Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > Flaw in Window’s random number generator

Reply
Thread Tools Display Modes

Flaw in Window’s random number generator

 
 
The poster formerly known as 'The Poster Formerly Known as Nina DiBoy'
Guest
Posts: n/a

 
      11-15-2007
http://blogs.techrepublic.com.com/te...60&tag=nl.e019

"Security researchers are claiming that the pseudo-random number
generator used by Microsoft in Windows is flawed. Only Windows 2000 is
evaluated, though the shortcomings of the random number generator are
most likely present in Windows XP and Vista.

Excerpt from The Register:

A team of cryptographers led by Dr. Benny Pinkas from the
Department of Computer Science at the University of Haifa, Israel, were
able to unravel how the CryptGenRandom function Windows 2000 worked,
without assistance from Microsoft. This analysis revealed that random
number generation in Windows 2000 is far from genuinely random — or even
pseudo-random.

Because of this it was possible for the researchers to predict
numbers generated by the software, after first determining the internal
state of the generator.

The implications here is that a local attack can be used to determine a
single state of the random number generator. It will be possible after
that to predict all random values, such as used in SSL keys, and
possibly other cryptographic functions.

If you enjoy reading Greek geek-stuffs, you can check out the results of
the research titled Cryptanalysis of the Windows Random Number Generator."

--
Priceless quotes in m.p.w.vista.general group -
Submit your nomination at the link below:
http://protectfreedom.tripod.com/kick.html

"Fair use is not merely a nice concept--it is a federal law based on
free speech rights under the First Amendment and is a cornerstone of the
creativity and innovation that is a hallmark of this country. Consumer
rights in the digital age are not frivolous."
- Maura Corbett
 
Reply With Quote
 
 
 
 
Mick Murphy
Guest
Posts: n/a

 
      11-15-2007
"Only Windows 2000 is
evaluated, though the shortcomings of the random number generator are
most likely present in Windows XP and Vista."

Don't waste my time, cockhead!


"The poster formerly known as 'The Poster" wrote:

> http://blogs.techrepublic.com.com/te...60&tag=nl.e019
>
> "Security researchers are claiming that the pseudo-random number
> generator used by Microsoft in Windows is flawed. Only Windows 2000 is
> evaluated, though the shortcomings of the random number generator are
> most likely present in Windows XP and Vista.
>
> Excerpt from The Register:
>
> A team of cryptographers led by Dr. Benny Pinkas from the
> Department of Computer Science at the University of Haifa, Israel, were
> able to unravel how the CryptGenRandom function Windows 2000 worked,
> without assistance from Microsoft. This analysis revealed that random
> number generation in Windows 2000 is far from genuinely random — or even
> pseudo-random.
>
> Because of this it was possible for the researchers to predict
> numbers generated by the software, after first determining the internal
> state of the generator.
>
> The implications here is that a local attack can be used to determine a
> single state of the random number generator. It will be possible after
> that to predict all random values, such as used in SSL keys, and
> possibly other cryptographic functions.
>
> If you enjoy reading Greek geek-stuffs, you can check out the results of
> the research titled Cryptanalysis of the Windows Random Number Generator."
>
> --
> Priceless quotes in m.p.w.vista.general group -
> Submit your nomination at the link below:
> http://protectfreedom.tripod.com/kick.html
>
> "Fair use is not merely a nice concept--it is a federal law based on
> free speech rights under the First Amendment and is a cornerstone of the
> creativity and innovation that is a hallmark of this country. Consumer
> rights in the digital age are not frivolous."
> - Maura Corbett
>

 
Reply With Quote
 
Bill Yanaire
Guest
Posts: n/a

 
      11-15-2007

"Mick Murphy" <> wrote in message
news:2062C71F-C8B1-4CD8-A03A-...
> "Only Windows 2000 is
> evaluated, though the shortcomings of the random number generator are
> most likely present in Windows XP and Vista."
>
> Don't waste my time, cockhead!


Wasn't it YOU just a FEW minutes ago telling some poster:


"Mick Murphy" <> wrote in message
news:2382C5E4-E535-434E-9FD7-...
> 1. this is a newsgroup; no personal email replies.
>



and you are nasty to people. Shouldn't you be told: this is a newsgroup,
no nasty name calling

Looks like you can dish it out but can't take it. By the way, do you go to
anger management class?

If not, you should

>
>
> "The poster formerly known as 'The Poster" wrote:
>
>> http://blogs.techrepublic.com.com/te...60&tag=nl.e019
>>
>> "Security researchers are claiming that the pseudo-random number
>> generator used by Microsoft in Windows is flawed. Only Windows 2000 is
>> evaluated, though the shortcomings of the random number generator are
>> most likely present in Windows XP and Vista.
>>
>> Excerpt from The Register:
>>
>> A team of cryptographers led by Dr. Benny Pinkas from the
>> Department of Computer Science at the University of Haifa, Israel, were
>> able to unravel how the CryptGenRandom function Windows 2000 worked,
>> without assistance from Microsoft. This analysis revealed that random
>> number generation in Windows 2000 is far from genuinely random - or even
>> pseudo-random.
>>
>> Because of this it was possible for the researchers to predict
>> numbers generated by the software, after first determining the internal
>> state of the generator.
>>
>> The implications here is that a local attack can be used to determine a
>> single state of the random number generator. It will be possible after
>> that to predict all random values, such as used in SSL keys, and
>> possibly other cryptographic functions.
>>
>> If you enjoy reading Greek geek-stuffs, you can check out the results of
>> the research titled Cryptanalysis of the Windows Random Number
>> Generator."
>>
>> --
>> Priceless quotes in m.p.w.vista.general group -
>> Submit your nomination at the link below:
>> http://protectfreedom.tripod.com/kick.html
>>
>> "Fair use is not merely a nice concept--it is a federal law based on
>> free speech rights under the First Amendment and is a cornerstone of the
>> creativity and innovation that is a hallmark of this country. Consumer
>> rights in the digital age are not frivolous."
>> - Maura Corbett
>>



 
Reply With Quote
 
The poster formerly known as 'The Poster Formerly Known as Nina DiBoy'
Guest
Posts: n/a

 
      11-15-2007
Mick Murphy wrote:
> "Only Windows 2000 is
> evaluated, though the shortcomings of the random number generator are
> most likely present in Windows XP and Vista."
>
> Don't waste my time, cockhead!
>


Funny you blame me for 'waisting your time' when noone but you chose to
spend the time reading the post and article and responding to it. Also,
as I am not male, cockhead seems wasted on me. My but you are a
wasteful person!

>
> "The poster formerly known as 'The Poster" wrote:
>
>> http://blogs.techrepublic.com.com/te...60&tag=nl.e019
>>
>> "Security researchers are claiming that the pseudo-random number
>> generator used by Microsoft in Windows is flawed. Only Windows 2000 is
>> evaluated, though the shortcomings of the random number generator are
>> most likely present in Windows XP and Vista.
>>
>> Excerpt from The Register:
>>
>> A team of cryptographers led by Dr. Benny Pinkas from the
>> Department of Computer Science at the University of Haifa, Israel, were
>> able to unravel how the CryptGenRandom function Windows 2000 worked,
>> without assistance from Microsoft. This analysis revealed that random
>> number generation in Windows 2000 is far from genuinely random — or even
>> pseudo-random.
>>
>> Because of this it was possible for the researchers to predict
>> numbers generated by the software, after first determining the internal
>> state of the generator.
>>
>> The implications here is that a local attack can be used to determine a
>> single state of the random number generator. It will be possible after
>> that to predict all random values, such as used in SSL keys, and
>> possibly other cryptographic functions.
>>
>> If you enjoy reading Greek geek-stuffs, you can check out the results of
>> the research titled Cryptanalysis of the Windows Random Number Generator."



--
Priceless quotes in m.p.w.vista.general group -
Submit your nomination at the link below:
http://protectfreedom.tripod.com/kick.html

View nominations already submitted:
http://htmlgear.tripod.com/guest/con...dom&i=1&a=view

"Fair use is not merely a nice concept--it is a federal law based on
free speech rights under the First Amendment and is a cornerstone of the
creativity and innovation that is a hallmark of this country. Consumer
rights in the digital age are not frivolous."
- Maura Corbett
 
Reply With Quote
 
DanS
Guest
Posts: n/a

 
      11-16-2007
=?Utf-8?B?TWljayBNdXJwaHk=?= <>
wrote in news:2062C71F-C8B1-4CD8-A03A-:

> "Only Windows 2000 is
> evaluated, though the shortcomings of the random number generator are
> most likely present in Windows XP and Vista."
>
> Don't waste my time, cockhead!


It's a good bet it was just carried thru versions of Windows.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Number of Linux Distributions Surpasses Number of Users !!!!!! Moshe Goldfarb Windows Vista General Discussion 190 04-19-2008 10:32 PM
APP: Amnesty Generator>>> From Web Widget to Sidebar Gadget Tie Various Windows Vista General Discussion 0 10-30-2007 05:08 PM
Flaw with Vista ... but nobody seems to care doon Windows Vista General Discussion 48 10-22-2007 10:04 PM
Windows Zero Day Flaw Alias Windows Vista General Discussion 38 04-01-2007 05:38 PM
Security Flaw Ludwig Windows Vista General Discussion 4 01-02-2007 12:39 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59