<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Cryptography and Encryption Blog</title>
	<atom:link href="http://quantumcrypto.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://quantumcrypto.wordpress.com</link>
	<description></description>
	<lastBuildDate>Thu, 27 Mar 2008 15:28:00 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='quantumcrypto.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/651220993cfa8ebf20df3ff318d43aef?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Cryptography and Encryption Blog</title>
		<link>http://quantumcrypto.wordpress.com</link>
	</image>
			<item>
		<title>Re: [FDE] USB device that can send keystrokes?</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/27/re-fde-usb-device-that-can-send-keystrokes-2/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/27/re-fde-usb-device-that-can-send-keystrokes-2/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 15:28:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/27/re-fde-usb-device-that-can-send-keystrokes-2/</guid>
		<description><![CDATA[On Wed, Mar 26, 2008 at 4:45 PM, mb &#60;nospam.maillists@googlemail.com&#62; wrote:&#62; Hm, just use autostart features and a script!? Something like a modern&#62;  bootsector virus 
hmm that will require a software/script to be loaded on the computer.
I was thinking more along the lines of WiebeTech&#39;s MouseJiggler[1],where it just sends the mouse commands without loading [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1451&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>On Wed, Mar 26, 2008 at 4:45 PM, mb &lt;nospam.maillists@googlemail.com&gt; wrote:<br />&gt; Hm, just use autostart features and a script!? Something like a modern<br />&gt;  bootsector virus <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />
<p>hmm that will require a software/script to be loaded on the computer.
<p>I was thinking more along the lines of WiebeTech&#39;s MouseJiggler[1],<br />where it just sends the mouse commands without loading any software.<br />Or maybe a pre-programmed keyboard that can send keystroke as soon as<br />it is connected, without requiring any software/script to be loaded.<br />Obviously this device would require a built-in processor and some<br />memory.
<p>1. <a href="http://www.wiebetech.com/products/MouseJiggler.php">http://www.wiebetech.com/products/MouseJiggler.php</a><br />_______________________________________________<br />FDE mailing list<br />FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br /><a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1451/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1451/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1451/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1451/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1451/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1451/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1451/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1451/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1451&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/27/re-fde-usb-device-that-can-send-keystrokes-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>paper enigma machine</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/27/paper-enigma-machine/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/27/paper-enigma-machine/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 13:10:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/27/paper-enigma-machine/</guid>
		<description><![CDATA[A paper enigma machine:
http://mckoss.com/Crypto/Enigma.htm
&#8211; Perry E. Metzger		perry@piermont.com
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;The Cryptography Mailing ListUnsubscribe by sending &#34;unsubscribe cryptography&#34; to majordomo@metzdowd.com
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1454&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>A paper enigma machine:
<p><a href="http://mckoss.com/Crypto/Enigma.htm">http://mckoss.com/Crypto/Enigma.htm</a>
<p>&#8211; <br />Perry E. Metzger		perry@piermont.com
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />The Cryptography Mailing List<br />Unsubscribe by sending &quot;unsubscribe cryptography&quot; to majordomo@metzdowd.com</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1454/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1454/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1454/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1454&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/27/paper-enigma-machine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>Re: [FDE] Paula Parker&#8217;s, Detective Inspector of Merseyside</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/27/re-fde-paula-parkers-detective-inspector-of-merseyside-2/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/27/re-fde-paula-parkers-detective-inspector-of-merseyside-2/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 01:51:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/27/re-fde-paula-parkers-detective-inspector-of-merseyside-2/</guid>
		<description><![CDATA[Sure thing. In general, if your users are using pass-phrases shorter  than 9 characters, they can be cracked. If they use pass-phrases  longer than 9 characters, they may not be crackable. As someone else  said, if they are using two-factor authentication, they are in good  shape.
On Mar 26, 2008, at 10:25 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1450&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Sure thing. In general, if your users are using pass-phrases shorter  <br />than 9 characters, they can be cracked. If they use pass-phrases  <br />longer than 9 characters, they may not be crackable. As someone else  <br />said, if they are using two-factor authentication, they are in good  <br />shape.
<p>On Mar 26, 2008, at 10:25 AM, Owens Bernard B wrote:
<p>&gt; On Tue, 25 Mar 2008 20:04:29 -0700, Simson Garfinkel wrote:<br />&gt;<br />&gt;&gt; But if you use strong passphrases and your users are torture-proof,<br />&gt; they&#39;re probably on a pretty good footings.<br />&gt;<br />&gt; My users are tax collectors.  They don&#39;t care enough to be<br />&gt; torture-proof.  For them, the methods you cite are of no practical<br />&gt; value, being either unnecessary or illegal.<br />&gt;<br />&gt; For the general public, though, I think the original story spread<br />&gt; disinformation.  The quote from the DS made it sound like encryption<br />&gt; simply doesn&#39;t work and so, to quote from another area of interest,<br />&gt; &quot;Resistance is futile.&quot;  I find this sort of spin from law enforcement<br />&gt; sources rather unsettling.  It smacks of a lack of integrity and<br />&gt; intellectual honesty.  I always hope for better.<br />&gt;<br />&gt; Thanks for your thoughts,<br />&gt;<br />&gt; Bernard Owens<br />&gt; USTreas/IRS<br />&gt;<br />&gt; _______________________________________________<br />&gt; FDE mailing list<br />&gt; FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br />&gt; <a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a><br />&gt;
<p>_______________________________________________<br />FDE mailing list<br />FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br /><a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1450/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1450/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1450/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1450/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1450/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1450/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1450/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1450&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/27/re-fde-paula-parkers-detective-inspector-of-merseyside-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>Re: [FDE] USB device that can send keystrokes?</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-usb-device-that-can-send-keystrokes/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-usb-device-that-can-send-keystrokes/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 23:45:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/26/re-fde-usb-device-that-can-send-keystrokes/</guid>
		<description><![CDATA[Hm, just use autostart features and a script!? Something like a modernbootsector virus 
Regards,Mark
Ali, Saqib wrote:&#62; Hello All,&#62; &#62; I am looking for a USB device that can send pre-programmed key strokes&#62; when plugged-into the USB port. Any suggestions?&#62; &#62; &#62; Saqib&#62; _______________________________________________&#62; FDE mailing list&#62; FDE@www.xml-dev.com&#62; http://www.xml-dev.com/mailman/listinfo/fde
_______________________________________________FDE mailing listFDE@www.xml-dev.comhttp://www.xml-dev.com/mailman/listinfo/fde
      [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1449&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Hm, just use autostart features and a script!? Something like a modern<br />bootsector virus <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />
<p>Regards,<br />Mark
<p>Ali, Saqib wrote:<br />&gt; Hello All,<br />&gt; <br />&gt; I am looking for a USB device that can send pre-programmed key strokes<br />&gt; when plugged-into the USB port. Any suggestions?<br />&gt; <br />&gt; <br />&gt; Saqib<br />&gt; _______________________________________________<br />&gt; FDE mailing list<br />&gt; FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br />&gt; <a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a>
<p>_______________________________________________<br />FDE mailing list<br />FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br /><a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1449/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1449/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1449/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1449&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-usb-device-that-can-send-keystrokes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>[FDE] USB device that can send keystrokes?</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/26/fde-usb-device-that-can-send-keystrokes/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/26/fde-usb-device-that-can-send-keystrokes/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 21:53:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/26/fde-usb-device-that-can-send-keystrokes/</guid>
		<description><![CDATA[Hello All,
I am looking for a USB device that can send pre-programmed key strokeswhen plugged-into the USB port. Any suggestions?
Saqib_______________________________________________FDE mailing listFDE@www.xml-dev.comhttp://www.xml-dev.com/mailman/listinfo/fde
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1448&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Hello All,
<p>I am looking for a USB device that can send pre-programmed key strokes<br />when plugged-into the USB port. Any suggestions?
<p>Saqib<br />_______________________________________________<br />FDE mailing list<br />FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br /><a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1448/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1448/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1448/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1448&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/26/fde-usb-device-that-can-send-keystrokes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>[FDE] Brute-force password cracking</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/26/fde-brute-force-password-cracking/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/26/fde-brute-force-password-cracking/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 19:14:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/26/fde-brute-force-password-cracking/</guid>
		<description><![CDATA[On Mar 25, 2008, at 12:31 PM, Owens Bernard B wrote:
&#62; The nexus between the referenced article and this list seems to be &#62; when Detective Sergeant Geoff Conway is quoted:  &#34;Encryption and &#62; passwords hold no fear for us. If there is something on a computer, we
&#62; will find it.&#34;
Simson Garfinkel said:&#62;My understanding [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1447&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>On Mar 25, 2008, at 12:31 PM, Owens Bernard B wrote:
<p>&gt; The nexus between the referenced article and this list seems to be <br />&gt; when Detective Sergeant Geoff Conway is quoted:  &quot;Encryption and <br />&gt; passwords hold no fear for us. If there is something on a computer, we
<p>&gt; will find it.&quot;
<p>Simson Garfinkel said:<br />&gt;My understanding is that there are several standard ways of attacking  <br />drive encryption:
<p>* Asking the suspect for the encryption key<br />* Threatening the suspect to get the encryption key<br />* Brute forcing the passphrase using other information around<br />* Looking for the key in memory
<p>&gt;But if you use strong passphrases and your users are torture-proof,  <br />they&#39;re probably on a pretty good footings.
<p>Although isn&#39;t clear that the good detective was considering an FDE<br />solution, I would take exception to the above statement:
<p>1. FDE solutions only protect the data when the computer has been<br />powered down, and in the case of software FDE, only after five minutes<br />or so have passed, because of the cold boot attack and other attacks.<br />2.  Threatening the suspect with jail time or torture may or may not<br />work, depending on the jurisdiction, although it presumably won&#39;t work<br />in the case of a stolen laptop (unless the Mafia stole it along with<br />your kids.)<br />3.  Brute-forcing the password with an offline attack is much easier<br />than most people realize, and is why we urge users to use two-factor<br />authentication with a hardware token to control their encryption keys.
<p>Consider the following.  Assuming you use a completely random password<br />generator to generate printable characters from the standard<br />96-character keyboard, that amounts to about 6.5 bits of entropy per<br />character.  If you use numbers only, or natural language words, the<br />entropy drops to about 3.3 bits per character.
<p>Most people have trouble remembering more than 8 random characters.<br />That amounts to 52 bits of entropy, or less than single-DES strength,<br />which as we know can be broken in less than a day with comparatively<br />modest resources &#8211; maybe even by the Metropolitan Police.  If numbers or<br />words are used for an equivalent of a 26-bit key, a high-school kid<br />could break it on his PC in an afternoon.
<p>Now, if the password mechanism uses PKCS#5 to slow down the logon<br />process deliberately, this might have the effect of adding some<br />additional resistance.  Let&#39;s assume that an attacker might be able to<br />compute a password hash in a microsecond, but that PKCS#5 is used to<br />cause that to take 1 second per trial.  That adds a factor of 10^6, or<br />another 20 bits of entropy.  Now we are up to the equivalent of a 72-bit<br />key.  But NIST is requiring at least 80-bit cryptography be used today,<br />and at least 128-bit keys for information that will have a useful life<br />past 2030.
<p>That would require a 16-character fully random password, and if you want<br />to match the strength of AES-256, a 35-character password would be<br />required!
<p>If you aren&#39;t using two-factor authentication with a hardware token that<br />enforces a hard limit on the number of incorrect PINs, then yes, you are<br />risk of merely annoying your users and fooling yourself into thinking<br />that you have more than passable security.
<p>Bob
<p>_______________________________________________<br />FDE mailing list<br />FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br /><a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1447/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1447/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1447/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1447&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/26/fde-brute-force-password-cracking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>Re: How is DNSSEC</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/26/re-how-is-dnssec-8/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/26/re-how-is-dnssec-8/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 18:01:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/26/re-how-is-dnssec-8/</guid>
		<description><![CDATA[Dave Howe wrote:&#62; James A. Donald wrote:&#62;&#62;  From time to time I hear that DNSSEC is working fine, and on &#62;&#62; examining the matter I find it is &#34;working fine&#34; except that &#8230;.&#62; &#62; DNSSEC is &#34;working fine&#34; as a technology. However, it is worth &#62; remembering that it works based on digitally signing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1453&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Dave Howe wrote:<br />&gt; James A. Donald wrote:<br />&gt;&gt;  From time to time I hear that DNSSEC is working fine, and on <br />&gt;&gt; examining the matter I find it is &quot;working fine&quot; except that &#8230;.<br />&gt; <br />&gt; DNSSEC is &quot;working fine&quot; as a technology. However, it is worth <br />&gt; remembering that it works based on digitally signing an entire zone &#8211; <br />&gt; the state of the world being what it is, most people prohibit xfer so <br />&gt; any other technology that would allow a zonewalk is not going to be <br />&gt; deployed.<br />&gt; <br />&gt; as far as I can tell, this is a basic design flaw, so isn&#39;t going to be <br />&gt; rectified anytime soon.
<p>RFC 5155 rectifies this design flaw.
<p>&#8211;
<p><a href="http://www.apache-ssl.org/ben.html">http://www.apache-ssl.org/ben.html</a>
<p><a href="http://www.links.org/">http://www.links.org/</a>
<p>&quot;There is no limit to what a man can do or how far he can go if he<br />doesn&#39;t mind who gets the credit.&quot; &#8211; Robert Woodruff
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />The Cryptography Mailing List<br />Unsubscribe by sending &quot;unsubscribe cryptography&quot; to majordomo@metzdowd.com</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1453/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1453/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1453/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1453&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/26/re-how-is-dnssec-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>Re: [FDE] Paula Parker&#8217;s, Detective Inspector of Merseyside Police, response to Child Pornography on internet</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-paula-parkers-detective-inspector-of-merseyside-police-response-to-child-pornography-on-internet-3/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-paula-parkers-detective-inspector-of-merseyside-police-response-to-child-pornography-on-internet-3/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 17:26:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/26/re-fde-paula-parkers-detective-inspector-of-merseyside-police-response-to-child-pornography-on-internet-3/</guid>
		<description><![CDATA[On Tue, 25 Mar 2008 20:04:29 -0700, Simson Garfinkel &#60;simsong@acm.org&#62;wrote&#8230;
&#62; My understanding is that there are several standard ways of&#62; attacking drive encryption:&#62; &#62; * Asking the suspect for the encryption key&#62; * Threatening the suspect to get the encryption key&#62; * Brute forcing the passphrase using other information around&#62; * Looking for the key [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1446&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>On Tue, 25 Mar 2008 20:04:29 -0700, Simson Garfinkel &lt;simsong@acm.org&gt;<br />wrote&#8230;
<p>&gt; My understanding is that there are several standard ways of<br />&gt; attacking drive encryption:<br />&gt; <br />&gt; * Asking the suspect for the encryption key<br />&gt; * Threatening the suspect to get the encryption key<br />&gt; * Brute forcing the passphrase using other information around<br />&gt; * Looking for the key in memory<br />&gt; <br />&gt; But if you use strong passphrases and your users are torture-proof,<br />&gt; they&#39;re probably on a pretty good footings.
<p>You forgot the other side of the rubber hose attacks&#8230;extortion,<br />bribery (in this case, maybe a plea bargain for a severely reduced<br />sentence), etc. A user may be torture-proof, but assuming that their<br />is some other evidence that may convict them (as there often is),<br />they may still not want to waste away the rest of their lives<br />in jail.
<p>I&#39;m hoping&#8211;at this point at least&#8211;that the police in this country<br />aren&#39;t routinely sending their suspects to Gitmo for water-boarding<br />camp.
<p>-kevin<br />&#8212;<br />Kevin W. Wall		Qwest Information Technology, Inc.<br />Kevin.Wall@qwest.com	Office Phone: 614.215.4788<br />&quot;The reason you have people breaking into your software all <br />over the place is because your software sucks&#8230;&quot;<br /> &#8212; Former White House cyber security advisor, Richard Clarke,<br />    at eWeek Security Summit
<p>This communication is the property of Qwest and may contain confidential or<br />privileged information. Unauthorized use of this communication is strictly <br />prohibited and may be unlawful.  If you have received this communication <br />in error, please immediately notify the sender by reply e-mail and destroy <br />all copies of the communication and any attachments.
<p>_______________________________________________<br />FDE mailing list<br />FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br /><a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1446/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1446/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1446/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1446&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-paula-parkers-detective-inspector-of-merseyside-police-response-to-child-pornography-on-internet-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>Re: [FDE] Paula Parker&#8217;s, Detective Inspector of Merseyside</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-paula-parkers-detective-inspector-of-merseyside/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-paula-parkers-detective-inspector-of-merseyside/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 17:25:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/26/re-fde-paula-parkers-detective-inspector-of-merseyside/</guid>
		<description><![CDATA[On Tue, 25 Mar 2008 20:04:29 -0700, Simson Garfinkel wrote:
&#62;But if you use strong passphrases and your users are torture-proof,they&#39;re probably on a pretty good footings.
My users are tax collectors.  They don&#39;t care enough to betorture-proof.  For them, the methods you cite are of no practicalvalue, being either unnecessary or illegal.
For the general [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1445&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>On Tue, 25 Mar 2008 20:04:29 -0700, Simson Garfinkel wrote:
<p>&gt;But if you use strong passphrases and your users are torture-proof,<br />they&#39;re probably on a pretty good footings.
<p>My users are tax collectors.  They don&#39;t care enough to be<br />torture-proof.  For them, the methods you cite are of no practical<br />value, being either unnecessary or illegal.
<p>For the general public, though, I think the original story spread<br />disinformation.  The quote from the DS made it sound like encryption<br />simply doesn&#39;t work and so, to quote from another area of interest,<br />&quot;Resistance is futile.&quot;  I find this sort of spin from law enforcement<br />sources rather unsettling.  It smacks of a lack of integrity and<br />intellectual honesty.  I always hope for better.
<p>Thanks for your thoughts,
<p>Bernard Owens<br />USTreas/IRS
<p>_______________________________________________<br />FDE mailing list<br />FDE@<a href="http://www.xml-dev.com">www.xml-dev.com</a><br /><a href="http://www.xml-dev.com/mailman/listinfo/fde">http://www.xml-dev.com/mailman/listinfo/fde</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1445/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1445/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1445/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1445/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1445/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1445/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1445/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1445/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1445/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1445/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1445/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1445/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1445&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/26/re-fde-paula-parkers-detective-inspector-of-merseyside/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
		<item>
		<title>Re: How is DNSSEC</title>
		<link>http://quantumcrypto.wordpress.com/2008/03/26/re-how-is-dnssec-7/</link>
		<comments>http://quantumcrypto.wordpress.com/2008/03/26/re-how-is-dnssec-7/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 17:20:00 +0000</pubDate>
		<dc:creator>Saqib Ali</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://quantumcrypto.wordpress.com/2008/03/26/re-how-is-dnssec-7/</guid>
		<description><![CDATA[On Fri, 21 Mar 2008 08:52:07 +1000&#34;James A. Donald&#34; &#60;jamesd@echeque.com&#62; wrote:
&#62;  From time to time I hear that DNSSEC is working fine, and on&#62; examining the matter I find it is &#34;working fine&#34; except that &#8230;.&#62; &#62; Seems to me that if DNSSEC is actually working fine, I should be able&#62; to provide an [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1452&subd=quantumcrypto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>On Fri, 21 Mar 2008 08:52:07 +1000<br />&quot;James A. Donald&quot; &lt;jamesd@echeque.com&gt; wrote:
<p>&gt;  From time to time I hear that DNSSEC is working fine, and on<br />&gt; examining the matter I find it is &quot;working fine&quot; except that &#8230;.<br />&gt; <br />&gt; Seems to me that if DNSSEC is actually working fine, I should be able<br />&gt; to provide an authoritative public key for any domain name I control,<br />&gt; and should be able to obtain such keys for other domain names, and<br />&gt; use such keys for any purpose, not just those purposes envisaged in<br />&gt; the DNSSEC specification.  Can I?  It is not apparent to me that I<br />&gt; can.<br />&gt; <br />You might want to look at RFC 3445 and draft-iab-dns-choices-05.txt.
<p>As for DNSSEC keys &#8212; DNSSEC is for securing the DNS.  Once you&#39;ve done<br />that, you can put other records in the DNS, but there are some subtle<br />points in DNS RR design that should be heeded.
<p>		&#8211;Steve Bellovin, <a href="http://www.cs.columbia.edu/~smb">http://www.cs.columbia.edu/~smb</a>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />The Cryptography Mailing List<br />Unsubscribe by sending &quot;unsubscribe cryptography&quot; to majordomo@metzdowd.com</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/quantumcrypto.wordpress.com/1452/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/quantumcrypto.wordpress.com/1452/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/quantumcrypto.wordpress.com/1452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/quantumcrypto.wordpress.com/1452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/quantumcrypto.wordpress.com/1452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/quantumcrypto.wordpress.com/1452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/quantumcrypto.wordpress.com/1452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/quantumcrypto.wordpress.com/1452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/quantumcrypto.wordpress.com/1452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/quantumcrypto.wordpress.com/1452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/quantumcrypto.wordpress.com/1452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/quantumcrypto.wordpress.com/1452/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=quantumcrypto.wordpress.com&blog=1945331&post=1452&subd=quantumcrypto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://quantumcrypto.wordpress.com/2008/03/26/re-how-is-dnssec-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a6c8c18caf16643b9ffc9c2aa6fc889b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Saqib Ali</media:title>
		</media:content>
	</item>
	</channel>
</rss>