May 22, 2012

Cryptographic Lock Baffles the FBI

encryption

Cryptography: The art of writing or solving codes.

Daniel Dantas: A Brazilian banker whose arrested in 2008 for attempting to bribe a police officer. He is also suspected of money laundering, embezzlement and other financial crimes. More importantly, he has managed to fool not only the South American authorities with his cryptographic locks on his numerous hard drives, but also the FBI.

That’s right — since July 2008, when Dantas was arrested, the FBI and officials throughout South America have tried fruitlessly to decrypt files held on the banker’s hardware (a story I first saw this morning on the Schneier on Security blog).

As The Register, a UK-based newspaper, states:

The files were encrypted using Truecrypt and an unnamed algorithm, reportedly based on the 256-bit AES standard. In the UK, Dantas would be compelled to reveal his passphrase under threat of imprisonment, but no such law exists in Brazil. The Brazilian National Institute of Criminology (INC) tried for five months to obtain access to the encrypted data without success before turning over the job to code-breakers at the FBI in early 2009. US computer specialists also drew a blank even after 12 months of efforts to crack the code.

A full year of diligent work from highly-intelligent code breakers and still nothing? Dantas seems to have chosen the right encryption software and password. We’ve seen that choosing a secure password, though very important, seems difficult for many to do. In an article we ran back in April entitled “The Real Enemy,” we highlighted the ignorance of many password-choosers.

Back in 1990, a Unix password study revealed that the most popular password was “12345.” Today, even with the proliferation of hacking and data security warnings, the most popular password, chosen by 320,000 of all users on RockYou [a web app company], was “123456″-an entire digit longer. This was followed by the 1990 favorite “12345″ and then, creatively enough, “123456789″ and “password.” About 20% of the people on the site picked from a relatively small pool of only 5,000 passwords. According to the data security firm Imperva, these poor passwords mean that “with only minimal effort, a hacker can gain access to one new account every second or 1,000 accounts every 17 minutes.”

It’s 2010 and it seems only Dantas and a handful of others are successful at securely encrypting their sensitive data. What can we learn from this? Choose better passwords, engage encryption software if necessary — and the FBI isn’t as smart as we think.

The above article is reprinted from the Risk Management Monitor - the official blog of Risk Management magazine .

Reprinted with permission from the Risk Management Monitor. Copyright 2010 Risk and Insurance Management Society, Inc. All rights reserved.

About the Author

Editor

Emily Holbrook is the editor of Risk Management magazine and the Risk Management Monitor blog.

212-655-5915

Boost: AJAX core statistics

Legal Disclaimer

You are responsible for reading, understanding and agreeing to the National Law Review's (NLR’s) and the National Law Forum LLC's  Terms of Use and Privacy Policy before using the National Law Review website. The National Law Review is a free to use, no-log in database of legal and business articles. The content and links on www.NatLawReview.com are intended for general information purposes only. Any legal analysis, legislative updates or other content and links should not be construed as legal or professional advice or a substitute for such advice. No attorney-client or confidential relationship is formed by the transmission of information between you and the National Law Review website or any of the law firms, attorneys or other professionals or organizations who include content on the National Law Review website. If you require legal or professional advice, kindly contact an attorney or other suitable professional advisor.  

Some states have laws and ethical rules regarding solicitation and advertisement practices by attorneys and/or other professionals. NLR does not accept advertising from attorneys or law firms. The National Law Review is not a law firm nor is www.NatLawReview.com  intended to be an advertisement or a referral service for attorneys and/or other professionals. The NLR does not wish, nor does it intend, to solicit the business of anyone or to refer anyone to an attorney or other professional.  NLR does not answer legal questions nor will we refer you to an attorney or other professional if you request such information from us. 

Under certain state laws the following statements may be required on this website and we have included them in order to be in full compliance with these rules. The choice of a lawyer or other professional is an important decision and should not be based solely upon advertisements. Attorney Advertising Notice: Prior results do not guarantee a similar outcome. Statement in compliance with Texas Rules of Professional Conduct. Unless otherwise noted, attorneys are not certified by the Texas Board of Legal Specialization, nor can NLR attest to the accuracy of any notation of Legal Specialization or other Professional Credentials.