home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.security.misc:1667 alt.security:4766 comp.unix.admin:6090
- Newsgroups: comp.security.misc,alt.security,comp.unix.admin
- Path: sparky!uunet!newsgate.watson.ibm.com!yktnews!admin!aixproj!uri
- From: uri@watson.ibm.com (Uri Blumenthal)
- Subject: Re: Tripwire release
- Sender: news@watson.ibm.com (NNTP News Poster)
- Message-ID: <1992Nov06.173036.28994@watson.ibm.com>
- Date: Fri, 06 Nov 1992 17:30:36 GMT
- Reply-To: uri@watson.ibm.com
- Disclaimer: This posting represents the poster's views, not necessarily those of IBM
- References: <1992Nov4.203802.10885@cs.sandia.gov> <Bx8757.HoF@acsu.buffalo.edu> <LIMES.92Nov5142000@ouroborous.eng.sun.com> <1992Nov6.161125.10283@ghost.dsi.unimi.it>
- Nntp-Posting-Host: aixproj.watson.ibm.com
- Organization: You're not cleared to know...
- Lines: 29
-
- |> >If I can make that backward calculation either
- |> >directly or by trial-and-error in a reasonable time, then your
- |> >signature protection system is no protection.
- |>
- |> I strongly agree. That's why I wrote my ATP program. A version
- |> portable to BSD will be ready soon. Anyway ATP is very like tripwire
- |> but is protects its database with DES/CBC. I gonna release it to
- |> the net and to ftp@ghost.dsi.unimi.it:/pub/security as soon as I finish.
-
- I'd say two things:
-
- a) The signature should be cryptographically strong. It
- means that it's infeasible for an adversary to compose
- a message with the same signature as yours. There are
- several algorithms available, MD5 one of them... There
- is no reason to be afraid of an adversary being able
- to "make backward calculation" [using decent sig, that
- is].
-
- b) The database of signatures is to be protected from [malicious]
- modifications [because since the algorithm is known, an enemy,
- even if he can't modify your file to fit the "old" signature,
- could in this case to change the file AND the signature]. I'd
- think, DES/CBC is quite enough of protection...
- --
- Regards,
- Uri. uri@watson.ibm.com
- ------------
- <Disclaimer>
-