NODE c7c3e0f6Single computer breaks 40-bit RC4 in under 8 days
daveg@pakse.mit.edu (David Golombek)Fri, 19 Jan 1996 09:57:44 +0800
MIT Student Uses ICE Graphics Computer
To Break Netscape Security in Less Than 8 Days
Cost to crack Netscape security falls from $10,000 to $584
CAMBRIDGE, Mass., January 10, 1996 -- An MIT undergraduate and part-time
programmer used a single $83,000 graphics computer from Integrated Computing
Engines (ICE) to crack Netscape's export encryption code in less than eight
days. The effort by student Andrew Twyman demonstrated that ICE's advances
in hardware price/performance ratios make it relatively inexpensive -- $584
per session -- to break the code.
While being an active proponent of stronger export encryption, Netscape
Communications (NSCP), developer of the SSL security protocol, has said that
to decrypt an Internet session would cost at least $10,000 in computing time.
Twyman used the same brute-force algorithm as Damien Doligez, the French
researcher who was one of the first to crack the original SSL Challenge.
The challenge presented the encrypted data of a Netscape session, using the
default exportable mode, 40-bit RC4 encryption. Doligez broke the code in
eight days using 112 workstations.
"The U.S. government has drastically underestimated the pace of technology
development," says Jonas Lee, ICE's general manager. "It doesn't take a
hundred workstations more than a week to break the code -- it takes one ICE
graphics computer. This shuts the door on any argument against stronger
export encryption."
Breaking the code relies more on raw computing power than hacking expertise.
Twyman modified Doligez's algorithm to run on ICE's Desktop RealTime Engine
(DRE), a briefcase-size graphics computer that connects to a PC host to
deliver performance
of 6.3 Gflops (billions of floating point instructions per second).
According to Twyman, the program tests each of the trillion 40-bit keys
until it finds the correct one. Twyman's program averaged more than 830,000
keys per second, so it would take 15 days to test every key. The average
time to find a key, however, was 7.7 days. Using more than 100
workstations, Doligez averaged 850,000 keys per second.ICE used the
following formula to determine its $584 cost of computing power: the total
cost of the computer divided by the number of days in a three-year lifespan
(1,095), multiplied by the number of days (7.7) it takes to break the code.
ICE's Desktop RealTime Engine combines the power of a supercomputer with the
price of a workstation. Designed for high-end graphics, virtual reality,
simulations and compression, it reduces the cost of computing from $160 per
Mflop (millions of floating point instructions per second) to $13 per Mflop.
ICE, founded in 1994, is the exclusive licensee of MeshSP technology from
the Massachusetts Institute of Technology (MIT).
###
INTEGRATED COMPUTING ENGINES, INC.
460 Totten Pond Road, 6th Floor
Waltham, MA 02154
Voice: 617-768-2300, Fax: 617-768-2301
FOR FURTHER INFORMATION CONTACT:
Bob Cramblitt, Cramblitt & Company
(919) 481-4599; cramco@interpath.com
Jonas Lee, Integrated Computing Engines
(617) 768-2300, X1961; jonas@iced.com
Note: Andrew Twyman can be reached at kurgan@mit.edu.
NODE c821cd49Re: Single computer breaks 40-bit RC4 in under 8 days
Rich Graves <llurch@networking.stanford.edu>Sat, 20 Jan 1996 07:07:25 +0800
This takes "cracking Netscape security as a new benchmark" to a whole new
level.
On Thu, 18 Jan 1996, David Golombek wrote:
> MIT Student Uses ICE Graphics Computer
>
> To Break Netscape Security in Less Than 8 Days
What does this have to do with Netscape? This is about brute-forcing
40-bit RC4. While Netscape does deserve flogging with a wet noodle down
to the seventh generation for their initial press response, this singling
out Netscape is annoying me a little.
> While being an active proponent of stronger export encryption, Netscape
> Communications (NSCP), developer of the SSL security protocol, has said that
> to decrypt an Internet session would cost at least $10,000 in computing time.
OK, well, in that case.
> workstations, Doligez averaged 850,000 keys per second.ICE used the
> following formula to determine its $584 cost of computing power: the total
> cost of the computer divided by the number of days in a three-year lifespan
> (1,095), multiplied by the number of days (7.7) it takes to break the code.
This assumes, of however, that collecting encrypted communications,
feeding them to the computer with 100% efficiency, electricity, labor,
etc. are completely free.
I hope everyone recognizes this as more old news and ICE marketing. In a
fantasy world, the press et al would see this and clamor for the
revocation of ITAR.
-rich
NODE b11606c2Re: Single computer breaks 40-bit RC4 in under 8 days
Sten Drescher <stend@grendel.texas.net>Fri, 19 Jan 1996 23:23:05 +0800
Rich Graves <llurch@networking.stanford.edu> said:
>> workstations, Doligez averaged 850,000 keys per second.ICE used the
>> following formula to determine its $584 cost of computing power: the
>> total cost of the computer divided by the number of days in a
>> three-year lifespan (1,095), multiplied by the number of days (7.7)
>> it takes to break the code.
RG> This assumes, of however, that collecting encrypted communications,
RG> feeding them to the computer with 100% efficiency, electricity,
RG> labor, etc. are completely free.
RG> I hope everyone recognizes this as more old news and ICE
RG> marketing. In a fantasy world, the press et al would see this and
RG> clamor for the revocation of ITAR.
This is old news to those of us who understand it. But this new
way of presenting the information is newsworthy. Yes, it
over-simplifies the costs of collecting the transactions to force, but
the sound bite nature of reporting today requires that. The government
is trying to give people warm fuzzies about the 'security' of 40-bit
encryption, and we, unfortunately, need to be spreading FUD about that.
This helps to do that.
--
#include <disclaimer.h> /* Sten Drescher */
1973 Steelers About Three Bricks Shy of a Load 1994 Steelers
1974 Steelers And the Load Filled Up 1995 Steelers?
To get my PGP public key, send me email with your public key and
Subject: PGP key exchange
Key fingerprint = 90 5F 1D FD A6 7C 84 5E A9 D3 90 16 B2 44 C4 F3
Unsolicited email advertisements will be proofread for a US$100/page fee.