×
Encryption

Submission + - Cryptographers Aim to Find New Password Hashing Algorithm (threatpost.com)

Trailrunner7 writes: Passwords are the keys to our online identities, and as a result, they're also near the top of the target list for attackers. There have been countless breaches in the last few years in which unencrypted passwords have been stolen from a database and leaked online, and security experts often shake their heads at the lack of use of encryption or even hashing for passwords. Now, a group of cryptographers is sponsoring a competition to come up with a new password hash algorithm to help improve the state of the art.

Hashing algorithms are used to secure passwords by taking the plaintext password, passing it through the cryptographic hash algorithm, and then storing the resulting digest, rather than the plaintext password itself. That way, if attackers are able to compromise the database of passwords, what they get are the hashes and not the actual passwords.

However, the algorithms used to hash passwords in most cases are functions such as SHA-1 and MD5, which have known weaknesses that open them up to brute-force attacks. So if an attacker is able to access a database of hashed passwords, he may be able to crack them, given enough time and compute power. When these algorithms were designed years ago, the hardware needed to crack a hash produced by one of them was not commonly available. But now, powerful GPUs and FPGAs are widely available and can be used by an attacker to crack hashes relatively quickly.

"Password hashing is important because it's where we have a problem. NIST has given us some great standard hashing algorithms. The problem is that these hashes aren't necessarily designed for the specific problem of password hashing — where you need something that's fast enough to hash on a server at login time, but slow enough that a GPU can't crack ten million of them," Green said.

Medicine

Submission + - Alcoholism Vaccine Makes Alcohol Intolerable to Drinkers

Hugh Pickens writes writes: "Ariel Schwartz reports that researchers are working on an alcoholism vaccine that makes alcohol intolerable to anyone who drinks it. The vaccine builds on what happens naturally in certain people--about 20% of the Japanese, Chinese, and Korean population--with an alcohol intolerance mutation. Normally, the liver breaks down alcohol into an enzyme that’s transformed into the compound acetaldehyde (responsible for that nasty hangover feeling), which in turn is degraded into another enzyme. The acetaldehyde doesn’t usually have time to build up before it’s broken down. But people with the alcohol intolerance mutation lack the ability to produce that second enzyme; acetaldehyde accumulates, and they feel terrible. Dr. Juan Asenjo and his colleagues have come up with a way to stop the synthesis of that second enzyme via a vaccine, mimicking the mutation that sometimes happens naturally. "People have this mutation all over the world. It’s like how some people can’t drink milk," says Asenjo. Addressing the physiological part of alcohol addiction is just one piece of the battle. Addictive tendencies could very well manifest in other ways; instead of alcohol, perhaps former addicts will move on to cigarettes. Asenjo admits as much: "Addiction is a psychological disease, a social disease. Obviously this is only the biological part of it.""
Google

Submission + - Microsoft Could Earn Billions from Office for iOS: Analyst (slashdot.org)

Nerval's Lobster writes: "Microsoft is leaving billions of dollars on the table by not porting Office to the iPad, according to a new analyst report. That analyst, Morgan Stanley’s Adam Holt, believes that Office for iOS would sell to approximately 30 percent of all iPad users; priced at $60 per copy, that comes to a grand total of $2.5 billion per year—minus Apple’s cut of the revenues, of course. But does Microsoft actually want Office for iOS out there? It’s not necessarily in the company’s best interest to rush such a platform to market, even if billions of dollars potentially hang in the balance—it’s too busy pushing Office as a cloud-based, OS-agnostic platform. And Microsoft has another reason, aside from pushing the cloud version of Office, to de-emphasize the prospect of its productivity software on iOS: In a bid to draw more customers to its new hardware, Microsoft preloaded its Surface RT tablets with Office; offering the software on a rival touch-screen would take a major selling point off the table."
United Kingdom

Submission + - Transport for London ticketing chief dubious about mobile NFC (techworld.com) 1

An anonymous reader writes: The head of business development at Transport for London (TfL), whose Oyster card system is one of the most successful contactless ticketing programmes in the world, claims he is “not convinced” about mobile payments using NFC because there are too many stakeholders – with banks, retailers, mobile network operators, device manufacturers and advertisers all fighting for a share of the revenues. “It's taken ages. How much money is there to make with all these parties trying to get a piece of it?” said Hudson, speaking at a Westminster eForum on the future of digital payments. “We've just sat back and said we're not interested. When you've worked it out come back to us and we'll engage.”

Slashdot Top Deals