Information Security News mailing list archives

CSS broken


From: mea culpa <jericho () DIMENSIONAL COM>
Date: Fri, 29 Oct 1999 09:36:17 -0600

From: "Jay D. Dyson" <jdyson () techreports jpl nasa gov>

-----BEGIN PGP SIGNED MESSAGE-----

Courtesy of Cryptography List.

DVD and weak crypto.  Seems to be the "industry standard"...  *sigh*

- ---------- Forwarded message ----------
Date: Wed, 27 Oct 1999 14:54:17 +0200 (CEST)
From: Frank Andrew Stevenson <frank () funcom com>
Subject: CSS broken

Monday sourcecode for the CSS algorithm was released through an anonymous
remailer. CSS is the encryption algoritm used on DVD movies, and it was
supected that it was weak beyond just having a 40 bit key. Yesterday I
found it to be vulnerable to a trivial 2^16 attack with as little as 6
bytes of known plaintext.

I posted the details on:
http://livid.on.openprojects.net/pipermail/livid-dev/1999-October/000589.html

  frank

This sentence is unique in this respect; it can safely
be attributed to my employer, Funcom Oslo AS.
E3D2BCADBEF8C82F A5891D2B6730EA1B PGPmail preferred, finger for key
There is no place like N59 50.558' E010 50.870'. (WGS84)

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBOBctNYzYnY/37fGZAQEzwgQAhmUHwZYYHyg6R6b+WZzBHO5pd88JaiGY
ob12gHXpv1GZMI9xw+flFRkaCXfW8GT1uOPS/BcGS3A6Q+PTlWImqKSDmCoefAAf
1LcP0TQIhQrnPzsPG0PfBbtOOsE7nshFHHi5gk9QtgeBAWZuixGVBDZ3lSelmb9G
WxAXZINTzKQ=
=hwGo
-----END PGP SIGNATURE-----

ISN is sponsored by Security-Focus.COM


Current thread: