For example if you live in a country blocking certain contents (like anti-local-government website, porn, etc) and/or protocols (like skype, voip) you would probably want to move your internet connectivity outside the nasty blocking country by using encrypted VPN tunnels.</p>
<p>I evaluated several hosted VPN server and a couple of them sounds quite good among the widespread offering of such services:</p>
<p><b><a href="http://www.swissvpn.net/">SwissVPN</a></b></p>
<p style="text-align: left;">Exit to the internet from Switzerland.</p>
<p style="text-align: left;">Cost 6 CHF / months</p>
<p style="text-align: left;">Optional public fixed IP address</p>
<p style="text-align: left;">Useful if you need:</p>
<p style="text-align: left;">
<ul>
<li>Just bypass local country filters with good high bandwidth</li>
<li>Expose public services trough the VPN with the optional fixed public IP address.</li>
</ul>
<p style="text-align: left;"><b><a href="https://www.overplay.net/">Overplay</a></b></p>
<p>Exit to the internet by choosing among 20 different countries (each time you connect).</p>
<p>Useful if you need to do:</p>
<ul>
<li>business intelligence on competitor (appearing to come from country X when connecting them)</li>
<li>see film/telefilm allowed only from national IP web spaces</li>
<li>see google results among different countries</li>
</ul>
<p></p>]]></content:encoded>
</item>
<item>
<title>Not every elliptic curve is the same: trough on ECC security</title>
<link>https://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/</guid>
<pubDate>Sun, 26 Sep 2010 13:05:34 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>voicesecurity</category>
<category>zrtp</category>
<description>My own ECC curve security and selection analysis Most modern crypto use Elliptic Curve Cryptographic (ECC) that, with a smaller key size and reduce…</description>
<content:encoded><![CDATA[<pre style="text-align: center; font-size: 15px;">
</pre>
<pre style="text-align: center; font-size: 15px;">
</pre>
<div style="display: inline !important;">
<pre style="text-align: center; font-size: 15px; display: inline !important;">
</pre>
<pre style="text-align: center; font-size: 15px;">
</pre>
<pre style="text-align: center; font-size: 15px;">
<font face="Helvetica"><span style="white-space: normal;"><b><font face="Helvetica"><font face="Helvetica" size="3"><font size="4"><font face="Helvetica"><font face="Helvetica"><span style="white-space: normal;"><b>My own ECC curve security and selection analysis</b></span></font></font></font></font></font></b></span></font>
</pre>
</div>
<p style="text-align: center;"><span style="font-size: 15px; white-space: pre;"><img src="https://infosecurity.ch/wp-content/uploads/2010/09/vn9jna1BdgrzDCYNBJHi09q09q.jpg" width="200" height="200" alt="vn9jna1BdgrzDCYNBJHi09q09q.jpg"/></span></p>
<p style="text-align: left;">Most modern crypto use Elliptic Curve Cryptographic (ECC) that, with a smaller key size and reduce computation power, give equivalent security strength of traditional crypto system known as DH (Diffie-Hellman) or RSA (<span style="visibility: visible;" id="search">Rivest, Shamir and Adleman</span>) .</p>
<p>Not everyone knows that ECC encryption is selected for any future encryption applications and that even TLS/SSL (encryption used for securing the web) is moving to ECC.</p>
<p>I found plenty of so called &#8220;proprietary encryption products&#8221; which abandoned RSA and DH to goes with ECC alternatives, that tend to arbitrary use ECC bit key size without even specifying which kind of ECC crypto get used.</p>
<p>However there is a <a href="http://www.thetechherald.com/article.php/200830/1573/Q&amp;A-with-Bill-Lattin-of-Certicom">lot of confusion around Elliptic Curves,</a> with a lot of different names and key size making difficult for a non-cryptographically-experienced-user to make your own figure when evaluating some crypto stuff.</p>
<p>Because of so diffused confusion i decided to make my own analysis to find out which are the best ECC encryption curves and right ECC key size to use.</p>
<p>This analysis would like to provide a security industry based choice among various curves and key sizes, leaving the mathematical and crypto analytical considerations that has been already been done during the years, summarizing the various choices taken in several standards and security protocols.</p>
<p>First the conclusion.</p>
<p>From my analysis <b>only the following ECC curves</b> are to be considered for use in encryption systems because are the only one selected among different authorities (ANSI, NSA, SAG, NIST, ECC BrainPool), different security protocol standards (IPSec, OpenPGP, ZRTP, Kerberos, SSL/TLS) and the only one matching NSA Suite B security requirements (de-facto standard also for NATO military environment):</p>
<ul>
<li><span style="font-family: Helvetica; white-space: normal;">Elliptic Prime Curve 256 bit - P-256</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">Elliptic Prime Curve 384 bit - P-384</span></li>
</ul>
<p>with optional, just for really paranoid that want to get more key size bit, still not considered useful:</p>
<ul>
<li><span style="font-family: Helvetica; white-space: normal;">Elliptic Prime Curve 521 bit - P-521</span></li>
</ul>
<p>I would like to state that <b>Koblitz curves should be avoided</b>, in any key size (163 / 283 / 409 / 571) as they does not have enough warranty on crypto analytic activity and effectively they are:</p>
<ul>
<li><span style="font-family: Helvetica; white-space: normal;">Not part of NSA Suite-B cryptography selection</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">Not part of ECC Brainpool selection</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">Not part of ANSI X9.62 selection</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">Not part of OpenPGP ECC extension selection</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">Not part of Kerberos extension for ECC curve selection</span></li>
</ul>
<p>I invite the reader to follow trough my analysis to understand the fundamentals that could be understood even without deep technical background but at least with a good technological background a some basic bit of cryptography.</p>
<pre style="text-align: center; font-size: 15px;">
</pre>
<pre style="text-align: center; font-size: 15px;">
</pre>
<div style="display: inline !important;">
<pre style="text-align: center; font-size: 15px; display: inline !important;">
<font face="Helvetica"><span style="white-space: normal;"><b><font face="Helvetica"><font face="Helvetica" size="3"><span style="font-size: 12px; white-space: normal;"><b><font size="4"><span style="font-size: 15px;">Here we go with the analysis</span></font></b></span></font></font></b></span></font>
</pre>
</div>
<pre style="text-align: center; font-size: 15px; display: inline !important;">
</pre>
<div style="display: inline !important;">
<pre style="text-align: center; font-size: 15px; display: inline !important;">
</pre>
<pre style="text-align: center; font-size: 15px; display: inline !important;">
</pre>
<pre style="text-align: center; font-size: 15px; display: inline !important;">
<span style="font-family: Helvetica; white-space: normal;"><b><font face="Helvetica"><font face="Helvetica" size="3"><font size="4"><font face="Helvetica"><span style="font-family: Helvetica;"> </span></font></font></font></font></b></span>
</pre>
</div>
<p><span style="font-family: Helvetica; white-space: normal;">My goal is to make an analysis on what/how the open scientific and security community choose ECC crypto system for usage in security protocols and standards defined by IETF RFC (the ones who define Internet Standards in a open and peer-reviewed way).</span></p>
<p><span style="font-family: Helvetica; white-space: normal;">Below a set of RFC introducing ECC into existing system that get analyzed to understand what’s better to use and what’s better to exclude:<br/></span></p>
<ul>
<li><span style="font-family: Helvetica; white-space: normal;"><span style="font-family: Helvetica; white-space: normal;"><a href="http://www.rfc-editor.org/rfc/rfc5639.txt">RFC5639</a>: ECC Brainpool Standard Curves & Curve Generation</span></span></li>
<li><span style="font-family: Helvetica; white-space: normal;"><a href="http://www.ietf.org/rfc/rfc4869.txt">RFC4869</a>: NSA Suite B Cryptographic Suites for IPsec</span></li>
<li><span style="font-family: Helvetica; white-space: normal;"><a href="http://www.ietf.org/rfc/rfc5430.txt">RFC5430</a>: NSA Suite B profile for Transport Layer Security (TLS)</span></li>
<li><span style="font-family: Helvetica; white-space: normal;"><a href="http://www.ietf.org/rfc/rfc5008.txt">RFC5008</a>: NSA Suite B in in Secure/Multipurpose Internet Mail Extensions (S/MIME)</span></li>
<li><span style="font-family: Helvetica; white-space: normal;"><a href="http://www.ietf.org/rfc/rfc3766.txt">RFC3766</a>: Determining Strengths For Public Keys Used For Exchanging Symmetric Keys</span></li>
<li><span style="font-family: Helvetica; white-space: normal;"><a href="http://www.ietf.org/rfc/rfc5349.txt">RFC5349</a>: Elliptic Curve Cryptography (ECC) Support for Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)</span></li>
<li><span style="font-family: Helvetica; white-space: normal;"><a href="http://www.ietf.org/rfc/rfc4492">RFC4492</a>: Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS)</span></li>
<li><span style="font-family: Helvetica; white-space: normal;"><a href="http://tools.ietf.org/html/draft-zimmermann-avt-zrtp">ZRTP voice encryption</a> by Philip Zimmermann ECC curve</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">ECC in OpenPGP (draft d<a href="http://tools.ietf.org/html/draft-jivsov-openpgp-ecc-06">raft-jivsov-openpgp-ecc-06</a>)</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">ECC Curves selected by Microsoft for <a href="http://technet.microsoft.com/en-us/library/ff404285%28WS.10%29.aspx">Smartcard Kerberos login</a></span></li>
</ul>
<p>We will use the choice made by scientist defining Internet Security Protocols to make part of our evaluation.<br/>
Additionally it must be understood that the <b>Curve selection comes from different authorities</b> that made their own selection of Curves in order to tell to the industry what to use and what to skip:</p>
<ul>
<li><span style="font-family: Helvetica; white-space: normal;">US <a href="http://www.nist.gov/">NIST</a> (US National Institute of Standards) with <a href="http://csrc.nist.gov/publications/fips/archive/fips186-2/fips186-2.pdf">186-2</a> (recently superseded in 2009 by the new <a href="http://csrc.nist.gov/publications/fips/fips186-3/fips_186-3.pdf">186-3</a>)</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">US <a href="http://www.ansi.org/">ANSI</a> (American National Standard Institute) with <a href="http://webstore.ansi.org/RecordDetail.aspx?sku=ANSI+X9.62%3A2005">X9.62</a></span></li>
<li><span style="font-family: Helvetica; white-space: normal;">US <a href="http://www.nsa.gov/">NSA</a> (National Security Agency) <a href="http://www.nsa.gov/ia/programs/suiteb_cryptography/">Suite-B Cryptography</a> for <a href="http://en.wikipedia.org/wiki/Security_clearance#Top_Secret">TOP SECRET</a> information exchange</span></li>
<li><span style="font-family: Helvetica; white-space: normal;">International <a href="http://www.secg.org/">SACG</a> (Standards for efficient cryptography group) with <a href="http://docs.google.com/viewer?url=www.secg.org/collateral/sec2_final.pdf">Recommended Elliptic Curve Domain Parameters</a></span></li>
<li><span style="font-family: Helvetica; white-space: normal;">German <a href="http://www.ecc-brainpool.org/">ECC Brainpool</a> withECC Brainpool with their <a href="http://docs.google.com/viewer?url=http://www.ecc-brainpool.org/download/Domain-parameters.pdf">Strict Security Requirements</a></span></li>
<li><a href="http://docs.google.com/viewer?url=www.filibeto.org/~aduritz/truetrue/solaris10/security/crypto/ecc/rsa-ecc-rev8.pdf">ECC Interoperability Forum</a> composed by Certicom, Microsoft, Redhat, Sun, NSA</li>
</ul>
<p>We will use the choice made by scientist defining security requirements in the standardization agencies to make part of our evaluation.<br/>
Additionally, something that most people does not know, but that it’s extremely relevant to our analysis, is that there are different kind of ECC curve cryptography and their &#8220;size&#8221; it’s different depending on the kind of curve:</p>
<ul>
<li><span style="font-family: Helvetica; white-space: normal;"><span style="font-family: Helvetica; white-space: normal;">ECC Curves over Prime Field (often referred as <b>Elliptic Curve</b> and represented by <b>P-keysize</b>)</span></span></li>
<li><span style="font-family: Helvetica; white-space: normal;">ECC Curves over Binary Field (often referred as <b>Koblitz Curve</b> and represented by <b>K-keysize</b>)</span></li>
</ul>
<p>Given a <b>security strength equivalence</b> the Elliptic Curve and the Kobliz Curve have different key size, for example when we read ECC 571 we are referring to Koblitz Curve with an equivalent strength to ECC 521 Prime curve.</p>
<p>A comparison of strength between Elliptic Curves and Kotbliz Curves is reported below (from <a href="http://tools.ietf.org/html/draft-ietf-msec-mikey-ecc">Mikey ECC internet Draft</a>):</p>
<pre class="newpage">
| Koblitz |  ECC  |  DH/DSA/RSA
|   163   |  192  |     1024
|   283   |  256  |     3072
|   409   |  384  |     7680
|   571   |  521  |    15360
</pre>
<p>Below there’s a comparison of all selected curves by all the various entities and their respective name (from <a href="http://www.ietf.org/rfc/rfc4492">IETF RFC4492 for ECC usage for TLS</a>) :</p>
<pre>
Curve names chosen by different standards organizations
------------+---------------+-------------
SECG        |  ANSI X9.62   |  NIST
------------+---------------+-------------
sect163k1   |               |   NIST K-163
sect163r1   |               |
sect163r2   |               |   NIST B-163
sect193r1   |               |
sect193r2   |               |
sect233k1   |               |   NIST K-233
sect233r1   |               |   NIST B-233
sect239k1   |               |
sect283k1   |               |   NIST K-283
sect283r1   |               |   NIST B-283
sect409k1   |               |   NIST K-409
sect409r1   |               |   NIST B-409
sect571k1   |               |   NIST K-571
sect571r1   |               |   NIST B-571
secp160k1   |               |
secp160r1   |               |
secp160r2   |               |
secp192k1   |               |
secp192r1   |  prime192v1   |   NIST P-192
secp224k1   |               |
secp224r1   |               |   NIST P-224
secp256k1   |               |
secp256r1   |  prime256v1   |   NIST P-256
secp384r1   |               |   NIST P-384
secp521r1   |               |   NIST P-521
------------+---------------+-------------
</pre>
<p>What immediately appear is that there are only two curves selected by all authorities, and that there is a general dumping of koblitz curves by ANSI.The only commonly agreed among the 3 authorities are the following two ECC curve:</p>
<ul>
<li><span style="font-family: Helvetica; white-space: normal;"><span style="font-family: monospace; white-space: pre;">secp192r1 / prime192v1 /</span> NIST P-192</span></li>
<li><span style="font-family: monospace; white-space: pre;">secp256r1 / prime256v1 /</span> NIST P-256</li>
</ul>
<p>Of those selection of ECC curve for TLS the <a href="http://www.ietf.org/rfc/rfc5430.txt">RFC5430</a> skipped completely koblitz curves and selected for usage only:</p>
<ul>
<li>P-256, P-384, P-521</li>
</ul>
<p>The <a href="http://www.ecc-brainpool.org/">ECC Brainpool</a> skipped completely Koblitz curves and selected for usage the following ECC Curves:</p>
<ul>
<li>P-160, P-192, P-224, P-256, P-320, P-384, P-512 (<b>that’s the only particular because it’s not P-521 but P-512, the only key-size referred by ECC brainpool. Tnx Ian Simons from <a href="http://athena-scs.com/">Athena SCS</a>)</b></li>
</ul>
<p>The OpenPGP internet draft for ECC usage in PGP d<a href="http://tools.ietf.org/html/draft-jivsov-openpgp-ecc-06">raft-jivsov-openpgp-ecc-06</a> skipped completely Koblitz curves and selected the following ECC curves</p>
<ul>
<li>P-256, P-384, P-521</li>
</ul>
<p>The Kerberos protocol extension for ECC use, defined in <a href="http://www.faqs.org/rfcs/rfc5349.html">RFC5349</a> and defined by Microsoft for <a href="http://technet.microsoft.com/en-us/library/ff404285%28WS.10%29.aspx">smartcard logon</a> skipped completely Koblitz curves and selected the following ECC curves:</p>
<ul>
<li>P-256, P-384, P-521</li>
</ul>
<p>So, sounds clear that the right selection of ECC is for P-256, P-384 and P-521 while the Koblitz curve have been skipped for Top Secret use and for any security sensitive protocol (IPSec, OpenPGP, ZRTP, Kerberos, SSL/TLS).</p>
<div style="text-align: center;">
  <b>Why i made this analysis?</b>
</div>
<p>I have done this analysis following a discussion i had regarding certain voice encryption products, all based on custom and proprietary protocols, that are all using Elliptic Curve Diffie Hellman 571 bit / ECDH 571 / 571-bit ECDH / Koblitz 571 bits .<br/>
All them are using the K-571 that, as described before, has been removed from all security sensitive environment and protocols and being myself a designer of voice encryption stuff i think that their cryptographic choice is absolutely not the best security choice.<br/>
Probably it has been done just for marketing purpose, because K-571 (Koblitz curve) seems stronger than P-521 (Elliptic curve based on Prime number). If you have &#8220;more bit&#8221; your marketing guys can claim to be &#8220;more secure&#8221;. Koblitz elliptic curve are faster than the top secret enabled prime elliptic curve and so give the product manager a chance to provide &#8220;more bit&#8221; in it’s own product while keeping the key exchange fast.</p>
<p>It’s a matter of philosophical choice.</p>
<p>I prefer to follow the trend of scientific community with the humility of not to considering myself a cryptographic expert, knowledgable more than the overall security and scientific community itself.</p>
<p>I prefer instead to use only algorithms that are approved for use in highly sensitive environments (top secret classification), that have been selected by all the authorities and working group analyzing encryption algorithms existing out-there and that represent the choice of almost all standard security protocols (IPSec, OpenPGP, ZRTP, Kerberos, SSL/TLS, etc).<br/>
I prefer to count the amount of brains working on the crypto i use, that check that’s really secure, that evaluate whether there’s some weakness.</p>
<p>The number of brais working on Crypto widely diffused are of order of magnitude more than the number of brains working on crypto used by just few people (like Koblitz curve).<br/>
So i am not demonizing who use ECDH 571 using Koblitz Curve, but for sure i can affirm that they did not taken the best choice in terms of security and that any security professionals doing a security benchmarking would consider the fact that Elliptic Curve Diffie Hellman 571 bit done with Koblitz Curve is not widely diffused, it’s dumped from standard security protocols and it’s not certified for top secret use.</p>]]></content:encoded>
</item>
<item>
<title>ESSOR, European Secure Software Defined Radio (SDR)</title>
<link>https://infosecurity.ch/20100925/essor-european-secure-software-defined-radio-sdr/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100925/essor-european-secure-software-defined-radio-sdr/</guid>
<pubDate>Sat, 25 Sep 2010 21:18:06 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>hacking</category>
<category>mobile</category>
<description>I had a look at European Defense Agency website and found the ESSOR project, a working project funded for 106mln EUR to develop strategic defense…</description>
<content:encoded><![CDATA[<p>I had a look at <a href="http://www.eda.europa.eu/">European Defense Agency</a> website and found the <a href="http://www.eda.europa.eu/genericitem.aspx?Area=Organisation&amp;ID=593">ESSOR</a> project, a working project funded for 106mln EUR to develop strategic defense communication products based on new <a href="http://en.wikipedia.org/wiki/Software-defined_radio">Software Defined Radio</a> approach.</p>
<p>SDR approach is a revolutionary system that’s completely changing the way scientist and industry is approach any kind of wireless technology.</p>
<p>Basically instead of burning hardware chip that implement most of the radio frequency protocols and techniques, they are pushed in &#8220;software&#8221; to specialized radio hardware that can work on a lot of different frequency, acting as radio interface for a lot of different radio protocols.</p>
<p>For example the USRP (Universal Software Radio Peripheral) from <a href="http://www.ettus.com/">Ettus Research</a> that cost 1000-2000USD fully loaded, trough the opensource <a href="http://gnuradio.org/">GnuRadio</a> framework, have seen opensource implementation of:</p>
<ul>
<li><a href="http://openbts.sf.net/">GSM</a></li>
<li><a href="http://sourceforge.net/projects/gr-bluetooth/">Bluetooth</a></li>
<li><a href="http://docs.google.com/viewer?url=userver.ftw.at%2F~zemen%2Fpapers%2FFuxjaeger10-WSR-paper.pdf">WiFi</a>&nbsp;&nbsp;</li>
</ul>
<p>And a lot more protocols and transmission technologies.</p>
<p>That kind of new approach to Radio Transmission System is destinated to change the way radio system are implemented, giving new capability such as to upgrade the &#8220;radio protocol itself&#8221; in software in order to provide &#8220;radio protocol&#8221; improvements.</p>
<p>In the short terms we have also seen very strong security research using SDR technologies such as the <a href="https://svn.berlin.ccc.de/projects/airprobe/">GSM cracking</a> and the <a href="http://www.usenix.org/event/woot07/tech/full_papers/spill/spill_html/">Bluetooth Sniffing</a>.</p>
<p>We can expect that other technologies, weak by design but protected by the restriction to hardware devices to hack the low level protocols, will be soon get hacked. In the first list i would really like to see the hacking of TETRA, a technology born with closed mindset and secret encryption algorithms, something i really dislike ;-)</p>]]></content:encoded>
</item>
<item>
<title>Product management and organization</title>
<link>https://infosecurity.ch/20100912/product-management-and-organization/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100912/product-management-and-organization/</guid>
<pubDate>Sun, 12 Sep 2010 20:52:44 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>business</category>
<category>management</category>
<category>marketing</category>
<description>I had to better understand the concepts, roles and duties related to Product management and Product marketing management in software companies, why are…</description>
<content:encoded><![CDATA[<p>I had to better understand the concepts, roles and duties related to Product management and Product marketing management in software companies, why are needed, which are the differences and how they fit inside an organization structure.</p>
<p>Most person i know never interested into this specific area of work, but when you want to be a product company (and not a consulting or solution company), you start having different products on different platforms for different target customers sold trough different channels with different pricing with a installation/different delivery process and that complexity must be managed in the proper way.</p>
<p>You realize that in order to let the product company grow in the right direction you need to organize product management activities formally, not closing your mind in rigid organization roles such as Marketing, Sales, R&D.</p>
<p>When we speak about Product Management i recommend the reading of the illuminating <a href="https://docs.google.com/viewer?url=http://www.pragmaticmarketing.com/strategic-role-of-product-management/Strategic_Role_Product_Management.pdf">The strategic role of Product Management</a> (How a market-driven focus leads companies to build products people want to buy) that clarify a lot of things, even if it outlook net separation of roles in product management, something t<i>hat’s too heavy for a small company like a startup</i>.</p>
<p>Still it provide a differentiation of duties between <b>Product Management</b> and <b>Product Marketing</b>.</p>
<p>A good understanding of the <i>product management related to startup i</i>s given in the article <a href="http://www.pragmaticmarketing.com/publications/topics/05/0502jm2">Creating Product Management at Startup</a> showing up different case related to the roles of the <b>product visionary</b> into the company.</p>
<p>It introduce the terms ceo of the product in the sense that the product management duties jump around into the various organization function by providing focus and effort where it’s needed, independently from the fact that the internal function requiring more effort is Development, Marketing, Sales or Communication. That’s means practically enhancing the product vision as it’s needed across all major product-related functions making the vision corporate-wide coherent.</p>
<p>A good representation of product management and product marketing activities is well described with the differentiation of between <b>Strategical, Technical</b> and <b>Marketing</b> sector and is not clearly separated between Management, Marketing(and Sales) and R&D :</p>
<div style="text-align: center;">
  <img src="https://infosecurity.ch/wp-content/uploads/2010/09/Triad.jpg" width="398" height="298" alt="Triad.jpg"/>
</div>
<p>I read that product manager background and knowledge are different depending on the company focus (<a href="http://www.pragmaticmarketing.com/publications/topics/07/where-does-product-management-belong-in-the-organization">where does product management belong in the organization?</a>):</p>
<ul>
<li>B2C -&gt; Marketing experience</li>
<li>B2B -&gt; Technical experience</li>
</ul>
<p>An <b>illuminating (for me) and very important differentiation</b> regarding product management duties is the differentiation between:</p>
<ul>
<li><b>Product Management</b></li>
<li><b>Product Marketing</b></li>
</ul>
<p>The specific duties belonging to <b>Product</b> <b>Marketing vs Management</b> are greatly explained in <a href="http://docs.google.com/viewer?url=www.toolsforproductmanagement.com/PM_PMMRoles.doc">Role Definitions For Product Management and Product Marketing</a> that i suggest to read, letting you to better define tasks and responsibilities across your organization. It also provide a good definition of job requirements if you need to look for that figure!</p>
<p>At the same time it’s important to understand what’s NOT product management, effectively <a href="http://onproductmanagement.wordpress.com/2007/11/17/prioritizing-features-does-not-equal-product-management/">Product management is not just feature prioritization</a>.</p>
<p>At the same time it’s important to understand which professional figure is NOT itself a product manager:</p>
<ul>
<li><b>Product manager is not a marketing manager</b> – while product management is usually seen as a marketing discipline, marketers are focused on the marketing plan and are usually not driving the overall product direction. In that context could however be found <b>Product marketing manager</b> that’s the arms of the marketing of the product, especially in small organization.</li>
</ul>
<ul>
<li><b>Product manager is</b> <b>not a sales manager</b> - sales manager are about finding out how to sell a product, following which sales methodology, technique and channels and they could drive the company from a market oriented company (<b>product)</b> to a customer oriented company <b>(solution and consulting)</b></li>
</ul>
<ul>
<li><b>Product manager is not a developer</b> – Developers are focused on the technology and not the overall product. Some great product managers are former developers, but it is difficult to do both at once. There is a natural tension between developers and product managers that should be maintained to create a balanced product.</li>
<li><b>Product manager is not a software manager</b> – the software manager is a functional manager and usually not focused on the product or the customers.</li>
<li><b>Product manager is</b> <b>not a project manager</b> – project managers are about how and when, while the product manager is about what. Project managers work closely with product managers to ensure successful completion of different phases in the product life cycle.</li>
</ul>
<p>The typical product management activities could be in extreme synthesis summarized as follow:</p>
<ul>
<li>Strategy: Planning a product strategy</li>
<li>Technical: leading product developments</li>
<li>Marketing: providing product and technical content</li>
<li>Sales: provide pre sales support and <a href="http://www.goodproductmanager.com/2008/03/06/work-effectively-with-sales/">work effectively with sales</a></li>
</ul>
<p>Product management so it’s not precisely development, is not precisely marketing, it’s not precisely sales, so typically it’s difficult to identify &#8220;where it should stay&#8221; inside the organization structure (it’s even difficult to understand that’s needed)?</p>
<p>The Silicon Valley Product Group provide a nice insight on <a href="http://www.svproduct.com/product-organizational-structure/">Product Organization Structure</a> by pointing out which are the advantages and risks of several choices. Still the Cranky Product Manager say that <a href="http://crankypm.com/2008/12/where-product-manager-resides-organization/">It doesn’t matter where the product manager live in the organization</a>.</p>
<p>It’s relevant to be careful not to have persons that are too much technical or too much sales oriented in order to fill the gap among different organization. Too much fragmentation of assigned duties across the organization may lead to bureaucracy, too much duties on one person may lead to ineffective implementation of needed tasks in some area and to a internal competition perception respect to the traditional roles.</p>
<p>Check there <a href="http://alsargent.com/">a very nice Resume</a> of a professional with practical experience in product management (it’s an half techie/half marketing guys).</p>
<p>Ah! Another very common misunderstanding is to <b>confuse</b> <b>marketing with communication</b> where a i found a so good definition of Marketing that i really like and understand for strict relationship with Product Management:</p>
<p style="text-align: center;">
<blockquote>
<p style="text-align: center;">Marketing is know the market so well that the product sell itself</p>
</blockquote>
<p>But what happen when you don’t handle a product management and product marketing management process in a defined way?</p>
<p>A nice story is shown as example in <a href="https://docs.google.com/viewer?url=http://www.pragmaticmarketing.com/strategic-role-of-product-management/Strategic_Role_Product_Management.pdf">The strategic role of Product Management</a> :</p>
<p style="text-align: justify;">
<blockquote>
<p>Your founder, a brilliant technician, started the company years ago when he quit his day job to market his idea full time. He created a product that he just knew other people needed. And he was right. Pretty soon he delivered enough of the product and hired his best friend from college as VP of Sales. And the company grew. But before long, the VP of Sales complained, “We’re an engineering-led company. We need to become customer-driven.” And that sounded fine. Except… every new contract seemed to require custom work. You signed a dozen clients in a dozen market segments and the latest customer’s voice always dominated the product plans. You concluded that “customer-driven” meant “driven by the latest customer” and that couldn’t be right.</p>
</blockquote>
<p>If you want to be a product company it’s relevant to precisely <b>follow a strategy driven by product marketing and management and not by sales.</b></p>
<p>Confusion between duties of product management/marketing and sales could lead to unsuccessful product company that are not able to proceed within their strategy, simply because they getting opportunities that drive the business out-of-scope.</p>
<p>A product company must invest in it’s own product development and marketing in order to let sales activity stay focused and guarantee that the organization is every day more effective on the market.</p>
<p>After this reading, my understanding is that it’s relevant to identify how to create a set of flexible business process on how to handle various product management and product marketing duties separating them from sales.</p>]]></content:encoded>
</item>
<item>
<title>Remotely intercepting snom VoIP phones</title>
<link>https://infosecurity.ch/20100910/remotely-intercepting-snom-voip-phones/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100910/remotely-intercepting-snom-voip-phones/</guid>
<pubDate>Fri, 10 Sep 2010 11:08:42 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>hacking</category>
<category>privacy</category>
<category>voicesecurity</category>
<description>I suggest reading remotely tapping VoIp phones ” on VoIP Security Alliance Blog by Shawn Merdinger . A concrete example on how current telephony…</description>
<content:encoded><![CDATA[<p>I suggest reading <a href="http://voipsa.org/blog/2010/09/07/its-a-feature-remote-tapping-a-snom-voip-phone/">remotely tapping VoIp phones</a>&#8221; on <a href="http://voipsa.org/">VoIP Security Alliance</a> Blog by <a href="http://www.linkedin.com/profile/view?id=18379882">Shawn Merdinger</a> .</p>
<p>A concrete example on how current telephony infrastructure are getting more vulnerable to cyber attacks.</p>]]></content:encoded>
</item>
<item>
<title>Voice communication security workshop</title>
<link>https://infosecurity.ch/20100826/voice-communication-security-workshop/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100826/voice-communication-security-workshop/</guid>
<pubDate>Thu, 26 Aug 2010 12:04:41 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>mobile</category>
<category>privacy</category>
<category>voicesecurity</category>
<description>Hi, i made a talk about voice communication security technologies at University of Trento following an interesting information exchange with Crypto Lab…</description>
<content:encoded><![CDATA[<p>Hi,</p>
<p>i made a talk about voice communication security technologies at University of Trento following an interesting information exchange with <a href="http://www.science.unitn.it/~sala/lab/index.html">Crypto Lab</a> managed Professor <a href="http://www.science.unitn.it/~sala/">Massimiliano Sala</a> .</p>
<p>I suggest interested people to read it, especially the second part, as there is an innovative categorization of the various voice encryption technologies that get used in several sectors.</p>
<p>I tried to explain and get out from this widely fragmented technological sector by providing a wide overview on technologies that usually are absolutely unrelated one-each-other but practically they all apply to <b>voice encryption</b> following that categorization:</p>
<ul>
<li>Mobile TLC Industry voice encryption standards</li>
<li>Government and Military voice encryption standards</li>
<li>Public safety voice encryption standards</li>
<li>IETF voice encryption standards</li>
<li>Misc proprietary voice encryption technologies</li>
</ul>
<p>It’s a huge slideware, 122 slides, i suggest to go reading the 2nd part skipping interception technologies overview already covered by my presentation of 2009.</p>
<p><strong style="display: inline !important; margin-top: 12px; margin-right: 0px; margin-bottom: 4px; margin-left: 0px;"><a href="http://www.slideshare.net/fpietrosanti/voice-communication-security" title="Voice communication security">Voice communication security</a></strong></p>
<div style="width:425px" id="__ss_5059251">
  <object id="__sse5059251" width="425" height="355"><param name="movie" value="https://static.slidesharecdn.com/swf/ssplayer2.swf?doc=voicecommunicationsecurity-unitn-100826053447-phpapp01&amp;stripped_title=voice-communication-security"/><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed name="__sse5059251" src="https://infosecurity.ch/swf/ssplayer2_doc-voicecommunicationsecurity-unitn-100826053447-phpapp01-stripped_title-voice-communication-security.swf" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"/></object></p>
<div style="padding:5px 0 12px">
    View more <a href="http://www.slideshare.net/">presentations</a> from <a href="http://www.slideshare.net/fpietrosanti">Fabio Pietrosanti</a>.
