Sunday, August 21, 2022

How To Recover the Password for an Encrypted Veracrypt Container

Veracrypt, the successor of Truecrypt, is a free and open-source encryption software. Think of it like Microsoft's Bitlocker -- except it is free and completely open source.[1]

In this blog post, I will briefly show you how to recover the password for a (non-system) Veracrypt container if you still remember a substantial part of it. I've managed to recover my own partially forgotten passwords using the methods I detail below. Essentially, we will be conducting a hybrid attack on the PBKDF2-derived key for the Veracrypt container -- i.e., a hybrid between a dictionary attack and a brute-force attack. The tools that we will make use of are any Linux distribution (Debian, Red Hat, etc.), Python, and Hashcat, a powerful and open-source password cracker.[2]

Let us begin. The first thing to bear in mind is that the first 512 bytes of a Veracrypt container is a header which contains all the necessary ingredients to calculate the key to your container (e.g., the salt). Below is a detailed table of (at least) what is contained in the first 512 bytes.


 

Note that the header is the first 512 bytes only in standard volumes or containers, not in system volumes. In the latter, Veracrypt documentation specifies that the header is the last 512 bytes of the first logical track. This is what the documentation states:

The first 512 bytes of the volume (i.e., the standard volume header) are read into RAM, out of which the first 64 bytes are the salt (see VeraCrypt Volume Format Specification). For system encryption (see the chapter System Encryption), the last 512 bytes of the first logical drive track are read into RAM (the VeraCrypt Boot Loader is stored in the first track of the system drive and/or on the VeraCrypt Rescue Disk).
In any case, we want to extract this derived key-hash and then check to see if it matches any of our computed hashes from a word list. If we get a match, then we will know that we have recovered our password! So the first thing we want to do is to extract these initial 512 bytes. This can be easily done in the Linux command line; just type the following in your terminal:

dd if=[container name] of=[anything] bs=512 count=1



"If" stands for "input file," and "of" stands for "output file." "bs" just means bytesize, and "count" just means how many iterations of the bytes to go through. So the above terminal command will produce the same output as the following:

dd if=[container name] of=[anything] bs=1 count=512



Alternatively, you can just run the following Python code to the same effect (just be sure to change the file names accordingly):

with open("in-file", "rb") as in_file, open("out-file", "wb") as out_file: out_file.write(in_file.read(512))

 

We have now extracted the header from the Veracrypt container. As we shall soon see, Hashcat has an option that will automatically recognize a Veracrypt header and compute the derived key from the information contained therein (e.g., from the salt and key-derivation function used). But first, let's generate the wordlist we will pass to Hashcat.

Now, for the sake of the demonstration here, we'll keep it simple. So let's say that our password that we forgot was ACHILLESheel2385. Furthermore, let's say that we remember ACHILLESheel, and that there was a 1 - 5 digit number at the end. So, taking a step back, it should be clear what we need to do: produce a word list containing every character set that matches the following RegEx pattern:

/ACHILLESheel\d{1,5}/

Thankfully, there's a great Python module that will construct all the strings that match a specified RegEx pattern -- exrex. In your terminal, type the following command (but just make sure that you have the exrex module installed):

python exrex.py 'ACHILLESheel\d{1,5}' -o wordlist

 

This will generate a wordlist of ACHILLESheel{all combinations of five digits} in wordlist.txt of your current working directory. We are now ready to use Hashcat. If you type "hashchat -h" in your terminal you should see that hashcat has a lot of numerical numbers associated with different types of hashing algorithms and software, including Veracrypt. Hashcat basically has preprogrammed binaries that are used to compute the hashes made from a wide variety of algorithims and programs. The numerical value that we are looking for is 13721, as this is Hascut's reference for Veracrypt's default encryption settings. There are other non-default options that Hashcat has, but 13721 is the one we are looking for.



So all the preparation is done: we are now ready to to run hashcat and crack the password! Type in the following command:

hashcat -m 13721 --status out-file wordlist.txt



Note that if you see that the 111110 passwords are taking too long to crack on your system, you can just "cheat" and use a different regex pattern that will drastically decrease the computing time (since this is just an example). For example, you can use /ACHILLESheel23\d{2}/. This will cut the password wordlist down from 111110 to 100! After you run Your output should be something like the following:

So there you have it  -- this is the process for successfully recovering a Veracrypt password that you partially remember! It's important to underscore that the more of your password you remember, the way easier it is to crack it. If you don't have any idea of what your password is, and just remember that it is very long and complex, it's very likely that all the computers in the world wouldn't be able to crack the password for aeons!

----------------------------------------------------------------------------

[1] In general, I believe that FOSS that is widely used is more secure than closed-source software counterparts. This is for the simple reason that FOSS is open-source software and so, if it is quite prominent (like Veracrypt, Signal, DD-WRT, Ansible, Ubuntu, Libre Office, Android, etc.), it should have undergone more security-expert scrutiny than its closed-source counterparts. Indeed, it should be continuously undergoing more scrutiny than its commercial closed-source counterparts. Now, one may argue that the sword cuts both ways here: the open-source nature of FOSS means that there are more malicious developers with access to the code base and actively trying to develop exploits against it. Thus, for example, there is more malware written against (closed-source) Windows operating systems than there is written against (open-source) Linux operating systems. While this is true, I still think that the sword cuts more in the way of security than insecurity here, as I doubt that critical vulnerabilities discovered by an APT open-source software will go undetected by the rest of the world's security experts for much longer than similar bvulnerabilities in closed-source software. The latter are simply lack boxes. There's no way for the world's security community to tell whether such software is safe and free of backdoors. So my view is that when it comes to security, FOSS is king. And I believe most infosec experts would agree. 

[2] We could also use Crunch, a program that generates password wordlists based on user-defined parameters. But if one knows RegEx it should be easier to use the Python module exrex to generate wordlists based on specified RegEx patterns. One can use a tool like RegExPal to check if one's desired output text(s) matches one's RegEx pattern.

Sunday, June 19, 2022

A Quick Anselmian Argument Against the Coherence of Orthodox Trinitarianism

 

 File:Shield-Trinity-Scutum-Fidei-English.svg

On "orthodox" Trinitarianism (OT), the Trinitarianism expounded by, e.g., the Catholic Church and Eastern Orthodox Church, the second person of the Trinity, the Son, is eternally begotten of the Father. That is, the Son stands in an asymmetric dyadic relation of being eternally begotten of the Father. However, OT also teaches that each of the three persons of the Trinity, including the Son, is absolutely perfect. 

I believe that this is incoherent given the truth of certain extremely plausible metaphysical propositions. The following is my argument to this effect.

Stipulative Definitions and The Argument:  

A perfect being = df. a being who has all perfections and lacks all imperfections. 

Orthodox Trinitarianism = df. the Trinitarism held in common by Catholics, Eastern Orthodox, and classical Protestants.

  1. (Suppose that) Orthodox Trinitarianism is true. [Assumption]
  2. If (1), then the Father is perfect, the Son is perfect, and the Holy Spirit is perfect.  [definition]
  3. If (1), then the Son is eternally begotten of the Father.  [definition]
  4. The Father is perfect, the Son is perfect, and the Holy Spirit is perfect.  [1,2 --> E]
  5. The Son is perfect.  [4 &E]
  6. The Son is eternally begotten of the Father. [1,3 --> E]
  7. If (6), then the Son is ontologically dependent on the Father for his existence. [prem]
  8. Therefore, the Son is ontologically dependent on the Father for his existence. [6,7 --> E]
  9. Every entity that is ontologically dependent on another entity for its existence is not perfect. [prem]
  10. Therefore, the Son is not perfect.  [8,9]
  11. (5) contradicts (10); therefore, reject the assumption: It is not the case that Orthodox Trinitarianism is true. 

