[00:00.000 --> 00:01.080] I'm going to explain it to you. [00:02.640 --> 00:06.260] First things first, I've been doing cryptography for a number of years. [00:06.500 --> 00:15.000] This is a sort of side project that I stumbled on when talking to somebody at Black Hat who was giving talks on covert channels. [00:15.360 --> 00:19.480] So I mentioned this and people were interested in it. [00:19.560 --> 00:21.500] So I wrote some code and here it is. [00:22.440 --> 00:23.700] It's very, very interesting. [00:23.860 --> 00:24.940] Hopefully you'll get something from it. [00:25.140 --> 00:30.880] I try to make my talks as technical as possible so that you can actually get something from it. [00:33.680 --> 00:36.680] I'm also used to giving talks in academic settings. [00:36.960 --> 00:44.540] So basically what this means is if you have no idea what I'm talking about, raise your hand and be like, hey, over here, I don't know what you're talking about. [00:44.660 --> 00:45.520] Can you explain this? [00:46.300 --> 00:52.160] So if you have a question, feel free to raise your hand and get my attention and I'll try to explain things better. [00:53.600 --> 00:55.240] So I guess I'll begin. [00:56.180 --> 01:00.040] There are going to be two main parts and then summary and two questions. [01:00.320 --> 01:04.120] The first part is an explanation of digital signatures. [01:04.560 --> 01:06.360] Basically what they are, what they do. [01:07.100 --> 01:10.480] Then I'm going to cover two specific types of digital signatures. [01:10.860 --> 01:15.240] ElGamal signatures and then DSA or digital signature algorithm. [01:15.520 --> 01:17.380] Very creative name signatures. [01:17.960 --> 01:20.420] Then I'm going to look at the subliminal channels. [01:20.760 --> 01:25.180] These subliminal channels that are able to leak all this nice information to people. [01:25.800 --> 01:26.760] give an overview. [01:27.060 --> 01:28.640] Tell you what they are, how they work. [01:29.360 --> 01:31.900] I'll explain the subliminal channel in DSA. [01:32.340 --> 01:40.000] And then I'll show you some fun things that you can do with the subliminal channel that some people might be very concerned about. [01:40.900 --> 01:44.980] And then at the end, I'm not just talking out of my ass here. [01:45.120 --> 01:50.060] I have a program that will do this all and actually show you just how dangerous this can be. [01:50.060 --> 01:53.020] And then I'll just do a summary and take questions. [01:54.080 --> 01:56.100] So starting off, digital signatures. [01:57.940 --> 01:59.480] What are digital signatures? [02:00.340 --> 02:01.960] Basically, they're numbers. [02:02.520 --> 02:04.900] Anything digitally can be represented as a number. [02:05.380 --> 02:09.060] When people think of signatures, they think of something that's handwritten usually. [02:09.620 --> 02:12.320] With a digital signature, it's just a number. [02:12.320 --> 02:14.500] It's attached to some sort of message. [02:14.800 --> 02:16.820] It's bound to the message in some way. [02:16.820 --> 02:25.340] And it's created by the person who's doing the signing in such a way that hopefully nobody else can forge it. [02:26.580 --> 02:30.220] They're used, implemented with public key cryptography. [02:30.420 --> 02:35.600] So anybody who wants to make digital signatures will have a key pair, a public key and a private key. [02:35.840 --> 02:37.860] They'll use the private key to make the signature. [02:38.080 --> 02:41.200] And then the public key, they give out to everybody else. [02:41.200 --> 02:45.300] And it's used to verify whether a signature is correct or not. [02:47.480 --> 02:49.100] So what do they do? [02:49.600 --> 02:56.060] Basically, digital signatures try to recreate all of the functionality that handwritten signatures give you. [02:56.260 --> 03:00.040] All of the things that signatures were created for and actively used for. [03:00.580 --> 03:04.360] One of the things that they are trying to do is authenticate. [03:04.640 --> 03:12.620] So if somebody signs a document, you can look at the signature and hopefully tell whether this is actually their signature or not. [03:13.800 --> 03:21.240] It binds some sort of proof of I was here to a document for a specific person. [03:22.560 --> 03:27.860] In this case, signatures also handle verification of the data integrity. [03:28.300 --> 03:32.280] Usually you'll sign a contract when it's all done or sign a document when it's all done. [03:32.420 --> 03:36.360] And you put your signature at the bottom after you've looked it over and made sure everything is cool. [03:37.580 --> 03:43.740] And then if any changes are made to the document, hopefully you'll be able to tell that they were made after the signature. [03:44.280 --> 03:45.960] Handwritten signatures aren't really good at this. [03:46.300 --> 03:47.320] Digital signatures are. [03:47.560 --> 03:55.760] If you put a digital signature on a message and the message is changed in any way, the verification of the signature will fail. [03:55.960 --> 04:00.440] So the signature is bound to a particular message or document. [04:01.400 --> 04:07.120] The last thing that... the last primary thing that digital signatures do is give non-repudiation. [04:07.780 --> 04:15.160] Basically, if you sign something and then later you try to be a scumbag and say, oh, I never saw that, then it's your signature. [04:15.380 --> 04:16.260] You put it there. [04:16.480 --> 04:27.460] And in this case, not only does it prove that it's you to somebody else, it proves that it's you to anybody who says, hey, you really were here if you're trying to back out of it. [04:30.180 --> 04:34.420] So, let's look at the first type of signatures, ElGamal digital signatures. [04:35.220 --> 04:44.540] I'm bringing this up because ElGamal is the algorithm that DSA is based on and there are a number of similarities between the two. [04:45.220 --> 04:57.060] ElGamal can be used for both encryption and for digital signatures, but in practice the digital signatures aren't used because of a number of flaws in the algorithm that make it not optimal. [04:58.820 --> 05:10.260] DSA is a variant of ElGamal and these subliminal channels that are in DSA, they also exist in ElGamal signatures, but they're not as strong. [05:10.880 --> 05:20.960] It's harder to send messages through them and you can't send all possible messages through them and sometimes if you send a message, you won't be able to recover it on the other end. [05:20.960 --> 05:25.720] So, it's not as good for this purpose or as bad for this purpose as the case may be. [05:27.200 --> 05:28.820] Here we get into the technical stuff. [05:29.020 --> 05:30.260] How do you generate a key pair? [05:31.500 --> 05:34.200] Who here is familiar with public key cryptography at all? [05:35.040 --> 05:35.520] Excellent. [05:35.780 --> 05:36.200] Excellent. [05:36.200 --> 05:40.060] Okay, so it's a discrete logarithm problem based algorithm. [05:40.900 --> 05:52.300] Basically the premise of anything that is DLP based is that when you're working over a finite field of numbers, it's easy to do exponentiation. [05:52.300 --> 05:54.180] So, if you're doing modulus. [05:54.320 --> 05:55.860] Does anybody not know what modulus is? [05:56.440 --> 05:58.580] Where you divide and you take the remainder? [05:59.580 --> 06:06.700] So, if you do exponentiation and then take a modulus, basically you're chopping off a bit of information that you can't get back. [06:06.700 --> 06:09.200] So, to do exponentiation, it's easy. [06:09.380 --> 06:15.020] You do the exponentiation first and then you chop it off and reduce it and you have your answer. [06:15.480 --> 06:27.580] But to do... to take a logarithm, to do the reverse of exponentiation, it's really difficult because you've lost this information to begin with and you can't just go backwards. [06:27.580 --> 06:33.120] You have to come up with some way of taking guesses until you figure out what the right answer is. [06:33.120 --> 06:34.700] So, going forwards is easy. [06:34.920 --> 06:35.860] Going back is hard. [06:36.340 --> 06:39.680] And that's the basic premise of the DLP based algorithms. [06:40.020 --> 06:43.380] When you have a public key, you're doing the exponentiation. [06:43.900 --> 06:49.180] When you've got the private key, you're trying to use some secret that you know to go backwards and circumvent that. [06:49.400 --> 06:51.120] That's the simple explanation of it. [06:51.380 --> 06:53.060] So, this is how you generate the keys. [06:53.700 --> 06:56.000] If anybody has questions, you can find me later. [06:56.460 --> 06:58.700] I'm not going to get too much into detail here. [07:02.600 --> 07:03.080] Signatures. [07:03.080 --> 07:09.960] The basic way to explain this is that you're putting two values, R and S. [07:10.200 --> 07:16.360] You're computing them in such a way that there's a secret that only the signer knows. [07:16.520 --> 07:18.020] In this case, it's this value K. [07:18.360 --> 07:19.680] You pick a value K. [07:19.900 --> 07:20.900] You do some math. [07:20.980 --> 07:22.820] You get these two values R and S out. [07:22.820 --> 07:36.860] And because it's based on your private parameters, this math, the person who made the signature can go forwards and basically use the random variable to blind a variable in there. [07:36.860 --> 07:44.500] So, you can do math but you're blinding it by putting another variable into the mix that only you have and they don't. [07:45.820 --> 07:47.460] Everybody sort of understand that? [07:48.020 --> 07:48.500] Yeah? [07:48.740 --> 07:48.900] Okay. [07:50.260 --> 07:51.980] So, you pick a random value K. [07:52.180 --> 07:55.920] You use it to blind the process and you get R and S out as your signature. [07:57.180 --> 08:03.000] To do the verification, then you do a basic check to make sure that the value is sane. [08:03.180 --> 08:04.580] If it's not, you throw it out. [08:04.580 --> 08:10.360] Otherwise, you use the public key to go backwards and just check whether the signature is valid. [08:10.940 --> 08:14.080] If the signature is valid, then it's good. [08:14.360 --> 08:20.520] If it's not, then any number of things may have happened and that maybe it wasn't created by the right key. [08:20.840 --> 08:22.440] Maybe the message was changed. [08:22.700 --> 08:26.360] You can't tell just by knowing that the signature is invalid. [08:26.360 --> 08:28.700] But somewhere along the line, something went wrong. [08:32.180 --> 08:38.540] So, digital signature standard contains the definition of the digital signature algorithm. [08:38.800 --> 08:41.880] Again, very creative names here made by the United States government. [08:42.640 --> 08:46.240] And it's based on these El-Gamal signatures. [08:46.240 --> 08:55.240] It's defined as part, you know, DSS and the Federal Information Processing Standard number 186. [08:55.760 --> 08:58.600] It was originally made in 94. [08:58.600 --> 09:02.400] It's been updated twice, once in 98 and once in 2000. [09:03.060 --> 09:15.080] Basically, they've added extra algorithms and made a few changes and tried to keep it as current as possible for people to be using it actively and adopting the technology and spreading it. [09:16.060 --> 09:17.720] All of this is public information. [09:17.720 --> 09:20.680] It was all put up for public peer review. [09:21.220 --> 09:23.160] There were a lot of discussions about it. [09:23.460 --> 09:25.280] All of the details of the system are open. [09:25.400 --> 09:27.220] So, there's nothing being hidden here. [09:29.500 --> 09:30.800] So, DSA. [09:31.240 --> 09:32.120] Very similar. [09:32.620 --> 09:33.700] Generate key pairs. [09:34.740 --> 09:36.280] Make a public and a private key. [09:36.400 --> 09:37.520] They're related to each other. [09:39.520 --> 09:42.280] And, again, I won't get into too much detail here. [09:42.280 --> 09:45.100] But, if you're wondering the math, there it is. [09:46.720 --> 09:47.280] DSA. [09:47.640 --> 09:53.040] Your keys will be anywhere from 512 to 1024 bits. [09:53.700 --> 09:56.140] That's why that whole T value is in there. [09:56.280 --> 09:59.820] It scales up your key in multiples of 64 bits. [10:00.460 --> 10:02.740] So, it has to be one of these sizes. [10:03.040 --> 10:10.960] This is actually a problem with this particular algorithm because a lot of people are starting to wonder if 1024 bits is enough these days. [10:10.960 --> 10:14.040] And, DSA cannot go over 1024 bits. [10:15.300 --> 10:17.780] Everything else is fairly similar to El-Gamal. [10:18.020 --> 10:26.780] And, you end up with a public key, which has a large prime, P. And, a smaller one, Q. [10:27.540 --> 10:29.840] A generator, alpha. [10:30.280 --> 10:32.060] And, the public key itself, Y. [10:32.780 --> 10:36.120] And, then, a private key, which is just one value, which is X. [10:36.120 --> 10:45.320] But, in practice, whenever you have a private key being used, you'll have all of the public key parameters included with the private key. [10:45.560 --> 10:48.720] So, if you've got the private key, you've also got access to the public key, obviously. [10:50.600 --> 10:54.320] When you want to make a signature, again, you've got this random K that you pick. [10:54.860 --> 10:56.940] And, it's a lot simpler than El-Gamal. [10:57.320 --> 11:00.480] You just compute these values R and S again. [11:02.920 --> 11:07.040] And, in the El-Gamal case, you have to take the hash of a message. [11:07.260 --> 11:12.360] When you put a digital signature on a message, generally, you're not putting it on the entire message. [11:12.360 --> 11:16.740] You take a hash, a one-way hash of the message first. [11:17.160 --> 11:26.340] And, what that is, is a one-way function, hopefully, that will go from an arbitrarily sized message to one of a smaller fixed size. [11:26.620 --> 11:32.420] But, large enough that it's hard to find out two messages that will hash to the same value. [11:33.240 --> 11:37.960] Generally, hashes are like 128, 160, 256 bits. [11:37.960 --> 11:43.860] So, trying to find a collision in that space is still really difficult because two to the 128 is a really big number. [11:45.000 --> 11:51.960] But, you're dealing with 128 bits as opposed to, you know, megabytes, gigabytes, however much data you have. [11:53.060 --> 11:58.620] So, you effectively make a one-way compression of your message using a hash function. [11:58.880 --> 12:00.760] And then, you sign the hash. [12:00.900 --> 12:02.640] You don't actually sign the actual message. [12:02.860 --> 12:07.620] And, hashes are made so that, hopefully, you can't find two messages that hash to the same thing. [12:09.160 --> 12:13.260] In DSA's case, there is a very specific hash you have to use. [12:13.400 --> 12:14.080] SHA-1. [12:14.420 --> 12:16.680] Again, it's another United States standard. [12:16.980 --> 12:17.900] Again, it's open. [12:18.060 --> 12:19.600] Again, it's been up for peer review. [12:20.040 --> 12:21.660] It's fairly commonly used. [12:21.800 --> 12:23.560] And, it's been out there for a while now. [12:23.680 --> 12:25.060] So, everybody thinks it's pretty good. [12:26.200 --> 12:29.740] So, you have message M and you get a signature RS on it. [12:30.900 --> 12:34.420] To verify the signature, again, you do basic sanity checking first. [12:34.480 --> 12:35.760] Make sure that the numbers are okay. [12:36.340 --> 12:41.060] And then, you compute these two values and then crunch out something else and compare it to the signature. [12:41.540 --> 12:46.620] And, if your basic number crunching using the public key works out, then the message is good. [12:48.100 --> 12:51.940] If it's not, again, you can't tell whether it was made with a bad key or if it was changed. [12:51.960 --> 12:53.420] You just know that something is wrong. [12:53.540 --> 12:54.260] It's not good. [12:54.780 --> 12:55.740] Don't trust it. [12:59.540 --> 13:01.140] So, that's digital signatures. [13:01.280 --> 13:03.680] Now, we'll look at actual subliminal channels. [13:03.880 --> 13:05.680] I bet you're all wondering what they are at this point. [13:06.700 --> 13:07.520] You had something to ask? [13:07.520 --> 13:11.600] In the last slide, in the previous couple, you had the inverse notation? [13:11.860 --> 13:12.100] Yeah. [13:12.140 --> 13:12.340] Yes. [13:14.960 --> 13:17.700] Inverse is multiplicative inverse. [13:18.000 --> 13:21.100] So, the inverse of S is one over S. [13:21.220 --> 13:21.600] Oh, that's it? [13:21.600 --> 13:24.120] That's it, but it's also a matter of notation. [13:24.120 --> 13:32.040] Because you're working with integers over a finite group here, you can't actually just do division as you would normally think about it. [13:32.060 --> 13:34.560] Because that will give you, you know, a nice big floating point number or whatever. [13:35.240 --> 13:44.400] There's actually an inverse defined for any possible number system where S times S inverse equals one. [13:44.400 --> 13:48.060] However you want to define multiplication, inverse is based on that. [13:49.040 --> 13:49.280] Yeah. [13:49.560 --> 13:50.260] Two questions. [13:50.560 --> 13:55.160] One, you spoke about the DSA algorithm being essentially too small. [13:55.340 --> 13:55.620] Uh-huh. [13:55.700 --> 13:57.840] Is it possible? [13:58.020 --> 14:01.140] Is there not a problem with scaling the balance of the algorithm to make it larger? [14:02.080 --> 14:02.600] Okay. [14:02.700 --> 14:03.460] The question... [14:03.460 --> 14:08.860] He was asking if there was a way to make DSA larger based on its restrictions. [14:09.060 --> 14:09.920] How about scaling the balance? [14:10.700 --> 14:12.640] I don't think there is. [14:12.640 --> 14:16.680] But I think by the way that the algorithm is defined... [14:16.680 --> 14:20.160] I think there are a few things that you would have to change in order to scale it effectively. [14:20.500 --> 14:22.120] I'm pretty sure it can be scaled. [14:22.440 --> 14:26.500] But by the way this standard is in place, you're not allowed to scale it. [14:26.840 --> 14:30.440] And as a result, everybody is using this algorithm that is weak. [14:30.800 --> 14:31.360] Or not... [14:31.360 --> 14:33.520] It's not weak, but it's not as weak as... [14:33.520 --> 14:34.840] It's not as strong as it could be. [14:35.080 --> 14:36.660] You can't use SHA-1. [14:36.940 --> 14:37.420] I'm sorry? [14:37.660 --> 14:39.160] You can't use SHA-1. [14:39.540 --> 14:40.660] Why can't you use SHA-1? [14:40.660 --> 14:41.620] That's the restriction. [14:41.860 --> 14:43.360] You have to pick another half. [14:43.540 --> 14:43.800] Excellent. [14:43.980 --> 14:44.180] Thank you. [14:44.700 --> 14:44.720] Yeah. [14:48.610 --> 14:48.970] Okay. [14:49.150 --> 14:49.390] Thank you. [14:50.510 --> 14:51.390] There's the bottleneck. [14:51.810 --> 14:53.390] SHA-1 is fixed at 160 bits. [14:54.250 --> 14:55.770] Which is the size of Q. [14:56.950 --> 15:00.850] So if you want to expand it, you'd have to use a different hash that would allow Q to be bigger. [15:00.850 --> 15:05.550] But given another hash, there's no actual mathematical issue for scaling the size? [15:05.770 --> 15:05.830] No. [15:06.170 --> 15:07.170] Can you copy the equation? [15:07.710 --> 15:07.930] Oh. [15:09.230 --> 15:09.710] Yeah. [15:09.830 --> 15:12.730] If you use a different hash, then you can expand it. [15:12.870 --> 15:16.090] Thanks to somebody in the audience pointing out something that I forgot. [15:17.190 --> 15:24.070] If you use a different hash that can get larger than SHA-1, which is fixed at 160 bits, then you can scale DSA. [15:24.070 --> 15:29.630] But the standard itself, DSS, cannot scale because it requires SHA-1. [15:29.750 --> 15:30.790] Unless it's written . [15:30.790 --> 15:31.450] Unless what? [15:31.630 --> 15:32.930] Unless it's written . [15:33.530 --> 15:34.810] Yeah, but it's not. [15:35.270 --> 15:35.870] So... [15:37.710 --> 15:38.310] Yes. [15:39.350 --> 15:40.050] All right. [15:40.170 --> 15:40.770] Subliminal channels. [15:41.870 --> 15:44.610] So you're all wondering what it is at this point. [15:45.050 --> 15:54.190] And basically it's a way of embedding information in some sort of public communication in a way that's not detectable unless you know what you're looking for. [15:54.690 --> 16:00.070] Unless you have some sort of secret that you know is there, you're not going to find the information. [16:00.430 --> 16:03.290] How is that definition different between steganography? [16:04.730 --> 16:10.950] Um, steganography is one form of a covert or, you know, you can call it a subliminal channel. [16:11.730 --> 16:12.570] It's very similar. [16:13.230 --> 16:15.150] Do you have people use the mic and the mic? [16:15.410 --> 16:16.330] Uh, okay, yeah. [16:16.470 --> 16:19.250] If you have a question and you want to run up and use the mic, you can do that too. [16:20.210 --> 16:29.510] Um, so yeah, it's similar to steganography in that you're putting information in a public channel, but you're hoping that only the person on the other end knows what it is. [16:29.510 --> 16:36.290] And in steganography's case, it's basically how to look for it with a subliminal channel in DSA. [16:36.470 --> 16:37.270] There's another trick to it. [16:39.830 --> 16:42.990] There are two types of subliminal channels in digital signatures. [16:43.450 --> 16:44.650] Broadband and narrowband. [16:45.150 --> 17:09.430] Um, basically when you look at the amount of bits you have in a digital signature, you can, you know, make a nice information-theoretic estimate of how many bits are being used to actually do the duties of a digital signature, uh, in terms of making the thing resistant to forgery or attacks of other sorts on it. [17:10.050 --> 17:12.250] But usually there's extra space in there. [17:12.370 --> 17:17.490] Because if you look at information theory, you might say, you know, there are this many bits and this larger number of bits. [17:17.650 --> 17:21.570] But that doesn't mean you can isolate, say, 17 out of 25 bits. [17:21.930 --> 17:25.770] It's actually smoothed out 17 bits of information in the 25. [17:26.050 --> 17:27.390] So there's extra space in there. [17:28.570 --> 17:31.150] Broadband channels use all of that extra space. [17:31.390 --> 17:36.350] You're figuring out absolutely what is non-essential and you're using it. [17:37.350 --> 17:39.890] Narrowband channels don't use all of it. [17:39.990 --> 17:41.510] They use a much smaller amount. [17:41.690 --> 17:44.630] Um, maybe one bit or two bits per signature. [17:45.050 --> 17:52.530] And the advantages to not using nearly as much space is that you get to pull all sorts of other neat tricks with it. [17:53.330 --> 17:56.430] Um, maybe it's harder to detect. [17:56.910 --> 18:04.470] Maybe it has other advantages in terms of, uh, the verification of the signatures. [18:04.470 --> 18:06.570] But there are good reasons for using it. [18:08.930 --> 18:11.510] So let's look at the subliminal channels in DSA. [18:12.310 --> 18:13.230] Um, 85. [18:13.650 --> 18:18.050] A man by the name of Gustavus Simmons found a subliminal channel in ElGamal. [18:18.870 --> 18:26.390] One of the notable things about this subliminal channel is that the recipient of the information needs to know your private key. [18:27.270 --> 18:39.990] Now, if you want to communicate information with somebody else out there, you can generate a key pair and give the other guy your private key and view it as some sort of symmetric information hiding cipher. [18:39.990 --> 18:42.090] But it's got one drawback. [18:42.530 --> 18:52.090] And that is, if you're actually using this key pair for signatures, or even if you're not, they can generate a signature with whatever identity you put on it. [18:52.550 --> 18:57.010] And if anybody tries to verify it, it will come out as being you. [18:57.630 --> 19:02.610] And if you say, oh, well, my key was compromised, people will say, why are you still using it? [19:02.610 --> 19:07.930] If you pretend your key wasn't compromised, then you get stuck with the blame for whatever they sign. [19:08.210 --> 19:14.430] And this is a little more bothersome today because digital signatures are actually starting to become legally binding. [19:14.790 --> 19:23.710] Do you want to give somebody else the ability to sign documents as you without any way of telling whether it was actually you signing it or not? [19:23.790 --> 19:25.110] You probably don't want to do that. [19:26.070 --> 19:32.310] The other problem with the ElGamal subliminal channel is that there's only a fraction of all the possible messages you can send. [19:32.310 --> 19:34.190] Some messages will just fail. [19:34.430 --> 19:38.310] You won't be able to do it mathematically and have the signature verify at the same time. [19:39.510 --> 19:45.910] And some messages you can send, but it is computationally infeasible to get it back out. [19:46.330 --> 19:49.570] So the information's in there somewhere, but the other person can't pull it. [19:50.550 --> 19:51.730] Approximately what fraction? [19:52.570 --> 19:55.390] He asked approximately what fraction of messages. [19:55.630 --> 19:57.790] I don't remember off the top of my head. [19:57.930 --> 20:00.070] It's a fairly decent amount. [20:00.070 --> 20:02.070] I mean, you can still send things whatever... [20:02.670 --> 20:06.650] You can still send whatever you want as long as you're willing to be creative about how you phrase it. [20:07.770 --> 20:11.390] It's not that terribly restrictive, but it's still... [20:11.390 --> 20:13.310] There are a lot of messages you just can't send. [20:14.370 --> 20:17.010] So I can look up the numbers afterwards for you if you'd like. [20:18.430 --> 20:23.110] So, 91 DSS, including the digital signature algorithm, is proposed. [20:23.510 --> 20:29.890] It's put out in this proposal, the FIPS publication, part of the National Institute of Standards and Technology. [20:30.890 --> 20:36.690] Two years later, this guy finds one broadband and two narrow bench sublinal channels in the algorithm. [20:37.550 --> 20:39.870] So, it's still up for review at this time. [20:40.030 --> 20:40.910] He's doing his analysis. [20:41.250 --> 20:42.630] He found something before. [20:42.830 --> 20:43.750] He sees that they're related. [20:43.750 --> 20:45.030] He finds them in DSA. [20:45.850 --> 20:48.670] Again, the broadband channel requires sharing the private key. [20:48.970 --> 20:50.410] All messages can be sent, though. [20:50.470 --> 20:52.390] You can send any message you want. [20:52.890 --> 20:58.870] The narrow band channels, you can maybe only send a few bits at a time, but the other person doesn't need your key. [20:59.330 --> 21:15.710] So, anybody out there with just your public key, which everybody would supposedly have to verify your signature anyways, they can all pull out a few bits of information from each signature that is absolutely hidden in the signature and you can only find if you know what you're looking for. [21:21.810 --> 21:27.850] 94, one year later, after he makes a run of conferences in America, elsewhere. [21:27.850 --> 21:36.010] He gave a nice talk in Italy, I believe, Rome, on these subliminal channels and basically said, hey, look, these things exist. [21:36.210 --> 21:39.750] Not only do they exist, it's really easy to use them. [21:39.870 --> 21:45.250] And it's really easy to use them for whatever you want, and this is possibly a very bad thing. [21:46.910 --> 21:51.910] 94, DSS is accepted as the first digital signature standard by any government. [21:53.230 --> 21:55.250] Nobody's really heard much about this since. [21:55.510 --> 21:58.870] So, the question is, are these subliminal channels a bug or a feature? [22:03.830 --> 22:05.130] So, we want to use this. [22:05.430 --> 22:14.790] We'll look at the broadband channel because you can put a lot more in it, you can show off a lot more with it, and it's simpler than the narrowband channels. [22:15.410 --> 22:21.010] What you want to do is just stuff some information in the signature such that the signature is still valid. [22:21.370 --> 22:26.950] Anybody with your public key who has no idea what's going on can still verify the signature. [22:27.170 --> 22:27.990] Everything looks good. [22:28.770 --> 22:33.050] And they have no way of actually proving that the information is there or not. [22:35.050 --> 22:40.070] There's also the problem of, without this shared secret, they shouldn't be able to stumble upon your information. [22:40.330 --> 22:48.750] They shouldn't just be poking at it and pull out bits 1, 3, 7, 9 and, you know, find a message of whatever terrorist plans you have. [22:48.950 --> 22:55.190] There has to be some way of knowing a little more than that to be able to actually reconstruct the full message. [22:58.960 --> 23:02.120] And the best part is, the math is really simple. [23:02.380 --> 23:06.300] So, remember that random variable k used as the blinding factor? [23:06.840 --> 23:07.880] Everybody remember that? [23:09.380 --> 23:14.940] So, if you know the private key, you can backtrack and figure out what k was. [23:15.540 --> 23:22.220] So, all you do is you give the private key to somebody else and they can go back and they can find out what k is. [23:22.220 --> 23:24.140] k is 160 bits. [23:24.500 --> 23:26.340] So, it's pretty hard to guess randomly. [23:26.780 --> 23:30.780] So, your private key is generally safe if somebody is just trying to do an attack. [23:31.680 --> 23:35.900] But if somebody else has your key, then they can pull 160 bits out. [23:36.140 --> 23:46.640] And as long as you distribute these bits and messages fairly well, then chances are somebody is not going to be able to tell that you're working with a specific pattern. [23:46.640 --> 23:59.420] If all of your 160-bit numbers start with a few particular bytes, then yeah, you might run into problems because you're reducing the amount of space you would have to go through for a brute force attack. [23:59.700 --> 24:05.840] So, as long as you're smart about it, you can get 160 bits each time, no work, as long as you're willing to give up your private key. [24:10.520 --> 24:13.180] Unfortunately, this also works the other way around. [24:13.180 --> 24:18.260] If somebody knows k, they can backtrack and get your private key. [24:19.960 --> 24:21.480] It's actually pretty simple. [24:21.760 --> 24:26.360] You know all of the variables but one, and you just solve for the private key x. [24:27.060 --> 24:36.920] So, all you have to do is figure out some way of knowing what random variable k is that they're using, and you've got their key. [24:36.920 --> 24:47.540] Now, you might think of all sorts of ways of doing this, whether by putting some sort of backdoor into their program to playing with their random number generator. [24:47.740 --> 24:53.760] If their random number generator is bad, then you've effectively reduced the key space for any sort of attack. [24:54.140 --> 24:57.900] There are all sorts of great things that you can do with this if you want somebody's key. [25:01.430 --> 25:02.790] People know what diffs look like? [25:04.290 --> 25:06.250] How many lines of source code am I changing here? [25:07.030 --> 25:07.370] One. [25:08.090 --> 25:20.750] I'm changing one line of source code, where you pick k randomly, and to two lines, which can be reduced to one if I'm not being terribly lazy and want to change, you know, some other things here and there, or compress it a little so that it doesn't go off the end of the slide. [25:20.750 --> 25:24.630] But changing one line of source code to two lines. [25:24.790 --> 25:31.690] Instead of picking k randomly, you just allocate the memory space for k, and then set it to something in particular. [25:32.010 --> 25:35.770] In this case, let's set it to the value of the hash. [25:36.990 --> 25:39.610] Simple, easy to remember, it works. [25:40.770 --> 25:48.930] So, you now know what k is if you are using a patched version of GPG that you shouldn't be using. [25:50.870 --> 25:51.730] One line. [25:51.970 --> 25:52.810] That's all it takes. [25:55.670 --> 26:02.870] So, say you want to get their key from this value x, which technically makes up the private key. [26:03.210 --> 26:05.330] Well, it's actually pretty easy to do. [26:05.730 --> 26:17.410] You just solve for x, pull all the parameters out of their public key, then you go through all of the open PGP defined stuff for encapsulating keys and turning them into whatever you want to do. [26:17.830 --> 26:19.070] However you want to use them. [26:19.230 --> 26:24.010] Whether RFC whatever compliant or ASCII armored or however you want your key. [26:24.150 --> 26:25.470] Whatever flavor you want it in. [26:25.890 --> 26:28.910] All you do is you take the key, you encapsulate the key in a certificate. [26:29.290 --> 26:30.390] You make a key block. [26:30.590 --> 26:32.150] You put the certificate in the key block. [26:32.410 --> 26:33.850] You copy out their user ID. [26:34.170 --> 26:35.330] Put it in the key block. [26:35.770 --> 26:38.310] Put a signature, self signature on the key. [26:38.510 --> 26:40.730] Which you can do because you have got the key. [26:41.190 --> 26:42.330] Add it to the key block. [26:42.910 --> 26:43.890] Armor it if you want. [26:44.230 --> 26:45.170] Write it to a file. [26:45.350 --> 26:46.270] You have got their key. [26:47.350 --> 26:48.430] Want to see how this works? [26:55.120 --> 26:56.160] Can everybody see this? [26:59.620 --> 27:00.520] How to do this? [27:02.720 --> 27:04.820] I don't think that will change the size of the font. [27:05.140 --> 27:06.000] Can you kill the lights? [27:06.200 --> 27:08.480] Can you put the lights down a little so it will make it a little more visible? [27:09.300 --> 27:10.540] Control right button. [27:10.540 --> 27:11.640] Control right button. [27:12.740 --> 27:13.740] I didn't do it. [27:17.620 --> 27:21.180] Is that? [27:21.360 --> 27:22.540] No, that's not much better. [27:23.260 --> 27:23.400] Yeah. [27:26.560 --> 27:27.840] Yeah, I'm going to do that right now. [27:31.580 --> 27:32.340] There you go. [27:32.460 --> 27:33.160] Get that menu back. [27:33.640 --> 27:34.120] Ah. [27:34.720 --> 27:35.060] Okay. [27:36.080 --> 27:36.560] Inside. [27:37.240 --> 27:38.300] It's just highlighting. [27:39.380 --> 27:39.860] Inside. [27:39.860 --> 27:40.340] Maximum. [27:40.900 --> 27:41.380] Maximum. [27:41.420 --> 27:41.840] Maximum. [27:42.740 --> 27:44.720] I think I'll just have to do that. [27:45.160 --> 27:45.700] Is this any? [27:45.960 --> 27:46.580] Uh-oh. [27:46.820 --> 27:47.400] Where'd it go? [27:48.680 --> 27:49.440] Where'd it go? [27:50.260 --> 27:50.920] All right. [27:51.700 --> 27:54.440] So this might not be as good of a demonstration as I was hoping. [27:54.600 --> 27:55.140] Oh well. [27:55.940 --> 27:56.520] Uh-oh. [27:56.740 --> 27:57.100] Come on up. [27:57.180 --> 27:57.460] Come on up. [27:57.460 --> 27:58.300] Let's see. [27:58.600 --> 27:59.860] Let's see. [28:02.940 --> 28:03.540] Ah. [28:03.880 --> 28:04.300] See that? [28:04.380 --> 28:04.700] Uh-huh. [28:05.840 --> 28:06.260] Huge. [28:06.800 --> 28:07.620] There we go. [28:07.800 --> 28:15.980] Thank you very... I've never... I've never seen that menu before. [28:16.180 --> 28:16.540] Thank you. [28:18.860 --> 28:19.900] All right. [28:20.800 --> 28:24.980] So let's generate a key pair. [28:29.350 --> 28:31.670] So we want a DSA and ElGamal key. [28:32.330 --> 28:33.890] 1024 bits is fine. [28:40.170 --> 28:41.930] And we'll let it generate a key. [28:43.150 --> 28:48.690] And it generates and it generates... Brand new key. [28:49.070 --> 28:49.650] All right. [28:51.510 --> 28:52.670] Now let's make a message. [28:58.980 --> 29:01.480] We have a nice simple test message. [29:01.900 --> 29:03.580] And let's make a signature on it. [29:04.400 --> 29:07.860] Let's use the bad version of GPG to make the signature. [29:09.840 --> 29:11.120] The patched version. [29:14.770 --> 29:15.390] All right. [29:15.570 --> 29:18.170] So we should now have a signature. [29:19.570 --> 29:20.530] And there it is. [29:21.090 --> 29:23.190] So looks like any regular signature. [29:23.550 --> 29:24.330] Everything is going fine. [29:24.470 --> 29:24.690] Okay. [29:25.090 --> 29:25.950] Everything is going fine. [29:26.570 --> 29:28.370] Let's see if we can verify the signature. [29:33.510 --> 29:35.530] Good signature from test key. [29:35.870 --> 29:36.910] The signature is fine. [29:37.970 --> 29:39.590] So everything looks normal. [29:39.850 --> 29:41.730] You attach the signature to the message. [29:41.890 --> 29:46.290] You send it out on... In an email or to Usenet or whatever you do with your digital signatures. [29:46.290 --> 29:48.850] And random people grab your key. [29:49.110 --> 29:51.670] And you go through the whole key signing process. [29:52.030 --> 29:52.630] Hint, hint. [29:52.870 --> 29:53.810] Five o'clock tomorrow. [29:54.090 --> 29:54.370] Hint, hint. [29:54.590 --> 29:57.750] And then you verify the signature. [29:57.910 --> 29:59.070] And the signature is okay. [29:59.210 --> 30:00.070] Everything looks fine. [30:01.670 --> 30:03.230] So what's the problem here? [30:11.390 --> 30:19.850] Well... So we've got this program called sub-DSA key written in Perl using the Crypt OpenPGP Perl module. [30:20.150 --> 30:22.450] Very nice set of modules, by the way. [30:22.610 --> 30:25.970] I highly suggest using it if you want to do anything with OpenPGP keys. [30:27.070 --> 30:28.650] And we run the program. [30:29.670 --> 30:31.370] And it computes some values. [30:32.090 --> 30:32.910] And... Oh, look. [30:33.090 --> 30:34.730] Key armored and written to disk. [30:36.250 --> 30:37.670] I wonder what's in that key. [30:37.950 --> 30:39.450] Well, let's take a look at it first. [30:40.250 --> 30:41.530] Actually, what does it do? [30:42.230 --> 30:45.570] Up top, you'll see that it reads the signature first. [30:46.130 --> 30:48.310] In this case, it's a V3 signature. [30:48.550 --> 30:51.410] Type 17, which corresponds to DSA. [30:51.710 --> 30:55.950] So if somebody is trying to use an RSA or other signature, it will abort and say... [30:55.950 --> 30:57.390] Hey, sorry, this doesn't work. [30:57.770 --> 30:59.930] You get your user ID and timestamp. [31:00.110 --> 31:02.510] You get a hash of the message that the signature is on. [31:03.130 --> 31:04.650] And you get the values R and S. [31:05.190 --> 31:07.250] Then it goes and it grabs that public key. [31:07.390 --> 31:07.850] Looks it up. [31:07.950 --> 31:09.430] Pulls it out of the public ring file. [31:10.250 --> 31:11.550] Texts the fingerprint on the key. [31:11.810 --> 31:12.970] It's a version 4 key. [31:13.090 --> 31:13.930] It's not a sub key. [31:14.250 --> 31:15.710] And it pulls out the public key. [31:15.830 --> 31:18.790] P, Q, alpha, in this case G, and Y. [31:19.830 --> 31:21.550] Checks the signature to make sure it's valid. [31:21.690 --> 31:22.630] It's a valid signature. [31:23.490 --> 31:25.690] Then it figures out what your private key is. [31:25.890 --> 31:26.890] Oh look, there's X. [31:27.530 --> 31:35.150] And then just to make sure X is correct, it goes through the process to make sure that when you do the exponentiation, it matches up with the public key. [31:35.290 --> 31:36.790] And yes, it does in fact match up. [31:37.790 --> 31:39.930] And then it does all that stuff that I just told you. [31:39.930 --> 31:48.030] It puts a password on it, adds an identity, self signs it, and then armors it and writes it to disk. [31:48.390 --> 31:53.050] So, what we have here, begin PGP private key block. [31:53.730 --> 31:54.210] Huh. [31:54.530 --> 31:56.330] I wonder if this is a valid key. [32:01.180 --> 32:02.080] Yes it is. [32:13.850 --> 32:20.330] So, all you got to do is get somebody to use this patch, whether they know it or not. [32:21.210 --> 32:27.250] And a lot of people aren't very good at making sure their encryption programs are actually trustworthy. [32:27.250 --> 32:32.510] They download something, they install it, they run it on somebody else's system. [32:32.870 --> 32:35.510] They never bother to check whether it's okay or not. [32:36.010 --> 32:41.590] And somebody just has to slip this one line patch in there and your signatures go out. [32:41.750 --> 32:42.850] You don't know anything's wrong. [32:43.070 --> 32:44.790] Everybody else doesn't know something's wrong. [32:45.230 --> 32:49.530] But if you know this value K, then their key is yours. [32:49.530 --> 32:54.450] And when their key is yours, you can sign whatever you want as them. [32:54.690 --> 32:59.410] As their identity in which case, in many cases, may be legally binding. [33:03.510 --> 33:04.810] So, there we have it. [33:04.970 --> 33:06.150] That proof of concept. [33:06.170 --> 33:07.450] It does in fact work. [33:07.630 --> 33:09.170] This is something you should be worried about. [33:10.950 --> 33:20.730] And I mention this because the shock value of seeing, you know, your key stolen is a lot more memorable than actually using this to send secret messages over covert channels. [33:20.730 --> 33:23.510] But just as good for that as well. [33:25.870 --> 33:26.910] So, summary. [33:27.610 --> 33:28.510] What have we done? [33:28.810 --> 33:35.490] Well, we've seen that, as Simmons says, he in fact entitled his paper on the subject that, you know, it's easy to do. [33:36.190 --> 33:40.010] Subliminal communication is very, very easy using this algorithm. [33:41.130 --> 33:44.110] And subliminal channels, they're a feature, not a bug. [33:44.330 --> 33:47.510] Because he pointed it out a year before the standard was adopted. [33:48.370 --> 33:54.870] And he made a big fuss over it, published a few papers on it, and then everything got quiet again. [33:55.030 --> 33:57.730] And the standard was adopted a year later. [33:58.970 --> 34:03.710] These channels can be used for all sorts of communication, some of which are extremely malicious. [34:04.010 --> 34:08.350] And again, they're the ones that make a bigger impression on a large audience, which is why you've seen it. [34:08.350 --> 34:28.670] And if you want to not be affected by anything like this, if you want to sleep better at night knowing some jackass like me isn't stealing your secret keys, then whenever you use an encryption program, like GPG, PGP, whatever, grab the source, check it against an MD5 hash or a signature on it, [34:28.830 --> 34:33.250] but do some basic verification to make sure everything is okay before you use it. [34:33.250 --> 34:39.770] If you wouldn't trust a random stranger with your key, why would you trust a random stranger's program with your key? [34:40.090 --> 34:41.150] Make sure it's okay. [34:43.770 --> 34:45.110] Some other stuff I'm writing. [34:45.590 --> 34:53.570] Well, I'm almost done with the Perl program, which does the nice version of this. [34:54.310 --> 34:57.270] Didn't have quite enough time to finish it, but it's just about done. [34:57.330 --> 34:58.190] I'll be releasing it soon. [34:58.990 --> 35:16.030] I'm working on a patch to GPG C code to do the functionality directly, the good functionality, so that you can choose to make a subliminal message using some command line argument and actually build that functionality right into the program. [35:17.170 --> 35:34.330] I'm also working on a couple of programs to use the narrowband channels, which will be a lot more difficult because, well, at least in terms of leaking keys, but I guess in anything, because if you only have a couple of bits at a time, you need some way of figuring out how to reconstruct the message if it's more than one or two bits, [35:34.470 --> 35:35.670] which most messages are. [35:35.670 --> 35:46.210] So you have to figure out some way of doing maybe sequencing or reordering or putting a larger message back together from a collection of small number of bits. [35:46.770 --> 36:04.510] And I'm working on some other programs which will automatically scan signatures out there for, say, the default version of what I've done, because I'm sure a whole lot of script kiddies will run out there and start hacksoring and there will be a lot of these messages out there where the value of K is set to the hash. [36:05.230 --> 36:05.910] It's inevitable. [36:06.070 --> 36:06.490] It happens. [36:06.730 --> 36:18.010] So maybe write a program that just scans all signatures automatically and, hey, look, if you just happen to find somebody's key, then at the very least, you know, you can tell them, hey, you've been compromised, revoke your key immediately, generate a new key pair. [36:20.050 --> 36:21.310] So that's it. [36:21.470 --> 36:22.870] I have a couple of references here. [36:23.030 --> 36:26.490] The first one is the actual standard itself. [36:26.770 --> 36:35.950] And the second one is the paper where Gustavus Simmons actually demonstrates that this is possible and easy. [36:36.190 --> 36:40.790] So if anybody is interested in learning more about it, you can definitely look this stuff up. [36:40.910 --> 36:44.370] It's very well documented, professionally done, academically done. [36:44.370 --> 36:45.490] So it's out there. [36:45.590 --> 36:46.110] It's known about. [36:46.250 --> 36:47.770] It's been out there for more than 10 years. [36:48.090 --> 36:48.750] 10 years. [36:49.190 --> 36:50.390] So there it is. [36:50.790 --> 36:51.590] And that's it. [36:51.670 --> 36:55.030] So if anybody has any questions, I'd be more than happy to try to answer them for you. [36:55.070 --> 36:55.870] And thanks for your time. [37:06.520 --> 37:06.920] Hi. [37:07.160 --> 37:11.180] You said the narrow band channels were a lot harder to use. [37:11.280 --> 37:14.440] Could you please describe what they are, why they're harder? [37:16.040 --> 37:21.700] They're harder to use because the math is more complicated than just setting one variable. [37:22.540 --> 37:24.180] So do they manipulate K? [37:24.340 --> 37:25.900] Do they choose properties of K? [37:26.140 --> 37:26.340] Or...? [37:26.920 --> 37:29.220] I don't know a good way to explain this off the top of my head. [37:29.570 --> 37:29.660] Okay. [37:29.820 --> 37:31.700] If you want to talk more about it, just find me. [37:31.840 --> 37:32.700] I'm definitely available. [37:33.160 --> 37:33.300] Okay. [37:33.340 --> 37:34.140] To talk about it. [37:34.320 --> 37:34.460] Sorry. [37:34.960 --> 37:36.100] Another quick question. [37:36.260 --> 37:36.340] Yeah. [37:36.360 --> 37:45.340] Can you... if a broad band attack or subliminal channel message is already sent, can you also use a narrow band or are they mutually exclusive? [37:45.640 --> 37:47.140] I believe they're mutually exclusive. [37:47.400 --> 37:47.540] Okay. [37:50.920 --> 37:52.420] Maybe I can explain the narrow band. [37:52.620 --> 37:58.820] You pick, say, four values of K and depending on which one you determine, you get two bits of data out of it. [37:59.160 --> 38:03.460] But you can't recover Q, private key, because you don't know the other bits. [38:03.560 --> 38:03.960] They're random. [38:04.520 --> 38:05.440] That's my understanding. [38:05.760 --> 38:05.980] Anyway. [38:06.620 --> 38:06.840] Okay. [38:06.840 --> 38:08.760] I was really surprised at your recommendation. [38:09.140 --> 38:11.120] My recommendation is much, much simpler. [38:11.320 --> 38:12.700] Don't use DSS. [38:13.080 --> 38:14.260] Use RSA. [38:14.700 --> 38:17.700] Use 2049 bit keys or larger. [38:18.080 --> 38:20.260] 2048 is possibly too small. [38:21.420 --> 38:24.540] And do not leave the GPG people. [38:24.800 --> 38:27.920] DSA is not better than RSA. [38:28.060 --> 38:28.260] Okay? [38:28.380 --> 38:30.160] I absolutely agree with you on that. [38:30.400 --> 38:37.160] Well, with the exception of using larger than 2048 bit keys, because quantum cryptography... [38:37.160 --> 38:42.140] There is a belief that 2048 is a sweet spot. [38:42.300 --> 38:46.760] If you build a hardware cracking device that you're going to build it for 2048 and smaller bit keys. [38:47.040 --> 38:47.240] Really? [38:47.480 --> 38:47.740] Okay. [38:47.740 --> 38:47.780] Okay. [38:48.420 --> 38:57.500] And so, eight bits larger than that is 256 times harder, which means that they need 256 units to crack your key in the same amount of time. [38:57.660 --> 39:00.580] So, go just a little bit more and you get out of that sweet spot. [39:00.720 --> 39:01.000] I don't know. [39:01.060 --> 39:09.500] See, my general belief is if they're going to try to crack a 2048 bit key, before they try that, they're just going to send a SWAT team to your house and break your legs. [39:09.500 --> 39:13.640] Right, but that leaves a lot more evidence, in my opinion. [39:13.660 --> 39:20.120] It does, but if they can afford to build a machine that will break a 2048 bit key, they can afford to throw your body into a ditch somewhere. [39:20.760 --> 39:30.020] The point is not that 2048 is cheap to crack, but that if you're going to build a piece of hardware, that's the natural point to do that. [39:30.220 --> 39:30.980] I didn't know that. [39:30.980 --> 39:45.240] And the thing that I also maybe you can talk about is, as we move to digital identities, what is the attack on you when someone signs your key and puts a supplemental message in it unknown to you? [39:47.160 --> 39:48.760] I didn't even think of that. [39:48.920 --> 39:49.200] Wow. [39:49.320 --> 39:49.440] Okay. [39:49.720 --> 39:51.300] So, let me explain the problem. [39:51.560 --> 39:54.140] Let's say you have people that you don't like in your society. [39:54.500 --> 39:55.020] Okay? [39:55.300 --> 39:56.840] Pick your favorite scapegoat. [39:56.840 --> 39:59.460] It's the same thing as using the regular IDs. [39:59.460 --> 40:00.040] Yeah, I see. [40:00.140 --> 40:00.160] Right. [40:00.280 --> 40:00.520] Okay? [40:00.940 --> 40:07.120] So, now you put a little bit that says they are a Jew, a nigger, whatever your epithet is. [40:07.620 --> 40:07.680] Okay? [40:07.860 --> 40:08.760] Irish, exactly. [40:09.040 --> 40:11.240] I mean, it says they're Irish. [40:11.540 --> 40:13.680] Don't serve them more than three drinks at the bar. [40:14.000 --> 40:14.520] Okay? [40:15.680 --> 40:16.200] Right? [40:17.480 --> 40:29.900] So, it comes up and you get to the official who then looks at your application, you know, for food and says, oh, well, I can't help you today. [40:30.920 --> 40:31.360] Okay? [40:31.680 --> 40:39.820] So, that's the serious risk of this thing is that you will be essentially, you know, these bands, you will be banded and you won't even know it. [40:40.100 --> 40:41.860] You won't know what bits you have set. [40:42.020 --> 40:44.460] You won't know what's going on until you get thrown in prison. [40:45.540 --> 40:46.220] Thank you. [40:50.780 --> 40:55.480] I agree with that risk, but I think you were closer on the right track. [40:56.600 --> 41:06.460] With the movement towards the digital rights management and stuff, the idea of, like, Intel burning a number into some tamper-proof hardware or something. [41:06.820 --> 41:16.620] Yeah, there comes the idea that you may have tamper-proof hardware around a DSA implementation that's going to generate your private key and do the signing for you and have random numbers and things in there. [41:16.620 --> 41:30.880] Maybe somebody can correct me on the details, but there was a proposal that had the feature that even if you knew exactly how it worked, how they were generating extra bits and how they were using subliminal channels, since it's in tamper-proof hardware, [41:31.240 --> 41:34.320] there's no way you could even demonstrate that it was happening. [41:34.320 --> 41:49.700] And not just having the is Irish bit, but it could be, in each signature, leaking a few bits of your private key so that eventually the evil person who put this in there in the first place can be producing certificates with your signature that you didn't really sign. [41:49.900 --> 41:50.080] Yep. [41:50.400 --> 41:58.960] And it's amazing that people would go with something that has this property that, even if you know exactly how it's cheating, there's no way to prove that it's happening. [41:59.120 --> 42:01.360] It sounds almost like our election machines. [42:07.480 --> 42:10.480] Except we have the source code for those and we know they're crap. [42:14.320 --> 42:21.560] I'm going to demonstrate my mathematical retardation by asking some mathematically not so Top Gun questions. [42:21.980 --> 42:33.100] It's my understanding of the subliminal channel that it's only a susceptibility in signing algorithms that use a random value K, and that's why it doesn't apply to algorithms like RSA? [42:33.920 --> 42:35.980] RSA uses a completely different method. [42:36.300 --> 42:43.300] But yes, in this case, because you're picking a random value, and that random value is being used in the equations... [42:43.840 --> 42:45.500] I can actually bring this back up. [42:47.360 --> 42:52.040] Hold on, I've got nifty navigation buttons here, if they worked. [42:53.240 --> 42:53.640] Come on. [42:54.120 --> 42:54.520] Come on. [42:54.760 --> 42:55.300] Okay, never mind. [42:58.240 --> 42:59.560] Go back a little bit. [42:59.560 --> 43:00.180] Okay. [43:01.240 --> 43:09.380] Basically, what it is, is that you're using K as a randomizing thing to prevent anybody else from seeing what you're doing in the process. [43:10.120 --> 43:18.320] If you know one of the other value, X or K, then in these equations, you've only got one unknown. [43:18.520 --> 43:20.460] So you can manipulate them however you want. [43:20.460 --> 43:26.300] And because you only have one unknown, it's particular to the algorithm. [43:26.580 --> 43:31.320] RSA uses a completely different method that something like this just doesn't apply because it's different. [43:31.560 --> 43:33.780] Are there known subliminal channels in RSA? [43:34.440 --> 43:36.000] I don't think so. [43:36.320 --> 43:36.500] Okay. [43:36.500 --> 43:37.520] Not that I'm aware of. [43:37.560 --> 43:38.400] I could be wrong on that. [43:38.400 --> 43:43.960] And then also, again, just if it's off topic, just say it's off topic. [43:44.080 --> 43:45.680] I'm going to go back to my seat after I ask it. [43:47.900 --> 43:54.320] In GPG, they recently, maybe not too recently, discontinued the use of ElGamal signatures. [43:54.660 --> 43:54.860] Uh-huh. [43:54.960 --> 44:00.560] And being that I'm a mathematical retard, I don't get any of why that was done. [44:00.560 --> 44:04.160] And maybe if you could explain a little bit of the weakness in the ElGamal signature scheme. [44:04.160 --> 44:06.220] There are different attacks against them. [44:06.440 --> 44:07.600] They're bigger. [44:07.800 --> 44:08.560] They're less efficient. [44:12.440 --> 44:12.880] Yeah. [44:13.400 --> 44:13.480] Yeah. [44:14.360 --> 44:17.580] As somebody said, it was just the using ElGamal for both. [44:17.760 --> 44:17.980] Right. [44:18.440 --> 44:19.300] Bad idea. [44:20.020 --> 44:22.540] So, also, they're trying to... [44:22.540 --> 44:26.720] The bottom line, unfortunately, is that they're also trying to become more standards compliant. [44:27.620 --> 44:31.260] And in this case, the standard is not something that you really want to become compliant with. [44:32.040 --> 44:37.980] As that other guy said, you know, simple solution is don't use DSS at all. [44:39.080 --> 44:43.860] And unfortunately, if you look at the way PGP is going, you need to use it these days. [44:44.040 --> 44:49.260] Because, you know, RSA is limited in functionality to like PGP2 and PGP5. [44:49.500 --> 44:50.720] And otherwise, it's deprecated. [44:50.840 --> 44:51.440] Don't use it. [44:52.560 --> 44:54.340] But it might be a good idea. [44:57.700 --> 45:03.640] Yeah, not in GPG, but if all the Windows users are using PGP, then you've got an interoperability problem. [45:04.000 --> 45:05.740] And there you go. [45:06.340 --> 45:11.180] And if you're really concerned about your security with somebody else who knows what's going, distribute one-time pads. [45:11.420 --> 45:12.300] Do it that way. [45:12.400 --> 45:13.240] You're secure. [45:16.420 --> 45:17.580] How paranoid are you? [45:19.460 --> 45:19.900] Sorry. [45:20.240 --> 45:20.500] Go ahead. [45:21.160 --> 45:25.980] Gus Simmons wrote an excellent book on cryptography, has the chapters on subliminal messages. [45:26.160 --> 45:27.400] You've referenced him a lot. [45:28.640 --> 45:34.800] If I remember right, he basically says it seems that you can't really design algorithms that don't have subliminal channels. [45:34.940 --> 45:38.000] And so the goal is to reduce them as much as possible. [45:38.220 --> 45:44.920] And if I remember right, he had like a goal of one or two bits per second as being a leak rate you should try to achieve. [45:45.200 --> 45:48.540] But the thing with DSS is a whole lot more. [45:48.540 --> 45:48.920] Yeah. [45:49.640 --> 45:50.380] Yes, exactly. [45:50.600 --> 45:56.560] There's always some little quirk that you can find where you can play with it and get some hidden information through. [45:56.780 --> 46:00.820] But I was unaware that there was a per-time measurement on it. [46:00.940 --> 46:02.200] But that's absolutely correct. [46:03.840 --> 46:04.480] Anything else? [46:04.940 --> 46:05.740] Any more questions? [46:05.920 --> 46:08.000] Any more little bits of information to share with me? [46:08.120 --> 46:08.700] Anything like that? [46:09.760 --> 46:10.120] Drink? [46:10.440 --> 46:10.740] All right. [46:10.880 --> 46:11.260] Thank you very much. [46:11.320 --> 46:11.720] Wait, wait, wait. [46:11.780 --> 46:12.260] We have one more. [46:12.340 --> 46:12.620] One more. [46:12.780 --> 46:12.940] Sorry. [46:13.200 --> 46:13.840] False alarm. [46:14.680 --> 46:16.540] I don't know this book by Simmons. [46:16.900 --> 46:22.000] What do you read to learn more about this from a sort of tutorial simple standpoint? [46:23.160 --> 46:26.200] If you're looking at learning more about cryptography in general... [46:26.200 --> 46:26.580] No, no. [46:26.680 --> 46:27.160] About this... [46:27.160 --> 46:27.820] About signatures? [46:28.100 --> 46:30.000] About this channel. [46:30.240 --> 46:31.040] About the channel. [46:31.320 --> 46:33.360] First of all, grab a crypto book. [46:33.480 --> 46:39.920] Learn more about digital signatures, specifically ElGamal, DSA, and the mathematics behind them. [46:39.920 --> 46:44.880] And then you can get Simmons' book or his papers, which are written specifically on the subject. [46:45.440 --> 46:46.460] They're in the references. [46:46.460 --> 46:47.940] I'm going to be sharing these slides. [46:48.020 --> 46:50.360] Or if you download the code, they're in the code. [46:50.800 --> 46:52.660] I can just give it to you if you'd like. [46:53.500 --> 46:56.460] But basically, he wrote some papers specifically on this subject. [46:56.640 --> 46:58.220] Does Schneier's book have anything about it? [46:58.680 --> 47:00.980] Schneier mentions it in his book, but that's about it. [47:02.260 --> 47:04.320] But if you're interested, I can point you in the right direction. [47:06.360 --> 47:06.720] All right. [47:06.780 --> 47:07.900] Well, thanks very much for your time. [47:08.160 --> 47:09.320] Hope you got something out of it. [47:09.500 --> 47:09.980] Have a good night.