Teraflop Troubles: The Power of Graphics Processing Units May Threaten the World’s Password Security System
Georgia Tech Research Institute (08/10/10) Englehardt, Kirk J.; Toon, John
Georgia Tech Research Institute (GTRI) computer scientists are studying whether desktop computers with graphics processing units (GPUs) are so powerful that they compromise password protection. "Right now we can confidently say that a seven-character password is hopelessly inadequate--and as GPU power continues to go up every year, the threat will increase," says GTRI's Richard Boyd. Modern GPUs are so fast because they are designed as parallel computers. When given a problem, GPUs divide the task among multiple processing units and tackle different parts of the problem simultaneously. Software programs designed to break passwords are freely available on the Internet, and these programs, combined with the availability of GPUs, mean it is only a matter of time before the password threat will be immediate, the researchers say. GTRI's Joshua L. Davis says the best password is an entire sentence that includes numbers or symbols, because it is both long and complex and yet easy to remember.
Tuesday, August 10, 2010
Blog: Teraflop Troubles: The Power of Graphics Processing Units May Threaten the World's Password Security System
Monday, July 19, 2010
Blog: Passwords That Are Simple--and Safe
Passwords That Are Simple--and Safe
Technology Review (07/19/10) Garfinkel, Simson
Microsoft researchers have developed a new approach to creating passwords that retains the security of complex passwords but does away with their complexity requirements. The method makes sure that no more than a few users can have the same password, which has a similar effect on overall security when employed by organizations with millions of users. The system counts how many times any user on the service chooses a given password, and when more than a small number of users pick a password, it is banned and no one else is allowed to choose it. "Replacing password creation rules with popularity limitations has the potential to increase both security and usability," write Microsoft researchers Cormac Herley and Stuart Schechter in a paper to be published at the upcoming Hot Topics in Security conference. "Since no passwords are allowed to become too common, attackers are deprived of the popular passwords they require to compromise a significant faction of accounts using online guessing."
Monday, June 7, 2010
Blog: Researchers: Poor Password Practices Hurt Security for All
Researchers: Poor Password Practices Hurt Security for All
IDG News Service (06/07/10) Heichler, Elizabeth
University of Cambridge researchers recently completed a large study of password-protected Web sites and found that a lack of industry standards harms end-user security. Weak implementations of password authentication at low-level sites compromises the protections offered by higher-security sites because individuals reuse passwords, write Cambridge researchers Joseph Bonneau and Soren Preibusch. Attackers can use low-security Web sites such as news outlets to learn passwords associated with specific email addresses, and then use those passwords to access higher-security sites such as e-commerce vendors, Bonneau says. Based on data collected from 150 Web sites, the researchers say they found widespread, poor design choices, inconsistencies, and mistakes. "Sites' decisions to collect passwords can be viewed as a tragedy of the commons, with competing Web sites collectively depleting users' capacity to remember secure passwords," write the researchers. More than 75 percent of sites examined failed to provide users with feedback or advice on choosing a secure password. The researchers also found widespread weaknesses in how passwords are submitted to the server when users log in.
Wednesday, October 24, 2007
Security: Password-Cracking Chip Causes Security Concerns
Password-Cracking Chip Causes Security Concerns
New Scientist (10/24/07) Brandt, Andrew
Russia's Elcomsoft has filed a U.S. patent application for a technique for cracking computer passwords using inexpensive off-the-shelf computer graphics hardware. Using an inexpensive graphics card, Elcomsoft was able to increase its password cracking speed by a factor of 25, says Elcomsoft's Vladimir Katalov. The most difficult passwords, such as those used to log onto a Windows Vista computer, would normally take months of continuous computer processing using a normal central processing unit. However, Katalov says they can be cracked in as little as three to five days by using a graphics processing unit. He says less complex passwords can be cracked in a few minutes instead of hours or days. The speed increase comes from how a GPU processes information. Password cracking is an effective way to access information on a computer, but is generally ineffective at accessing online banking services since their Web sites often require multiple passwords and shut down after several incorrect attempts. Cryptography Research's Benjamin Jun says the technique is an impressive achievement that required elegant, intelligent design, and while the ability to crack passwords using GPUs is concerning, it is not a cause for panic. Advancements in cryptographic keys and the growing trend of encrypting entire hard drives is making accessing sensitive data more difficult. "Should I throw away my Web server and run for the hills?" asks Jun. "I don't think so."