This reductio ad absurdum argument contains only two premises that are not either definitions or merely follow from the logical rules of inference, viz., (7) and (9). I regard (9) as obviously true. Being such that one is ontologically independent is a perfection. I know that this is true by intuition, and in the same way I know that being unconditionally loving is a perfection -- it just obviously is. And so the complement of this property, viz., being ontologically dependent, is an imperfection. And any being that has an imperfection is by definition not perfect. Hence (9) is true. So what about (7)? Well, I also regard (7) as obviously true. Talk of being begotten makes no sense to me whatsoever if it doesn't imply ontological dependence. Indeed, if one reads the early church fathers, it seems clear that those who held that the Son was eternally begotten of the Father believed that he was ontologically dependent on him and that his point of origination was somehow in the Father. They believed in an ancient view called the Monarchy of the Father, wherein the Father is the supreme being and source of all reality. Everything -- including the Son and the Holy Spirit -- originates in the Father. Now, I don't have time to dig up quotes to prove this point, but suffice it to say interpreting "being eternally begotten of the father" to entail "being ontologically dependent on the Father" is a completely natural straightforward interpretation of this locution, and one that I believe was the view of the early church fathers. Modern theologians and Christian philosophers may try to say that such a locution doesn't imply ontological dependence, but only something like logical dependence, whatever that means. But quite honestly, I see these attempts as nothing more than ad hoc theological rationalizations. Orthodox Trinitarianism, and hence Catholicism, Eastern Orthodoxy, etc., is simply incoherent given certain very plausible metaphysical assumptions.

Sunday, June 5, 2022

عقيدة التجسد: تناقض مبين

 

المسيحية ديانة غير صحيحة. لم يكن المسيح الله.

واما يسوع فكان يتقدم في الحكمة والقامة والنعمة عند الله والناس. - إنجيل لوقا

واما ذلك اليوم وتلك الساعة فلا يعلم بهما احد ولا الملائكة الذين في السماء ولا الابن الا الآب. - إنجيل مرقص

عقيدة التجسد عقيدة متناقضة و هراء بمعنى الكلمة. الله المفروض يكون كامل المعرفة، غير مقترن بزمان و مكان، الخ. المسيح لم يكن كامل المعرفة حسب الآيات المذكورة آنفا و كان مقترنا بزمان و مكان لانه عاش و مات في فلسطين قبل نحو الفين سنة. فبكل بساطة المسيح ليس الله. اللاهوتيون عبر العصور حاولوا و ما زالوا يحالون ان يجدوا مخرجا من هذا التناقض المبين، فحلهم الأكثر سائدا او انتشار هو أن المسيح كامل المعرفة بلاهوته و لكن ليس كامل المعرفة بناسوته، مقترن بزمان و مكان بناسوته ولكن غير مقترن بزمان و مكان بلاهوته. فعلى سبيل المثال، يقولون ان كان المسيح يعلم وقت مجيء ابن الإنسان (وقت مجيئه) بلاهوته ولكن كان يجهل ذلك بناسوته.(١) هذا الحل مجرد لعب بالكلمات و لا يعد حلا حقيقيا. ليست الطبيعة هي التي تعرف، و إنما الشخص. طبيعة المسيح، لاهوته و ناسوته، لم تعرف شيئا ، و إنما هو كشخص يعرف الف أو باء. طبيعتي لا تعلم شيئا، و إنما أنا كشخص اعلم. اي، الطبيعات لا تعرف شيئا، الأشخاص يعرفون. لكل شخص S بوقت محدد T ، اما يعرف S أقتراح P اما S لا يعرف P. أما يعرف ان اثنين زائد اثنين يساوي أربعة اما لا يعرف. فان تقول انه يعلم P بلاهوته و لكن لا يعلمها بناسطه يعد مجرد لفا و دوران. يعني مثل ان تقول ان بوقت T انا اعرف P من خلال سروري و لكن لا اعلمها من خلال حزني. لا يوجد أي ارتباط هنا بين الوسيلة التي اعلم P و علمي ل P. بوقت T اما اعرف P اما لا أعرفه. خلاص. لا يوجد. مجال لللف و الدوران. ولكن اللاهوتيون إعتادوا على اللف و الدوران - هذا معظم شغلهم اصلا - اي، ان يخترعوا طرق لانقاذ العقائد الدينية من التسخيف و السخرية.

١. و على فكرة، بخصوصي معرفة مجيء ابن الإنسان، هذا الرد يعتبر هرطقة بالعقيدة الكاثوليكية. ولكن هرطقة هذا الحل يجعل حل المشكلة اكثر صعوبة للكاثوليك.