How I cracked NQ Vault's “encryption”
ninjadoge24.github.io
ninjadoge24.github.io
http://www.forbes.com/sites/afontevecchia/2013/10/24/nq-mobi...
link to original muddywaters research: http://www.muddywatersresearch.com/wp-content/uploads/2013/1...
The same technique is followed by several Chinese mobile companies. I don't think its well understood why these companies are buying installs and where the money is coming from.
Here are the top ten Tool in India. 8 of 10 are by Chinese companies (Primarily by buying Installs. I am not saying all of them but most of them are). India and China have Conflicts. Tools is one category that require scary permissions.
That being said, those that do not have the skills to realize that this is not sufficient need to reach out to those that do. If you organization does not have security staff, then a contracted audit is necessary. If someone is producing a product and are trying to claim it is secure, ignorance of what secure actually is, is not an excuse.
https://play.google.com/store/apps/details?id=com.netqin.ps
There are already a couple of comments by people who obviously read this article, please upvote them. I mean, you have to install it but I just told it to install it on a phone that broke years ago ;-)
Edit: formatting
So, the app might suck, but where can I rate the play store experience with a single star?
https://www.truste.com/business-products/dpm-services/#pCert
I can't find NQ in their search tool for certified companies. Perhaps it's been retracted or was never really issued? Maybe I'm looking in the wrong place
https://www.truste.com/consumer-resources/trusted-directory/
I routinely perform code and web app audits on companies that proudly bear this seal and find security flaws that will compromise users. The seal means nothing.
And also, what does the developer even gain from using XOR? In most common frameworks, using, perhaps incorrectly, AES is about the same effort.
I do not think that we currently have a good way as product creators to specify what secure actually means - and what is more - our customers won't understand the nuance either.
This is in no way trying to excuse passing this "encryption" scheme off as secure.
Of course, you do actually need to generate that keystream and not just repeat a short key.
Please do link it, if only to put your readers 1 click away from giving it bad but honest ratings. Do this also for search engines to find and associate your post with the app. Such bad software needs to be exposed. So here it is: https://play.google.com/store/apps/details?id=com.netqin.ps
But this encryption is laughably simple. Those organizations would probably encourage at least somewhat better security. From their point of view the best possible situation is if they can read the data but non-state actors can't.
If so, I wonder how effective it would be to encrypt just the complete frames, leaving the frame differences for the in between frames unencrypted?
The problem here is deriving something so simple from the key, and only applying it to the first 128 bytes. This is unforgivably dumb, when there are perfectly serviceable encryption services available as part of open source libraries, such as the aforementioned AES-256 algorithm.
[1]: http://en.wikipedia.org/wiki/One-time_pad [2]: http://en.wikipedia.org/wiki/Advanced_Encryption_Standard#Th...
The one-time-pad is a special case of any number of poly-alphabetic substitution ciphers, XOR just being one that happens to be implemented on lots of silicon. Considering this is all about an app that has very short keys (a few numeric digits) it's perfectly legitimate to criticise the use of a substitution cipher as they are especially poor when used with short keys compared to real crypto libraries that will use that short key as the passphrase for a real key.
char* xor_encrypt(char* input, char key) {
int i;
int m = sizeof(input);
output = (char*)malloc((int) m + 1);
for (i = 0; i < m; i++) {
output[i] = input[i] ^ key;
}
output[m] = 0;
return output;
}http://www.cryptofails.com/post/87697461507/46esab-high-qual...
Now you have two encryption problems.