A recently released tool that allegedly was designed to help al-Qaeda supporters encrypt their Internet-based communications is a well-written and easily portable piece of code, according to a security researcher who has analyzed the software.However, messages that are encrypted using the tool, which is known as Mujahedeen Secrets 2 (alternately spelled as Mujahideen), should be relatively easy for law enforcement authorities to spot and track, said Paul Henry, vice president of technology evangelism at Secure Computing Corp. in San Jose.The tool was previously downloaded and reviewed by information-security practitioner Jeff Bardin, a former USAF/NSA code-breaker and Arabic translator who blogs for CSOonline.com. In a blog entry, “A Gift from the Islamic Faithful Network – Mujahedeen Secrets 2 Program,” Bardin concluded that the tool showed a software development cycle with an increasing level of sophistication. Secure Computing Corp.’s Henry told Computerworld that based on his analysis of the encryption tool, “it will not be a difficult matter for law enforcement to identify files created using this software” because it puts a unique fingerprint on them, Henry said. “You may not be able to read the messages, but you will be able to figure out where it was sent from and to whom,” he added. Mujahideen Secrets 2 was released last month via an Arabic-language Web site set up by an Islamic forum called al-Ekhlaas. At the time, the password-protected Web site was running on a server belonging to a Web hosting firm in Tampa, Fla., after previously being on a system owned by another company in Rochester, Minn. But the URL that the group was using on the server in Tampa is no longer working.As of last week, the al-Ekhlaas site had been moved to a server owned by yet another hosting firm, this one based in Phoenix, Henry said. But the link to the site on that server also now appears to have been broken. The new encryption software is an updated version of an easier-to-crack tool that was released early last year by the same group. Henry said the copy of Mujahideen Secrets 2 that he evaluated was provided to him by J.M. Berger, a Cambridge, Mass.-based freelance journalist and documentary film maker who focuses on terrorism as well as science and business topics.Mujahideen Secrets 2 is a very compelling piece of software from an encryption perspective, according to Henry. He said the new tool is easy to use and provides 2048-bit encryption, an improvement over the 256-bit AES encryption supported in the original version. What makes the update especially interesting, he noted, is the fact that in addition to e-mails, it can be used to encrypt Yahoo and MSN chat messages.Another interesting aspect of the tool is its ability to take a binary file and encrypt it in such a way that the file can be posted in a pure ASCII or text-only format, Henry added. As a result, individuals could use Mujahideen Secrets 2 to encrypt files and post them on sites that aren’t even on the Internet — for instance, on a telephone-accessed bulletin board system. “If you wanted to do something covert, that’s one way of doing it,” he said.The new version of the tool also has a much better graphical user interface than the initial release did, Henry said. And he thinks the tool’s developers have done a better job of integrating bits and pieces of RSA Security Inc.’s encryption code in order to handle functions such as key generation and key management. Many of the mistakes they made in the first version seem to have been addressed in the new one, thereby making it harder to crack, he said.In addition, the revamped tool is highly portable, Henry said. For instance, he said that someone could put the software on a USB memory stick, go to an Internet cafe, plug in the USB device and run Mujihadeen Secrets 2 to encrypt any communications from that cafe.According to Berger, the new version of the tool sounds worrisome both because of its increased sophistication and the ease with which it can be used. The software appears to be designed for use by relatively low-level operators in the al Qaeda hierarchy, he said. The capabilities offered by Mujahideen Secrets 2 fit a pattern for al-Qaeda groups, Berger said, noting that the terrorist organization “has always been pretty current with what they use — cutting edge, but not bleeding edge.”Berger added that there is a “robust discussion” taking place within the counterterrorism community over the issue of online forums such as al-Ekhlaas being hosted on U.S.-based servers. Some people believe it is easier to monitor what’s going on in the forums when they are hosted on U.S.-based servers, he said. Others, though, want the Web sites to be taken down immediately.By Jaikumar Vijayan, Computerworld Related content news Gitlab fixes bug that exploited internal policies to trigger hostile pipelines It was possible for an attacker to run pipelines as an arbitrary user via scheduled security scan policies. By Shweta Sharma Sep 21, 2023 3 mins Vulnerabilities Security feature Key findings from the CISA 2022 Top Routinely Exploited Vulnerabilities report CISA’s recommendations for vendors, developers, and end-users promote a more secure software ecosystem. By Chris Hughes Sep 21, 2023 8 mins Zero Trust Threat and Vulnerability Management Security Practices news Insider risks are getting increasingly costly The cost of cybersecurity threats caused by organization insiders rose over the course of 2023, according to a new report from the Ponemon Institute and DTEX Systems. By Jon Gold Sep 20, 2023 3 mins Budget Data and Information Security news US cyber insurance claims spike amid ransomware, funds transfer fraud, BEC attacks Cyber insurance claims frequency increased by 12% in the first half of 2023 while claims severity increased by 42% with an average loss amount of more than $115,000. By Michael Hill Sep 20, 2023 3 mins Insurance Industry Risk Management Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe