well, if it's DES (and with 64 bit it's probably either that or some self-cooked vigenere cipher or something like that) then it's likely one of the five traditional encryption modes. if you have the key you can try them all.
-
-
Replying to @hanno @FiloSottile and
So I'm now trying to replay the capture and turns out they do seem to use something more clever than I expected. Even if I send the same 64 bit from a capture, the device sends over a different message, with what looks like two separate 64 bit values that are different.
1 reply 0 retweets 0 likes -
Replying to @flameeyes @hanno and
CBC mode, a random IV and one block? That would be pretty common.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @flameeyes and
If you know it's DES and the exact mode and don't have the key, you can crack the key for $30 at http://crack.sh . might get a bit pricy if you're guessing the format/parameters though.
1 reply 0 retweets 0 likes -
Unfortunately I can only _guess_ it's DES. What I have is (at least) 64-bit sent Host→Device and at least 2×64-bit sent Device→Host right now. I was trying to set up a second VM just to see if the parts I see constants are really constant, or generated at install.
1 reply 0 retweets 0 likes -
This Tweet is unavailable.
-
Replying to @Birdfly_tw @flameeyes and
Securekeybox, the WhiteCryption nonsense? Because I can pull keys out of those. Whitebox crypto is snake oil.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @Birdfly_tw and
Isn’t that like saying obfuscation in general is snake oil? Its trivial to renew and high effort to reverse.
1 reply 0 retweets 0 likes -
Replying to @MichailG @Birdfly_tw and
My experience says otherwise. You look at the thing once for a few hours and you can automate breaking it forever. It's snake oil because they actually sell it as basically unbreakable.
2 replies 0 retweets 1 like -
Replying to @marcan42 @Birdfly_tw and
What really? Like, in marketing claims?
1 reply 0 retweets 0 likes
It's the usual marketing nonsense about "keys always being encrypted" and "prevents hackers from stealing keys" "ultimate protection" yada yada. The fact is whitebox crypto is a CTF level these days, and the WhiteCryption approach is more of the same.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.