Re: [cryptography] the Zcash Open Source Miner Challenge (and about Zcash in general)

2016-11-14 Thread Zooko Wilcox-OHearn
bout the risks and limitations of the Zcash project. Sincerely, Zooko ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

[cryptography] the Zcash Open Source Miner Challenge (and about Zcash in general)

2016-10-10 Thread Zooko Wilcox-OHearn
work algorithm. :-) Regards, Zooko ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Should Sha-1 be phased out?

2015-11-06 Thread Zooko Wilcox-OHearn
thodology, from Linus Torvald: http://git.vger.kernel.narkive.com/9lgv36un/zooko-zooko-com-revctrl-colliding-md5-hashes-of-human-meaningful#post2 So, my attempted contribution to this pattern was to help specify BLAKE2, so that instead of telling people "MD5 is broken! Switch to this secure but

Re: [cryptography] hashes based on lots of concatenated LUT lookups

2014-07-11 Thread Zooko Wilcox-OHearn
reading my mind. As well as adding in a bunch of ideas that were not in my mind, from such sources as http://eprint.iacr.org/2014/452.pdf . Regards, Zooko ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo

Re: [cryptography] [Cryptography] Cuckoo Cycles: a new memory-hard proof-of-work system

2014-01-09 Thread Zooko O'Whielacronx
: https://password-hashing.net/ Regards, Zooko ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] [zfs] [Review] 4185 New hash algorithm support

2013-10-29 Thread Zooko Wilcox-OHearn
it to me, I'll spend some of my valuable time to learn, because I'm interested in filesystems in general and ZFS in particular. If not, I'm pretty sure everything I've written above is still true. Regards, Zooko Wilcox-O'Hearn Founder, CEO, and Customer Support Rep https://LeastAuthority.com Freedom

Re: [cryptography] [zfs] [Review] 4185 New hash algorithm support

2013-10-22 Thread Zooko Wilcox-OHearn
-R. ☺ That will probably be around 5 rounds. Regards, Zooko Wilcox-O'Hearn Founder, CEO, and Customer Support Rep https://LeastAuthority.com Freedom matters. --- illumos-zfs Archives: https://www.listbox.com/member/archive/182191/=now RSS Feed: https

[cryptography] my comment to NIST about reduced capacity in SHA-3

2013-10-16 Thread Zooko Wilcox-OHearn
Date: Tue, 1 Oct 2013 15:45:27 -0400 From: zooko zo...@zooko.com To: Multiple recipients of list hash-fo...@nist.gov Subject: Re: On 128-bit security Folks: Here are my personal opinions about these issues. I'm not expert at cryptanalysis. Disclosure: I'm one of the authors of BLAKE2

Re: [cryptography] [Cryptography] RSA equivalent key length/strength

2013-09-26 Thread zooko
here? :-) This is a very good resource because it includes recommendations from multiple sources and makes it easy to compare them: http://www.keylength.com/ Regards, Zooko ___ cryptography mailing list cryptography@randombit.net http

Re: [cryptography] Asynchronous forward secrecy encryption

2013-09-26 Thread zooko
and ephemeral keys are random. Or it could be used as an added, redundant defense. I guess if it is an added, redundant defense then this is the same as including the random nonce -- number 3 from the list above. Regards, Zooko ___ cryptography mailing

Re: [cryptography] LeastAuthority.com announces PRISM-proof storage service

2013-08-29 Thread zooko
/TahoeLAFSBasics https://tahoe-lafs.org/trac/tahoe-lafs/wiki/FAQ Regards, Zooko ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Reply to Zooko (in Markdown)

2013-08-29 Thread zooko
intrinsically in the email protocols themselves. Email as we know it with SMTP, POP3, and IMAP cannot be secure. https://silentcircle.wordpress.com/2013/08/09/to-our-customers/ (Kudos to Jon for saying something sensical in that last one!) Regards, Zooko

Re: [cryptography] Reply to Zooko (in Markdown)

2013-08-23 Thread Zooko Wilcox-OHearn
. But it is fixable! But to fix it starts with admitting what the problem is. Regards, Zooko Wilcox-O'Hearn Founder, CEO, and Customer Service Rep https://LeastAuthority.com Freedom matters. ___ cryptography mailing list cryptography@randombit.net http

Re: [cryptography] LeastAuthority.com announces PRISM-proof storage service

2013-08-16 Thread zooko
populations. Now maybe it was a mistake to label it as PRISM-Proof in our press release and media interviews! I said that because to me PRISM means mass surveillance of innocents. Perhaps to other people it doesn't mean that. Oops! Regards, Zooko

