Posts

Showing posts with the label site news

Quick Status Update

This is just a quick post to let you know that I for once have a valid excuse for not updating this blog in a timely manner. I actually found a job! Thanks to everyone who offered help, recommendations and encouragements. The only catch is that right now it's being decided if I have to run my posts through our public release office or not. Don't worry, this blog is not going away regardless of the decision.. It might just gain a few unwilling readers ;) As to my new company, I'm going to keep that a bit of an open secret. This blog reflects my personal views. I certainly don't speak for them, and I plan on avoiding any topics that have to do with my day job, (Don't worry, I'm not doing any password cracking there). Once again thanks, and I'll resume posting once I get the OK and can update this blog while complying with company policies. I just want to make sure I handle this situation the right way.

Protecting Physical Documents

Image
The above picture is of my Subaru Baja. Sometime last night, someone broke my back window, and stole almost everything from my car, (they apparently did not like my music; btw Punk is not dead). Normally this would be a costly annoyance, but in this case I'm in the process of moving and finding a new job. While most of my stuff is sitting safely in a storage locker, I still had several boxes of various items stored in my back seat, including unfortunately my "to-go" bag. My to-go bag contained all of my important possessions that I planned on grabbing if my house was in the process of burning down. For example, it contained two thumb drives with backups of all of my work plus assorted other documents. I'm not worried about them though since I used TrueCrypt. Good luck cracking those, which BTW, is the reason I love TrueCrypt. What I am concerned about though is that my social security card, my passport, my birth certificate, my extra banking checks, and a whole lot of...

They'll Let Anyone Graduate: My Password Cracking Dissertation

You've all heard me complain/stress out about writing my dissertation, so now that it's done of course I'm going to post it online. My PhD. dissertation, "Using Probabilistic Techniques to Aid in Password Cracking Attacks" is available for download from my tools page here . A lot of it is going to look fairly familiar if you've seen my talks or been reading this blog, which makes sense since my dissertation is a summary of what I've been up to for the last three years. Here's a quick breakdown of what's in it: Chapter 1: Overview + background info The need for password cracking General terms and techniques Obtaining the datasets, and basic statistics about the datasets A quick survey of common password hashes and popular password cracking tools Chapter 2: Brute Force Attacks 95% of it I've talked about on this blog before The remaining 5%, which I really should post an entry on, is a comparison of a targeted brute force attack against a pure Ma...

E-mail Address Change

Since I'm graduating, I was informed that I might not be able to keep my weir@cs.fsu.edu e-mail address. I'm trying to see what I can do to hold onto it, but for the time being I'd recommend e-mailing me at reusablesec@gmail.com.

State of the Blog: April Edition

Image
*Comic courtesy of http://www.phdcomics.com/ Well, it looks like after three years of work, I did it . I'm still putting some last minute touches on my dissertation but once that's finalized I'll post a copy. The crazy thing is that after going through all of that, I'm actually more motivated to do research. So that leads us to this blog. Don't worry, it's not going away. In fact one of my prerequisites for any new job I get is that I need to be allowed to keep on updating here. As far as posts go, I'm going to be shifting away from brute force attacks and start talking about dictionary attacks instead. I know, I've maintained this blog for over a year and I'm only getting to that now... Let me explain: 1) I'm lazy 2) My main area of study has been designing new ways to represent how people create passwords using probabilistic context free grammars. At it's heart this approach is an improvement to standard dictionary based attacks, though I...

Just a FYI

Image
I apologize for the lack of actual posts. Right now I'm facing several fairly strict deadlines when it comes to graduating, so you probably can ignore this blog for the next two weeks or so. I know, it's annoying for me too because from real life spies caught on camera , to a new WPA attack , there's a few things to blog about... For now though, it's LoLcats and funny comics 24/7

Shmoocon Bound

Leaving sunny, warm Florida for DC. What am I thinking... Ah, yah Shmoocon . I'll probably be wearing my FSU hat if anyone wants to grab a few drinks, (I know the picture on the side of the blog isn't very good for identification purposes).

Out of Context Graph Challenge #1

Image
I'm struggling with the best way to graph some new data I just analyzed based on the RockYou list. Since I'm also too lazy to write up a full post on it right now, I thought I might as well throw it out as a challenge to the five or so people who read this blog. I'll buy a beer for the first person who can correctly state what the following graph shows. The beer is redeemable at any conference I happen to meet you at, (For example: Shmoocon). Here are a few hints: It is based on a subset of one million passwords from the RockYou set It has to deal with a project I am working on There is one word you MUST include in your submission for it to be valid Answers will only be accepted in the comments. This contest will run until someone gets it right or I actually get around to writing a post on this. Imaginary bonus points are applied if you have any suggestions on a better way to graph the data.

New York Times Article

When I was interviewed a week and a half ago by a reporter from the New York Times about the Rockyou hack, I honestly never expected for it to end up on the front page of the newspaper, but there you go . As a friend mentioned though, it doesn't really count since it's below the fold ;) While I'm ecstatic about being quoted, there are a few things I wish could have been changed. Just saying that makes me feel like the guy who won the million dollar lottery, but is annoyed that he didn't get the 10 million jackpot. That being said, I have a blog, and this is the internet so I might as well complain away ;) First of all, I feel the need to explain my quote. Here is an excerpt from my conversation with the reporter: Matt's Brain: "Don't say anything stupid. Don't say anything stupid. Don't say anything stupid..." Reporter: "I take it this is the largest password list ever stolen right?" Me: "Well, it's the largest one ever p...

State of The Blog: 2010

I know most people normally do this at the beginning of January, but like so much else I'm running behind ;) What I really wanted to do was give you readers, (all 10 or so of you now), an update on where I'm at, my goals for the following 6 months, and why my update schedule might be kind of wacky. Goal 1: Graduate Yes, I have been researching password cracking since August 2007, and as much as I love college, it's time to move on to the real world. Or I hope it's time, as I still have that pesky dissertation to write. Getting that done is my #1 priority right now, and to be honest I don't know how that will impact this blog. The dissertation itself will mostly cover my work developing a probabilistic password cracker , though I'll also be covering some of my other tools such as my dictionary based rainbow tables . I'm a little ashamed I haven't posted more about my probabilistic password cracker here since I've become a true believer in it. It's...

Site News Update

As stated in the previous post, I'm in the middle of creating a new site to hold all the tools, custom dictionaries, and research papers I'm working on. It's fairly bare bones right now but I'm plugging away at it. Expect the layout to change quite a bit. I'd recommend only linking to the main page for the next month just because I'm still juggling around which pages should go where. I'm making the change since everyone ,(including me), hated the old googlepages site. The new site also allows comments so if you want to talk about a specific tool, file a bug report, or make a request please do. My one worry is hosting space, (aka some of these dictionaries and the rainbow tables in particular are large), but I'll cross that bridge when I get to it. The new site can be acessed from the link in the sidebar to the right or by going to http://sites.google.com/site/reusablesec/