[ISN] Analyst finds flaws in Canon image verification system

From: InfoSec News <alerts_at_private>
Date: Wed, 1 Dec 2010 00:39:11 -0600 (CST)
http://www.networkworld.com/news/2010/113010-analyst-finds-flaws-in-canon.html

By Jeremy Kirk
IDG News Service
November 30, 2010

A cryptographic system used by Canon to ensure that digital images 
haven't been altered is flawed and can't be fixed, according to a 
Russian security company that specializes in encryption.

Mid- to high-end Canon digital cameras have a feature called "Original 
Decision Data" (ODD), which is a digital signature that can be verified 
to see if a photo has been retouched or if data such as timestamps or 
GPS coordinates have been changed. The Associated Press news wire uses 
the system, which can also be used to verify photos used as evidence.

But the digital signature can be forged due to design flaws in Canon's 
system, according to Dmitry Sklyarov, an IT security analyst with 
Elcomsoft, which specializes in password recover systems. Sklyarov was 
due to give a presentation on the flaws at the Confidence IT security 
event in Prague on Tuesday afternoon.

Elcomsoft has published photos -- including one with an astronaut 
planting the flag of the Soviet Union on the moon -- that, if checked 
using a smart card and special software from Canon, confirm that the 
photo has not been tampered with.

[...]


___________________________________________________________      
Tegatai Managed Colocation: Four Provider Blended
Tier-1 Bandwidth, Fortinet Universal Threat Management,
Natural Disaster Avoidance, Always-On Power Delivery 
Network, Cisco Switches, SAS 70 Type II Datacenter. 
Find peace of mind, Defend your Critical Infrastructure.
http://www.tegataiphoenix.com/
Received on Tue Nov 30 2010 - 22:39:11 PST

This archive was generated by hypermail 2.2.0 : Tue Nov 30 2010 - 22:46:54 PST