Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
From: Elazar Broad (elazarhushmail.com)
Date: Wed Dec 31 2008 - 11:57:52 CST
-----BEGIN PGP SIGNED MESSAGE-----
That's true, keeping up with security is not cheap nor easy.
Tradeoff's are tradeoff's, the question is, when it comes down to
the $$$, is more cost effective to be proactive vs reactive in this
case. Time will tell...
On Tue, 30 Dec 2008 16:42:47 -0500 Valdis.Kletnieksvt.edu wrote:
>On Tue, 30 Dec 2008 16:13:07 EST, Elazar Broad said:
>> And they should have listened then, it was only a matter of time
>> before someone fleshed out a practical attack, and that time is
>> now. Then again, I am sure there some ATM's out there still
>> DES. How many time's do we need to prove Moore's law...
>Playing devil's advocate for a moment...
>And perhaps they *were* listening, but realized that security is
>tradeoffs, and they balanced the cost of doing the upgrade back
>against the chances that a team as technically and budget-wise
>as this one, *and with nefarious intent*, would do something
>drastic enough to dent their revenue stream.
>Read section 5.2 of the hashclash/rogue-ca paper. The victim CA
>out an average of 1,000 certs in 3 days, let's say at $12 per.
>$600K per year for just the weekends, not counting the Mon-Thurs
>is probably even higher (and why they targeted a weekend). So $2M
>Who wants to place a bet that said CA will be selling *the same
>of certs every week, meaning they had *no* economic loss due to
>because their customers won't actually *see* the news article and
>a bad feeling about their CA? And with no actual loss, why spend
>to implement the change?
>Hint: It *isn't* just a matter of changing one line in a script to
>'sha1' instead of 'md5' - you *also* need to go back and look at
>certs you've issued already and figure out if they've been
-----BEGIN PGP SIGNATURE-----
Version: Hush 3.0
Note: This signature can be verified at https://www.hushtools.com/verify
-----END PGP SIGNATURE-----
Go to massage therapy school and make up to $150/hour, click now!
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/