[00:00.700 --> 00:03.140] This is the first session of HOPE 5. [00:03.420 --> 00:05.340] We have David Burnick here to... [00:12.120 --> 00:14.420] My apologies. [00:14.700 --> 00:15.180] For me. [00:15.360 --> 00:16.000] You're cool. [00:17.270 --> 00:18.600] I just like being obnoxious. [00:19.840 --> 00:20.320] All right. [00:20.620 --> 00:22.080] Well, without further ado, here's Mr. Burnick. [00:22.780 --> 00:22.990] Hi. [00:23.280 --> 00:25.480] I'm doing a speech on distributed password cracking. [00:25.800 --> 00:34.200] And I'll go through distributed password cracking toward the middle to the end and be showing several APIs, including one I wrote that I'll be putting on SourceForge right after the talk. [00:35.580 --> 00:44.220] But on top of that, I'm going to talk about general kinds of cracking in general, and when you should really move from doing it on a single computer to putting huge amounts of computers behind it. [00:44.280 --> 00:50.520] Because a lot of things I see when I work are... A lot of people try to do distributed password cracking for things that are unnecessary and vice versa. [00:52.320 --> 00:55.660] So... Okay, so I used to write for 2600 occasionally. [00:55.860 --> 00:57.420] I wrote a lot of articles about social engineering. [00:58.700 --> 00:59.440] They're kind of lame. [00:59.620 --> 01:00.680] I did it a long time ago. [01:00.840 --> 01:02.380] I was much younger and had a lot more hair then. [01:02.720 --> 01:03.440] I don't anymore. [01:04.620 --> 01:07.680] I'm a big fan of Boston's 2600 hacker scene. [01:07.840 --> 01:10.880] If you live in Boston, you should, you know, kind of hang out. [01:11.340 --> 01:19.860] I used to work for Slashdot in VA Linux, and I've done distributed computing for Pixar, built some computers for Google, stuff like that. [01:20.000 --> 01:22.360] So doing distributed commodity computing is what I'm all about. [01:22.360 --> 01:25.940] I'm currently working for a company called Legal Computer Solutions up in Boston. [01:27.040 --> 01:36.520] Legal Computer Solutions, we handle very large court cases, criminal cases, civil cases that involve huge amounts of documents, millions to billions of pages per case. [01:37.360 --> 01:41.540] So we get them on hard drive, DVD, whatever, and we put them in a storage system and secure them. [01:42.860 --> 01:46.760] And the evidence comes in tons of different forms because it's electronic these days. [01:46.940 --> 01:55.700] So we get emails, PST files, DOC files, ZIP files, TIFs, just thumb drives, hard drives, just every single kind of thing. [01:55.700 --> 02:01.020] But sometimes these passwords are, sometimes these files are password protected or encrypted. [02:01.440 --> 02:11.570] And if there's a legal order to do so, and sometimes when there's not, and I'll tell you why not sometimes, we do in fact crack the files if we can, and usually we can. [02:13.880 --> 02:17.950] Now, why crack legally, or illegally for that matter? [02:17.950 --> 02:25.980] Well, if the defense says, well, we have 60 days to get it to you, and our prosecution who we work for say, well, we need it now. [02:27.370 --> 02:30.280] And we're not really changing data, we're just opening it very differently. [02:31.000 --> 02:31.880] That's how we say it. [02:31.940 --> 02:35.890] So we just have to crack it sometimes, even though there might be some issues with cracking it. [02:37.130 --> 02:44.700] And sometimes the original owner is dead, or can't be found, or is on the run, or whatever the case may be, and we just have to open this stuff. [02:44.860 --> 02:47.700] And if there's no passwords available, that's just the way we do it. [02:49.500 --> 02:51.180] It depends on the actual issue. [02:51.300 --> 03:00.660] Sometimes, as I said, the legality of password cracking is really weird, because we're not actually altering any of the data, especially since we take a forensic image of it. [03:00.760 --> 03:03.360] So we're just altering our forensic image of the data. [03:03.780 --> 03:12.420] And personally, I'm a licensed private investigator, so under the purview of the court, I'm usually just allowed to investigate as I see fit for the issue. [03:13.480 --> 03:17.280] Because all the stuff we have, we got through a warrant, anyhow. [03:17.500 --> 03:18.520] So we have it legally. [03:18.700 --> 03:20.050] The question is, can we legally crack it? [03:20.110 --> 03:22.880] And the answer is, we already got it legally, so usually yes. [03:24.800 --> 03:25.600] Sometimes, no. [03:25.820 --> 03:27.080] But usually we can. [03:27.260 --> 03:30.880] And even when it's sometimes no, it can be kind of fudged, and we do anyhow. [03:31.050 --> 03:31.600] Because we're mean. [03:32.380 --> 03:33.080] Or I'm mean. [03:33.580 --> 03:36.140] So mostly we crack a lot of Microsoft Office files. [03:37.440 --> 03:41.380] Microsoft Office files are interesting, because the encryption is weak. [03:41.720 --> 03:44.000] It's a 40-bit encryption, due to export reasons. [03:45.320 --> 03:47.540] But that's still not, like, super, super weak. [03:47.640 --> 03:50.000] You can't really crack that on one computer in a reasonable amount of time. [03:50.360 --> 03:51.550] But we're dealing with attorneys. [03:51.860 --> 03:52.940] And we're dealing with criminals. [03:53.180 --> 03:55.330] And for the most part, both are very stupid. [03:55.900 --> 03:57.200] Especially the attorneys, surprisingly. [03:57.480 --> 04:00.130] And they usually do three to five characters per password. [04:01.050 --> 04:04.500] So you can crack that conceivably on one computer with a simple brute force thing. [04:04.500 --> 04:07.080] Which is what we usually do for Microsoft Office. [04:07.320 --> 04:09.640] If, in case, it's a hugely long password. [04:10.000 --> 04:13.760] What we'll end up doing, instead, is just doing, searching the entire key space. [04:13.900 --> 04:14.760] Which is only 40-bit. [04:15.550 --> 04:18.080] And we string that together with about five or six computers. [04:18.300 --> 04:20.380] And it gets done in 20 minutes. [04:20.740 --> 04:22.060] How do you know what it is for? [04:22.520 --> 04:23.560] We take a guess at it. [04:23.640 --> 04:29.260] The first thing we do is we run a brute force against it between two to five characters, two to six characters. [04:29.960 --> 04:34.280] Because that takes on a, even like on a modern Pentium 4 will take about three minutes. [04:34.680 --> 04:37.340] So it's worth just trying, just to see if it's short or long. [04:38.880 --> 04:39.800] Yeah, exactly. [04:39.960 --> 04:41.820] If it's more than six characters, I consider it long. [04:42.020 --> 04:44.120] And I'll get into why that is in a second. [04:44.540 --> 04:47.960] Zip files also have a fairly interestingly weak problem with their encryption. [04:47.960 --> 04:57.580] If you have one of the files that you know is in the archive, and you have that unencrypted, you can usually search the key space based on that unencrypted file pretty quickly. [04:57.740 --> 05:00.000] In a matter of a couple hours or three hours or so. [05:00.800 --> 05:05.120] But if not, as I said, it's always better to start brute forcing it with three to five characters. [05:05.440 --> 05:08.000] Once you're beyond that, it's worth seeing if there's other ways around it. [05:09.200 --> 05:10.820] PDF files, pretty much the same thing. [05:10.940 --> 05:16.240] With Elcomsoft software, which we use a lot for smaller kinds of encryptions. [05:18.000 --> 05:19.000] Their stuff works great. [05:19.600 --> 05:23.220] I know the legalities in this country are iffy, but it does really, really work. [05:23.260 --> 05:24.900] And we do use it, and we are the government. [05:26.020 --> 05:27.660] Elcomsoft is a company out of Russia. [05:28.280 --> 05:30.540] E-L-C-O-M-S-O-F-T. [05:31.760 --> 05:36.020] And they make all sorts of cool cracking software that is fairly cheap. [05:36.180 --> 05:36.920] I mean, you should buy it. [05:36.920 --> 05:40.120] You shouldn't get it off of Kazaa, but if you do, it's not my fault. [05:41.820 --> 05:44.820] But it is fairly cheap, like $80, and it's really quite good. [05:44.820 --> 05:46.440] And sometimes we have to crack websites. [05:46.680 --> 05:50.160] We deal with a lot of pornography, because it's awesome. [05:50.740 --> 05:57.820] We deal with a lot of pornography, and sometimes some of these sites own child porn sites, or they funnel money through child porn sites, or whatever the case may be. [05:58.080 --> 06:02.620] And sometimes for an investigation, we'll just actually attack the website straight out if we get a court order to do so. [06:02.920 --> 06:07.960] And sometimes we'll just brute force a couple of passwords out of that, because we're mean and bad people. [06:10.100 --> 06:13.640] So, whenever we try to crack files, the first thing we do is do a dictionary attack. [06:13.840 --> 06:16.360] We have a nice big 60 megabyte or so dictionary file. [06:16.460 --> 06:19.460] I'm sure some of you have bigger ones and you can boast about it later, but I don't really care. [06:20.080 --> 06:20.820] It's good enough. [06:21.040 --> 06:26.080] We do some munging stuff to the end of it and do some alternating cap stuff in it, but it makes the key space fairly small. [06:26.440 --> 06:27.420] It's fairly fast. [06:27.680 --> 06:33.660] First thing you do, because it only takes a couple of minutes on a modern machine, and with a single machine, that's great. [06:34.240 --> 06:44.640] The next thing we do is we try to attack the encryption itself, which is, for the most part, pretty weak, unless you're talking about people who really care. [06:44.980 --> 06:48.340] Once again, in the work we do, most people actually don't care. [06:48.700 --> 06:54.360] And they might put a password on a file, but they have no idea what that really does, and they're not unaware that they're truly protected. [06:55.380 --> 06:57.700] If it's under six characters, just brute force it. [06:57.780 --> 06:59.020] It's faster on a modern machine. [06:59.200 --> 07:04.780] But if it's bigger than eight characters, we always try to consider running it across a distributed network if it's possible. [07:05.340 --> 07:07.440] So there's different kinds of distributed computing. [07:07.620 --> 07:08.920] There's big-ass iron machines. [07:09.220 --> 07:17.520] Sun has 24 processors and a giant mini cabinet box, and it's very, very, very, very expensive, but they're really fast. [07:18.320 --> 07:26.780] There's commodity clusters, and that's just you go and buy 20 machines that are identical, string them together with gigabit, and say, okay, here's my big computer. [07:26.960 --> 07:33.400] And you run an MPI kind of thing across it, which we'll get into later, which kind of strings them all together in some mechanism. [07:33.900 --> 07:46.160] But then there's a heterogeneous distributed clusters, which is what we're all kind of familiar with, with distributed.net, and SETI at home, and you and your friends' computers who kind of maybe link together in some mechanism. [07:46.520 --> 07:57.440] Or in our case of our office, we have our big commodity cluster, but we also have all the desktops that are all over the place, and people's palm pilots, and we have anything that we can squeeze CPU bandwidth out of. [07:57.620 --> 07:58.540] And so we do. [07:59.000 --> 08:00.340] And they're all really strung together. [08:01.060 --> 08:03.820] Anything that has a network can be part of a large cluster. [08:05.540 --> 08:07.160] So the heterogeneous distributed clusters. [08:08.260 --> 08:09.320] Doesn't matter what kind of hardware. [08:09.560 --> 08:10.580] Doesn't matter what kind of OS. [08:10.740 --> 08:12.260] You don't know how long it's on the network. [08:12.360 --> 08:13.900] You don't know how long it's going to be off the network. [08:14.500 --> 08:19.300] You don't know if it's gigabit, Ethernet, mirrornet, infiniband, whatever the case may be. [08:19.400 --> 08:22.480] As long as it speaks TCP IP, it's great. [08:22.640 --> 08:24.080] The problems are exactly those. [08:24.580 --> 08:29.600] You can't assume always that you know what the computer is that you're dealing with. [08:29.660 --> 08:35.260] You just have to assume that it can run TCP IP and maybe can run the program that you compiled. [08:35.430 --> 08:36.500] So that's the problem. [08:36.640 --> 08:38.540] The biggest problem we see is message latency. [08:39.140 --> 08:45.640] Unless you're dealing with an interconnect like mirrornet or infiniband, the latency period in between packets is incredibly slow. [08:45.810 --> 08:48.420] I mean, we think of gigabit as being fast, but it just isn't. [08:48.570 --> 08:52.760] When you're talking about the space in between individual packets, it takes a long time. [08:52.760 --> 08:54.240] It takes time for them to talk to each other. [08:55.670 --> 08:59.190] Differences in processor speed are an issue when you're dealing with this kind of stuff. [08:59.450 --> 09:07.880] Because, you know, if you say this task is yay big, and all the computers get the same size task, some of them just can't deal with it, and some of them deal with it too quickly. [09:08.040 --> 09:13.690] So you end up having a lot of computers waiting, and a lot of computers not waiting, instead of all of them doing work all the time. [09:14.050 --> 09:23.090] So you always want to do what's called watermarking in supercomputing to keep the level, to keep all the different computers working all the time, no matter what speed they are, no matter how fast they are. [09:23.970 --> 09:27.360] And the other issue is uptime of each machine. [09:27.550 --> 09:34.170] Some machines are on your network for 20 minutes, some are on the machine on there for hours, some need to have other work done to them that go back and forth. [09:34.920 --> 09:39.900] You really have to write your API to deal with that. [09:41.900 --> 09:54.900] So, yeah, distributed heterogeneous projects, SETI at home, distributed dot net, and the kind of graphic rendering that we did at Pixar, where we have our big computers, but then idle time on people's personal desktops also went to it, dealing with things like, [09:54.920 --> 09:58.970] you know, SGIs and HPs and all sorts of computers, all kind of doing the same stuff. [10:00.710 --> 10:05.620] So, back