Sunday, May 3, 2009

Crash of another Hash

SHA-1 has been reported to be broken.

What is SHA-1?

Simply put SHA-1 is an encryption system used to create online security transfer certificates.

Major banks, money vendors, online storefronts will all be using SHA-1 security certificates over SSL (https) to ensure that the right person is connecting to the right company to make transactions.

So now that it has been proven to be broken it means that now cryptography experts can  prove that fake SHA-1 certs could in fact be produced, and hence added to phishing sites, thus stealing customers money by fraud.

Very serious indeed. 

But fear not......The problem will be resolved soon as all of the big companies will be upgrading to SHA-2. And SHA-2  has already been around awhile and is still secure.

It was stories like these that pushed my team; the NiHao team, forward in our endeavour to replace the www world with a 3d world - NiHao World.

One simple fact is that it is a serious load harder to be a hacker when you are inside a 3d environment.

Lets look at some real world examples:

I am at a real world ATM machine, the guy behind me could easily be recording all that I am doing with the camera in his mobile phone.

Unsafe? Yeap just a little.

I want to send money from one account to another via my online banking system. A hacker down the street has tapped my IP and is copying all the data I am sending while it is in transit.

Scary? Yeap just a bit.

The NiHao solution: 

1/ The first example repeated; Another avatar is standing right next to me as I pop up the "Enter Pin" console at the NiHao 3d virtual world ATM while I  am taking money out for shopping in the 3d shops. The other avatar sees nothing as the console appears on my screen only. For all he knows I am chatting to a friend.

2/ Second example repeated; Mr hacker down the street sees me in NiHao 3d world and knows I am going to spend allot of money today on a car as he has been following me in the 3d environment. Mr hacker even heard me say to the salesperson that I wanted the car to be delivered to my home. What can Mr Hacker copy other than my fashion taste, and walk style?

So security is a big problem with today's internet, shops feel unsafe trading online but must, average Joe has anxiety attacks about entering his credit card details online but must, Aunt Mary loves to read email from her family but fears the sight of spam porn innuendoes that arrive daily to her mailbox, and young daughter Sue isn't even allowed to go online because her parents think the internet is far too nasty for young girls.

Should it be this way?

Well we at NiHao think not.

The idea of NiHao 3d world is not just one of enjoyment, gaming, and entertainment, it is also pschologically friendly, more natural, and somewhat more serene then the present day www world.

The 3d environment as opposed to the www web environment,  can also be a safe haven for big business transactions.

Why do I say this?

Lets look at some known facts.....

Hackers can and indeed do hack games and create cheat mods. This is true, but what can a mod really do?

Well a mod simply performs automated game transactions in games that run scripts based on events occurring, and a mod runs parallel scripts to allow the player get from Level A to Level Z in a game without human intervention. This is game cheating.

Yet in NiHao World this could not happen because;1/ Events are not server scripted. All that one sees happeningh is actually happening therefore cannot be scripted against as tomorrow it will all be very different.

2/ When the avatar must perform a human to human transaction such as when my avatar is communicating with the banker avatar; a mod could not achieve that automation either because the transaction is based upon real time communication not script triggers.

Example of script triggers. 
A script will call to ask did this happen: Y/N. If yes then did this happen: Y/N. And so on. In a real time environemnt the triggers are replaced with real staff controlling the company's avatars and hence able to ask abstract questions that can determine the validity of the customer.

eg. Bank Teller: "Sir could you please answer this question; What colour is missing from this sequence...Red, Yellow.....?"

Customer: "...ummm....(stoopid customer)....ummm....green?"

Bank Teller: "No Sir. Sorry, the answer is not green. Please try again."

Customer: "ummm....(really stoopid customer)...ummm....blue?"

Bank Teller: "Yes sir. Thankyou! And how much will you be withdrawing today?"

While hacking a hacker in a 3d world could hack some environment variables and could hack other avatars, but to what gain?Change the trees from green to blue? Or as Mr Stoopid Customer change the colour blue to green?

Again; in realtime 3d transactions a hacker cannot hack 3d space efficiently enough to steal your data, as 3d space is ever evolving, ever updating, and ever changing.

The difference I am vaguely showing here is that in the www world a hacker can see the code of the page on which you are performing your transaction, see the IP's of all invovled in the transaction, and interupt the transaction without even being noticed.

In a 3d world environment a hacker can visually see the environment that performs the transactions but cannot change it because the NiHao World 3d environment is being updated with new variables every milisecond and in real time.

Example: If I were to say hello to my banker, in a moment another avatar could be walking past me, a cat may jump from the rooftop above, or a car may be speeding down the street nearby.

These other user's events are constantly changing the environment's scripting.

A 3d environment is an ever changing environment that really would be super hard to hack into other than for making some superficial avatar bonuses and image changes. But that is not so of our today www world that is becoming more and more transparent in the eyes of our unfriendly hackers.

So I hope as you are reading this you will have come to understand that;

A/ The www world is boring and needs a 3d facelift anyhow that is why we built NiHao World :) B/ NiHao 3d world is not just a 3d world for fun, but is also a solution for the unstable marketplace that today still sits in www land.

So what is NiHao World?

NiHao World is a world of true freedom.

Now I can run and jump, as opposed to click the Forward and Back buttons.
Now I chat without annoying advertisements.
Now I can visit my friends and see them smile.
And now I can do business safely.

To sum it all up.....NiHao World is SECURITY +1.


No comments: