Computer Hope

Other => Computer News => Topic started by: Geek-9pm on January 08, 2016, 11:01:48 PM

Title: The SLOTH attacks in 2016
Post by: Geek-9pm on January 08, 2016, 11:01:48 PM
Laziness about cryptography puts you at risk.

Not a joke. Users have become complacent. The odds are you will suffer some kind of malware attack this year. Why? It is not just you, software companies, computer makers and financial institutions are just not taking the danger seriously.

Part of the problem is the governments fear of advanced cryptography.

These remarks are base on this article just just published.
The SLOTH attacks: why laziness about cryptography puts security at risk.  (https://nakedsecurity.sophos.com/2016/01/08/the-sloth-attacks-why-laziness-about-cryptography-puts-security-at-risk/)

Quote
The SLOTH paper is fairly technical, and relies on quite a lot of cryptographic jargon, making it hard to penetrate if you aren’t a cryptographer already.
Here, we’ll just give a general overview of the problems that were exploited by the SLOTH authors, and what that tells us about our attitudes to cryptography in particular, and security in general.

Here is the document.
http://www.mitls.org/downloads/transcript-collisions.pdf

Sounds weird, but it is not a joke!  8)