Re: [cryptography] embbeded pw kdf?

2016-08-05 Thread stef
general. it will be necessary, and if there's none, expect to have md5(password) all over the place. -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] embbeded pw kdf?

2016-08-05 Thread stef
tion and signing i guess. -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

[cryptography] embbeded pw kdf?

2016-08-05 Thread stef
que salt), 1<=nhttps://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] [Cryptography] Show Crypto: prototype USB HSM

2016-04-14 Thread stef
nice, but it also encourages continuous contact between the keystore and an untrusted device. i rather unplug my keystore when it's not needed. as a shameless plug, my designs are already in production, and will available in small quantities this summer. -- otr fp: https://www.ctrlc.hu/~stef/

Re: [cryptography] Design of a secure hardware dongle

2016-02-02 Thread stef
w. i have something like this ready. here's a video from last year when it was "under construction": https://youtu.be/zB_l09mzMs4 -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] The Intercept Releases ~1,264 pages of NSA Docs

2015-07-01 Thread stef
the intercept itself actually releasing this as a signed archive. -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Javascript scrypt performance comparison

2015-05-08 Thread stef
/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Javascript scrypt performance comparison

2015-05-08 Thread stef
On Fri, May 08, 2015 at 04:27:19PM +0300, Solar Designer wrote: On Fri, May 08, 2015 at 10:34:28AM +0200, stef wrote: according to someone close to the PHC compo, yescrypt is rich with side-channels, Worded like that, it's FUD. It's a fully expected kind of FUD, though. sorry - although

Re: [cryptography] OpenPGP in Python: Security evaluations?

2015-04-23 Thread stef
? -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Introducing SC4 -- feedback appreciated

2015-04-17 Thread stef
ohio, On Fri, Apr 17, 2015 at 10:56:01AM -0700, Ron Garret wrote: 1. It is a standalone web application. putting keys in the browser is like putting keys in front of a dmz. browsers are not designed for this, they are designed for delivering impressions and services to you. the security

Re: [cryptography] Introducing SC4 -- feedback appreciated

2015-04-17 Thread stef
don't see how this decision is not made in the sc4 case -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Unbreakable crypto?

2015-03-20 Thread stef
On Fri, Mar 20, 2015 at 06:12:31PM +, Dave Howe wrote: Or a reasonably clever and trolling satire on snakeoil products. :) the less optimistic alternative is this being a well-crafted water-holing site targeted at the members of this mailing-list. -- otr fp: https://www.ctrlc.hu/~stef

Re: [cryptography] Unbreakable crypto?

2015-03-19 Thread stef
://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Javascript Password Hashing: Scrypt with WebCrypto API?

2015-03-15 Thread stef
On Wed, Mar 11, 2015 at 01:02:14PM +0100, Fabio Pietrosanti (naif) - lists wrote: On 3/11/15 12:42 PM, stef wrote: against state level actors. i mean globaleaks clearly has state-level actors in their threat-model, right? No, GlobaLeaks doesn't consider in it's threat model an NSA-like

Re: [cryptography] Javascript Password Hashing: Scrypt with WebCrypto API?

2015-03-11 Thread stef
actors. i mean globaleaks clearly has state-level actors in their threat-model, right? -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Javascript Password Hashing: Scrypt with WebCrypto API?

2015-03-11 Thread stef
. serbia sounds like a state level actor, and i heard that the publeaks people also get attention from the local services. -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net

Re: [cryptography] Javascript Password Hashing: Scrypt with WebCrypto API?

2015-03-11 Thread stef
in a place where The rule of law is effective, it's that's a quite bold assumption even in europe today :/ -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo

Re: [cryptography] Crypto Vulns

2015-03-07 Thread stef
On Sat, Mar 07, 2015 at 10:23:40AM -0500, John Young wrote: No 1 vulnerability of crypto is the user absolutely: pls enjoy this: https://en.wikipedia.org/wiki/List_of_cognitive_biases which i also packed into an ebook for your convenience: http://www.ctrlc.hu/~stef/cognitive_biases_

