Archive for July, 2007

Seecrets On Security: A Gentle Introduction On Cryptography Part

Sunday, July 22nd, 2007

2

The recent explosive growth of PC’s and Internet-based commerce
has significantly increased the need for a wide variety of
computer security mechanisms. This article, the second of a
three-part series, lays the underlying foundation in plain
language.

A slightly longer series of articles \”Keeping Your Secrets
Secret\” will examine practical examples in greater detail and
provides useful tips and advice. Of course, these will continue
with the theme of making crypto and computer security easily
understood.

One-Way Hash

Also known as a one-way function, a message digest, a
fingerprint or a checksum, the algorithm creates a fixed-length
output that cannot be reversed. One-way hashes provide checksums
to validate files, create digital certificates and played a
central part in many authentication schemes.

Let us consider this example. For ages, the Chinese have a
fortune-telling method that relies on \”Ba Ji\” (eight characters)
which uses the time, day, month and year of birth according to
their calendar. There are sixty possibilities (almost equal to 6
bits) for each of the four variables. Since the Chinese use two
characters for each variable, the result is always eight
characters. This is an example of a nonsecure 24-bit one-way
hash.

Obviously, this way of producing a one-way hash is not
acceptable for security purposes because of the huge number of
collisions (different inputs producing the same output).

The most commonly used hashes are SHA-1 (Secure Hash Algorithm
uses 160 bits) and MD5 (Message Digest uses 128 bits). In August
2005, a team of cryptographers led by Xiaoyun Wang of Shandong
University, China, presented a paper that found faster ways of
finding collisions than the usual brute force method. These
exploits (vulnerabilities) may make digital certificates forgery
a reality.

The implications to e-commerce may be widespread not to mention
the millions of websites which used MD5 to hash the users’
passwords in their databases. Any webmaster can tell you that
converting these sites to use SHA-256 or SHA-512 will not be a
trivial task.

In a recent directive, NIST (National Institute of Standards &
Technology, U.S.A.) has advised U.S. governmental agencies to
use SHA-256 or SHA-512 (256 and 512 bits respectively) instead.

Biometrics

A biometric device is one that can identify unique
characteristics from a finger, eye or voice. Many believe that
biometrics should provide a higher level of security than other
forms of authentication.

There is a news story in March 2005 of how a Malaysian owner
lost his Mercedes car and index finger to car thieves armed with
machetes. Obviously the keyless ignition electronics cannot
detect whether the finger is still part of the original body nor
whether the finger (and by extension the person) is alive or not.

Recent security breaches have heightened concern over
depositories of personal information stored on many financial
sites. When such breaches occurred, the incidence of identity
thefts will thus rise also.

If you lose your credit card, you can always void the card and
get a new one. When you lose your fingerprint (stored
digitally), or other biometric features, who can replace those?

Passwords

When asked to conjure a random number or characters, most people
inevitably used materials that are familiar to them like
birthdays, names of family members, pets’ names and so forth.

For example, most will choose dates when asked to choose a
six-digit number for their ATM Personal Identification Number
(PIN). Doing so will reduce the number of possibilities by nine
times.

Random Numbers and Generators

Random numbers are central to crypto. To qualify as true random
numbers, the output from random number generators (RNG) must
pass statistical tests of randomness. Two suites considered as
de facto standards are the \”diehard\” suite developed by Prof.
George Marsaglia of State University of Florida and \”Statistical
Test Suite\” from NIST.

Second, the RNG’s output must be unpredictable even with
complete knowledge of the algorithm or hardware producing the
series and all the previous bits produced.

Third, the RNG’s output cannot be cloned in a repeat run even
with the same input.

The most common approach to producing random numbers is by using
an algorithm carried out by a computer program (Yarrow, Tiny,
Egads, Mersenne Twister). Such algorithms cannot produce random
numbers, hence their names, pseudo-random number generators
(PRNG).

Another approach is to use physical events such as entropy
produced by the keyboard, mouse, interrupts, white noise from
microphones or speakers and disk drive behavior as the seed
(initial value).

Some may argue that true random generators are those that can
detect quantum behavior in subatomic physics. This is because
randomness is inherent in the behavior of subatomic particles -
remember the electron cloud from your high school physics.

One-time Pad

The most effective system is often the simplest. A one-time pad
(OTP) is a series of random bits that has the same length as the
digital object to be encrypted. To encrypt, just use a simple
computer operation, exclusive OR (XOR). To decrypt, simply XOR
the encrypted result with the same random bits.

The downside of using OTP is that once used, it must be
discarded. Second, the OTP and the digital object must have the
same number of bits. Lastly, the obvious problem of
synchronizing the OTP between the receiver and sender.

[Author’s note: The concluding Part 3 will focus on keys
management and public key cryptography.]

\”In God we trust, others use crypto.\”

© Copyright 2005, Stan Seecrets. All rights reserved.

About the author:
The author, Stan Seecrets, is a veteran software developer with
25+ years experience. For more of his articles and website
promotion, visit http://www.seecrets.biz or http://www.rushprnews.com

Actual Title Buttons 3.7 extends window manipulationg

Saturday, July 21st, 2007

capabilities by means of adding new buttons to a window caption

Actual Tools announces Actual Title Buttons 3.7

For immediate release

September 15, 2005

Contact: Michael Tretyakov Company: Actual Tools E-mail:
press@actualtools.com

Extended window manipulation capabilities by means of adding new
buttons to a window caption.

