NODE c63b62c1POTP gets good press
Bryce <wilcoxb@nagina.cs.colorado.edu>Thu, 8 Feb 1996 04:19:00 +0800
-----BEGIN PGP SIGNED MESSAGE-----
The Sun Observer -- "An Independent Journal Devoted to the
Sun and Compatible Markets" -- ran an article in the Feb 96
issue entitled "New technology eliminates need for keys to
encrypt e-mail messages".
Byline: Bob Harvey. About the author: "Bob Harvey is vice
president of the Internet Security Corp., a Lexington,
Mass.-based network security solutions provider."
Content: includes diagrams entitled "Link Level Encryption"
in which sender transmits keys to receiver, and "Packet
Level Encryption" in which sender transmits key sto
certificate authority which transmits them to multiple
receivers, and "Synchronized Random Key Generation (SRKG)"
a la "Power One Time Pad" in which no keys are transmitted
and multiple recievers magically decipher messages via
built-in encryption devices.
Am I right in thinking this is utter unmitigated
bullsh snake oil? Does anybody have any other
dirt on this Bob Harvey guy and his Internet Security Corp?
What is his relationship with the POTP folks? An Alta
Vista search revealed several Bob Harveys, but none who
matched with "Internet Security".
I'm Cc'ing this to the editor in chief of The Sun
Observer. If he doesn't know about the cypherpunks he might
want to request some explanation...
Regards,
Bryce
"Toys, Tools and Technologies"
the Niche
New Signal Consulting -- C++, Java, HTML, Ecash
Bryce
PGP sig follows
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: Auto-signed under Unix with 'BAP' Easy-PGP v1.01
iQCVAwUBMRkD8/WZSllhfG25AQESBgP8CmmKb0+VMqs14FNQ2YoAllXcaqAtc09Y
99KljeM0gHpm19x14Tj011bngS59EyUCDvoFaY6HtOmOPNqR2SpQxoHp9IBWNJmS
dGEGwuqCLEB2gxMwgtjrwCNWyJmXk6Wp8UTRPcoG/woXWBCkyllbc62dV/RbILva
OeKJR5FpQ9Y=
=YT6V
-----END PGP SIGNATURE-----
NODE 3a2b9516Re: POTP gets good press
"Perry E. Metzger" <perry@piermont.com>Thu, 8 Feb 1996 04:46:00 +0800
Bryce writes:
> The Sun Observer -- "An Independent Journal Devoted to the
> Sun and Compatible Markets" -- ran an article in the Feb 96
> issue entitled "New technology eliminates need for keys to
> encrypt e-mail messages".
[...]>
> Am I right in thinking this is utter unmitigated
> bullsh snake oil?
Probably. Almost all such claims end up being crap. I haven't seen the
article yet so I can't say for sure, but 99% of the time these
companies have no idea what they are doing and feed the gullible lines
of utter bull. I don't know how so many of them survive in the market.
Perry
NODE c9b7bfb6Re: POTP gets good press
Simon Spero <ses@tipper.oit.unc.edu>Thu, 8 Feb 1996 05:47:34 +0800
On Wed, 7 Feb 1996, Bryce wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
>
> Content: includes diagrams entitled "Link Level Encryption"
> in which sender transmits keys to receiver, and "Packet
> Level Encryption" in which sender transmits key sto
> certificate authority which transmits them to multiple
> receivers, and "Synchronized Random Key Generation (SRKG)"
>
> Am I right in thinking this is utter unmitigated
> bullsh snake oil? Does anybody have any other
It could be doing something SKIP like; if the certificates are DH certs,
it could be using those to generate a shared secret, and combing that
with an IV to generate a key.
hard to tell from the article
Simon
NODE 32a6277eRe: POTP gets good press
Bryce <wilcoxb@nagina.cs.colorado.edu>Thu, 8 Feb 1996 11:20:38 +0800
-----BEGIN PGP SIGNED MESSAGE-----
I, Bryce, wrote:
> Content: includes diagrams entitled "Link Level Encryption"
> in which sender transmits keys to receiver, and "Packet
> Level Encryption" in which sender transmits key sto
> certificate authority which transmits them to multiple
> receivers, and "Synchronized Random Key Generation (SRKG)"
> a la "Power One Time Pad" in which no keys are transmitted
> and multiple recievers magically decipher messages via
> built-in encryption devices.
>
> Am I right in thinking this is utter unmitigated
> bullsh snake oil? Does anybody have any other
An entity calling itself "Simon Spero
<ses@tipper.oit.unc.edu>" is alleged to have written:
> It could be doing something SKIP like; if the certificates are DH certs,
> it could be using those to generate a shared secret, and combing that
> with an IV to generate a key.
>
> hard to tell from the article
But this would entail a certificate authority to prevent
MITM attack, right? The article clearly claimed that POTP
did away with the necessity of key management completely--
a claim that I find only slightly more believable than a
patent application for a perpetual motion machine.
Regards,
Bryce
"Toys, Tools and Technologies"
the Niche
New Signal Consulting -- C++, Java, HTML, Ecash
Bryce
PGP sig follows
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: Auto-signed under Unix with 'BAP' Easy-PGP v1.01
iQCVAwUBMRkkNPWZSllhfG25AQG02QP/V5SKi0K0Ywj/wcqGVCF3SU9qqQbrHFKn
GCp/f5AoltP0ZTuZ46M6ObE7ER0rmzx8CQClqfZUBdj0IOXD1wlRwvppZASRiXms
BWxm3XLC/s9rcHH/CVKREinUKU0BK5Id+gnBQaR5D8dzE6PtEicoY5I9ZnGFSLUd
knGdNO3GqjY=
=xfpS
-----END PGP SIGNATURE-----
NODE 5172c6e1Re: POTP gets good press
Simon Spero <ses@tipper.oit.unc.edu>Thu, 8 Feb 1996 10:45:57 +0800
On Wed, 7 Feb 1996, Bryce wrote:
[original messsage]
> I, Bryce, wrote:
> ...
> > certificate authority which transmits them to multiple
> ...
[reply to my reply]
> But this would entail a certificate authority to prevent
> MITM attack, right? The article clearly claimed that POTP
I guess I ought to try and find the article; I took this line in your
message to suggest that there was such a CA. Could you possibly type in
the relevant bit of the original article (though I suspect there's not
much in there anyway)
NODE 5c047f4bRe: POTP gets good press
Bryce <wilcoxb@taussky.cs.colorado.edu>Thu, 8 Feb 1996 10:29:30 +0800
-----BEGIN PGP SIGNED MESSAGE-----
An entity calling itself "Simon Spero
<ses@tipper.oit.unc.edu>" is alleged to have written:
> I guess I ought to try and find the article; I took this line in your
> message to suggest that there was such a CA. Could you possibly type in
> the relevant bit of the original article (though I suspect there's not
> much in there anyway)
Sorry. Here's what I originally said:
> Content: includes diagrams entitled "Link Level Encryption"
> in which sender transmits keys to receiver, and "Packet
> Level Encryption" in which sender transmits key sto
> certificate authority which transmits them to multiple
> receivers, and "Synchronized Random Key Generation (SRKG)"
> a la "Power One Time Pad" in which no keys are transmitted
> and multiple recievers magically decipher messages via
> built-in encryption devices.
And here's what I meant:
The central theme of the article, from a 'technical' point
of view, was that in the past there have been two kinds of
encryption in use, which the author calls "Link Level
Encryption", in which the sender transmits his key to the
receiver, and "Packet Level Encryption", in which the sender
transmits is key to a certificate authority which transmits
them to multiple receivers.
Now for starters the network layer is really independent of
key-distribution schemes, as far as I can see. So I don't
know why the diagrams showing the two schemes
(sender->recipient vs. certificate authority) are labelled
"Link Level" and "Packet Level". But we haven't even gotten
to the good stuff:
"Synchronized Random Key Generation", which shows a single
sender and multiple recipients transmitting securely
*without* having to do any key management! Yee haw!
100% pure unrefined snake oil.
Okay I think I've made my point to the Editor In Chief on
the industry rag in question. Hopefully they'll be
conscientious enough to print a retraction, or perhaps run
an article about the hazards of snake oil in the info
security industry. :-)
Bryce
"Toys, Tools and Technologies"
the Niche
New Signal Consulting -- C++, Java, HTML, Ecash
Bryce
PGP sig follows
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: Auto-signed under Unix with 'BAP' Easy-PGP v1.01
iQCVAwUBMRk+evWZSllhfG25AQEuNgP/dEXVKJCff638xYs1j3NouaU9oDyrs4rK
c5carfnwYqC/97J0ntIpLRlX3bg9syg45Ubi8COAhozcX6olVZ2hqw6qNgfZIDN0
xbfiUEDsxAdc/K3ya0eeNhz0RGs8pzFFTrVJqTuVSpgqafDe9qS0RlXx1I0MZXig
29SgiKbjIE8=
=l+Og
-----END PGP SIGNATURE-----
NODE 02eb7dbbRe: POTP gets good press
Don <don@cs.byu.edu>Thu, 8 Feb 1996 18:35:43 +0800
bryce@colorado.edu sez:
> "Synchronized Random Key Generation", which shows a single
> sender and multiple recipients transmitting securely
> *without* having to do any key management! Yee haw!
You mean you don't have this capability? Gee, I've had this for months,
ever since the mother ship^H^H^H^Hmy mother gave me the proprietary program.
*sigh* Cypherpunks teach. I think we'd better brace for this, cuz most of
the important code is already written. (PGP 3.0 and PGP stealth people, this
doesn't apply, and definately any end-to-end stuff is needed)
Unfortunately, you can't set up a CGI counter to tick off the number of time
encryption saved your data, not to mention your butt, but it would sure make
good PR if you could.
Don