Re: Java key hiding stealth method.

New Message Reply About this list Date view Thread view Subject view Author view

Bill Frantz (frantz@netcom.com)
Wed, 17 Jun 1998 09:56:22 -0800


At 4:01 AM -0800 6/17/98, Victor Emanuel Luz wrote:
>Hi.
>
> I've been trying to use a Blowfish Java implementation by Markus Hahn
>( http://www-hze.rz.fht-esslingen.de/~tis5maha/software.html ) to
>encrypt a small amount of data (less than 256 bytes) whith a 80 bit
>secret key.
> The communication is made from a Applet to a Servlet using simmetric
>encryptation.
> The info that I am trying to encrypt has a valid time of about two
>monthes and it is _not_ too sesitive.
>
>Problem:
>
> Even devius stealth methods are quite simple do declassify the applet
>and gain access to the secret key or function to generate key see
>http://www.awesome.com/declass.html (it's free!) for details.
>
> Does anyone has some clue on how to defeat this ?

Generate the secret key through a Diffie-Hellman key exchange.

-------------------------------------------------------------------------
Bill Frantz | If hate must be my prison | Periwinkle -- Consulting
(408)356-8506 | lock, then love must be | 16345 Englewood Ave.
frantz@netcom.com | the key. - Phil Ochs | Los Gatos, CA 95032, USA


New Message Reply About this list Date view Thread view Subject view Author view

 
All trademarks and copyrights are the property of their respective owners.

Other Directory Sites: SeekWonder | Directory Owners Forum

The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:18:36 ADT