<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kaizar Amin &#187; Security</title>
	<atom:link href="http://kaizaramin.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://kaizaramin.com</link>
	<description>Technology Simplified</description>
	<lastBuildDate>Wed, 16 Jun 2010 11:28:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>VoIP Encryption in a Surveillance Society</title>
		<link>http://kaizaramin.com/2010/03/06/voip-encryption-in-a-surveillance-society/</link>
		<comments>http://kaizaramin.com/2010/03/06/voip-encryption-in-a-surveillance-society/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 17:48:19 +0000</pubDate>
		<dc:creator>kaizar</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false">http://kaizaramin.com/?p=294</guid>
		<description><![CDATA[In one of my previous articles, I touched upon the basics of VoIP security. Recently I came across this YouTube video covering a seminar given by Phillip Zimmermann (the Father of PGP) talking about VoIP encryption for the Stanford University Computer Systems Colloquium. Basically, Zimmermann talks about ephemeral encryption of VoIP traffic using Diffie-Hellman key [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">In one of my <a href="http://kaizaramin.com/2009/03/18/voip-security-the-basics/" target="_self">previous articles</a>, I touched upon the basics of VoIP security. Recently I came across this YouTube video covering a seminar given by Phillip Zimmermann (the Father of PGP) talking about VoIP encryption for the Stanford University Computer Systems Colloquium. Basically, Zimmermann talks about ephemeral encryption of VoIP traffic using Diffie-Hellman key exchange. Its a lengthy video (1 hour 15 mins) but quite an interesting watch.</p>
<p><span class="youtube">
<object width="425" height="373">
<param name="movie" value="http://www.youtube.com/v/IP39ISsX9o0&amp;rel=0&amp;color1=d6d6d6&amp;color2=f0f0f0&amp;border=1&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0" />
<param name="allowFullScreen" value="true" />
<embed wmode="transparent" src="http://www.youtube.com/v/IP39ISsX9o0&amp;rel=0&amp;color1=d6d6d6&amp;color2=f0f0f0&amp;border=1&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="373"></embed>
<param name="wmode" value="transparent" />
</object>
</span><p><a href="http://www.youtube.com/watch?v=IP39ISsX9o0">www.youtube.com/watch?v=IP39ISsX9o0</a></p></p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share this Post:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;title=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20&amp;bodytext=In%20one%20of%20my%20previous%20articles%2C%20I%20touched%20upon%20the%20basics%20of%20VoIP%20security.%20Recently%20I%20came%20across%20this%20YouTube%20video%20covering%20a%20seminar%20given%20by%20Phillip%20Zimmermann%20%28the%20Father%20of%20PGP%29%20talking%20about%20VoIP%20encryption%20for%20the%20Stanford%20University%20Compute" title="Digg"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;title=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20&amp;notes=In%20one%20of%20my%20previous%20articles%2C%20I%20touched%20upon%20the%20basics%20of%20VoIP%20security.%20Recently%20I%20came%20across%20this%20YouTube%20video%20covering%20a%20seminar%20given%20by%20Phillip%20Zimmermann%20%28the%20Father%20of%20PGP%29%20talking%20about%20VoIP%20encryption%20for%20the%20Stanford%20University%20Compute" title="del.icio.us"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;t=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20" title="Facebook"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;title=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20&amp;annotation=In%20one%20of%20my%20previous%20articles%2C%20I%20touched%20upon%20the%20basics%20of%20VoIP%20security.%20Recently%20I%20came%20across%20this%20YouTube%20video%20covering%20a%20seminar%20given%20by%20Phillip%20Zimmermann%20%28the%20Father%20of%20PGP%29%20talking%20about%20VoIP%20encryption%20for%20the%20Stanford%20University%20Compute" title="Google Bookmarks"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;title=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20&amp;source=Kaizar+Amin+Technology+Simplified&amp;summary=In%20one%20of%20my%20previous%20articles%2C%20I%20touched%20upon%20the%20basics%20of%20VoIP%20security.%20Recently%20I%20came%20across%20this%20YouTube%20video%20covering%20a%20seminar%20given%20by%20Phillip%20Zimmermann%20%28the%20Father%20of%20PGP%29%20talking%20about%20VoIP%20encryption%20for%20the%20Stanford%20University%20Compute" title="LinkedIn"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;title=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20" title="Live"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;t=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20" title="MySpace"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;title=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20" title="Reddit"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://slashdot.org/bookmark.pl?title=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20&amp;url=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F" title="Slashdot"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;title=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20" title="StumbleUpon"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F" title="Technorati"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="" title="TwitThis"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/" title="TwitThis" alt="TwitThis" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fkaizaramin.com%2F2010%2F03%2F06%2Fvoip-encryption-in-a-surveillance-society%2F&amp;submitHeadline=VoIP%20Encryption%20in%20a%20Surveillance%20Society%20&amp;submitSummary=In%20one%20of%20my%20previous%20articles%2C%20I%20touched%20upon%20the%20basics%20of%20VoIP%20security.%20Recently%20I%20came%20across%20this%20YouTube%20video%20covering%20a%20seminar%20given%20by%20Phillip%20Zimmermann%20%28the%20Father%20of%20PGP%29%20talking%20about%20VoIP%20encryption%20for%20the%20Stanford%20University%20Compute&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  target="_blank" href="" title="YahooMyWeb"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/" title="YahooMyWeb" alt="YahooMyWeb" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://kaizaramin.com/2010/03/06/voip-encryption-in-a-surveillance-society/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On-the-Fly Encryption with TrueCrypt</title>
		<link>http://kaizaramin.com/2010/01/28/on-the-fly-encryption-with-truecrypt/</link>
		<comments>http://kaizaramin.com/2010/01/28/on-the-fly-encryption-with-truecrypt/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 15:16:58 +0000</pubDate>
		<dc:creator>kaizar</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://kaizaramin.com/?p=274</guid>
		<description><![CDATA[Technical Introduction from TrueCrypt.org
TrueCrypt is a software system for establishing and maintaining an on-the-fly-encrypted volume (data storage device). On-the-fly encryption means that data is automatically encrypted or decrypted right before it is loaded or saved, without any user intervention. No data stored on an encrypted volume can be read (decrypted) without using the correct password/keyfile(s) [...]]]></description>
			<content:encoded><![CDATA[<h3 style="text-align: justify;">Technical Introduction from <a href="http://www.truecrypt.org/" target="_blank">TrueCrypt.org</a></h3>
<p style="text-align: justify;">TrueCrypt is a software system for establishing and maintaining an on-the-fly-encrypted volume (data storage device). On-the-fly encryption means that data is automatically encrypted or decrypted right before it is loaded or saved, without any user intervention. No data stored on an encrypted volume can be read (decrypted) without using the correct password/keyfile(s) or correct encryption keys. Entire file system is encrypted (e.g., file names, folder names, contents of every file, free space, meta data, etc).</p>
<p style="text-align: justify;">Files can be copied to and from a mounted TrueCrypt volume just like they are copied to/from any normal disk (for example, by simple drag-and-drop operations). Files are automatically being decrypted on the fly (in memory/RAM) while they are being read or copied from an encrypted TrueCrypt volume. Similarly, files that are being written or copied to the TrueCrypt volume are automatically being encrypted on the fly (right before they are written to the disk) in RAM. Note that this does <em>not</em> mean that the <em>whole</em> file that is to be encrypted/decrypted must be stored in RAM before it can be encrypted/decrypted. There are no extra memory (RAM) requirements for TrueCrypt.</p>
<h3 style="text-align: justify;">Practical Use</h3>
<p style="text-align: justify;">Some of the above technical description might sound too complex to be used by a normal (non-technical) computer user. However, in reality TrueCrypt is very simple to use. Lets say you have some important and confidential files such as MS Word documents, Powerpoint presentations, PDF documents, and your emails.  You want to have all of this data on your computer or USB drive, however only YOU should be able to read it even if someone else has physical access to the system.</p>
<p style="text-align: justify;">
<div id="attachment_275" class="wp-caption alignnone" style="width: 310px"><a href="http://kaizaramin.com/wp-content/uploads/2010/03/createVolume.png"><img class="size-medium wp-image-275" title="TrueCrypt Volume" src="http://kaizaramin.com/wp-content/uploads/2010/03/createVolume-300x254.png" alt="TrueCrypt Volume" width="300" height="254" /></a><p class="wp-caption-text">TrueCrypt Volume</p></div>
<p style="text-align: justify;">After installing TrueCrypt on your computer, you need to create a volume. A volume is nothing but a logical disk partition that will contain all your secured and encrypted data. This volume will reside as a normal file on your computer. You can give it any name, e.g. “My Encrypted Data”. While you create your volume you will be asked to mention the volume location, encryption algorithm (AES, Twofish, etc), volume size, and the volume password.</p>
<p style="text-align: justify;">
<div id="attachment_276" class="wp-caption alignnone" style="width: 310px"><a href="http://kaizaramin.com/wp-content/uploads/2010/03/mount.png"><img class="size-medium wp-image-276" title="Mount Volume" src="http://kaizaramin.com/wp-content/uploads/2010/03/mount-300x254.png" alt="Mount Volume" width="300" height="254" /></a><p class="wp-caption-text">Mount Volume</p></div>
<p style="text-align: justify;">Once you have created a volume, you can then mount it on your computer as a normal drive and use it just like you would use your C: or D: . The benefit you get here is just before the data is written to the mounted drive it is encrypted and likewise decrypted when data is read from it. When the drive is unmounted, the volume resides on your computer like a regular data file with some encrypted binary text that no one can understand. The volume container can be treated as a regular file and can be copied on USB or transferred to another computer where it can be mounted to a drive again using TrueCrypt, thereby giving you portability with your secured data.</p>
<p style="text-align: justify;">TrueCrypt is an open source application and is FREE. If you are skeptical about using a freebie application for protecting your confidential data, think again. Some of the best brains in the realm of security (<a href="http://www.schneier.com/blog/archives/2008/07/truecrypts_deni.html" target="_blank">Bruce Schneier</a>, <a href="http://theinvisiblethings.blogspot.com/2009/10/evil-maid-goes-after-truecrypt.html" target="_blank">Joanna Rutkowska</a>) have given it a serious look in terms of breaking its security. Like every security system hackers will continuously try to break it while the application will evolve to thwart these attacks. Having said that, TrueCrypt is quite an impressive tool to achieve security and confidentiality of your important data without having to pay for commercial products which pretty much do the same thing.</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share this Post:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;title=On-the-Fly%20Encryption%20with%20TrueCrypt&amp;bodytext=Technical%20Introduction%20from%20TrueCrypt.org%0D%0ATrueCrypt%20is%20a%20software%20system%20for%20establishing%20and%20maintaining%20an%20on-the-fly-encrypted%20volume%20%28data%20storage%20device%29.%20On-the-fly%20encryption%20means%20that%20data%20is%20automatically%20encrypted%20or%20decrypted%20right%20befor" title="Digg"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;title=On-the-Fly%20Encryption%20with%20TrueCrypt&amp;notes=Technical%20Introduction%20from%20TrueCrypt.org%0D%0ATrueCrypt%20is%20a%20software%20system%20for%20establishing%20and%20maintaining%20an%20on-the-fly-encrypted%20volume%20%28data%20storage%20device%29.%20On-the-fly%20encryption%20means%20that%20data%20is%20automatically%20encrypted%20or%20decrypted%20right%20befor" title="del.icio.us"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;t=On-the-Fly%20Encryption%20with%20TrueCrypt" title="Facebook"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;title=On-the-Fly%20Encryption%20with%20TrueCrypt&amp;annotation=Technical%20Introduction%20from%20TrueCrypt.org%0D%0ATrueCrypt%20is%20a%20software%20system%20for%20establishing%20and%20maintaining%20an%20on-the-fly-encrypted%20volume%20%28data%20storage%20device%29.%20On-the-fly%20encryption%20means%20that%20data%20is%20automatically%20encrypted%20or%20decrypted%20right%20befor" title="Google Bookmarks"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;title=On-the-Fly%20Encryption%20with%20TrueCrypt&amp;source=Kaizar+Amin+Technology+Simplified&amp;summary=Technical%20Introduction%20from%20TrueCrypt.org%0D%0ATrueCrypt%20is%20a%20software%20system%20for%20establishing%20and%20maintaining%20an%20on-the-fly-encrypted%20volume%20%28data%20storage%20device%29.