Computerworld
Update improves encryption tool for al-Qaeda backers
Security exec's analysis shows code is well written but messages may be easy to track
Jaikumar Vijayan  05 February, 2008 08:34

A recently released tool that allegedly was designed to help al-Qaeda supporters encrypt their Internet-based communications is a well-written and easily portable piece of code, according to a security researcher who has analyzed the software.

However, messages that are encrypted using the tool, which is known as Mujahideen Secrets 2, should be relatively easy for law enforcement authorities to spot and track, said Paul Henry, vice president of technology evangelism at Secure Computing.

Henry said that based on his analysis of the encryption tool, "it will not be a difficult matter for law enforcement to identify files created using this software" because it puts a unique fingerprint on them, Henry said. "You may not be able to read the messages, but you will be able to figure out where it was sent from and to whom," he added.

Mujahideen Secrets 2 was released last month via an Arabic-language Web site set up by an Islamic forum called al-Ekhlaas. At the time, the password-protected Web site was running on a server belonging to a Web hosting firm in Tampa, Fla., after previously being on a system owned by another company in Rochester, Minn. But the URL that the group was using on the server in Tampa is no longer working.

As of last week, the al-Ekhlaas site had been moved to a server owned by yet another hosting firm, this one based in Phoenix, Henry said. But the link to the site on that server also now appears to have been broken.

The new encryption software is an updated version of an easier-to-crack tool that was released early last year by the same group. Henry said the copy of Mujahideen Secrets 2 that he evaluated was provided to him by J.M. Berger, a freelance journalist and documentary film maker who focuses on terrorism as well as science and business topics.

Mujahideen Secrets 2 is a very compelling piece of software from an encryption perspective, according to Henry. He said the new tool is easy to use and provides 2048-bit encryption, an improvement over the 256-bit AES encryption supported in the original version. What makes the update especially interesting, he noted, is the fact that in addition to e-mails, it can be used to encrypt Yahoo and MSN chat messages.

Another interesting aspect of the tool is its ability to take a binary file and encrypt it in such a way that the file can be posted in a pure ASCII or text-only format, Henry added. As a result, individuals could use Mujahideen Secrets 2 to encrypt files and post them on sites that aren't even on the Internet -- for instance, on a telephone-accessed bulletin board system. "If you wanted to do something covert, that's one way of doing it," he said.

The new version of the tool also has a much better graphical user interface than the initial release did, Henry said. And he thinks the tool's developers have done a better job of integrating bits and pieces of RSA Security Inc.'s encryption code in order to handle functions such as key generation and key management. Many of the mistakes they made in the first version seem to have been addressed in the new one, thereby making it harder to crack, he said.

In addition, the revamped tool is highly portable, Henry said. For instance, he said that someone could put the software on a USB memory stick, go to an Internet cafe, plug in the USB device and run Mujihadeen Secrets 2 to encrypt any communications from that cafe.

According to Berger, the new version of the tool sounds worrisome both because of its increased sophistication and the ease with which it can be used. The software appears to be designed for use by relatively low-level operators in the al Qaeda hierarchy, he said.

The capabilities offered by Mujahideen Secrets 2 fit a pattern for al-Qaeda groups, Becker said, noting that the terrorist organization "has always been pretty current with what they use -- cutting edge, but not bleeding edge."

Berger added that there is a "robust discussion" taking place within the counterterrorism community over the issue of online forums such as al-Ekhlaas being hosted on US-based servers. Some people believe it is easier to monitor what's going on in the forums when they are hosted on US-based servers, he said. Others, though, want the Web sites to be taken down immediately.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Whitepaper

IDC Report: Managed Communications - Delivering on a Holistic ICT Vision

IDC believes that advances in technology combined with convergence, consolidation, centralisation and consumerisation drivers are set to change communications business models and the ICT landscape. Read on and enable your business to do more with less.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.