• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

The Wikileaks "insurance.aes256" File

I dunno. Is quantum computing brute? But they have an amazing amount of computing horsepower, that I am sure of.
Assuming they've got quantum computing capability and not knowing much about decrypting, I'd assume it'd just be put towards brute-forcing the key at an obscene speed.

Again, layman's idea. There's probably a plethora of ways to crack something.

And a quick googling suggests that brute force is next to useless against 128 or 256 bit keys.

But it's an interesting thought.
 
Assuming they've got quantum computing capability and not knowing much about decrypting, I'd assume it'd just be put towards brute-forcing the key at an obscene speed.

Again, layman's idea. There's probably a plethora of ways to crack something.

And a quick googling suggests that brute force is next to useless against 128 or 256 bit keys.

But it's an interesting thought.


In combination with "Wikileaks" Rubberhose filesystem there is no way in hell to crack the file with all computer power on this planet in the next 10 years. Unless there is a secret and intentionally included backdoor for AES, that is.
 
It's very unlikely that an aes256 encrypted file can be brute-forced during the lifetime of our solar system, with current technology. They key space is just too big. There are methods to decrease the key space that has to be searched (see here for example), but still it is extremely large.

Keep in mind that you have to do more than just generate a random bit-sequence and compare it against something else. You have to actually decrypt a block of data and see if the result is valid, and that is actually what takes the majority of time needed.

Then, there is no indication that the file is, or is only, aes256 encrypted. It could be anything else, and the name is chosen just to put people on the wrong track. Then, it is possible that the decrypted result will actually be another encrypted file. Pretty much like you can encrypt your harddisk or containers with TrueCrypt, where you can use a chain of different ciphers.

Since Assange is no fool in regards to cryptography, i really doubt that he chose a method that would be easy to brute-force. But then, for all we know the password could be "wikileaks" or "assange" or whatever obvious passphrase.

Greetings,

Chris

Edit: To give a hint at the proportions: 256 bits equal 2^256 possibilities. That equals a number range from 0 to 115792089237316195423570985008687907853269984665640564039457584007913129639935

Now lets assume you only want to count through that range on your computer, and lets assume your computer can actually increment a 256 bit number in one cycle, and that your computer runs at 2GHz clock speed. Unless i'm borking up my math here, that would be 2^256 / 2000000000 / 60 / 60 / 24 / 365 = 1835871531540401373000000000000000000000000000000000000000000 years. Using a rounded-up age of the universe of 14 billion years, that makes 131133680824314383800000000000000000000000000000000 times the age of the universe.

And that is for _only_ counting through the 2^256 space.
 
Last edited:
I've been pondering how attackable the password to this is. It seems to me that there's a limitation on how complex the password can be, by the neccesity to be able to distribute it in an emergency. Worst case scenario, Julian Assange shouts it in a courtroom, or while being dragged past reporters outside a prison, or some such.
It could just be "I love pie, it doesn't make you fat!" Essentially uncrackable and exposes one of the greatest conspiracies ever at the same time.


Thanks for the tip, DDT. :) I guess it does not matter which program someone uses since AES is a standardized encryption format, right?
If it's just raw encrypted data, but you have no actual way of knowing if it is. AES is just an algorithm. It isn't a file format. Knowing the encryption algorithm doesn't mean you know how the file itself is structured. It could for instance have a header, be split into multiple independently encrypted sections, be split into 100MB chunks that are randomly ordered, and so on.


Also, there are rumors that NSA and CIA do know some kind of backdoor to AES. Does someone know more about the probability of such a backdoor?
Not very likely since it has been widely studied by independent people. It could have an intentional design weakness that was intended as a sort of backdoor (Microsoft has been accused of this from time to time), but it's not very likely.


Remember that it is entirely likely that NSA has bleeding edge technology you and I can only dream of.
Why?
 
