Snake Oil Crypto Competition
snakeoil.cr.yp.to
snakeoil.cr.yp.to
Many products make outrageous claims about their security. Try browsing the aisles of Best Buy or any major department store. From smart-home sensors to security-cameras to anti-virus software, the shelves are stocked full with snake-oil security products advertising themselves as legitimate. These are the products that big retailers and OEM partners are marketing to the public as "secure," with much lower standards for security than any expert would assert.
To prove this to the public, what better way than a competition for benevolent security researchers to create a wolf-in-sheeps-clothing? The competition is to produce most shiny, marketable product design that looks like a "security" product, but does something far more sinister than protect its users.
Product ideas: "Anonymous router" that actually logs all traffic and sends it to a printer in the local police office; "Smart Home Hub" that performs active exploitation attacks against connected devices; "Smart TV" that actually films its users and live streams their living room to a website.
(Bonus points if they credit real products!)
Apparently this year's contest just opened.
That's been done, 2 years ago:
http://money.cnn.com/2013/08/01/technology/security/tv-hack/
This is hilarious.
Please, can someone explain what this is about? E.g. Dan mentions the inventors of Rijndael, which is AES. What is his complaint about it?
https://www.reddit.com/r/crypto/comments/1us6a1/snake_oil_cr...?
I have no idea if that is what this specific dig ("they already master the art of snake oil") pertains to.
>Changing winner's parameters to default ones.
>Retraction of the idea to change parameters.
Speaking of Keccak their landing page is full of snake-oily marketing such as "rock-solid security strength level" and "heavier SHAKE512" or "extremely high 256 bits" like they are trying to sell me a battle armor video game addon. I realize there is misinformation floating around ever since the questionable SHA3 competition but bolding arbitrary words and injecting "rock-solid" into your criticism debunking isn't helping. http://keccak.noekeon.org/
> "+ Protection against front-channel attacks."
I think I just hurt myself laughing.
Lucks is a well known research cryptanalyst and one of the co-inventors of the Skein SHA3 finalist.
https://www.youtube.com/watch?v=l6jTFxQaUJA - Her and the author of this parody at 31C3 last year, teaching ECC.