to the... back to brute forcing stuff. [10:05.970 --> 10:08.430] So, there's different ways you can brute force a password. [10:09.540 --> 10:19.420] One is to use an algorithm that figures out what the pronounceable-ish words are, and only run them against it, as opposed to doing all possible combinations, which lessens your key size quite a bit. [10:20.970 --> 10:27.670] Most of the stuff that we see are protected by only lowercase and uppercase and numbers only, so only alphanumeric characters, no special characters. [10:27.920 --> 10:38.930] We don't usually run against special characters, just simply because the possibilities in our work of them being special characters in some password-protected file, some lawyer did, is virtually none. [10:39.860 --> 10:47.520] Most of our stuff is just lowercase, so we always just try that, and searching an eight to ten character key space of a lowercase is fairly fast. [10:48.450 --> 10:53.540] And so, let's say you have six-character alphanumeric password on a Pentium 4. [10:53.690 --> 10:58.330] It takes about twelve hours against a ZIP file or a local crypt file per password. [10:58.970 --> 11:02.520] An eight character password all of a sudden jumps to about 2,537 days. [11:03.800 --> 11:07.140] And that's assuming that the machine is completely dedicated to that task. [11:07.320 --> 11:13.380] So you see the problem that we have is that once it gets to that point, it all of a sudden is a much harder issue to crack. [11:13.560 --> 11:14.740] So hence distributed stuff. [11:16.970 --> 11:17.380] Yeah. [11:17.660 --> 11:17.920] Yeah. [11:18.120 --> 11:19.040] That's on one machine. [11:20.120 --> 11:21.940] So there's different ways to do distributed cracking. [11:23.090 --> 11:26.420] You can cut a search space into different parts and have each cracker be independent. [11:26.660 --> 11:29.540] There's a distributed John the Ripper thing called D-John that's out there. [11:30.240 --> 11:38.540] And D-John is interesting in that basically what you do is you take each instance of John the Ripper and you put it on four or five or blah, blah, blah different amount of machines. [11:38.830 --> 11:41.900] And you say, the first one goes through A through B. [11:42.020 --> 11:43.760] The next one goes to C to D. [11:43.940 --> 11:46.380] And you just give it a limited key space to search. [11:46.520 --> 11:47.900] And you just say, okay, go. [11:48.180 --> 11:50.860] And when everyone comes back with it, comes back with it and then that's it. [11:52.090 --> 11:56.210] This is kind of inefficient because, as I said, you have to know exactly what machines you're dealing with. [11:56.300 --> 11:57.560] You have to own these machines yourself. [11:58.400 --> 12:01.040] You have to know when you're allowed to use them and when you can't. [12:01.460 --> 12:06.440] Because if someone stops one of those processes in the middle and that's where your password is, it's lost and you'll never find it. [12:07.120 --> 12:15.460] But distributed John the Ripper is a good way to do stuff like WEP cracking and other kinds of brute forcing that you might come up against. [12:16.320 --> 12:18.580] You can use a queuing system like a network renderer. [12:19.080 --> 12:23.780] And what you do there is that you just have a large task space that's such as frames in an animation. [12:24.440 --> 12:28.210] And each one is fairly large and each computer just grabs one and works on it. [12:28.280 --> 12:29.660] And when it's done, it puts it back into it. [12:30.240 --> 12:32.500] There's not a lot of communication between the clients and the servers. [12:32.580 --> 12:34.740] They just communicate when they're done and only when they're done. [12:35.880 --> 12:37.860] So you can't really understand if things have aborted. [12:37.970 --> 12:39.620] There's no transactional locking. [12:39.760 --> 12:40.500] There's nothing like that. [12:41.330 --> 12:43.320] But it does in fact work. [12:43.470 --> 12:44.260] And that's what most systems are. [12:44.780 --> 12:45.090] What's up? [12:47.780 --> 12:50.200] Well, there's lots of different ones depending on what software you're using. [12:50.400 --> 12:54.560] But there's queue systems like... there's one that you can use generic queuing for. [12:54.800 --> 12:57.000] Like you can use any kind of thing that you want to queue up. [12:57.090 --> 12:59.920] Whether it be bash scripts or whatever you want. [13:00.020 --> 13:01.960] And that is actually really cool for password cracking. [13:02.210 --> 13:03.160] And it's called PBS. [13:11.820 --> 13:13.080] And there's [13:21.260 --> 13:23.900] a portable batch scheduler, I believe. [13:24.760 --> 13:25.820] And but... what? [13:27.320 --> 13:32.240] Yes, that would be P and B and then S. [13:33.500 --> 13:34.210] Cool stuff. [13:34.920 --> 13:37.400] Actually, it's a very cool tool that hackers should get used to. [13:37.590 --> 13:40.200] It's officially open source, but it's not GPL. [13:40.520 --> 13:42.710] You have to fill out some registration form to get it. [13:43.320 --> 13:45.880] And when you get the open version, there's no docs for it. [13:46.000 --> 13:47.260] So, it's fun. [13:48.860 --> 13:50.120] In that really awful way. [13:50.320 --> 13:56.960] But if you want to pay an obscene amount of money, you can get the non-open PBS version and, you know, do it that way. [13:57.140 --> 13:57.970] But who wants that? [13:59.040 --> 14:07.280] And that's really cool because you can just say, like, you know, look, I have a billion crack scripts on a billion machines and I'm just going to queue them all up and just going to do it that way. [14:08.090 --> 14:12.620] And then the other way to do distributed cracking is using a tuple-based messaging system. [14:12.620 --> 14:17.380] Like MPI or Java spaces or T spaces, which is what I'll be mostly talking about. [14:17.920 --> 14:23.860] MPI is a very robust system for passing messages between clients and servers. [14:24.020 --> 14:25.470] It doesn't really differentiate between the two. [14:25.680 --> 14:29.740] And it's useful for communication between processes. [14:29.970 --> 14:30.800] It's kind of like a... [14:30.800 --> 14:39.960] So, it builds up on... It builds against RPC kind of things and remote method invocation and distributing objects across networks and having them talk to each other. [14:41.900 --> 14:43.860] So, tuples are a message-based system. [14:44.640 --> 14:53.000] Basically, you have a pool of tasks and each waiting computer takes one and it communicates fairly consistently back to the server telling it what kind of process it's on with it. [14:53.740 --> 14:57.260] If it fails, then it says, okay, put it back in the pool and I'll deal with transactions. [14:57.940 --> 15:04.470] And it takes advantage... It takes different advantage of speeds between different computers and different networks because it says, okay, this guy's a little slower. [15:04.560 --> 15:05.300] This guy's a little faster. [15:05.420 --> 15:06.140] We'll give him this chunk. [15:06.260 --> 15:07.000] We'll give him this chunk. [15:07.180 --> 15:11.360] And you can kind of manipulate that via things like MPI and