Re: [cryptography] random number generator

2014-11-22 Thread stef
On Sat, Nov 22, 2014 at 08:13:31PM +1000, James A. Donald wrote: The question is, does all this entropy show up in Jytter? I rather think it does. the question is: is your adversary nature, or human nature? -- otr fp: https://www.ctrlc.hu/~stef/otr.txt

Re: [cryptography] Email encryption for the wider public

2014-09-18 Thread stef
. -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Email encryption for the wider public

2014-09-18 Thread stef
On Thu, Sep 18, 2014 at 11:13:04AM +0200, Krisztián Pintér wrote: On Thu, Sep 18, 2014 at 10:57 AM, stef s...@ctrlc.hu wrote: let me summarize (and ask you to reread and understand) grapamps response to you: email is dead. email is not dead, it is a zombie that walks around for at least 20

Re: [cryptography] Question About Best Practices for Personal File Encryption

2014-08-16 Thread stef
: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Stealthy Dopant-Level Hardware Trojans

2014-06-22 Thread stef
one have copies? http://sgnsa2lp64l6v3l6.onion/BeckerChes13.pdf -- otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] [Ach] Better Crypto

2014-01-07 Thread stef
On Tue, Jan 07, 2014 at 11:39:42AM +0100, L. Aaron Kaplan wrote: On Jan 7, 2014, at 11:24 AM, stef s...@ctrlc.hu wrote: On Tue, Jan 07, 2014 at 11:18:45AM +0100, L. Aaron Kaplan wrote: 1. We will have three config options: cipher String A,B,C ( generic safe config, maximum

Re: [cryptography] Can we move to a forum, please?

2013-12-24 Thread stef
On Tue, Dec 24, 2013 at 11:54:51PM +, Malcolm Matalka wrote: - Nobody complaining about top posting, trimming cruft and other such nonsense calling etiquette nonsense -- pgp: https://www.ctrlc.hu/~stef/stef.gpg pgp fp: FD52 DABD 5224 7F9C 63C6 3C12 FC97 D29F CA05 57EF otr fp: https

Re: [cryptography] Quality of HAVEGE algorithm for entropy?

2013-11-29 Thread stef
://www.irisa.fr/caps/projects/hipsor/misc.php#measure on an arm cortex m3 stm32f2xx and streamed the results over uart and plotted them here: https://www.ctrlc.hu/~stef/stm32f2x-jitter.png prefetch, data and instruction cache where enabled. cheers,s -- pgp: https://www.ctrlc.hu/~stef/stef.gpg pgp fp: FD52

Re: [cryptography] Allergy for client certificates

2013-10-09 Thread stef
: https://www.ctrlc.hu/~stef/stef.gpg pgp fp: FD52 DABD 5224 7F9C 63C6 3C12 FC97 D29F CA05 57EF otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] no-keyring public

2013-08-26 Thread stef
ECDH also to my new tool: https://github.com/stef/pbp which is based on libsodium, based on nacl. also i created a new wrapper for python, pysodium: https://github.com/stef/pysodium hope you enjoy and play around with simple command line crypto utilities. -- pgp: https://www.ctrlc.hu/~stef

Re: [cryptography] Jingle and Otr

2013-08-21 Thread stef
/004370.html http://lists.jitsi.org/pipermail/dev/2011-May/001484.html someone needs to contribute a port to otr4j or evaluate their inhouse implementation. -- pgp: https://www.ctrlc.hu/~stef/stef.gpg pgp fp: FD52 DABD 5224 7F9C 63C6 3C12 FC97 D29F CA05 57EF otr fp: https://www.ctrlc.hu/~stef

Re: [cryptography] random permutations

2013-05-17 Thread stef
permutations? i have this naive algo where i generate a random number with n! as an upper limit, and then convert the resulting number into base n, where each digit then is an index to the unshuffled/ordered list of all elements. dunno if that fits your expectations. -- pgp: https://www.ctrlc.hu/~stef

Re: [cryptography] Rocra malware targets files encrypted by Acid Cryptofiler

2013-01-16 Thread stef
/Acid_Cryptofiler regards,s -- pgp: https://www.ctrlc.hu/~stef/stef.gpg pgp fp: FD52 DABD 5224 7F9C 63C6 3C12 FC97 D29F CA05 57EF otr fp: https://www.ctrlc.hu/~stef/otr.txt ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman