<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kryptering - Information och nyheter om krypto &#187; rc4</title>
	<atom:link href="http://kryptera.se/t/rc4/feed/" rel="self" type="application/rss+xml" />
	<link>http://kryptera.se</link>
	<description>Senaste nytt om kryptering och krypto</description>
	<lastBuildDate>Thu, 29 Dec 2011 11:16:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>	<div id='fb-root'></div>
					<script type='text/javascript'>
						window.fbAsyncInit = function()
						{
							FB.init({appId: null, status: true, cookie: true, xfbml: true});
						};
						(function()
						{
							var e = document.createElement('script'); e.async = true;
							e.src = document.location.protocol + '//connect.facebook.net/sv_SE/all.js';
							document.getElementById('fb-root').appendChild(e);
						}());
					</script>	
						<item>
		<title>Windows 8 lösenord, RC4, Google Wallet och MSB</title>
		<link>http://kryptera.se/windows-8-losenord-rc4-google-wallet-och-msb/</link>
		<comments>http://kryptera.se/windows-8-losenord-rc4-google-wallet-och-msb/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 18:19:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Okategoriserade]]></category>
		<category><![CDATA[Ciphers]]></category>
		<category><![CDATA[DANE]]></category>
		<category><![CDATA[dnssec]]></category>
		<category><![CDATA[Google Wallet]]></category>
		<category><![CDATA[Moxie Marlinspike]]></category>
		<category><![CDATA[MSB]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[Python SSl]]></category>
		<category><![CDATA[rc4]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[RSA SecurID]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://kryptera.se/?p=921</guid>
		<description><![CDATA[Vi sammanfattar här några av de nyhterna vi tweetat ut de senaste dagarna: Windows 8 will have picture password sign in http://t.co/GdH4Ku7z Moxie Marlinspike Answers Your Questions http://to.ly/bKLa Python SSL stack doesn&#8217;t support ordering of Ciphers http://t.co/RHaVasiG Google’s mobile payment app (Google Wallet)  fails to encrypt personal data, according to research http://t.co/K6RV41VE What&#8217;s the deal with RC4? http://t.co/3JJYP5bF Klart vilka [...]<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://kryptera.se/windows-8-losenord-rc4-google-wallet-och-msb/' layout='default' show_faces='false' width='400' action='like' colorscheme='light' send='false' /></div><div class="alignleft"><div class="g-plusone" data-href="http://kryptera.se/windows-8-losenord-rc4-google-wallet-och-msb/" size="tall" count="true"></div></div><p>Vi sammanfattar här några av de nyhterna vi tweetat ut de senaste dagarna:</p>
<ul>
<li>Windows 8 will have picture password sign in <a href="http://t.co/GdH4Ku7z" target="_blank">http://t.co/GdH4Ku7z</a></li>
<li><a href="http://kryptera.se/t/moxie-marlinspike/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Moxie Marlinspike">Moxie Marlinspike</a> Answers Your Questions <a title="http://t.co/DTmyotLc" href="http://t.co/DTmyotLc" rel="nofollow" target="_blank" data-expanded-url="http://to.ly/bKLa" data-ultimate-url="http://t.co/DTmyotLc" data-display-url="to.ly/bKLa">http://to.ly/bKLa</a></li>
<li><a href="http://kryptera.se/t/python-ssl/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Python SSl">Python SSL</a> stack doesn&#8217;t support ordering of <a href="http://kryptera.se/t/ciphers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Ciphers">Ciphers</a> <a href="http://t.co/RHaVasiG" target="_blank">http://t.co/RHaVasiG</a></li>
<li>Google’s mobile payment app (<a href="http://kryptera.se/t/google-wallet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google Wallet">Google Wallet</a>)  fails to encrypt personal data, according to research <a href="http://t.co/K6RV41VE" target="_blank">http://t.co/K6RV41VE</a></li>
<li>What&#8217;s the deal with <a href="http://kryptera.se/t/rc4/" class="st_tag internal_tag" rel="tag" title="Posts tagged with rc4">RC4</a>? <a href="http://t.co/3JJYP5bF" target="_blank">http://t.co/3JJYP5bF</a></li>
<li>Klart vilka kommuner som får medel för <a href="http://kryptera.se/t/dnssec/" class="st_tag internal_tag" rel="tag" title="Posts tagged with dnssec">DNSSEC</a> <a title="https://www.msb.se/sv/Start1/Nyheter-fran-MSB/Nyheter---Informationssakerhet/Klart-vilka-kommuner-som-far-medel-for-DNSSEC" href="http://t.co/JILUjqEe" rel="nofollow" target="_blank" data-expanded-url="http://to.ly/bKxB" data-ultimate-url="https://www.msb.se/sv/Start1/Nyheter-fran-MSB/Nyheter---Informationssakerhet/Klart-vilka-kommuner-som-far-medel-for-DNSSEC" data-display-url="to.ly/bKxB">http://to.ly/bKxB</a> - 86 av 120 kommuner får bidrag av <a href="http://msbs.e" target="_blank">MSB </a>för att inför DNSSEC.</li>
<li><a href="http://kryptera.se/t/rsa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with rsa">RSA</a> <a href="http://kryptera.se/t/securid/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SecurID">SecurID</a> Software Token for Windows DLL Loading Error Lets Remote Users Execute Arbitrary Code <a title="http://www.doecirc.energy.gov/bulletins/u-063.shtml" href="http://t.co/vLBeY84G" rel="nofollow" target="_blank" data-expanded-url="http://to.ly/bKxy" data-ultimate-url="http://www.doecirc.energy.gov/bulletins/u-063.shtml" data-display-url="to.ly/bKxy">http://to.ly/bKxy</a></li>
<li>GlobalSign concludes investigation of hacker attack <a title="http://www.h-online.com/security/news/item/GlobalSign-concludes-investigation-of-hacker-attack-1396349.html" href="http://t.co/46g2BqEH" rel="nofollow" target="_blank" data-expanded-url="http://www.h-online.com/security/news/item/GlobalSign-concludes-investigation-of-hacker-attack-1396349.html" data-ultimate-url="http://www.h-online.com/security/news/item/GlobalSign-concludes-investigation-of-hacker-attack-1396349.html" data-display-url="h-online.com/security/news/…">http://www.h-online.com/security/news/item/GlobalSign-concludes-investigation-of-hacker-attack-1396349.html</a></li>
<li>Sovereign Keys: A Proposal to Make <a href="http://https.se" target="_blank">HTTPS </a>and Email More Secure <a title="https://www.eff.org/deeplinks/2011/11/sovereign-keys-proposal-make-https-and-email-more-secure" href="http://t.co/4qYZOo65" rel="nofollow" target="_blank" data-expanded-url="http://to.ly/bqio" data-ultimate-url="https://www.eff.org/deeplinks/2011/11/sovereign-keys-proposal-make-https-and-email-more-secure" data-display-url="to.ly/bqio">http://to.ly/bqio</a></li>
<li>Decrypt TrueCrypt Headers <a title="http://www.reddit.com/r/crypto/comments/nepid/decrypt_truecrypt_headers" href="http://t.co/KV2lGHOc" rel="nofollow" target="_blank" data-expanded-url="http://www.reddit.com/r/crypto/comments/nepid/decrypt_truecrypt_headers/" data-ultimate-url="http://www.reddit.com/r/crypto/comments/nepid/decrypt_truecrypt_headers" data-display-url="reddit.com/r/crypto/comme…">http://www.reddit.com/r/crypto/comments/nepid/decrypt_truecrypt_headers/</a></li>
<li>Ett miniseminarium om <a href="http://kryptera.se/t/dane/" class="st_tag internal_tag" rel="tag" title="Posts tagged with DANE">DANE</a> hos .SE med bl.a.<a href="https://twitter.com/jschlyter" target="_blank"> Jakob Schlyter</a> och <a href="https://twitter.com/staffanha" target="_blank">Staffan Hagnell</a> som talare <a href="https://www.iis.se/evenemang/ett-miniseminarium-om-dane" target="_blank">https://www.iis.se/evenemang/ett-miniseminarium-om-dane</a></li>
</ul>
<p>Du följer väl oss på Twitter? <a href="https://twitter.com/kryptera" target="_blank">https://twitter.com/kryptera</a></p>
<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></content:encoded>
			<wfw:commentRss>http://kryptera.se/windows-8-losenord-rc4-google-wallet-och-msb/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BEAST: Nygammal sårbarhet i SSL</title>
		<link>http://kryptera.se/beast-nygammal-sarbarhet-i-ssl/</link>
		<comments>http://kryptera.se/beast-nygammal-sarbarhet-i-ssl/#comments</comments>
		<pubDate>Tue, 27 Sep 2011 07:09:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Okategoriserade]]></category>
		<category><![CDATA[Anonymiseringsnätverk]]></category>
		<category><![CDATA[beast]]></category>
		<category><![CDATA[CBC]]></category>
		<category><![CDATA[IT-säkerhetsforskare]]></category>
		<category><![CDATA[Juliano Rizzo]]></category>
		<category><![CDATA[rc4]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[Thai Duong]]></category>
		<category><![CDATA[tor]]></category>

		<guid isPermaLink="false">http://kryptera.se/?p=898</guid>
		<description><![CDATA[IT-säkerhetsforskarna Thai Duong och Juliano Rizzo hittade ett nytt sätt att använda en gammal sårbarhet i TLS &#60;= 1.0 där CBC används som går ut på att injicera känd klartext i en krypterad SSL 1.0-session vilket gör att det går att knäcka anslutningen på ca 10 minuter. Detta påverkar ej anonymiseringsnätverket Tor. Samt så påverkar detta ej TLS version [...]<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://kryptera.se/beast-nygammal-sarbarhet-i-ssl/' layout='default' show_faces='false' width='400' action='like' colorscheme='light' send='false' /></div><div class="alignleft"><div class="g-plusone" data-href="http://kryptera.se/beast-nygammal-sarbarhet-i-ssl/" size="tall" count="true"></div></div><p>IT-säkerhetsforskarna <a href="http://kryptera.se/t/thai-duong/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Thai Duong">Thai Duong</a> och <a href="http://kryptera.se/t/juliano-rizzo/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Juliano Rizzo">Juliano Rizzo</a> hittade ett nytt sätt att använda en <a href="http://www.mail-archive.com/openssl-dev@openssl.org/msg10664.html" target="_blank">gammal </a>sårbarhet i TLS &lt;= 1.0 där <a href="http://kryptera.se/t/cbc/" class="st_tag internal_tag" rel="tag" title="Posts tagged with CBC">CBC</a> används som går ut på att injicera känd klartext i en krypterad <a href="http://kryptera.se/t/ssl/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ssl">SSL</a> 1.0-session vilket gör att det går att knäcka anslutningen på ca 10 minuter.</p>
<p>Detta <a href="https://blog.torproject.org/blog/tor-and-beast-ssl-attack" target="_blank">påverkar ej </a>anonymiseringsnätverket <a href="http://kryptera.se/t/tor/" class="st_tag internal_tag" rel="tag" title="Posts tagged with tor">Tor</a>. Samt så påverkar detta ej TLS version 1.1 men dock används denna version ej i stor utsträckning.</p>
<p>Värt att notera är även att Googles servrar ej påverkas av detta då de använder <a href="http://kryptera.se/t/rc4/" class="st_tag internal_tag" rel="tag" title="Posts tagged with rc4">RC4</a> och inte CBC-läge i sin SSL/TLS.</p>
<p>Läs mer hos <a href="http://isc.sans.edu/diary.html?storyid=11635" target="_blank">ISC/SANS</a>, <a href="http://it.slashdot.org/story/11/09/20/1833232/Hackers-Break-Browser-SSLTLS-Encryption" target="_blank">Slashdot</a>, <a href="http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/" target="_blank">The Register</a>, <a href="http://threatpost.com/en_us/blogs/new-attack-breaks-confidentiality-model-ssl-allows-theft-encrypted-cookies-091911" target="_blank">Threatpost</a>.</p>
<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></content:encoded>
			<wfw:commentRss>http://kryptera.se/beast-nygammal-sarbarhet-i-ssl/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skype krypteringen knäckt</title>
		<link>http://kryptera.se/skype-krypteringen-knackt/</link>
		<comments>http://kryptera.se/skype-krypteringen-knackt/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 15:16:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Okategoriserade]]></category>
		<category><![CDATA[aes]]></category>
		<category><![CDATA[rc4]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[skype]]></category>

		<guid isPermaLink="false">http://kryptera.se/?p=466</guid>
		<description><![CDATA[Eller rättare sagt så har en del av Skype-protokollet reverse-engineerats. Det är den del av Skype som använder RC4-algoritmer och varianter på denna. Följande framgår av källkoden: &#124;*&#124; Skype Library RC4 v1.109 by Sean O&#8217;Neil. &#124;*&#124; Copyright (c) 2004-2010 VEST Corporation. &#124;*&#124; All rights reserved. &#124;*&#124; Not for commercial use. &#124;*&#124; &#124;*&#124; We are reverse [...]<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://kryptera.se/skype-krypteringen-knackt/' layout='default' show_faces='false' width='400' action='like' colorscheme='light' send='false' /></div><div class="alignleft"><div class="g-plusone" data-href="http://kryptera.se/skype-krypteringen-knackt/" size="tall" count="true"></div></div><p>Eller rättare sagt så har en del av <a href="http://kryptera.se/t/skype/" class="st_tag internal_tag" rel="tag" title="Posts tagged with skype">Skype</a>-protokollet reverse-engineerats. Det är den del av <a href="http://kryptera.se/t/skype/" class="st_tag internal_tag" rel="tag" title="Posts tagged with skype">Skype</a> som använder <a href="http://kryptera.se/t/rc4/" class="st_tag internal_tag" rel="tag" title="Posts tagged with rc4">RC4</a>-algoritmer och varianter på denna. Följande framgår av källkoden:</p>
<blockquote><p>|*| Skype Library RC4 v1.109 by Sean O&#8217;Neil.<br />
|*| Copyright (c) 2004-2010 VEST Corporation.<br />
|*| All rights reserved.<br />
|*| Not for commercial use.<br />
|*|<br />
|*| We are reverse engineers.<br />
|*| We can prove if you have used this code in your product.<br />
|*| We will find you.<br />
|*| We will prosecute for copyright infringement.<br />
|*| This code is quite unique and is easily identifiable.<br />
|*| Result may match Skype&#8217;s 100%, but this code is ours.<br />
|*| The computation is significantly different from Skype&#8217;s.<br />
|*|<br />
|*| For academic research and educational purposes only.<br />
|*| If you require Skype compatibility in your products,<br />
|*| feel free to contact Sean O&#8217;Neil on <a href="http://www.enrupt.com">www.enrupt.com</a><br />
|*|<br />
|*| Last changes: 09.07.2009 (a minor correction from 1.108 that does not affect its use in Skype-compatible projects)<br />
|*| Published: 07.07.2010<br />
|*| More will be published at 27C3, December 2010 (<a href="http://www.ccc.de/en/calendar">http://www.ccc.de/en/calendar</a>)</p></blockquote>
<p>Som hittas här: <a href="http://cryptolib.com/ciphers/skype/">cryptolib.com/ciphers/skype/</a></p>
<p>Sean O&#8217;Neil har även skrivit ett antal förtydliganden på sin <a href="http://www.enrupt.com/index.php/2010/07/09/ddos-etc">blogg</a> där han bl.a. skriver att detta inte påverkar säkerheten i Skype eftersom tal, filöverföringar etc. är krypterade med <a href="http://kryptera.se/t/aes/" class="st_tag internal_tag" rel="tag" title="Posts tagged with aes">AES</a> 256-bit nycklar,  1024-bit <a href="http://kryptera.se/t/rsa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with rsa">RSA</a> algoritm samt autentiserade med a 2048-bit <a href="http://kryptera.se/t/rsa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with rsa">RSA</a>-nycklar. Källkoden som han har släppt hanterar enbart kommunikation mellan Skype-klienten och dess noder.</p>
<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></content:encoded>
			<wfw:commentRss>http://kryptera.se/skype-krypteringen-knackt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