%20On-the-fly%20encryption%20means%20that%20data%20is%20automatically%20encrypted%20or%20decrypted%20right%20befor" title="LinkedIn"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;title=On-the-Fly%20Encryption%20with%20TrueCrypt" title="Live"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;t=On-the-Fly%20Encryption%20with%20TrueCrypt" title="MySpace"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;title=On-the-Fly%20Encryption%20with%20TrueCrypt" title="Reddit"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://slashdot.org/bookmark.pl?title=On-the-Fly%20Encryption%20with%20TrueCrypt&amp;url=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F" title="Slashdot"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;title=On-the-Fly%20Encryption%20with%20TrueCrypt" title="StumbleUpon"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F" title="Technorati"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="" title="TwitThis"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/" title="TwitThis" alt="TwitThis" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fkaizaramin.com%2F2010%2F01%2F28%2Fon-the-fly-encryption-with-truecrypt%2F&amp;submitHeadline=On-the-Fly%20Encryption%20with%20TrueCrypt&amp;submitSummary=Technical%20Introduction%20from%20TrueCrypt.org%0D%0ATrueCrypt%20is%20a%20software%20system%20for%20establishing%20and%20maintaining%20an%20on-the-fly-encrypted%20volume%20%28data%20storage%20device%29.%20On-the-fly%20encryption%20means%20that%20data%20is%20automatically%20encrypted%20or%20decrypted%20right%20befor&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  target="_blank" href="" title="YahooMyWeb"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/" title="YahooMyWeb" alt="YahooMyWeb" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://kaizaramin.com/2010/01/28/on-the-fly-encryption-with-truecrypt/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Basics of Cryptography</title>
		<link>http://kaizaramin.com/2009/08/31/the-basics-of-cryptography/</link>
		<comments>http://kaizaramin.com/2009/08/31/the-basics-of-cryptography/#comments</comments>
		<pubDate>Mon, 31 Aug 2009 17:17:22 +0000</pubDate>
		<dc:creator>kaizar</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://kaizaramin.com/?p=257</guid>
		<description><![CDATA[Recently, I have been working towards establishing an enterprise framework for PGP encryption. In that regards, I came across this very useful link that outlines the basic concepts of cryptography.  I am simply summarizing these concepts in short.

Encryption and Decryption
Data that can be read and understood without any special measures is called plaintext or cleartext. The [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align: justify;">Recently, I have been working towards establishing an enterprise framework for PGP encryption. In that regards, I came across this very useful <a href="http://www.pgpi.org/doc/pgpintro/" target="_blank">link</a> that outlines the basic concepts of cryptography. <span> </span>I am simply summarizing these concepts in short.</p>
<p class="MsoNormal" style="text-align: justify;">
<h3><a name="p2">Encryption and Decryption</a><span></span></h3>
<p class="MsoNormal" style="text-align: justify;"><span>Data that can be read and understood without any special measures is called <em>plaintext </em>or <em>cleartext. </em>The method of disguising plaintext in such a way as to hide its substance is called <em>encryption. </em>Encrypting plaintext results in unreadable gibberish called <em>ciphertext. </em>You use encryption to ensure that information is hidden from anyone for whom it is not intended, even those who can see the encrypted data. The process of reverting ciphertext to its original plaintext is called <em>decryption</em>.</span></p>
<p class="MsoNormal" style="text-align: justify;"><span> </span></p>
<h3><a name="p3">What is Cryptography?</a><span></span></h3>
<p class="MsoNormal" style="text-align: justify;"><em><span>Cryptography </span></em><span>is the science of using mathematics to encrypt and decrypt data. Cryptography enables you to store sensitive information or transmit it across insecure networks (like the Internet) so that it cannot be read by anyone except the intended recipient.</span></p>
<p><a name="p5"><strong>How does cryptography work?</strong></a><span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span><span>A</span></span><span><span> </span></span><span><em><span>cryptographic algorithm,</span></em></span><span><em><span> </span></em></span><span><span>or cipher, is a mathematical function used in the encryption and decryption process. A cryptographic algorithm works in combination with a</span></span><span><span> </span></span><span><em><span>key —</span></em></span><span><em><span> </span></em></span><span><span>a word, number, or phrase — to encrypt the plaintext. The same plaintext encrypts to different ciphertext with different keys. The security of encrypted data is entirely dependent on two things: the strength of the cryptographic algorithm and the secrecy of the key.</span></span><span><span></span></span></p>
