By John P. Mello Jr. TechNewsWorld Part of the ECT News Network
10/25/07 10:13 AM PT
According to ElcomSoft, it has found a way to harness the combined power of a PC's Central Processing Unit and its video card's Graphics Processing Unit. "The resulting hardware/software powerhouse," it asserts, "will allow cryptology professionals to build affordable PCs that will work like supercomputers when recovering lost passwords." Others question how original the method really is.
A Moscow-based software maker filed this week for a U.S. patent on a technology it claims will significantly reduce the time it takes to crack computer passwords.
The Russian company, Elcomsoft, said in a statement that it has discovered "a breakthrough technology that will decrease the time that it takes to perform password recovery by a factor of up to 25."
However, some cryptology experts questioned just how much of a breakthrough the company's technology really is.
"I don't think it's a breakthrough at all," John Callas, chief technology officer for the global security software company PGP in Palo Alto, Calif., told TechNewsWorld.
He cited research at Columbia Univeristy in New York City in the 2003 to 2005 time frame that described the underpinnings of the Russian firm's technology.
Hardware/Software Powerhouse
According to ElcomSoft, it has found a way to harness the combined power of a PC's Central Processing Unit (CPU) and its video card's Graphics Processing Unit (GPU).
"The resulting hardware/software powerhouse," it asserts, "will allow cryptology professionals to build affordable PCs that will work like supercomputers when recovering lost passwords."
The patent-pending technique can reduce the time for "brute force" password recovery -- a trial and error process that requires enormous computing power -- from months to days, Elcomsoft maintains.
Frozen Daiquiris
Callas argues, however, that the Columbia researchers made the connection between cryptography and computer graphics cards long before Elcomsoft's announcement this week.
"Once you've shown you can do cryptography with a graphics card, doing cryptanalysis with a graphics card is really the same sort of thing," he reasoned.
"Once you've heard you can make a frozen daiquiri with a blender, it's like saying the frozen Pina Colada is a new invention," he analogized. "It's not really a new invention. It's changing the ingredients and realizing the blender works that way."
"The first person that made the frozen drink made an invention," he continued. "The second person didn't do anything.
"To those of us skilled in the art," he said, "this is completely obvious."
There have been projects using graphics cards for this purpose before, added Benjamin Jun, vice president for technology for Cryptography Research in San Francisco.
"I applaud this group because I think they're getting tremendous performance out of this, and it's a new tool that can be used in breaking keys," he told TechNewsWorld. "But I don't think it is the first announcement in this regard."
Low-Cost Cracking
Whether Elcomsoft's technology is patentable or not, it does drastically change the economies involved in cracking passwords.
To obtain the horsepower to compromise passwords, researchers sometimes turn to computers specially designed for the task.
Cryptography Research's Jun recalled working on the development of such a machine in the late 1990s. Called "Dcrack," it was used to crack DES (Data Encryption Standard) encryption and cost US$250,000 to build.
Compare that with the cost of Elcomsoft's solution and it can be seen why some security experts are watching developments in this area very closely.
When ElcomSoft ran some preliminary tests with its password recovery software on Windows NTLM (NT LAN Manager) logon passwords, it found it could increase the recovery speed of a PC by a factor of 20, simply by hooking into the machines's $150 video card.
Hacker Arsenal Enhanced?
"One of the things that's very interesting right now is that there's more computing power in your graphics card than in your CPU," explained Callas, of PGP, "but it's very specialized computing power designed for drawing pixels on the screen."
As it turns out, that specialization is suitable for cryptographic calculations.
"Cyrptographic applications are essentially basic arithmetic done in clever combinations a whole bunch of times," Callas said. "That sort of repetitive arithmetic is the same thing that you do in graphics operations."
With the cost of cracking passwords going down, will the risks to society go up?
"It changes the arsenal of what's available to someone who is doing brute-force attacks," Jun opined, "but I don't think that we need to run for hills with respect to today's cryptography just yet."
iPhone Hackers Flip Off Apple With Complete Brick Fix October 12, 2007
A company that released a software hack for unlocking Apple's iPhone now has developed a workaround to the firmware upgrade that rendered many iPhones useless. SimFree v1.6 counters Apple's 1.1.1 firmware upgrade, which "bricked" any of the devices that had been hacked to unlock them from the AT&T wireless network. One caveat: The company can't guarantee that Apple won't come up with a countermeasure.
Related Stories
Leopard vs. Vista, Brazil vs. Cisco, True Security Horror Story, Product of the Week October 22, 2007
Every company has its strengths and weaknesses. In this regard, Apple and Microsoft are almost polar opposites. Apple is very strong on marketing but generally not as strong on the aspects of its platform which have kept Microsoft dominant in the PC space. The market is clearly changing and trending, if the iPhone and iPod are any indications, toward Apple's strengths.
VPNs and Small Business, Part 1: The SMB Case October 19, 2007
From a business application viewpoint, virtual private network technology is just one more communication tool. That may make VPNs just as valuable to SMBs as they are to larger corporations. Especially on the SMB level, a VPN can enhance the connectivity of a company's workers to multiple sites. SMB adopters may find the tunneling features a more cost-effective option than leasing T1 lines.
Related News Alerts
More by John P. Mello Jr.
McAfee Gives Enterprise Macs a Bodyguard November 02, 2009
When it comes to Mac use in an enterprise environment, running third-party security software isn't just a matter of using an abundance of caution. It may also be a matter of complying with governance mandates and regulations. McAfee's new Endpoint Protection for the Mac targets enterprise systems handling large amounts of sensitive data.
Adobe Elements Buffs Up for Mac October 26, 2009
For the almost-but-not-quite pro photog, Adobe Photoshop Elements offers a collection of tools that go beyond most free offerings but don't dish out the wallet-busting feature overload of full Photoshop. In the past, some Mac users have been annoyed with Adobe for having versions of Elements ready for Windows months before they were out on Mac. With version 8, both platforms get their chance at the same time.
GoToMyPC Gets Ready to Go to Your Mac October 19, 2009
GoToMyPC has been a popular remote access product in Citrix's portfolio, and previous versions have allowed any Net-connected computer to remotely control a PC. A new version, soon to come out of beta and into full release, can access Macs as well. With the growth of both telecommuting and Macs in the enterprise, Citrix felt the time was right.