Главная
Study mode:
on
1
Intro
2
Presentation
3
Background
4
Signature
5
PKBDF2
6
Design problem
7
Key verification
8
Openssl
9
File encryption
10
File malleability
11
Disclosure
12
Background of the company
13
Vulnerability report
14
triage
15
challenges
16
product combinations
17
Cybertext reliability
18
Copy in copy out mode
Description:
Explore the vulnerabilities discovered in the DataVault encryption software used by major storage device manufacturers in this conference talk. Delve into the analysis process that revealed serious flaws in the "military-grade" encryption claims, including a weak key derivation function, constant salt usage, and malleable data encryption. Learn about the reverse engineering techniques employed, the practical implications of these vulnerabilities, and the development of a John the Ripper plugin for brute-forcing the encryption. Gain insights into the coordinated disclosure process with multiple vendors and the subsequent improvements made to address these security issues.

Practical Brute Force of Military Grade AES-1024 - Sylvain Pelissier, Boi Sletterink

media.ccc.de
Add to list