Click Here to View Full Article
Sunday, October 21, 2007
Security: 'Half-Quantum' Cryptography Promises Total Security; quantum-encrypted key only
'Half-Quantum' Cryptography Promises Total Security
New Scientist (10/21/07) Marks, Paul
Many cryptographers believed that the only way to achieve complete security when transmitting information was to use quantum cryptography to share the key used for encryption. However, researchers say they can achieve the same level of security even if one party stays in the world of classical physics. In conventional quantum cryptography, a sender, dubbed Alice, generates a string of 0s and 1s and encodes them using a photon polarized in either the computational "basis" in which 0 and 1 are represented by vertical and horizontal polarizations, or in diagonal bases in which 1 and 0 are represented by 45 degree and negative 45 degree polarizations. When the photons arrive at their destination, the receiver, dubbed Bob, chooses either the computational or diagonal bases to measure each one, telling Alice which he has chosen. If the chosen basis is wrong, Alice tells Bob to discard that bit. The bits that are guessed correctly form the secret key. If an eavesdropper intercepts any photons, the stream is interrupted and Bob's ability to read a number of the photons he might have read correctly is destroyed. The increase in unreadable photons tells Bob the communication channel has been compromised. Researchers at the Israel Institute of Technology in Haifa and the University of Montreal have demonstrated that only Alice needs to be quantum-equipped. Alice encodes the bits as usual, though Bob can only use the computational basis. Bob randomly measures some of the received photons and returns the rest to Alice untouched. The bits read in the computational basis form the key. The system is still secure because anyone eavesdropping does not know which photons will be returned to Alice unmeasured.
Click Here to View Full Article
Blog Archive
-
▼
2012
(35)
-
▼
April 2012
(13)
- Blog: Algorithmic Incentives
- Blog: Finding ET May Require Giant Robotic Leap
- Blog: New Julia Language Seeks to Be the C for Sci...
- Blog: Fast Data hits the Big Data fast lane
- Blog: Beyond Turing's Machines
- Blog: Cooperating Mini-Brains Show How Intelligenc...
- Blog: Transactional Memory: An Idea Ahead of Its Time
- Blog: Bits of Reality
- Blog: Berkeley Group Digs In to Challenge of Makin...
- Blog: Programming Computers to Help Computer Progr...
- Blog: To Convince People, Come at Them From Differ...
- Blog: Self-Sculpting Sand
- Blog: UMass Amherst Computer Scientist Leads the W...
- ► March 2012 (16)
- ► February 2012 (3)
- ► January 2012 (3)
-
▼
April 2012
(13)
-
►
2011
(118)
- ► December 2011 (9)
- ► November 2011 (11)
- ► October 2011 (7)
- ► September 2011 (13)
- ► August 2011 (7)
- ► April 2011 (8)
- ► March 2011 (11)
- ► February 2011 (12)
- ► January 2011 (15)
-
►
2010
(183)
- ► December 2010 (16)
- ► November 2010 (15)
- ► October 2010 (15)
- ► September 2010 (25)
- ► August 2010 (19)
- ► April 2010 (21)
- ► March 2010 (7)
- ► February 2010 (6)
- ► January 2010 (6)
-
►
2009
(120)
- ► December 2009 (5)
- ► November 2009 (12)
- ► October 2009 (2)
- ► September 2009 (3)
- ► August 2009 (16)
- ► April 2009 (4)
- ► March 2009 (20)
- ► February 2009 (9)
- ► January 2009 (19)
-
►
2008
(139)
- ► December 2008 (15)
- ► November 2008 (16)
- ► October 2008 (17)
- ► September 2008 (2)
- ► August 2008 (2)
- ► April 2008 (12)
- ► March 2008 (25)
- ► February 2008 (16)
- ► January 2008 (6)
-
►
2007
(17)
- ► December 2007 (4)
- ► November 2007 (4)
- ► October 2007 (7)
Blog Labels
- research
- CSE
- security
- software
- web
- AI
- development
- hardware
- algorithm
- hackers
- medical
- machine learning
- robotics
- data-mining
- semantic web
- quantum computing
- Cloud computing
- cryptography
- network
- EMR
- search
- NP-complete
- linguistics
- complexity
- data clustering
- optimization
- parallel
- performance
- social network
- HIPAA
- accessibility
- biometrics
- connectionist
- cyber security
- passwords
- voting
- XML
- biological computing
- neural network
- user interface
- DNS
- access control
- firewall
- graph theory
- grid computing
- identity theft
- project management
- role-based
- HTML5
- NLP
- NoSQL
- Python
- cell phone
- database
- java
- open-source
- spam
- GENI
- Javascript
- SQL-Injection
- Wikipedia
- agile
- analog computing
- archives
- biological
- bots
- cellular automata
- computer tips
- crowdsourcing
- e-book
- equilibrium
- game theory
- genetic algorithm
- green tech
- mobile
- nonlinear
- p
- phone
- prediction
- privacy
- self-book publishing
- simulation
- testing
- virtual server
- visualization
- wireless