Feeds

Cryptographers crack system for verifying digital images

Have you seen my signing key?

Combat fraud and increase customer satisfaction

Cryptographers have cracked software used to verify that images taken with Canon cameras haven't been altered.

Russian password-cracking company ElcomSoft said on Tuesday that it's able to extract the original signing key from the Canon Original Data Security Kit and use it to validate fake photos. Canon has billed the service as a way to verify the originality of an image and to confirm that global positioning coordinates, data, time, and other metadata hasn't been changed.

“The entire image verification system is proved useless,” ElcomSoft CEO Vladimir Katalov said in a statement. “If one company was able to produce fake images indistinguishable from originals, how do we know that others haven't been doing this for years?”

The Russian company mocked the system by posting doctored photos authenticated by the system purporting to show Russian cosmonauts landing on the moon ahead of US astronauts and Joseph Stalin brandishing an iPhone.

According to ElcomSoft, the verification kit embeds cryptographic data into every image taken with a compatible Canon camera that's supposed to verify the picture's authenticity and originality. The kit's demise joins a long list of other cracks by ElcomSoft that extract everything from iPhone 4 passwords to Wi-Fi encryption keys.

A PDF of the announcement is here. ®

SANS - Survey on application security programs

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.