Java spaces. [15:16.650 --> 15:20.430] The clients only talk to the... Well, it depends which system you're talking about. [15:20.650 --> 15:22.310] It depends how you have it coordinated. [15:22.610 --> 15:28.290] For the most part, since I tend to work on a closed network, I just have a machine being the task manager kind of. [15:28.490 --> 15:34.130] And he just distributes the tasks to the computers so he can maintain which guy's busy, which guy's not busy. [15:34.130 --> 15:45.030] You can have the clients all be completely heterogeneous and not understand who is a server, who is a client, and just take a task pool from, like, a file server and they're unaware of each other. [15:45.130 --> 15:46.830] And that does, in fact, work pretty well. [15:48.310 --> 15:50.510] They don't have to communicate to a server if you don't want them to. [15:50.710 --> 16:03.070] If you don't need to have a central place to get results and things like that, and you just want to check each client individually, yeah, they don't have to communicate with anything other than the initial task list, which they can get when they instantiate and never again. [16:07.150 --> 16:08.810] So, well, that's awesome. [16:09.430 --> 16:11.390] The QuickTime and TIFF uncompressed depression. [16:11.850 --> 16:14.290] Well, it's a cool picture of how tuple space works. [16:14.450 --> 16:15.270] It's really neat. [16:16.970 --> 16:17.710] It's amazing. [16:17.930 --> 16:18.970] You've never seen anything like it. [16:19.130 --> 16:19.910] It's unreal. [16:20.030 --> 16:25.610] No, basically the picture is you have several little client things. [16:25.710 --> 16:27.070] Here, I'm going to try to do this in interpretive dance. [16:27.690 --> 16:30.010] You have several little client things, right? [16:30.110 --> 16:37.790] And all the separate little client things take an entry from a central space, whether it's on a machine or they get it when they instantiate initially. [16:38.790 --> 16:41.330] And then they process it, and then they put it back. [16:41.670 --> 16:44.590] And they don't have to talk to each other, and they can, but they don't really have to. [16:44.810 --> 16:47.950] And that's why message passing is a really cool technology. [16:49.850 --> 16:54.050] So MPI is the most prominent message passing interface, which is why it's called MPI. [16:54.050 --> 16:55.950] And that's M-P-I. [16:57.750 --> 17:00.050] MPI is C-based API. [17:00.450 --> 17:05.210] I believe there's a C++ interface for it too, but it's C-based, and it's really robust. [17:05.370 --> 17:11.670] It's fairly portable if you're willing to put the libraries it requires and all the other things it requires on each machine. [17:11.930 --> 17:13.490] It does, in fact, work on Windows. [17:15.010 --> 17:18.430] It sort of works on Mac OS X, kind of, enough. [17:19.070 --> 17:19.250] It does. [17:19.570 --> 17:24.350] Apple has their own version of it they've been releasing for doing their big X serve distributed things. [17:24.570 --> 17:27.750] And they write on top of the MPI interface. [17:27.990 --> 17:28.650] So it kind of works. [17:29.470 --> 17:31.310] It's not very user friendly. [17:31.750 --> 17:38.450] There's a lot of documentation out there about it, but it really requires quite a bit of knowledge of not just C, but networking in general. [17:38.770 --> 17:41.490] And it's very ugly looking code once it starts happening. [17:42.230 --> 17:45.430] Even if you think you write pretty code, it just does not look good. [17:45.650 --> 17:48.670] It's got very heavy overhead when it comes to the network itself. [17:48.930 --> 17:50.650] It does pass a lot of messages. [17:51.610 --> 17:54.090] And each one of them is quite substantially large. [17:54.270 --> 17:59.650] And it ends up being a detriment to your program when you start dealing with heavy, heavy, heavy overhead. [18:00.410 --> 18:03.990] And you don't think about your network as being the bottleneck, but it ends up being the bottleneck. [18:03.990 --> 18:07.990] Even if you're not passing real data through it, it just ends up being very slow because of the latency. [18:10.170 --> 18:14.170] It doesn't force you to have a lot of structure and it goes back to the not pretty code. [18:14.370 --> 18:17.730] I mean, you can kind of write however you want and it will kind of still work. [18:18.710 --> 18:21.070] What's great about it is it's really, really, really fast. [18:21.250 --> 18:22.230] And it's really robust. [18:22.430 --> 18:24.650] And it's been used for ten years or more. [18:24.830 --> 18:26.130] And people have it all over the place. [18:26.230 --> 18:27.370] And it works really, really well. [18:28.810 --> 18:30.750] T-Space is the Java's... [18:31.310 --> 18:32.690] IBM's Java grid project. [18:32.690 --> 18:35.990] And just released it open source pretty recently. [18:36.250 --> 18:37.770] And it's under one of those weird IBM licenses. [18:38.870 --> 18:40.570] IBM funds it, which makes it... [18:40.570 --> 18:45.250] You know, it's progressing fairly fastly because IBM is funding it. [18:45.350 --> 18:51.270] But unfortunately, it's not completely open. [18:51.530 --> 18:54.430] And beyond that, it's fairly easy to use it. [18:54.510 --> 18:56.230] It's Java and people have problems with Java. [18:56.490 --> 18:57.110] I don't. [18:57.850 --> 18:59.850] So Java space is what I write in. [18:59.950 --> 19:00.730] Java space is... [19:00.730 --> 19:01.290] It uses Java. [19:01.730 --> 19:04.990] It's really portable as long as the machine has a JVM 1.2... [19:05.750 --> 19:06.370] JVM on it. [19:06.970 --> 19:08.690] And it can run as a client or a server. [19:08.850 --> 19:10.290] It doesn't really matter where you kind of put it. [19:11.130 --> 19:15.450] Using JNI, you can tie in whatever existing C code you have that you use for cracking into it. [19:16.070 --> 19:24.910] And it supports transactions, which is a really, really cool feature for supercomputing and distributed computing, especially if you hypothetically take over a computer and use it as a zombie host. [19:25.330 --> 19:31.770] Because if the process that it's doing fails, it'll put it back into the queue for other computers to get. [19:32.750 --> 19:39.570] So that way, if your stuff is within that key space that it's...that the failed computer is searching on, you can get it back somehow. [19:39.810 --> 19:41.330] You can continue to work on it. [19:42.470 --> 19:45.310] So the Java space's API is fairly simple. [19:45.470 --> 19:47.870] You just need two objects. [19:47.870 --> 19:48.890] You need a task entry. [19:49.090 --> 19:51.410] And that's the actual thing that gets submitted. [19:51.590 --> 19:57.090] And it contains the code that...that does the actual cracking, which I'll show in a minute. [19:57.690 --> 20:02.830] Such as your crypt routine or your brute force against the website routine or whatever the case may be. [20:04.150 --> 20:07.210] And then you have the entry, which is the result. [20:07.490 --> 20:08.470] And that's all you need. [20:08.730 --> 20:14.010] The entry stuff is really generic and you just write one ten line thing for your entry and that's that. [20:14.010 --> 20:16.930] The task entry can get fairly large. [20:17.130 --> 20:20.310] But even so, all that has to contain is a single method. [20:20.430 --> 20:22.930] And in that method, you have your cracking routine and that's all you need. [20:23.210 --> 20:25.570] And everything else is pretty much taken care of by the API. [20:27.810 --> 20:32.210] So here's one of...here's one of my execute methods. [20:32.370 --> 20:34.410] It's the only method that you need in this task entry space. [20:34.530 --> 20:35.610] And it returns the entry. [20:36.030 --> 20:37.550] And this is for cracking a website. [20:37.550 --> 20:45.290] So first thing it does is it says the for loop involves the number of times each task is going to try things. [20:45.570 --> 20:51.010] One of the interesting things about supercomputing is that you don't want each worker to just try things once and go back. [20:51.130 --> 20:52.510] You want it to try a large subset. [20:52.710 --> 20:58.830] But not too large to overwhelm it, but large enough that it's not spending a lot of time talking back to the server to get more tasks. [20:58.830 --> 21:00.490] So you want it to take a large subset. [21:00.830 --> 21:06.050] So for cracking a website, I'd say each worker takes 100,000 to 200,000 passwords to try. [21:06.530 --> 21:10.910] So, you know, for one...for 0 to 200,000, essentially, you should think of this as. [21:11.370 --> 21:12.610] And it gets a URL. [21:12.850 --> 21:14.230] Gets a connection to the URL. [21:15.950 --> 21:19.790] Uses the authorization, normal basic authorization, username and password. [21:20.790 --> 21:21.430] Sends it. [21:22.070 --> 21:26.930] And then the brute result, it sees if the result is valid. [21:28.270 --> 21:31.090] And if not, it tries another word. [21:31.250 --> 21:32.110] It just keeps doing that. [21:32.250 --> 21:36.490] And then when it exhausts its entire space, it just goes and gets another 200,000 passwords to try. [21:36.930 --> 21:38.310] Or whatever the case may be. [21:38.490 --> 21:44.730] So that's all you really need to do to make the API work for any kind of cracking that you want to do that takes brute forcing. [21:44.970 --> 21:46.210] And it's more than just passwords. [21:46.350 --> 21:48.290] You can do any task that you need to do a lot of it. [21:48.410 --> 21:50.230] And do it to a lot of computers, you can do. [21:50.630 --> 22:02.530] And the cool thing about that is that when you attack with Java spaces, if you're going to attack a machine using a distributed attack, all you need, as I said, is JVM on that other machine. [22:02.690 --> 22:04.290] And that will be a worker for you. [22:04.650 --> 22:16.390] And as long as it has access to the server that it's getting the task list from, unless it gets them upon substantiation, you can just... wherever you are, you can get part of that task. [22:16.390 --> 22:21.950] So if you hypothetically took over 2,000 machines, those could all be part of your little computer. [22:22.310 --> 22:24.770] And you can just use them whenever you want if no one notices you. [22:26.250 --> 22:37.470] So like a worm with Java spaces client payload, instead of having a DDoS zombie, you can set up a large distributed supercomputer to crack passwords, to attack websites, to do whatever it is. [22:37.470 --> 22:42.030] Because it's a lot more interesting of an attack and dangerous of an attack than a simple DDoS. [22:43.430 --> 22:44.550] The client is pretty small. [22:45.870 --> 22:51.530] As long as the machine has Java, as I said, the client is 10K or so. [22:51.750 --> 22:52.350] Probably smaller. [22:53.130 --> 22:54.210] Unfortunately, it is traceable. [22:54.350 --> 23:00.010] I mean, if it has to communicate back to the server if you've written your program that way, you can see it going back to the server a lot. [23:00.010 --> 23:01.970] And that obviously becomes traceable. [23:02.290 --> 23:12.970] Unless, of course, you put your machine on a Wi-Fi network somewhere hidden, hypothetically, in Boston and walk away from it and, you know, and use a disposable card that you pay for in cash, hypothetically. [23:14.310 --> 23:16.110] If you did that, it would not be as traceable. [23:16.190 --> 23:16.990] They would find it eventually. [23:17.130 --> 23:19.530] But ha, ha, ha, you're drinking coffee in the same cafe. [23:20.590 --> 23:20.910] Hypothetically. [23:22.250 --> 23:23.910] Because I don't like coffee, so it's not really me. [23:26.050 --> 23:35.890] Any repeatable task can be distributed with any kind of distributed system, be it Java spaces, or be it MPI, or be it whatever kind of attack you can think of. [23:36.090 --> 23:38.390] I did password cracking simply because that's what we do. [23:38.690 --> 23:42.530] I wrote a wrapper around the Java spaces thing called burn spaces for right now. [23:42.650 --> 23:51.830] I'll probably change it to something stupid, but it's burn spaces for right now that makes it really easy for you just to use an XML file to configure whatever attack you want to do. [23:52.030 --> 23:52.970] You submit it, and that's it. [23:53.630 --> 23:55.590] That's what's going to go in SourceForge later today. [23:55.830 --> 23:57.870] So you don't even have to really know the Java to get it working. [23:57.970 --> 24:05.170] You just have to know XML to build a certain kind of XML schema for it to use to attack whatever things you need to attack. [24:06.670 --> 24:10.070] But if anything that you can think of to brute force, distributed computing does work. [24:10.250 --> 24:16.430] Most clients are very small, so you can put them on any kind of computer you have lying around your house or someone else's house, for that matter. [24:16.850 --> 24:24.110] I did put Java spaces on a Palm pilot, my Palm phone, and this thing cracks about 500 passwords a second. [24:24.330 --> 24:24.770] It's amazing. [24:25.290 --> 24:26.910] That's what it cracks about, which is nothing. [24:27.210 --> 24:29.050] But still, it's kind of cool because it works. [24:29.770 --> 24:31.030] So here are some resources. [24:31.330 --> 24:34.910] You probably can't see them because I suck, but there are some resources. [24:36.050 --> 24:38.490] And now if anyone has any questions, I will answer questions. [24:38.490 --> 24:41.230] But if you don't, then... [24:53.240 --> 24:53.720] I'm fine. [25:07.980 --> 25:11.200] This is where all of the law enforcement officers go, ooh, fresh bait. [25:12.820 --> 25:14.280] Okay, I have a question. [25:14.460 --> 25:18.160] You were talking about other forms of distributed computing and that sort of thing. [25:18.360 --> 25:18.580] Yeah. [25:20.060 --> 25:28.240] I was playing a little while ago with OpenMozix and the OpenMozix auto-discovery daemon. [25:28.320 --> 25:29.080] Cool that you bring that up. [25:29.380 --> 25:29.580] Yeah. [25:29.760 --> 25:35.840] And there's actually on the Knoppix STD live CD... [25:36.160 --> 25:37.020] Could you spell STD, please? [25:38.580 --> 25:39.180] STD. [25:39.320 --> 25:39.860] Okay, everyone. [25:40.440 --> 25:41.460] It's very hard. [25:42.020 --> 25:42.620] S... [25:42.620 --> 25:43.560] T... [25:43.560 --> 