  </div>
</div>
<p>Especially i like the concept of <b>Chocolate grade encryption</b> that want to provide some innovation on the <b>Snake Oil Encryption</b> concept.</p>
<p>But i need to get more in depth about the Chocolate grade encryption context, will probably do before end-of-year by providing an applied course on understanding and evaluating <b>practically</b> the <b>real security context</b> of various voice encryption technologies.</p>]]></content:encoded>
</item>
<item>
<title>27C3 - CCC Congress CFP: We come in peace</title>
<link>https://infosecurity.ch/20100815/27c3-ccc-congress-cfp-we-come-in-peace/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100815/27c3-ccc-congress-cfp-we-come-in-peace/</guid>
<pubDate>Sun, 15 Aug 2010 08:39:47 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>hacking</category>
<description>We come in peace We come in peace, said the conquerers of the New World. We come in peace, says the government, when it comes to colonise, regulate, and…</description>
<content:encoded><![CDATA[<p style="text-align: center;"><b>We come in peace</b></p>
<p style="text-align: center;"><img src="https://infosecurity.ch/wp-content/uploads/2010/08/189322778_8cb9af1365_m.jpg" width="240" height="216" alt="189322778_8cb9af1365_m.jpg"/></p>
<p style="text-align: center;">
<p style="text-align: center;">We come in peace, said the conquerers of the New World.</p>
<p style="text-align: center;">We come in peace, says the government, when it comes to colonise, regulate, and militarise the new digital world.</p>
<p style="text-align: center;">We come in peace, say the nation-state sized companies that have set out to monetise the net and chain the users to their shiny new devices.</p>
<p style="text-align: center;">We come in peace, we say as hackers, geeks and nerds, when we set out towards the real world and try to change it, because it has intruded into our natural habitat, the cyberspace&#8230;</p>
<p style="text-align: center;"></p>
<p>Call for paper for participation to <a href="http://events.ccc.de/2010/07/30/27c3-we-come-in-peace-call-for-participation/">27C3 CCC congress</a> is open, and i never saw a so exciting payoff :-)</p>
<p>See you on 30 December 2010 in Berlin!</p>]]></content:encoded>
</item>
<item>
<title>GSM cracking in penetration test methodologies (OSSTMM) ?</title>
<link>https://infosecurity.ch/20100723/gsm-cracking-in-penetration-test-methodologies-osstmm/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100723/gsm-cracking-in-penetration-test-methodologies-osstmm/</guid>
<pubDate>Fri, 23 Jul 2010 08:16:30 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>hacking</category>
<category>privacy</category>
<category>voicesecurity</category>
<description>As most of this blog reader already know, in past years there was a lot of activities related to public research for GSM auditing and cracking. However when…</description>
<content:encoded><![CDATA[<p>As most of this blog reader already know, in past years there was a lot of activities related to <b>public research</b> for GSM auditing and cracking.</p>
<p>However when there was huge media coverage to GSM cracking research results, the <b>tools to make the cracking</b> was really early stage and still very inefficient.</p>
<p>Now <b><a href="http://en.wikipedia.org/wiki/Frank_A._Stevenson">Frank Stevenson</a></b> , norwegian cryptanalyst that already broke the <a href="http://en.wikipedia.org/wiki/DeCSS">Content Scrambling System</a> of DVD video disc, participating to the A51 cracking project started by <a href="http://www.cs.virginia.edu/~kn5f/">Karsten Nohl</a>, released <b><a href="http://lists.lists.reflextor.com/pipermail/a51/2010-July/000683.html">Kraken</a></b> , a new improved version of the A51 cracking system.</p>
<p>It’s interesting to notice that WiFi cracking had a similar story, as the first WiFi wep cracking discovery was quite slow in earlier techniques but later Korek, an hacker working on cracking code, improve the attack system drammatically.</p>
<p>That’s the story of security research cooperation, you start a research, someone follow it and improve it, some other follow it and improved it and at the end you get the result.</p>
<p>Read more on the <a href="http://www.computerworld.com/s/article/9179529/New_Kraken_GSM_cracking_software_is_released?taxonomyId=16">Kraken GSM Cracking software release</a>.</p>
<p>And stay tuned as next week at Blackhat Conference Karsten Nohl will explain the details of the required <b><a href="http://lists.lists.reflextor.com/pipermail/a51/2010-July/000694.html">hardware setup and detailed instructions on how to do it</a> :-)</b></p>
<p>I would really like to see those tools incorporated into <a href="http://www.backtrack-linux.org/">Penetration Testing Linux Distribution BackTrack</a> with <a href="http://www.isecom.org/osstmm/">OSSTMM</a> methodology enforcing the testing of GSM interception and man in the middle :-)</p>
<p>If things proceed that way and <a href="http://www.ettus.com/">Ettus Research</a> (The producer of USRP2 software radio used for low cost GSM signal receiving) will not be taken down, we can still see this.</p>]]></content:encoded>
</item>
<item>
<title>Snake-oil security claims on crypto security product</title>
<link>https://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/</guid>
<pubDate>Mon, 19 Jul 2010 21:33:54 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>business</category>
<category>encryption</category>
<category>management</category>
<category>marketing</category>
<category>policy</category>
<category>privacy</category>
<category>voicesecurity</category>
<description>Security market grow, more companies goes to the market, but how many of them are taking seriously what they do? You know, doing security technology mean…</description>
<content:encoded><![CDATA[<p>Security market grow, more companies goes to the market, but how many of them are taking seriously what they do?</p>
<p>You know, doing security technology mean that <b>you are personally responsible</b> for the protection of the user’s information. You must make them aware of what they need, exactly what your are doing and which kind of threat model your product protect.</p>
<p>A typical problem of product’s security features is represented by the inability of the user to evaluate the security claims of the product itself.</p>
<p>So there’s a lot companies doing a not-so-ethical marketing of security features, based on the facts that no user will be able to evaluate it.</p>
<p>The previously explained situation reside in the security topic of <b>Snake Oil Encryption</b>, an evolution in the scientific cryptographic environment that let us today use best of breed information protection technologies without having to worry too much about backdoors or insecurities.</p>
<p><b>Let’s speak about Snake Oil Encryption</b></p>
<p><a href="http://en.wikipedia.org/wiki/Snake_oil_%28cryptography%29">Snake Oil Cryptography</a> : In <a href="http://en.wikipedia.org/wiki/Cryptography" title="Cryptography">cryptography</a>, <b>snake oil</b> is a term used to describe commercial cryptographic methods and products which are considered bogus or fraudulent. Distinguishing secure cryptography from insecure cryptography can be difficult from the viewpoint of a user. Many cryptographers, such as <a href="http://en.wikipedia.org/wiki/Bruce_Schneier" title="Bruce Schneier">Bruce Schneier</a> and <a href="http://en.wikipedia.org/wiki/Phil_Zimmermann" title="Phil Zimmermann">Phil Zimmermann</a>, undertake to educate the public in how secure cryptography is done, as well as highlighting the misleading marketing of some cryptographic products.</p>
<p><b><span style="font-weight: normal;">The most referenced crypto security guru, Philip Zimmermann and Bruce Schneier, was the 1st to talk about Snake Oil Encryption:</span></b></p>
<p><b><span style="font-weight: normal;"><a href="http://www.philzimmermann.com/EN/essays/SnakeOil.html">Snake Oil</a> by Philip Zimmermann</span></b></p>
<p><b><span style="font-weight: normal;"><a href="http://www.schneier.com/crypto-gram-9902.html#snakeoil">Snake Oil</a> by Bruce Schneier</span></b></p>