Re: [cryptography] LeastAuthority.com announces PRISM-proof storage service

2013-08-16 Thread zooko
On Tue, Aug 13, 2013 at 01:52:38PM -0500, Nicolai wrote: Zooko: Congrats on the service. I'm wondering if you could mention on the site which primitives are used client-side. All I see is that combinations of sftp and ssl are used for data-in-flight. Thanks! I'm not sure what your

[cryptography] open letter to Phil Zimmermann and Jon Callas of Silent Circle, re: Silent Mail shutdown

2013-08-16 Thread Zooko Wilcox-OHearn
cloud storage API that people use to build other services.) Regards, Zooko Wilcox-O'Hearn .. _recent shutdown of Lavabit: http://boingboing.net/2013/08/08/lavabit-email-service-snowden.html .. _shutdown of Silent Circle's “Silent Mail” product: http://silentcircle.wordpress.com/2013/08/09/to-our

[cryptography] LeastAuthority.com announces PRISM-proof storage service

2013-08-13 Thread Zooko Wilcox-OHearn
Dear people of the cryptography@randombit.net mailing list: For obvious reasons, the time has come to push hard on *verifiable* end-to-end encryption. Here's our first attempt. We intend to bring more! We welcome criticism, suggestions, and requests. Regards, Zooko Wilcox-O'Hearn Founder, CEO

Re: [cryptography] LeastAuthority.com announces PRISM-proof storage service

2013-08-13 Thread Zooko Wilcox-OHearn
of their ciphertext. Also our customer and business partners like having the option of hiring us for support when they are integrating the free-and-open-source LAFS software into their own products. Regards, Zooko Wilcox-O'Hearn Founder, CEO, and Customer Support Rep https://LeastAuthority.com Freedom

[cryptography] ANNOUNCING Tahoe-LAFS v1.10

2013-05-13 Thread Zooko Wilcox-OHearn
ANNOUNCING Tahoe, the Least-Authority File System, v1.10 The Tahoe-LAFS team is pleased to announce the immediate availability of version 1.10.0 of Tahoe-LAFS, an extremely reliable distributed storage system. Get it here: https://tahoe-lafs.org/source/tahoe-lafs/trunk/docs/quickstart.rst

Re: [cryptography] Bitcoin-mining Botnets observed in the wild? (was: Re: Bitcoin in endgame

2012-05-11 Thread Zooko Wilcox-O'Hearn
Folks: Here's a copy of a post I just made to my Google+ account about this alleged Botnet herder who has been answering questions about his operation on reddit: https://plus.google.com/108313527900507320366/posts/1oi1v7RxR1i === introduction === Someone is posting to reddit claiming to be a

Re: [cryptography] DIAC: Directions in Authenticated Ciphers

2012-05-09 Thread Zooko Wilcox-O'Hearn
following-up to my own post: On Wed, May 9, 2012 at 6:34 AM, Zooko Wilcox-O'Hearn zo...@zooko.com wrote: 1. Decrypt the data, 2. Verify the integrity of the data, 3. Generate MAC tags for other data which would pass the integrity check. The fact that 3 is included in that bundle

Re: [cryptography] data integrity: secret key vs. non-secret verifier; and: are we winning? (was: “On the limits of the use cases for authenticated encryption”)

2012-04-26 Thread Zooko Wilcox-O'Hearn
On Wed, Apr 25, 2012 at 9:27 PM, Marsh Ray ma...@extendedsubset.com wrote: On 04/25/2012 10:11 PM, Zooko Wilcox-O'Hearn wrote: 1. the secret-oriented way: you make a MAC tag of the chunk (or equivalently you use Authenticated Encryption on it) using a secret key known to the good guy(s

[cryptography] “On the limits of the use cases for authenticated encryption”

2012-04-25 Thread Zooko Wilcox-O'Hearn
load the page yourself to read those. I also posted it on the tahoe-dev mailing list, where a small thread ensued: https://tahoe-lafs.org/pipermail/tahoe-dev/2012-April/007315.html Regards, Zooko *“On the limits of the use cases for authenticated encryption**”* *What is authenticated encryption

[cryptography] what do you get when you combine Phil Zimmermann, Jon Callas, and a couple of ex-Navy SEALs?