Thanks for the tip, DDT. :) I guess it does not matter which program someone uses since AES is a standardized encryption format, right?

Also, there are rumors that NSA and CIA do know some kind of backdoor to AES. Does someone know more about the probability of such a backdoor?
Indeed, AES is a publicly known algorithm. Everyone who studies the definition of AES can write his/her own program implementing it. I hadn't heard there were rumors about backdoors in AES, but here is an article debunking that, echoing my thoughts about it.

There had been persistent rumors about a backdoor in DES, the predecessor of AES as the US standard for (symmetric) encryption, and they were based on the fact that DES was based on a previously published encryption method, but with some steps added of which nobody really knew what they were good for. AES, however, is the result of a public contest organized by NIST. The winner of that contest, Rijndael, was created by two Belgian cryptographers working, then, at the University of Leuven, and has been adopted unchanged.

And while the NSA might have gotten away with a backdoor 30 years ago, when DES was adopted, it can't now. Back then, the cryptography field was relatively small. Now, it is big business and many bright cryptographers work in academia or in business. There are many eyeballs scrutinizing encryption algorithms, especially widely used ones as AES. There are regular news reports about (teams of) cryptographers discovering weaknesses in encryption algorithms - typically saying that they found a way to cut a few bits off the key space.

The basic concept around modern-day cryptography is that you can just publish the encryption algorithm, because the strength lies in devising an algorithm that is so strong that the only way to attack it is brute-force trial and error. Symmetric encryption algorithms as DES and AES make use of a single key, which is used both for encryption and for decryption. A brute-force attack means trying out all possible keys and look if something sensible comes out of it. DES has a key of 56 bits, which gives 2^56 possible keys. That was huge in the 1970s, but as you can see from the wiki-page, in 1999 it was possible to brute-force decrypt it within a day - that was done by a SETI-like network of hobbyists who all donated a bit of their computer time.

The number of keys of DES is already huge - 2^56 is a 17-digit number. When you increase the key length with a single bit, however, it means that you double the number of possible keys. Adding two bits means that the key space increases four-fold. Etcetera. AES comes in two variants: with a key length of 128 and with a key length of 256. That means that the number of possible keys is a 39-digit number, resp. a 77-digit number. That's huge. To imagine how huge, let's go with those 1999 numbers - cracking a 56-bit key in a day. The number of possible keys for AES-128 is a number that has 21 more digits (in decimal) than DES. So that means that you need 10^21 days to crack AES in 1999 terms. That is in the order of 10^18 years. Computers have become faster - let's very generously say they have doubled in computational power each year (Moore's law). That means they have become faster by a factor of 1,000 in 10 years. Then you're still left with 10^15 years to crack AES-128. The universe is 10^10 years old.

It's very unlikely that an aes256 encrypted file can be brute-forced during the lifetime of our solar system, with current technology. They key space is just too big.
As I already said in post #7 in this thread:
And AES is state-of-the-art encryption, you can't even begin to try to decrypt that - with the current technology, the world earlier comes to an end than you have decrypted it (brute force).
and quantified above. And that was for AES-128, whereas the Wikileaks-file is suggested to be encrypted in AES-256. :rolleyes:

What I said about increasing key length applies in the reverse direction for weaknesses discovered, Those discoveries are typically of the form that "key A is equivalent to key B" in a regular pattern over all keys, and thus, the key space is halved - or quartered when the discovery knocks off two bits of the key space. They have always involved knocking off only a few bits off the key space thus far. And I'm not aware of such weaknesses with AES. And while obviously, the NSA has some smart cookies on the payroll, it might be possible that the NSA has discovered a weakness and keeps it secret, eventually another smart cookie working outside the NSA discovers it. I really don't believe the NSA knew about a weakness 10 years ago when AES was standardized and nobody outside the NSA has yet discovered it.

But there are other ways to attack a cipher.