Actual Tools, the world\’s leading innovator in desktop
enhancement technologies, today announced the release of version
3.7 of Actual Title Buttons. Designed for Windows platforms, the
application enhances their window navigation system with such
breakthrough controls as Minimize to Tray, Roll Up, Stay on Top,
Align Window, Make Transparent and over handy functions.

The new window controls seamlessly integrate into the shell and
can be triggered via corresponding Windows-style buttons that
sit on a window title bar next to standard
Minimize/Restore/Close buttons. Besides activating new controls
with mouse clicks, version 3.7 allows controlling window
behavior by means of keystroke combinations, the standard
language of millions of IT professionals.

Besides on-the-fly window transparency control and window
roll-up unroll features, Actual Title Buttons allows you to
minimize any window to system tray notification area instead of
Taskbar, so that it makes Taskbar less cluttered, and keep any
window on top of others, so that the most important windows are
always accessible and couldn\’t be hidden by other windows.

Actual Title Buttons is intended both for home and corporate
users who would like to optimize common windows management
activities by utilizing hidden power of modern operating systems
with just one mouse-click. This extremely easy-to-use
application features native operating system style windows
buttons interface to allow on-the-go windows placement, size and
transparency control via intuitive graphical buttons located in
the title area of a window.

\”Everyone who have ever seen Microsoft Windows probably knows
what minimize, maximize and close buttons in the title bar are
intended for,\” – said Michael Tretyakov, CEO of Actual Tools.
\”However, many computer users have yet to discover how many
other things can be done with any window they use just to turn
an average cluttered desktop into a neat looking workspace
environment. Creators of Windows have placed a vast potential of
functionality into such a simple thing as window; creating the
most convenient way to utilize this power was our goal.\”

Actual Tools\’ team offers 7 handy functions that can now be
accessed with hotkeys. According to Michael Tretyakov, \”The
latest version of Actual Title Buttons is our next step to make
the product more flexible and easy to use for power users. They
won\’t have to modify their computer operating habits because the
new product has perfectly mastered the language of hotkeys they
use\”.

Actual Title Buttons runs under 95/98/Me/NT4/2000/XP, costs
$19.95(US), and may be purchased securely online at
http://www.ActualTools.com/

About Actual Tools

Founded in 2001, Actual Tools Software Company mainly
concentrates on enhancing currently available Windows operating
systems interfaces and providing expanded functionality to
commonly used shell resources. Actual Tools mission is to
provide end users of virtually any level of computer skills with
adequate software understanding and utilization concepts.
Instead of re-inventing the wheel, Actual Tools offers its
customers better ways of using the wheel for their own computing
pleasure and comfort. Actual Tools product range has power
solutions for both individuals and corporate customers.

# # #

For more information, contact Actual Tools at:

E-mail: press@actualtools.com Corporate web site:
http://www.ActualTools.com Product web site:
http://www.ActualTools.com/titlebuttons/ Screenshots:
http://www.ActualTools.com/images/atb_screenshot.gif Download:
http://www.ActualTools.com/files/atbsetup.exe

About the author:
Contact information: [Responsible person] Michael Tretyakov
[Phone] [Fax] [Email] submit@actualtools.com [Web-site]
http://www.actualtools.com/

The Advantages of Full Color Brochure Printing

Friday, July 20th, 2007

A brochure can be a great promotional tool, whether it is for is
a real estate listing, a trade show handout, a data sheet, or
another application. The most professional and eye-catching
brochures are usually those that are full color.

Full color brochure printing usually means standard four-color
printing, and is now offered at almost every brochure printing
company. Four-color printing is also referred to as standard
color printing and employs cyan (blue), magenta, yellow, and
black inks, often abbreviated to “CMYK.” Most computer software
programs will convert any text or image to CMYK, and this is
usually a requirement of printers.

Brochure printing companies will usually provide a clear
explanation of the four-color process. Most high quality, full
color commercial printing is done on offset presses using this
four-color build process. These four colors are used to create
or build the many color shades seen in a brilliant, full color
printed brochure.

Color can be tricky, because what you see on your computer
screen is called RGB color; it is a different color model than
the four-color process. Frequently there is a wide variation in
monitor technologies and calibration, and colors will be
similar, but not exactly the same. Make sure you communicate to
your printing service what color you need to see in the final
product. If you print a sample color brochure on your inkjet or
laser printer, there may be some variation from the color
produced from your printer to the offset lithographic presses.

One of the many advantages of the four-color process is that
computer-controlled inking and chemical mixing systems provide
color consistency. Automatic color and register control
maintains consistent quality, making four-color process the most
popular printing choice.

When an exact color match is essential, a spot color of
specially mixed ink is used in printing. These specially mixed
inks are called pantone colors. You can find color books showing
thousands of pantone colors and get an exact match. Spot colors
are used most frequently for one- and two-color jobs and when an
exact color needs to be produced every time. Full color brochure
printing is easy and affordable; so let your imagination soar.

About the author:
Brochure Printing
Info
provides detailed information about cheap, color, and
full color brochure printing services, and advice on finding a
brochure printing company and quote. Brochure Printing Info is
the sister site of Laser
Toner Web
.