<p style="text-align: left;">The <a href="http://www.mttlr.org/html/articles.html">Michigan Telecommunications and Technology Law Review</a> also made a very good analysis related to the Security Features of Security Products, <b><a href="http://www.mttlr.org/volnine/michener.pdf">SNAKE-OIL SECURITY CLAIMS” THE SYSTEMATIC MISREPRESENTATION OF PRODUCT SECURITY</a> .</b> They explain about the nasty marketing tricks used to tweak users inability to evaluate the security features, including economic and legal responsibility implication.</p>
<p style="text-align: left;"><b><span style="font-weight: normal;">Several</span> snake oil security product companies <span style="font-weight: normal;">does not explain and are not clear about the threat model to which the product apply.</span></b> Very famous is the sentence of <a href="http://russnelson.com/bio.html">Russ Nelson</a>:</p>
<blockquote><p>
  <i>&#8220;Remember, crypto without a threat model is like cookies without milk. &#8230;.. Cryptography without a threat model is like motherhood without apple pie. Can’t say that enough times. More generally, security without a threat model is by definition going to fail.&#8221;</i>
</p></blockquote>
<p style="text-align: center;"><b>So, how to spot snake oil security products?</b></p>
<p>Check a guideline of to spot Snake Oil Encryption Products: <a href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html">Snake Oil Warning Signs, Encryption Software to Avoid</a> by <a href="http://web.interhack.com/company/people/cmcurtin">Matt Curtin</a> .</p>
<p>You can see this very good <a href="http://www.ratliff.net/blog/2009/05/27/cryptographic-snake-oil/">Cryptographic Snake Oil Examples</a> by Emility Ratliff (IBM Architect at Linux Security), that tried to make clear example on how to spot Cryptographic Snake Oil.</p>
<p>Here represented the basic guideline from <a href="http://web.interhack.com/company/people/cmcurtin">Matt Curtin</a> paper:</p>
<ul>
<li><b><span style="font-weight: normal;">Companies that claim <a name="tex2html42" href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html#SECTION00051000000000000000" id="tex2html42">Trust Us, We Know What We’re Doing’</a></span></b></li>
<li><b><span style="font-weight: normal;">Companies that invent new technology terms without even explaining the innovation, called <a name="tex2html43" href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html#SECTION00052000000000000000" id="tex2html43">Technobabble</a></span></b></li>
<li><b><span style="font-weight: normal;">Product that use non public protocols along with proprietary and <a name="tex2html44" href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html#SECTION00053000000000000000" id="tex2html44">Secret Algorithms</a></span></b></li>
<li><b><span style="font-weight: normal;">Company that pretend to have invented new type of cryptography or a <a name="tex2html45" href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html#SECTION00054000000000000000" id="tex2html45">Revolutionary Breakthroughs</a></span></b></li>
<li><b><span style="font-weight: normal;">Companies that present <a href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html#SECTION00055000000000000000">Useless Certification and supposed Independent Evaluation without any security value</a></span></b></li>
<li><b><span style="font-weight: normal;">Product that claim to be <a href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html#SECTION00056000000000000000">Unbreakabl</a>e</span></b></li>
<li><b><span style="font-weight: normal;">Companies that <a href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html#SECTION00058000000000000000">claim other products are insecure with fake and artificial evidence</a></span></b></li>
<li><b><span style="font-weight: normal;">Companies that claim their system is <a name="tex2html52" href="http://www.interhack.net/people/cmcurtin/snake-oil-faq.html#SECTION000511000000000000000" id="tex2html52">Military Grade</a>, while everyone know that today cryptography in civil sector is driving the innovation</span></b></li>
<li><b><span style="font-weight: normal;">Product that have <a href="http://en.wikipedia.org/wiki/Snake_oil_%28cryptography%29">Unsubstantiated bit claims</a> (like 16384 bit or 46080 bit encryption and authentication of sessions)</span></b></li>
</ul>
<p><b><br/></b><b><span style="font-weight: normal;">By checking that points it’s possible to evaluate how serious an encryption technology or product is.</span></b></p>
<p style="text-align: center;"><b><span style="font-weight: normal;"><b>But all in all how to fix that unethical security approach?</b><br/></span></b></p>
<p>It’s very significative and it would be really useful for each kind of security product category to make some strongly and independent evaluation guideline (like <a href="http://www.isecom.org/">OSSTMM</a> for Penetration testing) , to make this security evaluation process really in the hands of the user.</p>
<p>It would be also very nice to have someone making analysis and evaluation of security product companies, publishing reports about Snake Oil signs.</p>]]></content:encoded>
</item>
<item>
<title>Web2.0 privacy leak in Mobile apps</title>
<link>https://infosecurity.ch/20100717/web2-0-privacy-leak-in-mobile-apps/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100717/web2-0-privacy-leak-in-mobile-apps/</guid>
<pubDate>Sat, 17 Jul 2010 09:02:59 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>hacking</category>
<category>mobile</category>
<category>policy</category>
<category>privacy</category>
<description>You know that web2.0 world it’s plenty of leak of any kind (profiling, profiling, profiling) related to Privacy and users starts being concerned about it…</description>
<content:encoded><![CDATA[<p>You know that web2.0 world it’s plenty of leak of any kind (profiling, profiling, profiling) related to Privacy and users starts <a href="http://www.bit-tech.net/columns/2006/06/03/web_2_privacy/">being concerned</a> about it.</p>
<p>Users continuously download applications without knowing the details of what they do, for example <a href="http://ifartmobile.com/ifart-top-20-paid-app/">iFart</a> just because are cool, are fun and sometime are useful.</p>
<p></p>
<div style="text-align: center;">
</div>
<p>On mobile phones users install from 1000% up to 10.000% more applications than on a PC, and those apps <a href="http://news.cnet.com/8301-27080_3-10446402-245.html">may contain malware</a> or other unexpected functionalities.</p>
<p>Recently infobyte analyzed <a href="http://www.ubertwitter.com/">ubertwitter client</a> and discovered that the client was leaking and sending to their server many personal and sensitive data such as:</p>
<p>- Blackberry PIN</p>
<p>- Phone Number</p>
<p>- Email Address</p>
<p>- Geographic positioning information</p>
<p>Read about UbertTwitter <a href="http://blog.infobytesec.com/2010/07/ubertwitter-your-secret-spy.html">&#8216;spyware’ features discovery here</a> by <a href="http://www.infobytesec.com/">infoByte</a> .</p>
<p>It’s plenty of applications leaking private and sensitive information but just nobody have a look at it.</p>
<p>Should mandatory <a href="http://www.sans.org/reading_room/whitepapers/backup/electronic-data-retention-policy_514">data retention and privacy policies</a> became part of application development and submission guideline for mobile application?</p>
<p>Imho a users must not only be warned about the application capabilities and API usage but also what will do with which kind of information it’s going to handle inside the mobile phone.</p>
<p>Capabilities means authorizing the application to use a certain functionalities, for example to use GeoLocation API, but what the application will do and to who will provide such information once the user have authorized it?</p>
<p>That’s a security profiling level that mobile phone manufacturer does not provide and they should, because it focus on the information and not on the application authorization/permission respect to the usage of device capabilities.</p>
<p>p.s. yes! ok! I agree! This kind of post would require 3-4 pages long discussion as the topic is hot and quite articulated but it’s saturday morning and i gotta go!</p>]]></content:encoded>