Sometimes the key strength is compromised in a way that exponentially reduces search time.
You need to knock off quite a few bits off the key length in order to get into the realm of the feasible, as my calculations above show.

Enough computing power and you do not need a back door.
This is a bit off-tangent, but who has the most computing power nowadays: the NSA or a network like SETI or distributed.net? We're in the internet age, and anyone with enough marketing can harness the power of millions of people around the world, who all have Gigahertz processors in their desktops and laptops now. Reliability or robustness or speed of peripheral devices is not interesting, cracking ciphers is a purely computational task where only the CPU speed is important and that can be excellently distributed among gazillions of different computers.

Remember that it is entirely likely that NSA has bleeding edge technology you and I can only dream of.
Which is where quantum computing will come in when we have it.
As far as I know, quantum computing is still very much in its infancy, and successful calculations have only involved a handful of qubits. Evidence that the NSA is in the frontline of this?

Moreover, the article I linked to above has Whit Diffie say that, even when it is fully functional, quantum computing will render cracking AES-256 to the order of magnitude of AES-128 with conventional computers.
 
Which is where quantum computing will come in when we have it.

Sure, but i think that it is still a long way to get there. Quantum computing is still in its infancy. And then, from what i understand, you don't get the final correct result, but a result with a certain probability of being the correct one. So the process has to be executed multiple times to "make more sure" to have found the correct answer.

Also, from what i know, QC would reduce the time needed for the problem of brute-forcing an encryption by going through the whole keyspace of n possibilities, n being 2^256 in our case, to the square-root of n, which would be 340282366920938463463374607431768211456 attempts still. Assuming an linear search, at a rate of 2 billion attempts per second, we are at 7692291642273818709000 years of processing time.

However, i have little knowledge of QC, so i might be horribly wrong here.

But there are other ways to attack a cipher.

Sometimes the key strength is compromised in a way that exponentially reduces search time.

True. That's what is also explained in the link i gave to Schneier's website. They talk about improving down to 2^110.5 for AES256, and that only under certain circumstances.

So let's be generous and assume 2^110 would be possible. Lets also assume that statistically, only half the number of attempts is needed, 2^109. With the 2GHz machine from my example, and still only for counting through that range, one count per clock, we are now down to 10290415831380857.65 years, which is still 735029.702241489832 times the age of the universe. Even if we now go for massive parallel computing and have one million machines working on it, without any overhead for communications etc., we are just so under three quarters the age of the universe.

Now factor in the time to actually do the AES256 cipher, instead of just counting through the key space, and you are back to many, many times the age of the universe again. And then, we still need to check if the result is actually really decrypted, which is hard to achieve if we have no plain-text sample from the contents.

In case the result would be second encrypted file instead of plaintext, that attempt is thwarted right from the start anyways.

Greetings,

Chris
 
Mhmm, Cryptome seems to be open to the idea that there might be a backdoor:

At the center of the drama was the posting last week of a massive 1.4 gigabyte mystery file named "Insurance" on the WikiLeaks website. The "Insurance" file is encrypted, nearly impossible to open until WikiLeaks provides the passwords. But experts suggest that if anyone can crack it — it would be the National Security Agency. *snip*

NSA has run a number of these disinformation campaigns about "unbreakable" encryption, secret (German, Japanese, Soviet, et al) and public -- the most famous public system involved Crypto AG, within whose cryptosystem NSA installed a backdoor to gain access to communications of worldwide users who believed the system was invulnerable. *snip*

Doubts about the invulnerability of AES have persisted since NSA selected an algorithm from an AES competition that was considered by cryptographers not to be the strongest. And that it is likely for strongest protection NSA uses a top secret cryptosystem while promoting AES for public and official use. It is argued that NSA, like all official comsec agencies, would never endorse a system it could not secretly access.

Full Article: http://cryptome.org/0002/wl-diary-mirror.htm
 
Mhmm, Cryptome seems to be open to the idea that there might be a backdoor:

Frankly, i very much doubt that. This looks just like the run-of-the-mill conspiracy theory.

