// COMPLETE THREAD

Hal's Third Challenge?

8 expanded posts ยท every known parent and child

NODE 0dc5099bHal's Third Challenge?
Any movement towards a third cracking session.  I know poor Netscape seems
like old hat but it might be good to do one more to establish a working
server (if we have one).

My interest arises out of the new Pentium 120 that has come my way and the
40,000 keys/second it gets running the 32-bit version of the Brue code.
Since my ISP is a local call, I might even be able to get away with an 8
hour PPP session to try the WIN95 client.

What's going on?

DCF

"Take your Writ of Ne Exeat Republica and shove it." --- words to keep
around to really impress the opposition with.
NODE 529af92aRe: Hal's Third Challenge?
> Any movement towards a third cracking session.  I know poor Netscape seems
> like old hat but it might be good to do one more to establish a working
> server (if we have one).

Indeed -- with the time to crack down to a few seconds using cryptanalytic
instead of brute, and netscape moving to 128 bit, there seemed little point in
going for netscape again.

It seems that microsoft was the one to go for, as they too use 40 bit for
each session ....  If someone can generate the CRACKing code and someone can
donate an example, I'd be DELIGHTED to arrange another BRUTE !


PS: any non US people willing to test my PGP "Multi Protocol fast lookup"
    as per http://www.pgp.net/pgp/ ? I'd like to see how fast it is from
    distant parts (at 0.3 - 0.6 s real time locally, network delays will
    be significant ...)
NODE be3d206dRe: Hal's Third Challenge?
On Tue, 10 Oct 1995, Piete Brooks wrote:

> It seems that microsoft was the one to go for, as they too use 40 bit for
> each session ....  If someone can generate the CRACKing code and someone can
> donate an example, I'd be DELIGHTED to arrange another BRUTE !

If you mean STT, they're using a hotch-potch of methods in the exportable 
version.  40 bit RC4 protects the purchase order form and receipt, single 
DES-CBC protects the financial data and they claim that direct RSA 
protects the credit card numbers although this is far from clear from the 
specification (can someone clarify this?).

So you're going to need brutedes and/or some network factoring code (the 
smallest modulus they use is 512 bits which, realistically we do not have 
a chance of attacking in a reasonable time).


Regards,

- Andy

+-------------------------------------------------------------------------+
| Andrew Brown  Internet <asb@nexor.co.uk>  Telephone +44 115 952 0585    |
| PGP (2048/9611055D): 69 AA EF 72 80 7A 63 3A  C0 1F 9F 66 64 02 4C 88   |
+-------------------------------------------------------------------------+
NODE 20a13366Re: Hal's Third Challenge?
> Duncan Frissell <frissell@panix.com> writes:
> Any movement towards a third cracking session.  I know poor Netscape seems
> like old hat but it might be good to do one more to establish a working
> server (if we have one).

I'd rather see a Microsoft challenge than a third Netscape 40-bitter.
We've made our point about 40-bit keys on Netscape's skull enough times,
and Microsoft is making smug product announcements referring to those
Netscape breaks.

Time to spread our joy around a bit, I'd say.

	Jim Gillogly
	Hevensday, 19 Winterfilth S.R. 1995, 20:42
NODE 37ab76b6Re: Hal's Third Challenge?
>I'd rather see a Microsoft challenge than a third Netscape 40-bitter.
>We've made our point about 40-bit keys on Netscape's skull enough times,
>and Microsoft is making smug product announcements referring to those
>Netscape breaks.
>
>Time to spread our joy around a bit, I'd say.

Indeed. With the huge amount of people that dislike m$ I think we will at
least double the amount of persons wanting to do their bit to rub their
noses in it.  Whats needed is someone to reverse engineer a m$ transfer,
according to the published specs, isolate the encrypted section and then
produce a brute engine which can be ported to the platforms we want to try.

For the person that cracks a session using the brute force program in the
next brutefest and provides the key, I will give a US$50 international money
order to. I'm sure others will pile t-shirts on you as well.

IMHO we owe Netscape some counter pr against m$, we've proved our point to
Netscape and they performed admirally by being open and responsible to the
net.community. Whilst it didnt seem to dent their share value, they did cop
some bad press (and some media weenies still think their product is broken)
because of the groups efforts. What goads me is m$ trying to use this in
their press dealing and acting like this is entirely different from their
situation. Seems to me they need it proved to them that because of their
proprietary attitude they are in a worse position. In short bring them down
to earth and serve their ego to them on a plate.

Cheers,
Mark
mark@lochard.com.au
The above opinions are rumoured to be mine.
NODE 1eafd261Re: Hal's Third Challenge?
> IMHO we owe Netscape some counter pr against m$, we've proved our point to
> Netscape and they performed admirally by being open and responsible to the
> net.community. Whilst it didnt seem to dent their share value, they did cop

	<yawn> This is old news. http://www.c2.org/hackmsoft/ has been
around for multiple weeks now.

> some bad press (and some media weenies still think their product is broken)
> because of the groups efforts. What goads me is m$ trying to use this in
> their press dealing and acting like this is entirely different from their
> situation. Seems to me they need it proved to them that because of their
> proprietary attitude they are in a worse position. In short bring them down
> to earth and serve their ego to them on a plate.
> 
> Cheers,
> Mark
> mark@lochard.com.au
> The above opinions are rumoured to be mine.
> 


-- 
sameer						Voice:   510-601-9777
Community ConneXion				FAX:	 510-601-9734
The Internet Privacy Provider			Dialin:  510-658-6376
http://www.c2.org (or login as "guest")			sameer@c2.org
NODE 57eb26d9Re: Hal's Third Challenge?
> My interest arises out of the new Pentium 120 that has come my way and the
> 40,000 keys/second it gets running the 32-bit version of the Brue code.
> Since my ISP is a local call, I might even be able to get away with an 8
> hour PPP session to try the WIN95 client.
> 
Im interested too... if there is a 32 bit client for NT/Win95 (or a single
thredded one for Win32s) capable of reporting automatic to the
server/local server, I could probably throw in c.a. 40-50 pentiums and a
lot more 486 (and a few HP/Sun/Alpha) :-)  Anyone working on self-reporting
win32 client?

  Logi.

-- 
Magnus Logi Magnusson
System programmer, State and Municipal Data processing center, Iceland
E-mail: mlm@skyrr.is & mlm@rhi.hi.is
NODE 73796af2Re: Hal's Third Challenge?
If the next challenge is advertised with time enough, I have a spare
MasPar I could use.

I've been considering porting brutessl to it for a while, but never 
actually tried. Maybe I could have time to do it... That would be real
fun!

OTOH I'm about to leave my current job. Maybe I won't have the time...
But I could try. <:-)

				jr