</item>
<item>
<title>AES algorithm selected for use in space</title>
<link>https://infosecurity.ch/20100708/aes-algorithm-selected-for-use-in-space/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100708/aes-algorithm-selected-for-use-in-space/</guid>
<pubDate>Thu, 08 Jul 2010 12:37:20 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>privacy</category>
<description>I encountered a nice paper regarding analysis and consideration on which encryption algorithm it’s best suited for use in the space by space ship and…</description>
<content:encoded><![CDATA[<p>I encountered a nice paper regarding analysis and consideration on which encryption algorithm it’s best suited for use in the space by space ship and equipments.</p>
<p>The paper has been done by the <a href="http://public.ccsds.org/default.aspx">Consultative Committee for Space Data Systems</a> that’s a consortium of all space agency around that cumulatively handled more than <a href="http://public.ccsds.org/implementations/missions.aspx">400 mission to space</a>.</p>
<p></p>
<div style="text-align: center;">
  <img src="https://infosecurity.ch/wp-content/uploads/2010/07/topban.jpg" width="480" height="61" alt="topban.jpg"/>
</div>
<p>Read the paper <a href="http://cwe.ccsds.org/sea/docs/SEA-SEC/Draft%20Documents/350.2-G-0%20Encryption%20Algorithm%20Trade%20SurveyRev1.doc">Encryption Algorithm Trade Survey</a> as it gives interesting consideration and comparison between different encryption algorithms.</p>
<p>Obviously the finally selected algorithm is <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard">AES</a>, while KASUMI (used in UMTS networks) was avoided.</p>]]></content:encoded>
</item>
<item>
<title>Blackberry Security and Encryption: Devil or Angel?</title>
<link>https://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/</guid>
<pubDate>Wed, 07 Jul 2010 22:39:43 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>business</category>
<category>encryption</category>
<category>hacking</category>
<category>mobile</category>
<category>privacy</category>
<description>Blackberry have good and bad reputation regarding his security capability, depending from which angle you look at it. This post it’s a summarized set of…</description>
<content:encoded><![CDATA[<p>Blackberry have good and bad reputation regarding his security capability, depending from which angle you look at it.</p>
<p>This post it’s a summarized set of information to let the reader the get picture, without taking much a position as RIM and Blackberry can be considered, depending on the point of view, an <b>extremely secure platform</b> or an <b>extremely dangerous one</b> .</p>
<p style="text-align: center;"><a href="https://infosecurity.ch/wp-content/uploads/2010/07/bblock.jpg"><img src="https://infosecurity.ch/wp-content/uploads/2010/07/bblock-tm.jpg" width="79" height="100" alt="bblock.jpg"/></a></p>
<p style="text-align: center;">Let’s goes on.</p>
<p>On one side Blackberry it’s a platform plenty of encryption features, security features everywhere, device encrypted (with custom crypto), communication encrypted (with <a href="http://docs.blackberry.com/en/admin/deliverables/16558/RIM_propietary_protocols_1107871_11.jsp">custom proprietary protocols</a> such as IPPP), very good Advanced Security Settings, Encryption framework from <a href="http://www.certicom.com/">Certicom</a> (<a href="http://www.digitalcommunitiesblogs.com/international_beat/2009/02/certicom-may-be-a-prized-posse.php">now owned by RIM</a>).</p>
<p>On the other side they does not provide only a device but an overlay access network, called BIS (<a href="http://docs.blackberry.com/en/smartphone_users/deliverables/16059/BlackBerry_Internet_Service-User_Guide-T987396-1026956-0510121134-001-3.1-US.pdf">Blackberry Internet Service</a>), that’s a global worldwide wide area network where your blackberry enter while you browse or checkmail using <b>blackberry.net</b> AP.</p>
<p>When you, or an application, use the <b>blackberry.net</b> APN you are not just connecting to the internet with the carrier internet connection, but you are entering inside the RIM network that will proxy and act as a <a href="#">gateway to reach the internet.</a></p>
<p>The very same happen when you have a corporate use: Both the BB device and the corporate BES connect to the RIM network that act as a sort of <a href="#">vpn concentration network</a>.</p>
<p>So basically all the communications cross trough RIM service infrastructure in encrypted format with a set proprietary encryption and communication protocols.</p>
<p>Just as a notice, think that google to provide gtalk over <b>blackberry.net</b> APN, made an agreement in order to offer service inside the BB network to the BB users. When you install gtalk you get added 3 <b><a href="http://www.mahalo.com/how-to-get-a-blackberry-service-book">service books</a></b> that point to <a href="http://www.blackberryforums.com/general-blackberry-discussion/28639-google-talk-blackberry-now-available.html">GTALKNA01</a> that’s the name of GTALK gateway inside the RIM network to allow intra-BIS communication and act as a GTALK gateway to the internet.</p>
<p>The mobile operators usually are not even allowed to inspect the traffic between the Blackberry device and the Blackberry Network.</p>
<p>So RIM and Blackberry are somehow unique for their approach as they provide a platform, a network and a service all bundled together and you cannot just &#8220;get the device and the software&#8221; but the user and the corporate are always bound and connected to the service network.</p>
<p>That’s good and that’s bad, because it means that RIM provide extremely good security features and capabilities to protect information, device and access to information at various level <b>against third party</b>.</p>
<p>But it’s always difficult to estimate the threat and risk related to RIM itself and who could make political pressure against RIM.</p>
<p>Please consider that i am not saying &#8220;RIM is looking at your data&#8221; but making an objective risk analysis: for how the platform is done RIM have authority on the device, on the information on-the-device and on the information that cross the network. (Read my <a href="http://www.slideshare.net/fpietrosanti/2010-mobile-security-whymca-developer-conference">Mobile Security Slides</a>).</p>
<p>For example let’s consider the very same context for Nokia phones.</p>
<p>Once the Nokia device is sold, Nokia does not have authority on the device, nor on the information on-the-device nor on the information that cross the network. But it’s also true that Nokia just provide the device and does not provide the value added services such as the Enterprise integration (The RIM VPN tunnel), the BIS access network and all the local and remote security provisioned features that Blackberry provide.</p>
<p>So it’s a matter of considering the risk context in the proper way when choosing the platform, with an example very similar to choosing Microsoft Exchange Server (on your own service) or whether getting a SaaS service like Google Apps.</p>
<p>In both case you need to trust the provider, but in first example you need to trust Microsoft that does not put a backdoor on the software while in the 2nd example you need to trust Google, as a platform and service provider, that does not access your information.</p>
<p>So it’s a different paradigm to be evaluated depending on your threat model.</p>
<p>If your threat model let you consider RIM as a trusted third party service provider (much like google) than it’s ok. If you have a very high risk context, like top-secret one, then let’s consider and evaluate carefully whether it’s not better to keep the Blackberry services fully isolated from the device or use another system without interaction with manufacturer servers and services.</p>
<p>Now, let’s get back to some research and some facts about blackberry and blackberry security itself.</p>
<p>First of all several governments had to deal with RIM in order to force them to provide access to the information that cross their service networks while other decided to directly ban Blackberry usage for high officials because of servers located in UK and USA, while other decided to install their own backdoors.</p>
<ul>
<li><a href="http://www.mobilemarketingmagazine.co.uk/content/blackberry-debuts-russia?quicktabs_1=0"><b>Russian Secret Services</b> (FSB) reach an agreement with RIM and now FSB can eavesdrop Blackberry email and web traffic</a> in Russia</li>
<li><a href="http://www.pcworld.com/businesscenter/article/133198/security_concerns_prompt_french_blackberry_ban.html"><b>French Government</b> banned Blackberry for use by Government officials</a> and also <a href="http://www.phonearena.com/htmls/French-President-receiving-a-new-encrypted-phone-after-a-BlackBerry-ban-article-a_8654.html">replaced the device for voice encryption use</a></li>
<li><a href="http://www.informationweek.com/news/mobility/messaging/showArticle.jhtml?articleID=208403978"><b>Indian government</b> made pressure on RIM to reduce encryption capabilities</a> and later announced that they <a href="http://www.zdnet.com/blog/security/indias-government-at-last-weve-cracked-blackberrys-encryption/1964">have cracked blackberry encryption</a> . A summary on <a href="http://www.schneier.com/blog/archives/2008/05/blackberry_givi_1.html">India-RIM story by Bruce Schneier</a>.</li>
<li><b>United Arab Emirates (UAE)</b> Etisalat operator <a href="http://internetthought.blogspot.com/2009/07/etisalat-and-ss8-hacking-your.html">tried to silently install a government spyware on all country blackberry</a> but they got caught</li>
<li><b>USA</b> <a href="http://www.nsa.gov/">National Security Agency</a> initially <a href="http://www.maclife.com/article/news/president_his_pda">prohibited Obama to use Blackberry</a> for his presidential works giving him a <a href="http://news.cnet.com/obamas-new-blackberry-the-nsas-secure-pda/">Sectera Edge Secure Phone</a>, after 2 years they managed to secure it with a custom encryption layer done specifically by NSA and <a href="http://www.blackberrycool.com/2009/01/22/obama-to-keep-his-blackberry-get-a-super-encryption/">allowed Obama to use a custom secured blackberry</a></li>
</ul>
<p>There’s a lot of discussion when the topics are RIM Blackberry and Governments for various reasons.</p>
<p>Below a set of official Security related information on RIM blackberry platform:</p>
<ul>
<li>Official <a href="http://na.blackberry.com/eng/ataglance/security/knowledgebase.jsp">Security Knowledgebase</a> on RIM website</li>
<li><a href="http://docs.blackberry.com/en/smartphone_users/deliverables/14212/BlackBerry_Internet_Service-Security_Feature_Overview--787371-0205030634-001-3.0-US.pdf">Blackberry Internet Service security features</a></li>
<li><a href="http://na.blackberry.com/eng/ataglance/security/features.jsp">Wireless Data Security</a></li>
</ul>
<p>And here a set of unofficial Security and Hacking related information on RIM Blackberry platform:</p>
<ul>
<li>Hackish blackbox security analysis by FX of <a href="http://www.phenoelit-us.org/">Phenoelit</a>:&nbsp;&nbsp;<a href="http://www.phenoelit-us.org/stuff/AnalysingComplexSystems.pdf">Analysing Complex Systems - The Blackberry case</a></li>
<li><a href="http://www.phenoelit-us.org/stuff/AnalysingComplexSystems.pdf"></a>Accessing corporate intranets trough <a href="http://www.blackberrytoday.com/articles/2006/8/2006-8-9-BBProxy-Hack-Exposes.html">Blackberry BBProxy Hack</a></li>
<li><a href="http://www.geckoandfly.com/6398/how-to-hack-and-modify-blackberry-settings-with-master-control-program/">Blackberry Master Control Program</a> little bit of hacking</li>
<li>How to <a href="http://www.blackberryinsight.com/2008/03/16/howto-remove-blackberrys-it-policy/">bypass Blackberry IT Policy</a></li>
<li>Blackberry Reversing research (mostly by Dr Bolsen, however no one have ever decompiled and published the whole RIMOS)</li>
<li>
<ul>
<li><a href="http://drbolsen.wordpress.com/2007/07/31/bypass-signature-requirement/">Bypassing Blackberry COD Signature</a></li>
</ul>
</li>
<li>
<ul>
<li><a href="http://drbolsen.wordpress.com/2006/07/26/blackberry-cod-file-format/">Reversing Blackberry</a> The COD format</li>
<li><a href="http://drbolsen.wordpress.com/2007/05/16/blackberry-internal-folders-layout/">Blackberry Internal Folders Layout</a></li>
<li><a href="http://drbolsen.wordpress.com/2007/01/30/how-it-looks-like/">Blackberry decompilated COD binaries</a></li>
<li><a href="http://drbolsen.wordpress.com/2008/07/14/coddec-released/">Blackberry Coddec decompilation tool release</a></li>
</ul>
</li>
</ul>
<p>Because it’s 23.32 (GMT+1), i am tired, i think that this post will end up here.</p>
<p>I hope to have provided the reader a set of useful information and consideration to go more in depth in analyzing and considering the overall blackberry security (in the good and in the bad, it always depends on your threat model!).</p>
<p>Cheers</p>
<p>Fabio Pietrosanti (naif)</p>
<p>p.s. i am managing security technology development (voice encryption tech) on Blackberry platform, and i can tell you that from the development point of view it’s absolutely better than Nokia in terms of compatibility and speed of development, but use only RIMOS 5.0+ !</p>]]></content:encoded>
</item>
<item>
<title>Celebrating “Hackers” after 25 years</title>
<link>https://infosecurity.ch/20100701/celebrating-hackers-after-25-years/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100701/celebrating-hackers-after-25-years/</guid>
<pubDate>Thu, 01 Jul 2010 08:25:23 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>hacking</category>
<description>A cult book , ever green since 25 years. It’s been 25 years since “Hackers” was published. Author Steven Levy reflects on the book and the movement…</description>
<content:encoded><![CDATA[<p style="text-align: center;">A <a href="http://oreilly.com/catalog/0636920010227/">cult book</a>, ever green since 25 years.</p>
<div style="text-align: center;">
  <img src="https://infosecurity.ch/wp-content/uploads/2010/07/201007010924.jpg" width="180" height="278" alt="201007010924.jpg"/>
</div>
<p><span style="font-family: monospace; white-space: pre-wrap;">It’s been 25 years since &#8220;Hackers&#8221; was published. Author Steven Levy</span> <span style="font-family: monospace; white-space: pre-wrap;">reflects on the book and the movement.</span></p>
<pre>
<a class="moz-txt-link-freetext" href="http://radar.oreilly.com/2010/06/hackers-at-25.html">http://radar.oreilly.com/2010/06/hackers-at-25.html</a><br/>Steven Levy wrote a book in the mid-1980s that introduced the term "hacker" -- the positive connotation -- to a wide audience. In the ensuing 25 years, that word and its accompanying community have gone through tremendous change. The book itself became a mainstay in tech libraries.<br/>O'Reilly recently released an updated 25th anniversary edition of "Hackers," so I checked in with Levy to discuss the book's development, its influence, and the role hackers continue to play.
</pre>]]></content:encoded>
</item>
<item>
<title>Botnet for RSA cracking?</title>
<link>https://infosecurity.ch/20100630/botnet-for-rsa-cracking/</link>
<guid isPermaLink="true">https://infosecurity.ch/20100630/botnet-for-rsa-cracking/</guid>
<pubDate>Wed, 30 Jun 2010 14:29:06 +0000</pubDate>
<dc:creator>Fabio Pietrosanti (naif)</dc:creator>
<category>encryption</category>
<category>privacy</category>
<description>I read an interesting article about putting 1.000.000 computers, given the chance for a serious botnet owner to get it, to crack RSA. The result is that in…</description>
<content:encoded><![CDATA[<p>I read an <a href="http://dev.cleversafe.org/weblog/?p=95">interesting article</a> about putting 1.000.000 computers, given the chance for a serious botnet owner to get it, to crack RSA.</p>
<p>The result is that in such context attacking an RSA 1024bit key would take only 28 years, compared to theoretical 19 billion of years.</p>
<p>Reading of <a href="http://dev.cleversafe.org/weblog/?p=95">this article</a>, is extremely interesting because it gives our very important consideration on the cryptography strength respect to the computation power required to carry on cracking attempt, along with industry approach to &#8220;default security level&#8221;.</p>
<p>I would say a <b>must read</b>.</p>]]></content:encoded>
</item>
</channel>
</rss>
