<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6690994337395244641.post5345960998095418690..comments</id><updated>2009-07-11T11:25:59.145-05:00</updated><title type='text'>Comments on Paul Melson's Blog: Quicky Binary File Visual Analysis</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://pmelson.blogspot.com/feeds/5345960998095418690/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5345960998095418690/comments/default'/><link rel='alternate' type='text/html' href='http://pmelson.blogspot.com/2008/03/quicky-binary-file-visual-analysis.html'/><author><name>PaulM</name><uri>http://www.blogger.com/profile/02530533566781746778</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6690994337395244641.post-869544617638340070</id><published>2008-04-01T12:58:00.000-05:00</published><updated>2008-04-01T12:58:00.000-05:00</updated><title type='text'>Thanks for the comment, Erik.You make a very good ...</title><content type='html'>Thanks for the comment, Erik.&lt;BR/&gt;&lt;BR/&gt;You make a very good point that this type of test is not in any way thorough, and that things like XOR-ing  a file will produce a similar visual result.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5345960998095418690/comments/default/869544617638340070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5345960998095418690/comments/default/869544617638340070'/><link rel='alternate' type='text/html' href='http://pmelson.blogspot.com/2008/03/quicky-binary-file-visual-analysis.html?showComment=1207072680000#c869544617638340070' title=''/><author><name>PaulM</name><uri>http://www.blogger.com/profile/02530533566781746778</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07710546765367697106'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://pmelson.blogspot.com/2008/03/quicky-binary-file-visual-analysis.html' ref='tag:blogger.com,1999:blog-6690994337395244641.post-5345960998095418690' source='http://www.blogger.com/feeds/6690994337395244641/posts/default/5345960998095418690' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6690994337395244641.post-3733350691646204020</id><published>2008-03-27T22:01:00.000-05:00</published><updated>2008-03-27T22:01:00.000-05:00</updated><title type='text'>Paul -First, thanks for sharing this code. I happe...</title><content type='html'>Paul -&lt;BR/&gt;&lt;BR/&gt;First, thanks for sharing this code. I happen to need something that does  just this!&lt;BR/&gt;&lt;BR/&gt;A few comments on using frequency analysis as a "Snake Oil" vs good crypto test:&lt;BR/&gt;&lt;BR/&gt;Please take a look at the Linux Penguin photos in this wikipedia entry: &lt;A HREF="http://en.wikipedia.org/wiki/Block_cipher_modes_of_operation" REL="nofollow"&gt; Block Cipher Modes &lt;/A&gt;.&lt;BR/&gt;&lt;BR/&gt;Note how you can still see many of the features of the image when it is encrypted with EBC mode. &lt;BR/&gt;&lt;BR/&gt;But, in another mode, like CBC, any block cipher will pass the frequency analysis test, even 8-bit XOR. (I am thinking about coding up a little example of that.)&lt;BR/&gt;&lt;BR/&gt;Also, be aware that how the keys are managed and protected is often much more critical than the cipher, mode, or key-length choices.&lt;BR/&gt;&lt;BR/&gt;Thanks for the great post !&lt;BR/&gt;&lt;BR/&gt;Erik Heidt&lt;BR/&gt;&lt;A HREF="http://artofinfosec.com" REL="nofollow"&gt;Art of Information Security&lt;/A&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5345960998095418690/comments/default/3733350691646204020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5345960998095418690/comments/default/3733350691646204020'/><link rel='alternate' type='text/html' href='http://pmelson.blogspot.com/2008/03/quicky-binary-file-visual-analysis.html?showComment=1206673260000#c3733350691646204020' title=''/><author><name>Erik Heidt</name><uri>http://artofinfosec.com</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://pmelson.blogspot.com/2008/03/quicky-binary-file-visual-analysis.html' ref='tag:blogger.com,1999:blog-6690994337395244641.post-5345960998095418690' source='http://www.blogger.com/feeds/6690994337395244641/posts/default/5345960998095418690' type='text/html'/></entry></feed>