<p style="text-align: justify;"><span>A cryptographic algorithm, plus all possible keys and all the protocols that make it work comprise a<span> </span><em>cryptosystem.<span> </span></em>PGP is a cryptosystem.</span><span></span></p>
<p class="MsoNormal" style="text-align: justify;">
<h3><a name="p6"><span>Conventional Cryptography</span></a><span></span></h3>
<p class="MsoNormal" style="text-align: justify;"><span>In conventional cryptography, also called <em>secret-key </em>or <em>symmetric-key </em>encryption, one key is used both for encryption and decryption. The Data Encryption Standard (DES) is an example of a conventional cryptosystem that is widely employed by the US Federal Government.</span></p>
<p><a name="p8"><strong>Key management and conventional encryption</strong></a><span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span><span>Conventional encryption has benefits. It is very fast. It is especially useful for encrypting data that is not</span></span><span><span> </span></span><span><em><span>going</span></em></span><span><em><span> </span></em></span><span><span>anywhere. However, conventional encryption alone as a means for transmitting secure data can be quite expensive simply due to the difficulty of secure key distribution.</span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span><span>For a sender and recipient to communicate securely using conventional encryption, they must agree upon a key and keep it secret between themselves. If they are in different physical locations, they must trust a courier, the Bat Phone, or some other secure communication medium to prevent the disclosure of the secret key during transmission. Anyone who overhears or intercepts the key in transit can later read, modify, and forge all information encrypted or authenticated with that key.</span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span><span> </span></span></p>
<h3><a name="p9"><span>Public key cryptography</span></a><span></span></h3>
<p class="MsoNormal" style="text-align: justify;"><span>Public key cryptography is an asymmetric scheme that uses a</span><span> </span><em><span>pair</span></em><em><span> </span></em><span>of keys for encryption: a</span><span> </span><em><span>public key,</span></em><em><span> </span></em><span>which encrypts data, and a corresponding</span><span> </span><em><span>private,</span></em><em><span> </span></em><span>or</span><span> </span><em><span>secret key</span></em><em><span> </span></em><span>for decryption. You publish your public key to the world while keeping your private key secret. Anyone with a copy of your public key can then encrypt information that only you can read. Even people you have never met.</span><span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span>It is computationally infeasible to deduce the private key from the public key. Anyone who has a public key can encrypt information but cannot decrypt it. Only the person who has the corresponding private key can decrypt the information. </span><span><span>The primary benefit of public key cryptography is that it allows people who have no preexisting security arrangement to exchange messages securely. The need for sender and receiver to share secret keys via some secure channel is eliminated; all communications involve only public keys, and no private key is ever transmitted or shared.</span></span></p>
<p class="MsoNormal" style="text-align: justify;">
<h3><a name="p10"><span>How PGP works</span></a><span></span></h3>
<p class="MsoNormal" style="text-align: justify;"><span>PGP combines some of the best features of both conventional and public key cryptography. PGP is a <em>hybrid cryptosystem. </em>When a user encrypts plaintext with PGP, PGP first compresses the plaintext. Data compression saves modem transmission time and disk space and, more importantly, strengthens cryptographic security. Most cryptanalysis techniques exploit patterns found in the plaintext to crack the cipher. Compression reduces these patterns in the plaintext, thereby greatly enhancing resistance to cryptanalysis. (Files that are too short to compress or which don&#8217;t compress well aren&#8217;t compressed.)</span></p>
<p class="MsoNormal" style="text-align: justify;"><span><span>PGP then creates a</span></span><span><span> </span></span><span><em><span>session key,</span></em></span><span><em><span> </span></em></span><span><span>which is a one-time-only secret key. This key is a random number generated from the random movements of your mouse and the keystrokes you type. This session key works with a very secure, fast conventional encryption algorithm to encrypt the plaintext; the result is ciphertext. Once the data is encrypted, the session key is then encrypted to the recipient&#8217;s public key. This public key-encrypted session key is transmitted along with the ciphertext to the recipient.</span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span><span>Decryption works in the reverse. The recipient&#8217;s copy of PGP uses his or her private key to recover the temporary session key, which PGP then uses to decrypt the conventionally-encrypted ciphertext.</span></span></p>
<p class="MsoNormal" style="text-align: justify;"><span><span>The combination of the two encryption methods combines the convenience of public key encryption with the speed of conventional encryption. Conventional encryption is about 1,000 times faster than public key encryption. Public key encryption in turn provides a solution to key distribution and data transmission issues. Used together, performance and key distribution are improved without any sacrifice in security</span></span>.<span></span></p>
<p class="MsoNormal" style="text-align: justify;">To understand these concepts in detail and read on additional topics such as Keys, Signatures, Digital Certificates, and Trust I would strongly suggest you take a look at the <a href="http://www.pgpi.org/doc/pgpintro/" target="_blank">original article</a>.</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share this Post:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;title=The%20Basics%20of%20Cryptography&amp;bodytext=Recently%2C%20I%20have%20been%20working%20towards%20establishing%20an%20enterprise%20framework%20for%20PGP%20encryption.%20In%20that%20regards%2C%20I%20came%20across%20this%20very%20useful%20link%20that%20outlines%20the%20basic%20concepts%20of%20cryptography.%20%20I%20am%20simply%20summarizing%20these%20concepts%20in%20short.%0D%0A%0D" title="Digg"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;title=The%20Basics%20of%20Cryptography&amp;notes=Recently%2C%20I%20have%20been%20working%20towards%20establishing%20an%20enterprise%20framework%20for%20PGP%20encryption.%20In%20that%20regards%2C%20I%20came%20across%20this%20very%20useful%20link%20that%20outlines%20the%20basic%20concepts%20of%20cryptography.%20%20I%20am%20simply%20summarizing%20these%20concepts%20in%20short.%0D%0A%0D" title="del.icio.us"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;t=The%20Basics%20of%20Cryptography" title="Facebook"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;title=The%20Basics%20of%20Cryptography&amp;annotation=Recently%2C%20I%20have%20been%20working%20towards%20establishing%20an%20enterprise%20framework%20for%20PGP%20encryption.%20In%20that%20regards%2C%20I%20came%20across%20this%20very%20useful%20link%20that%20outlines%20the%20basic%20concepts%20of%20cryptography.%20%20I%20am%20simply%20summarizing%20these%20concepts%20in%20short.%0D%0A%0D" title="Google Bookmarks"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;title=The%20Basics%20of%20Cryptography&amp;source=Kaizar+Amin+Technology+Simplified&amp;summary=Recently%2C%20I%20have%20been%20working%20towards%20establishing%20an%20enterprise%20framework%20for%20PGP%20encryption.%20In%20that%20regards%2C%20I%20came%20across%20this%20very%20useful%20link%20that%20outlines%20the%20basic%20concepts%20of%20cryptography.%20%20I%20am%20simply%20summarizing%20these%20concepts%20in%20short.%0D%0A%0D" title="LinkedIn"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;title=The%20Basics%20of%20Cryptography" title="Live"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;t=The%20Basics%20of%20Cryptography" title="MySpace"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;title=The%20Basics%20of%20Cryptography" title="Reddit"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://slashdot.org/bookmark.pl?title=The%20Basics%20of%20Cryptography&amp;url=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F" title="Slashdot"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;title=The%20Basics%20of%20Cryptography" title="StumbleUpon"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F" title="Technorati"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="" title="TwitThis"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/" title="TwitThis" alt="TwitThis" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fkaizaramin.com%2F2009%2F08%2F31%2Fthe-basics-of-cryptography%2F&amp;submitHeadline=The%20Basics%20of%20Cryptography&amp;submitSummary=Recently%2C%20I%20have%20been%20working%20towards%20establishing%20an%20enterprise%20framework%20for%20PGP%20encryption.%20In%20that%20regards%2C%20I%20came%20across%20this%20very%20useful%20link%20that%20outlines%20the%20basic%20concepts%20of%20cryptography.%20%20I%20am%20simply%20summarizing%20these%20concepts%20in%20short.%0D%0A%0D&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  target="_blank" href="" title="YahooMyWeb"><img src="http://kaizaramin.com/wp-content/plugins/sociable/images/" title="YahooMyWeb" alt="YahooMyWeb" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://kaizaramin.com/2009/08/31/the-basics-of-cryptography/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
