Re: [cryptography] Just how bad is OpenSSL ?

2012-10-29 Thread Von Welch
I am wondering just how bad openssl is ? While one can find various software engineer faults, I think that main issue is not that it is bad, it is that OpenSSL is written for cryptographic experts not standard software developers. The unfortunate thing is that most of the time the latter

Re: [cryptography] can the German government read PGP and ssh traffic?

2012-06-05 Thread Von Welch
passwords are insecure, PKCs are secure, therefore anything that uses PKCs is magically made secure Well as you said, you have to look at what happens in the real world. I would argue PKCs make things obscure, which buys you a fair amount of security until some undetermined point in time

Re: [cryptography] project cost of HSMs

2012-04-10 Thread Von Welch
Ian, I've led or been involved with several projects in academia that have used HSMs as a basis for a CA. I can't say I've done a cost analysis at the level of granularity you seem to be looking for, but I will say that at a high-level, the added personnel costs of integrating and maintaining

Re: [cryptography] Password non-similarity?

2012-01-02 Thread Von Welch
Bernie Cosell ber...@fantasyfarm.com writes: On 31 Dec 2011 at 15:30, Steven Bellovin wrote: Yes, ideally people would have a separate, strong password, changed regularly for every site. This is the very question I was asking: *WHY* changed regularly? What threat/vulnerability is