2012-04-24 Thread Zooko Wilcox-O'Hearn
http://allthingsd.com/20120423/pgp-creator-phil-zimmerman-has-a-new-venture-called-silent-circle/ https://silentcircle.com/ Continually nowadays I think I'm living in one of the science fiction novels of my youth. This one is by Neal Stephenson, I think. Regards, Zooko

Re: [cryptography] Doubts over necessity of SHA-3 cryptography standard

2012-04-13 Thread Zooko Wilcox-O'Hearn
like Blake, or a SHA-3 reject like Edon-R. I'm not saying you shouldn't use such a thing either. What I'm saying is: their existence is reason to believe that a secure hash function with this kind of efficiency could exist. Regards, Zooko [¹] http://csrc.nist.gov/groups/ST/hash/sha-3/Round1

[cryptography] workaround for length extension attacks (was: Doubts over necessity of SHA-3 cryptography standard)

2012-04-13 Thread Zooko Wilcox-O'Hearn
what length-extension attacks can or can't do to my designs. Of course, once you upgrade to a shiny new hash function with built-in protection against length-extension attack, then you should drop the HASH_d technique. Regards, Zooko ___ cryptography

Re: [cryptography] workaround for length extension attacks (was: Doubts over necessity of SHA-3 cryptography standard)

2012-04-13 Thread Zooko Wilcox-O'Hearn
AH, what about using a different MAC entirely, like say Poly1305-AES? :-) Regards, Zooko ¹ http://bench.cr.yp.to/results-hash.html ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] workaround for length extension attacks

2012-04-13 Thread Zooko Wilcox-O'Hearn
decision to use SHA-1 in git is going to mean that those web developers choose SHA-1 for many, many years to come. Regards, Zooko ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

[cryptography] Bitcoin-mining Botnets observed in the wild? (was: Re: Bitcoin in endgame

2012-03-28 Thread Zooko Wilcox-O'Hearn
. mining), which last about 48 hours. However, back-of-the-envelope calculations by yours truly indicate that a 100,000-node botnet would not contribute even 10% of the hash rate seen in the dip. Regards, Zooko ___ cryptography mailing list cryptography

[cryptography] announcing Tahoe-LAFS v1.8.3, fixing a security issue

2011-09-14 Thread Zooko O'Whielacronx
version available: http://tahoe-lafs.org/trac/tahoe-lafs/wiki/OSPackages Please contact us through the tahoe-dev mailing list if you have further questions. Regards, Zooko Wilcox-O'Hearn ANNOUNCING Tahoe, the Least-Authority File System, v1.8.3 The Tahoe-LAFS team announces the immediate

Re: [cryptography] preventing protocol failings

2011-07-22 Thread Zooko O'Whielacronx
tools that integrate into user workflow and take advantage of the information that is already present, *then* we'll still have some remaining hard problems about fitting usability and security together. Regards, Zooko ___ cryptography mailing list

Re: [cryptography] Is BitCoin a triple entry system?

2011-06-13 Thread Zooko O'Whielacronx
Also related, Eric Hughes posted about something he called Encrypted Open Books on 1993-08-16. The idea was to allow an auditor to confirm the correctness of the accounts without being able to see the details of people's accounts. Regards, Zooko

Re: [cryptography] rolling hashes, EDC/ECC vs MAC/MIC, etc.

2011-05-21 Thread Zooko O'Whielacronx
of this approach. But, if ZFS could be modified to fix these problems or if a new filesystem would add a feature of maintaining a canonical, reproducible Merkle Tree, then it might be extremely useful. Thanks to Brian Warner and Dan Shoutis for discussions about this idea. Regards, Zooko

Re: [cryptography] rolling hashes, EDC/ECC vs MAC/MIC, etc.

2011-05-20 Thread Zooko O'Whielacronx
of the above seems well suited to maintaining a Merkle Tree over the file data with a secure hash. Regards, Zooko ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Point compression prior art?

2011-05-20 Thread Zooko O'Whielacronx
Dear Paul Crowley: How about the Compact Representation, section 4.2, of RFC 6090: http://www.rfc-editor.org/rfc/rfc6090.txt Is that the same point compression that you were looking for? Regards, Zooko ___ cryptography mailing list cryptography

Re: [cryptography] Merkle Signature Scheme is the most secure signature scheme possible for general-purpose use

2010-09-01 Thread Zooko O'Whielacronx
likely to have preimage resistance than a non-iterated hash is to have collision-resistance. And I think it is quite clear that for any real hash function such as MD5, SHA-1, Tiger, Ripemd, SHA-2, and the SHA-3 candidates that this does hold! What do you think of that argument? Regards, Zooko

Re: [cryptography] 1280-Bit RSA

2010-07-17 Thread Zooko O'Whielacronx
with a better demonstration that they were generated with any possible back door than do the NIST curves [3]. Regards, Zooko [1] http://www.keylength.com/ [2] http://bench.cr.yp.to/results-sign.html [3] http://www.ecc-brainpool.org/download/draft-lochter-pkix-brainpool-ecc-00.txt