Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home Science & Technology Technology

Data scrambling systems used by millions of web servers could be much weaker say researchers

byCustoms Today Report
12/08/2015
in Technology
Share on FacebookShare on Twitter

LONDON: The data scrambling systems used by millions of web servers could be much weaker than they ought to be, say researchers. A study found shortcomings in the generation of the random numbers used to scramble or encrypt data. The hard-to-guess numbers are vital to many security measures that prevent data theft. But the sources of data that some computers call on to generate these numbers often run dry.

This, they warned, could mean random numbers are more susceptible to well-known attacks that leave personal data vulnerable. “This seemed like just an interesting problem when we got started but as we went on it got scary,” said security analyst Bruce Potter who, along with researcher Sasha Moore, carried out the study that was presented at the Black Hat security event in Las Vegas.

You might also like

Tesla driverless system to use updated radar technology

12/09/2016

Apple to develop its own self-driving technology

10/09/2016

It looked at the ways that widely used Linux-based web server software generated strings of data that were used as a “seed” for random numbers.

Large, hard-to-guess numbers are vital for encrypting data. They are also used by servers in more mundane security tasks such as randomising where data is stored in memory to thwart attempts by hackers to predict what a

Machine is doing. The process of generating a good random number begins with the server translating mouse movements, keyboard presses and other things a machine does into a data stream of ones and zeros. This data is gathered in a “pool” that is regularly called on for many security functions.

Ideally, said Mr Potter, this pool of data would possess a high degree of a property known as “entropy”. An unshuffled pack of cards has low entropy, said Mr Potter, because there is little surprising or uncertain about the order the cards would be dealt. The more a pack was shuffled, he said, the more entropy it had because it got harder to be sure about which card would be turned over next.

Data is taken from the pool in discrete chunks to make a “seed” that gives rise to a random number. Broadly, said Mr Potter, the higher the entropy, the harder a random number should be to guess. Unfortunately, he said, the entropy of the data streams on Linux servers was often very low because the machines were not generating enough raw information for them.

Also, he said, server security software did little to check whether a data stream had high or low entropy.

These pools often ran dry leaving encryption systems struggling to get good seeds for their random number generators, said Mr Potter. This might meant they were easier to guess and more susceptible to a brute force attack because seeds for new numbers were generated far less regularly than was recommended. The work had exposed unknown aspects of the basic workings of encryption on millions of widely used web servers, said Mr Potter. “That scared us because when you have unknowns in crypto that’s when things go sideways.

 

 

 

 

Related Stories

Tesla driverless system to use updated radar technology

byCT Report
12/09/2016

WASHINGTON: Electric carmaker Tesla announced Sunday it was upgrading its Autopilot software to use more advanced radar technology. In a...

Apple to develop its own self-driving technology

byCT Report
10/09/2016

SAN FRANCISCO: Apple may not become an automaker, but it still wants to develop its own self-driving technology. The iPhone-maker's...

‘YouTubers’ outshining old-school television

byCT Report
09/08/2016

SAN FRANCISCO: A media revolution is taking place, and most people over 35 years of age aren’t tuned in. Millennial...

Google pays tribute to Edhi

byCT Report
11/07/2016

ISLAMABAD: The technology giant, Google, has paid tribute to renowned social activist, philanthropist and humanitarian Abdul Sattar Edhi by placing...

Next Post

SBP allows banks to remit Saudi riyal for Haj

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.