25:43.900] X. [25:44.100 --> 25:44.340] No. [25:44.340 --> 25:50.340] It's STD as in Security Tools Distribution, not as in... [25:51.240 --> 25:51.620] Well, anyway. [25:52.740 --> 25:53.380] Yeah. [25:53.820 --> 26:04.360] And there's actually this one tool on there called Cecilia, which is for cracking Windows, you know, SAM passwords for NT2000, that sort of thing. [26:04.360 --> 26:17.630] And it's designed to figure out if you are on a Mozix cluster, at which point it will figure out how many nodes are on the cluster and will fork that many times. [26:18.100 --> 26:18.260] Right. [26:18.400 --> 26:21.000] And each process will go to each node. [26:21.120 --> 26:22.020] And it's actually quite neat. [26:22.280 --> 26:22.900] So... [26:22.900 --> 26:28.220] But that would work, wouldn't it, using the techniques you described here? [26:28.460 --> 26:28.660] Yeah. [26:28.820 --> 26:29.400] With Mozix? [26:29.880 --> 26:31.900] Mozix is actually a good thing you brought up. [26:32.020 --> 26:42.060] Mozix and OpenMozix, which are different, but let's say OpenMozix for intents and purposes, is a really cool project for distributing any kind of tasks that's threaded against... [26:42.960 --> 26:44.100] to multiple computers. [26:44.900 --> 26:47.040] Not easily manageable, the threads, unfortunately. [26:47.340 --> 26:51.520] So the transactioning kind of things aren't really there, if that's what you acquire. [26:51.640 --> 26:59.340] So, in other words, if you put OpenMozix on machines that aren't yours, hypothetically, and that means both legally and illegally stuff. [26:59.560 --> 27:05.640] But if you put stuff against machines that aren't yours, you can't really control so much what they're doing. [27:05.800 --> 27:09.340] OpenMozix tends to just spread the threads as much as humanly possible. [27:09.540 --> 27:13.200] And you can't really control which machines they go to once they've started. [27:14.480 --> 27:19.940] So if you have fairly large tasks going to each machine, you just have to hope they get it done right. [27:20.060 --> 27:21.560] And if they don't, you're kind of screwed. [27:21.560 --> 27:30.480] But in general, if you don't really care about the transaction kind of element of it, OpenMozix is a really cool solution for doing all different sorts of things that are threaded. [27:30.680 --> 27:36.020] The other problem is, it requires the writer of the code to know POSIX threads really well. [27:36.220 --> 27:40.500] Because you'll find lots of weird problems that creep up while you're writing OpenMozix code. [27:41.940 --> 27:44.960] If you're confident with your thread routines, hey, knock yourself out. [27:45.900 --> 27:47.580] If you're not, don't try it. [27:47.700 --> 27:48.860] Because it will fail a lot. [27:49.060 --> 27:51.620] And you'll have a lot of memory leaks and problems like that. [27:52.680 --> 27:52.920] Cool. [27:54.100 --> 27:56.960] Can you put any other type of passwords... [27:56.960 --> 28:03.140] Well, not passwords, but another type of database instead of passwords, like a password list, like a dictionary list? [28:03.160 --> 28:04.200] Can you put something else? [28:04.840 --> 28:11.280] Like different types of strings or different types of, you know, characters or anything like that? [28:11.280 --> 28:17.400] I mean, if you're going to crack a password, you have your character set, however long it is, whatever it is. [28:17.680 --> 28:20.820] And you can iterate through every possibility within that character set. [28:21.520 --> 28:22.980] Or you can generate your own dictionary. [28:23.200 --> 28:31.360] If you're going to do a dictionary attack, or a small area brute force attack against six characters or less, just use one computer, so you don't have to worry about any kind of distributed anything. [28:32.780 --> 28:36.700] Like, let's say for a password has 18 characters or more than that. [28:36.900 --> 28:37.000] Right. [28:37.120 --> 28:42.360] Can you actually distribute it and make a huge database of it? [28:43.320 --> 28:45.480] Well, can you kind of rephrase the question? [28:45.600 --> 28:45.860] All right. [28:46.120 --> 28:47.980] For example, let's say I have a character. [28:49.020 --> 28:50.840] A password is 18 characters long. [28:51.180 --> 28:51.280] Right. [28:51.300 --> 28:52.080] And I need to... [28:52.080 --> 28:53.360] I have a dictionary. [28:53.360 --> 28:58.360] I have to make a dictionary of different possible 18 character passwords. [28:59.360 --> 29:02.520] And I want to distribute all those within the network. [29:03.620 --> 29:03.940] Okay. [29:04.800 --> 29:05.180] Yeah. [29:05.300 --> 29:05.960] I mean, yeah. [29:06.200 --> 29:06.580] Absolutely. [29:06.660 --> 29:09.780] You can distribute a dictionary across if it's that size of a dictionary attack. [29:09.940 --> 29:10.240] Absolutely. [29:10.520 --> 29:10.760] Okay. [29:10.880 --> 29:17.360] In the same way you do this, you would set up the dictionary as a large task and say the first 100,000 words go here, the next 100,000 go here. [29:17.360 --> 29:18.680] Is there a way I could calculate it? [29:18.680 --> 29:25.340] Like you had for one machine on a regular brute force, it was like 200 and something. [29:25.340 --> 29:25.440] Okay. [29:25.600 --> 29:25.840] Well, yeah. [29:25.880 --> 29:28.840] The way you do it is you say how long is the key space you're dealing with? [29:29.040 --> 29:29.480] So how many... [29:29.480 --> 29:30.140] Well, basically the space. [29:30.340 --> 29:31.460] Does the space matter? [29:31.680 --> 29:35.940] You know, if I have like a five gig database of passwords. [29:36.160 --> 29:36.300] Right. [29:36.520 --> 29:41.280] And I have to distribute it within, you know, 20 something machines. [29:41.780 --> 29:42.960] Does it really matter? [29:43.180 --> 29:43.900] Is it really... [29:43.900 --> 29:44.680] Is there... [29:46.240 --> 29:46.660] No. [29:47.160 --> 29:47.820] Not really. [29:47.820 --> 29:51.720] As long as you manage what machines get what pieces and you manage your tasks as well. [29:51.740 --> 29:55.240] Is there a calculator where I could calculate how many... [29:55.240 --> 29:56.360] Or a math or some... [29:56.360 --> 29:56.720] Yeah. [29:56.940 --> 29:57.000] Okay. [29:57.120 --> 29:57.400] Here's... [29:57.400 --> 29:58.920] The math is exponential math. [29:59.060 --> 30:04.340] It's basically you take how many possible characters you're dealing with. [30:05.060 --> 30:05.460] Okay. [30:05.820 --> 30:08.560] And the exponent is how many characters you're dealing with. [30:08.700 --> 30:13.780] So in the ASCII set it would be 95 to the 18th power if you're dealing with an 18 character password. [30:14.160 --> 30:14.420] Okay. [30:14.440 --> 30:17.220] And that's how many permutations it has to do to go through it all the way. [30:17.220 --> 30:18.480] Which is be huge. [30:18.820 --> 30:19.120] Yeah. [30:19.320 --> 30:19.760] Yeah. [30:19.880 --> 30:20.600] You don't want to do that. [30:20.760 --> 30:21.240] That's... [30:21.240 --> 30:21.920] That's really bad. [30:24.900 --> 30:25.460] Hello. [30:25.780 --> 30:28.440] I'm fairly new to distributed computing. [30:28.660 --> 30:31.880] And the question I had was... [30:33.440 --> 30:34.480] How do you... [30:34.480 --> 30:35.120] Or is... [30:35.120 --> 30:43.020] Are there provisions in the API that handle hosts or clients that accept a task but don't perform the work? [30:43.860 --> 30:45.860] Is that handled by the Java spaces? [30:46.320 --> 30:47.360] Java spaces is... [30:47.360 --> 30:47.680] Portion of it? [30:47.820 --> 30:47.980] Yeah. [30:48.280 --> 30:51.760] Java spaces handles all the lower level everything. [30:52.380 --> 30:56.040] And you just call an object to deal with whatever function that you want. [30:56.120 --> 30:57.460] It really covers just about every kind of... [30:57.460 --> 31:00.020] Is there some sort of configurable time out that occurs? [31:00.020 --> 31:00.460] Yep. [31:01.280 --> 31:01.640] There's... [31:01.640 --> 31:04.000] You can set tons of different variables in it. [31:04.080 --> 31:07.800] And the Java spaces API requires, you know, there's a 250 page book for it. [31:07.980 --> 31:08.220] Okay. [31:08.320 --> 31:13.240] But, you know, whatever you can think of it for it to do, it pretty much will do. [31:15.060 --> 31:16.700] You can do time outs for APIs. [31:16.860 --> 31:18.320] You can have how long an API should wait... [31:18.320 --> 31:20.240] A host should wait before it gets a task. [31:20.300 --> 31:23.360] How long it should work on a task before it gets rid of it and puts it back into the queue. [31:24.140 --> 31:25.160] All those kinds of things. [31:26.060 --> 31:32.100] And the burn spaces wrapper around the Java API, which, as I said, I'll put up today, does have... [31:32.100 --> 31:34.380] Part of the XML does have all those kinds of features. [31:35.160 --> 31:40.140] I obviously don't cover all possible features that Java spaces covers, but I do cover a nice chunk of them. [31:40.140 --> 31:40.640] Cool. [31:40.980 --> 31:41.240] Cool. [31:45.700 --> 31:46.220] All right. [31:46.320 --> 31:47.860] Well, if you want me, I'm sticking around today. [31:48.040 --> 31:48.600] I'll be around somewhere. [31:48.820 --> 31:49.440] So that's all. [31:50.360 --> 31:50.840] Oh, wait, wait. [31:51.140 --> 31:51.320] Okay. [31:52.320 --> 31:52.720] Go on. [31:54.540 --> 31:57.980] Actually, just before you finish, I just remembered one thing. [31:58.140 --> 32:22.700] If anyone in this room, and I'm assuming you all know how to use the GPG encryption program, if people here do not want people like myself or him or just other people running attacks on their passwords, I highly recommend you download a word list, which is called the Diceware word list. [32:22.700 --> 32:32.060] And with Diceware, you can generate a password by taking five dice, and you roll them, and you read the dice from right to left. [32:32.240 --> 32:39.960] And from the corresponding numbers, you look those numbers up on your Diceware word list, and that gives you a word. [32:39.960 --> 32:56.620] And if you have a five to seven word passphrase, that will actually, it's strong enough that chances are that won't be cracked in the next, like, hundred million years, unless we have, you know, some breakthrough in quantum computing. [32:56.740 --> 32:58.100] Actually, yeah, that brings up a good point. [32:58.840 --> 33:11.320] Passwords aren't the best way to secure things, but if you're going to use them, anything over ten characters is almost completely sufficient, as long as you have a couple of alternating things, because the key space for ten characters with 95 possible things, [33:11.540 --> 33:15.700] especially if it's not dictionary recognizable, is just beyond huge. [33:15.740 --> 33:20.620] And we're talking 10,000 computers to take weeks to even put a dent in it. [33:20.780 --> 33:24.500] So, just make it ten characters, and then you're pretty much okay. [33:24.740 --> 33:32.000] And don't use a dictionary, something that's in a dictionary, or in any language, because my dictionary has Polish stuff to it for some reason. [33:34.890 --> 33:35.470] What's that? [33:36.570 --> 33:42.930] How difficult, well, comparatively, to, like, to crack Windows password versus, like, PEP passphrase? [33:43.970 --> 33:45.050] Oh, um... [33:45.050 --> 33:46.570] Or zip file passwords. [33:47.010 --> 33:49.390] I mean, but if Windows, you mean, like, the SAN, the, um... [33:49.390 --> 33:52.350] Sorry, the LAN man passwords. [33:53.110 --> 33:59.350] Um, L0phtcrack, which is a really good cracking software, um, and it's probably the best, uh, give props to Boston. [33:59.630 --> 34:06.270] It's probably the best, uh, cracking software out there, uh, for doing LAN man passwords, and it does it well. [34:06.590 --> 34:11.690] And I would recommend just doing that on a single computer, as opposed to distributing that. [34:11.890 --> 34:18.150] Because the way that you can crack the LAN man passwords, um, it just, you don't need the kind of brute force that you would otherwise. [34:19.550 --> 34:20.850] Uh, L0pht... [34:20.850 --> 34:20.950] L0pht... [34:20.950 --> 34:21.110] L0pht... [34:22.170 --> 34:22.730] Yeah. [34:23.470 --> 34:25.490] L0phtcrack is L0... [34:31.850 --> 34:33.790] Yes, because we're hackers and that's what we do. [34:35.790 --> 34:40.150] Um, I was just wondering, uh, how does the cracker know when it's done? [34:40.150 --> 34:46.510] And also, if you're trying to get a URL, how do you know, how is it intelligent enough to see what's gone in? [34:46.510 --> 34:49.610] It's built into the result thing called the entry object. [34:49.890 --> 34:52.570] If it's not null, it's done. [34:52.650 --> 34:53.750] If it is null, it isn't. [34:53.970 --> 35:00.390] And isn't it possible that if you're distributing this, say you're trying to get into a website, you might cause a DDOS attack? [35:00.470 --> 35:00.910] Absolutely. [35:01.110 --> 35:07.670] We've tested this against plenty of websites and the activity is extremely noticeable using a thousand hosts against the website. [35:08.670 --> 35:17.990] The thing is, though, unless you're doing serious log watching, unless you're a serious sysadmin, you don't notice that stuff unless someone calls you and says, hey, the website's really slow. [35:18.190 --> 35:26.230] And that's what's cool about supercomputing and watermarking, which is the idea that, let's say you only want 40 tasks going at a time, even if you have a thousand computers you're using. [35:26.610 --> 35:33.130] So some of the computers will have a lot of idle time, but you can maintain it so you're only having like 40 little attacks at a time out of the thousand machines. [35:33.610 --> 35:36.530] And each one waits quite a while before it takes another task. [35:38.290 --> 35:40.890] So there are ways to avoid being noticed. [35:41.050 --> 35:44.970] I mean, I'm surprised we haven't seen more attacks like this against websites. [35:44.990 --> 35:49.830] It's a really easy way to get passwords and people don't really watch their logs well enough. [35:49.930 --> 35:54.810] They watch it and they have some alarm systems that say like, oh, this one host keeps trying. [35:54.810 --> 36:02.890] But when you're talking about, when you're talking about like, you know, 50 hosts or a hundred hosts or a thousand hosts, you can't really notice that... [36:02.890 --> 36:06.130] You might notice that something's attacking, but you can't possibly block a thousand hosts. [36:06.250 --> 36:08.110] Well, you can, but that's just very heavy handed. [36:10.450 --> 36:18.870] I was asking, do you know anything, is it easy to crack a PGP passphrase? [36:19.330 --> 36:19.810] PGP? [36:20.030 --> 36:20.290] Yeah. [36:20.550 --> 36:21.610] If it's short, yeah. [36:22.250 --> 36:29.690] I mean, if someone has a PGP passphrase that's eight characters or even ten characters and you distribute it across a thousand machines, yeah, it's going to fall apart pretty quick. [36:30.570 --> 36:33.470] But you need to write a client for it or what? [36:34.790 --> 36:44.230] Well, I mean, actually, I don't know if anyone has written a client for it, but I've written a little thing that just calls the program directly and calls the API directly and just tries it over and over and over again. [36:44.570 --> 36:47.170] So the PGP API does exist. [36:47.370 --> 36:47.930] It is functional. [36:48.190 --> 36:53.510] You can just look up how to open up a PGP encrypted thing and try the password against it. [36:55.470 --> 37:00.510] And comment, can you comment a little bit on the legality of cracking that you were mentioning at the beginning? [37:00.910 --> 37:01.090] Yeah. [37:02.670 --> 37:05.990] If it's your file, you can open it. [37:06.110 --> 37:08.230] I mean, if you own it, you can crack your own passwords. [37:09.550 --> 37:14.550] The legality is really weird because data isn't property, but it is. [37:14.630 --> 37:17.450] It's intellectual property, which has a whole different governing set of rules. [37:18.310 --> 37:20.330] I am not a lawyer, but I work with them every day. [37:20.550 --> 37:24.410] So don't take my thing as legal advice, but I kind of know something about it. [37:24.690 --> 37:25.870] So the idea is this. [37:26.770 --> 37:40.110] If it's your file, it's your private property, and people aren't allowed to break your encryption, especially if it falls into the DMCA or any of the other acts that involve encryption, and you really just aren't legally allowed to break them. [37:41.390 --> 37:43.430] But if it's your file, you can break it. [37:43.610 --> 37:53.030] But if you work for a company, and you are given the right by the company to crack, let's say your assistant man, and they say, hey, look, just keep monitors on our employees and once in a while crack their stuff. [37:53.570 --> 37:54.630] That is completely legal. [37:54.770 --> 37:59.150] You can totally read your employees' stuff all you want because you're part of an umbrella organization. [37:59.350 --> 37:59.850] It's very different. [38:00.370 --> 38:03.890] Can the government come in and read your files as they want to? [38:04.010 --> 38:05.730] Not without a warrant, but once they have a warrant, yeah. [38:06.490 --> 38:07.250] And that's what we do. [38:07.410 --> 38:12.710] I mean, once we have the hard drive confiscated from a machine, that's ours, and we do whatever we want to it. [38:13.710 --> 38:17.630] And we try to keep it forensically sound, obviously, but we do whatever we want to it at that point. [38:20.150 --> 38:21.570] What's the largest thing you've ever cracked? [38:22.530 --> 38:27.490] A 12-character thing on 5,000 nodes, 12-character password. [38:30.430 --> 38:34.550] Well, we had initially 5,000 nodes and we were able to add another 10,000 at some point. [38:35.150 --> 38:37.630] It took eight weeks or so. [38:37.910 --> 38:40.190] I don't know why we did it either because we didn't really have to. [38:41.050 --> 38:44.810] I think it was to boast and say, hey, I cracked a 12-character password. [38:44.990 --> 38:45.850] What have you done recently? [38:47.330 --> 38:48.810] And we actually knew the first letter of it. [38:48.990 --> 38:49.470] That was the thing. [38:49.470 --> 38:53.470] So, we were able to mask the first letter out and then do the rest. [39:25.260 --> 39:25.700] Okay. [39:26.020 --> 39:28.400] The first question is, where do I get 5,000 machines? [39:28.400 --> 39:34.900] And the answer, I will reiterate to my pal Biggie Smalls up in heaven and I'll say, mo' money, mo' problems. [39:35.540 --> 39:37.020] That's how we get 5,000 machines. [39:38.080 --> 39:39.520] There's cash involved in what I do. [39:39.780 --> 39:41.520] And there aren't that expensive. [39:41.580 --> 39:43.000] Each machine is like a $1,500 machine. [39:43.100 --> 39:45.220] A dual-proc machine these days does not go for that much money. [39:45.520 --> 39:47.060] And we just have a lot of them in a big room. [39:47.060 --> 39:49.520] And they're strung together with... [39:50.880 --> 39:54.080] Well, some of them are that as well, which is a different issue. [39:56.160 --> 39:56.880] Or something. [40:00.380 --> 40:10.080] If one were to hypothetically use their neighbor's machines that are connected via wireless, they could hypothetically add more machines to their pool. [40:13.070 --> 40:13.890] Oh, legally. [40:14.130 --> 40:15.930] Oh, legally the only way to do it is either... [40:15.930 --> 40:19.010] There are some grid computing... legal grid computing systems out there. [40:19.330 --> 40:20.930] Distributed.net is one of them. [40:21.750 --> 40:22.210] And... [40:22.210 --> 40:25.070] But they're mostly used for cracking very large key space things. [40:25.250 --> 40:26.350] For challenge reasons only. [40:26.910 --> 40:29.530] But there are some public grid computing facilities. [40:30.090 --> 40:33.030] And you should just look up grid computing on Google and see what's around. [40:33.410 --> 40:34.110] What's the software? [40:35.490 --> 40:35.950] Nothing. [40:36.190 --> 40:37.210] That's what's cool about computers. [40:37.670 --> 40:44.190] I mean, if someone wants to build a 30,000 node cluster and start cracking passwords, hey, nothing we can do about it. [40:44.190 --> 40:47.190] Other than to have much better uncrackable systems. [40:47.390 --> 40:48.430] To constantly build it. [40:48.950 --> 40:50.590] Build a bomb with a computer. [40:53.170 --> 40:53.830] Same thing. [40:54.010 --> 40:56.170] I mean, if you have... a computer's a computer. [40:56.490 --> 40:58.350] It has neither good nor bad to it. [40:59.210 --> 40:59.390] Cool. [40:59.690 --> 41:00.350] One more question, then. [41:00.430 --> 41:00.770] I gotta go. [41:01.150 --> 41:01.770] How do you manage [41:07.040 --> 41:07.240] them? [41:08.320 --> 41:11.960] Each one just has a different cracking algorithm to crack against it. [41:12.400 --> 41:18.840] How do you manage them? [41:18.840 --> 41:20.460] Because at that point, we don't have that kind of time. [41:20.580 --> 41:23.020] And we just say, you know, screw it. [41:23.380 --> 41:24.500] This thing can stay secret. [41:24.540 --> 41:26.120] And we'll just get a court order to open it. [41:27.140 --> 41:28.120] Which we can do sometimes. [41:28.540 --> 41:30.080] Unless the person's dead or gone or whatever. [41:30.200 --> 41:31.700] And then we're just... we're screwed. [41:32.600 --> 41:32.920] Cool. [41:33.600 --> 41:33.920] Thanks.