It is one thing to put a backdoor in a crypto-system that no one else has access to in source form, and to put one into a system where the whole world has access to. The former you can hide nicely, the latter not so much.

Keep in mind that AES is not a brand-new thing. It exists for quite some years by now, and many people analyze it. Also, it would be stupid of them to have their own government use AES256 for top-secret material while knowing that it can be easily broken.

If it would be so easy to put backdoors in crypto-systems, why do you think they had severe export-limitations for strong cryptography? They could have given out the "strong" version, with the backdoor added, and have the foreign people believe it would be safe.

Greetings,

Chris

ETA: Also note that they give no sources for their claims. Then they talk about the insurance.aes256 file being compromised/replaced by NSA, but then talk about downloading it from them in case WL goes down. To me, that thing is a pretty fuzzy and weird story.
 
Last edited:
If you read the chat log
(2:17:59 PM) Manning: the investigating officers left the material unprotected, sitting in a directory on a centcom.smil.mil
(2:18:03 PM) Manning: server
(2:18:56 PM) Manning: but they did zip up the files, aes-256, with an excellent password… so afaik it hasn’t been broken yet

Perhaps wikileaks and/or NSA are just doing an experiment to see if anyone can break it?

By putting up a file that says "lots of juicy secrets inside" on the internet it represents sort of a challenge.
 
Frankly, i very much doubt that. This looks just like the run-of-the-mill conspiracy theory.
That was my first reaction when I read it to :). Does Cryptome have any reputation in the cryptography field - I'm not aware of that. OTOH, they are a competitor of sorts of Wikileaks. :)

It is one thing to put a backdoor in a crypto-system that no one else has access to in source form, and to put one into a system where the whole world has access to. The former you can hide nicely, the latter not so much.
Indeed. It seems that Crypto AG's designs were influenced by the NSA. There's an article in Der Spiegel from 1996 about it with some details (English translation).

Keep in mind that AES is not a brand-new thing. It exists for quite some years by now, and many people analyze it. Also, it would be stupid of them to have their own government use AES256 for top-secret material while knowing that it can be easily broken.
There are competing encryption algorithms out there, so it would be easy to plug in a new one when real weaknesses are found in AES. Note that the weaknesses you linked to earlier were not in a full implementation of AES256, but in a variant with only 7 or 10 rounds instead of the full mandated 14.

If it would be so easy to put backdoors in crypto-systems, why do you think they had severe export-limitations for strong cryptography? They could have given out the "strong" version, with the backdoor added, and have the foreign people believe it would be safe.
The export limitations have been lifted, and didn't really work anyway except for maybe chasing cryptographers out of the USA. Remember the Kerberos story? The source code from CMU could not be exported, but a textual description could - thanks to the First Amendment :D. So a Sweden-based club re-implemented Kerberos for the rest of the world (SuSE still uses this Kerberos implementation). Projects like IPSEC, OpenSWAN etc. just made sure that no code was produced within the US. Well, there are enough knowledgeable people outside the US to realized that.
 
If you have a copy of insurance.aes256, one thing you can do with it now is make sure that it's a legitimate, unaltered, copy. At this point there may be frivolously generated and distributed files of the same size out there, especially circulating via Torrent.

Of course, if and when the password becomes public, such hypothetical bogus files will be easy to identify because they won't decrypt into anything intelligible, but at that point it'll become possible to generate files with any content that will decrypt with the publicly released password. You might want to know ahead of time that the copy you currently have is the legitimate one.

Here's the correct SHA1 hash of insurance.aes256, which you can verify for yourself with a general web search:

SHA1: cce54d3a8af370213d23fcbfe8cddc8619a0734c

and one way to generate the hash of your copy for comparison is to download a program called "FCIV" from the Microsoft website. It's a command-line program that's easy to use. If you try it and the two hashes match, you can have extremely high confidence that your copy is legitimate.
 
Knowing what the hash is, how difficult would it be to generate a bogus file with the same hash?
 
It depends on what the goal is. Given the weaknesses that were found in SHA-1 back in 2005 and refined since, creating a collision (basically a file that hashes to the same value as insurance.aes256) are feasible, but still very difficult. Would this file be anything other than gibberish, unlikely, but in this context, it would be a successful countermeasure. If an agency were able to flood the torrentspace with a bogus file, of the same exact size, generating a duplicate hash it would minimize the spreading of the file.

But all anyone with the actual insurance.aes256 file needs to do is give out the SHA-2 hash (224, 256, 384 or 512-bit size), and then, no, at this time no collision will be found given current computing capabilities.

FYI, the my copy of insurance.aes256 has a SHA-256 hash:

SHA-256: 15bac5e815a38a998f4705945bd41975b736e7c723cfe851b9ed0e50c49316b4
 
Last edited:
Knowing what the hash is, how difficult would it be to generate a bogus file with the same hash?
Even though weaknesses were discovered in SHA-1, that doesn't mean that SHA-1 was actually cracked. Cryptographers often recognize such discovered weaknesses as warnings that it's time to begin working on replacement algorithms.

Beside, someone would have to do more than simply generate a file with the same SHA-1 hash. The file would also have to contain exactly the same number of bytes as the legitimate file (1,491,834,576 bytes) and would have to begin with the plaintext word, "Salted". I feel safe in saying that nobody is currently able to do that.
 
Even though weaknesses were discovered in SHA-1, that doesn't mean that SHA-1 was actually cracked. Cryptographers often recognize such discovered weaknesses as warnings that it's time to begin working on replacement algorithms.

Beside, someone would have to do more than simply generate a file with the same SHA-1 hash. The file would also have to contain exactly the same number of bytes as the legitimate file (1,491,834,576 bytes) and would have to begin with the plaintext word, "Salted". I feel safe in saying that nobody is currently able to do that.

++ When I stated "very difficult" in my reply, this was meant as while not impossible, very close. I also made reference to "an agency" which was meant to imply a government agency, not unlike the NSA or GCHQ. While I know that these agencies aren't magical and have computers that somehow can out perform the rest of the worlds by factors of 1000, they are adept at exploiting crytographic weaknesses that may give them an edge and they rarely publish their findings.

Given that SHA-1 already has known weaknesses and it's related algorithm SHA-0 was outed by the NSA as "broken" without much explanation, but upon further research was found to be very broken, I think they could possibly pull off the kind of stunt we are describing. Also, don't forget that the NSA developed SHA-0, SHA-1 and SHA-2. The bigger question is would they and thereby announce to the world how far they have come. I doubt that very much.
 
Last edited:
An update concerning the content of the insurance file (unless Assange is referring to additional insurance files) :

"There is no 'fall'. We have never published as much as we are now. WikiLeaks is now mirrored on more than 2,000 websites. I can't keep track of the spin-off sites – those who are doing their own WikiLeaks . . . If something happens to me or to WikiLeaks, 'insurance' files will be released."The contents of these files are unknown, but, according to Assange, "They speak more of the same truth to power." It is not just government that should be worried about the content of these files, however. "There are 504 US embassy cables on one broadcasting organisation and there are cables on Murdoch and News Corp," he says.


full source
 
I find filtering through videos annoying. Could you just briefly tell us what his conditions are? Or maybe post a link to a text version?


Sorry, I forgot about this thread. Actually I have no idea what the conditions are or if there's a text version.

Anyway, a British Journalist obviously published the password to the AES file in a book.

So it isn't a secret any longer...

Related news articles:
http://www.google.com/search?q=wikileaks+guardian+password&hl=en&safe=off&prmd=ivnsu&source=lnms&tbm=nws
 
Last edited:

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom