invoicing with PKI

2003-08-21 Thread Ian Grigg
Does anyone know any instances of invoicing and contracting systems that use PKI and digital orders? That is, purchasing departments and selling departments communicating with digitally signed contracts, purchase orders, delivery confirmations and so forth. And, the normal skeptical followup ques

WSJ: NSA Concerns on Undersea Optical Tapping Imperil Global Crossing Merger

2003-08-21 Thread John Gilmore
http://cryptome.org/nsa-seatap.htm 17 July 2003 Wall Street Jounral, July 17, 2003 Concerns of Wiretapping Imperil a Planned Merger By *YOCHI J. DREAZEN* and *DENNIS K. BERMAN* * Staff Reporters of THE WALL STREET JO

Digicash Patents

2003-08-21 Thread R. A. Hettinga
--- begin forwarded text Status: U Date: Wed, 30 Jul 2003 16:19:39 -0700 Subject: Digicash Patents From: YALB (Yet Amother Little Bird :-)) To: [EMAIL PROTECTED] (Bob Hettinga) Take my name off this if you forward it please. A little bird told me that the Chaum e-cash patent portfolio is

Secure Programming Cookbook for C and C++

2003-08-21 Thread R. A. Hettinga
oreilly.com -- Online Catalog: Secure Programming Cookbook for C and C++ Full Description Password sniffing, spoofing, buffer overflows, and denial of service: these are only a few of the attacks on today's computer systems and network

duplication of serial number in Thawte certificates

2003-08-21 Thread Mads Rasmussen
Maybe this is old news, but I saw an article from the Register regarding problems with duplication of serial numbers at Thawte, which could lead to problems when verifying certificates. http://www.securityfocus.com/news/6420 "Digital certificate specialist Thawte has discovered that its systems

a thesis investigating sigint sites

2003-08-21 Thread Steve Bellovin
Some people on this list may be interested in http://www.staff.ncl.ac.uk/d.f.j.wood/pages/thesis_index.htm (Note: I haven't read more than Chapter 1.) --Steve Bellovin, http://www.research.att.com/~smb - The Cry

Airline Security's False Hope?

2003-08-21 Thread R. A. Hettinga
Technology Review Airline Security's False Hope? An expert on aviation safety statistics says a new computer system to screen out terrorists may actually make things easier for them. By Arnold Barnett July 28,

Voting Machine Study Divides Md. Officials, Experts

2003-08-21 Thread R. A. Hettinga
washingtonpost.com Voting Machine Study Divides Md. Officials, Experts By Brigid Schulte Washington Post Staff Writer Saturday, July 26, 2003; Page B01 For some in Maryland, the report yesterday by Johns Hopkins U

S.E.E. PKI Paper 14 - International and New Zealand PKI experiences across government

2003-08-21 Thread Peter Gutmann
I thought the following might interest readers, it's an examination of PKI experiences in various parts of the world (Australia, Finland, Germany, Hong Kong, New Zealand, US). It reads best to the sound of an Alka-Seltzer fizzing in a glass :-). -- Snip -- A new paper on PKI (Public Key Infrastr

Accuris - Challenges Facing You

2003-08-21 Thread R. A. Hettinga
Accuris - Challenges Facing You The current situation has left operators facing a considerable list of challenges: As the services you offer your customers increase so too do the number of Interception services and therefore the workload on your company s

Accuris - Data Network Interception

2003-08-21 Thread R. A. Hettinga
Accuris - Data Network Interception LMD-IP The LMD-IP is Accuris' IP mediation product, it mediates between the ISP's network and the Law Enforcement Monitoring Facility, delivering intercepted target traffic according to the relevant national standard.

Accuris - Company History

2003-08-21 Thread R. A. Hettinga
Accuris - Company History Accuris is a specialist provider of lawful interception solutions in the communications field. Based in Dublin, Ireland - the software capital of Europe - Accuris continues to lead the market in its niche field. Established in

[Fwd: [fc-announce] FC '04: Call for Papers]

2003-08-21 Thread Ian Grigg
Original Message From: "Juels, Ari" <[EMAIL PROTECTED]> Subject: [fc-announce] FC '04: Call for Papers To: "'[EMAIL PROTECTED]'" <[EMAIL PROTECTED]> Call for Papers and Presentations Financial Cryptography '04 9-12 February 2004 Key West, Florida, USA Conference Web site:

US names the day for biometric passports

2003-08-21 Thread R. A. Hettinga
22 July 2003 Updated: 14:44 GMT The Register US names the day for biometric passports By John Leyden Posted: 22/07/2003 at 14:41 GMT A senior US government official has laid out detailed plans for the timing and form of US govern

Guilty plea in Kinko's keystroke caper

2003-08-21 Thread R. A. Hettinga
19 July 2003 Updated: 11:31 GMT The Register Guilty plea in Kinko's keystroke caper By Kevin Poulsen, SecurityFocus Posted: 19/07/2003 at 11:25 GMT If you used a computer at a Kinko's in New York City last year, or the year befor

Cnet: location wiretapping on hold; T-Mobile to pay up for E911 delay

2003-08-21 Thread John Gilmore
The FCC is certainly turning Orwellian these days. Now the firms that it regulates are making "voluntary" contributions to the government at the whim of the FCC. Remember, these are the regulators who sided totally with the FBI when it demanded that everything be designed for wiretapping, even th

Re: Computer Voting Expert, Dr. Rebecca Mercuri, Ousted From Elections Confer...

2003-08-21 Thread Freematt357
Some effort should be made to communicate the danger of e-ballots to the various grassroots, political organizations interested in voting issues. We really have to get a wider audience made aware of the tremendous danger. And somebody should work on producing an alternative hybrid voting machine

Re: Computer Voting Expert, Dr. Rebecca Mercuri, Ousted From Elections Conference

2003-08-21 Thread Adam Shostack
Well, if you can't win on the truth, win on the procedures. At least Dr. Mercuri is in fine company there, ranging all the way back to Socrates and Galileo. Little consolation, I know, as our democracy gets replaced by a kleptocracy, but what can you do? Maybe she should set up stealdemocracy.co

Computer Voting Expert, Dr. Rebecca Mercuri, Ousted FromElections Conference

2003-08-21 Thread R. A. Hettinga
Notice they did this to Chaum, too... Cheers, RAH --- begin forwarded text Status: U To: "johnmac's living room" <[EMAIL PROTECTED]> Cc: Dave Farber <[EMAIL PROTECTED]> From: "John F. McMullen" <[EMAIL PROTECTED]> Mailing-List: list [EMAIL PROTECTED]; contact [EMAIL PROTECTED] Date: Mon, 4 Aug

Tamper proof modules/chips

2003-08-21 Thread Donald Eastlake 3rd
Hi, Is there a decent book on how to tamper proof chips/modules? Thanks, Donald == Donald E. Eastlake 3rd [EMAIL PROTECTED] 155 Beaver Street +1-508-634-2066(h) +1-508-851-8280(w) Milford, MA

Abit's SecureIDE

2003-08-21 Thread Mads Rasmussen
There seems to be a new interesting product from Abit, a motherboard manufacturer. "SecureIDE", supposed to encrypt information between the CPU and the IDE HD. Have a look at http://www.abit.com.tw/abitweb/webjsp/english/SecureIDE.htm The idea is simple: CPU <--> Chip <--> HD And the concept

Criminals Focus on Weak Link in Banking: A.T.M. Network

2003-08-21 Thread R. A. Hettinga
The New York Times August 3, 2003 Criminals Focus on Weak Link in Banking: A.T.M. Network By WALT BOGDANICH He fenced stolen jewels, committed bank and credit-card fraud and had been accused of having links

Re: Digicash Patents

2003-08-21 Thread R. A. Hettinga
--- begin forwarded text Status: U From: "Scott Guthery" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]>,<[EMAIL PROTECTED]> Subject: Re: Digicash Patents Date: Fri, 1 Aug 2003 08:23:47 -0400 Sender: <[EMAIL PROTECTED]> List-Subscribe: Digicash/Ecash/InfoSpace al

PRNG design document?

2003-08-21 Thread Tim Dierks
Is there a definitive or highly recommended paper or book on the design of PRNGs? I'm assuming a cryptographic PRNG of the type in OpenSSL, PGP, etc., where entropic seeding data is accumulated into a pool and output is produced by operating on the pool with a secure hash or similar cryptograph

A new paper: When To Use Biometrics

2003-08-21 Thread Hagai Bar-El
Hello, I would like to bring to your attention a short paper I published, called "When To Use Biometrics". This paper discusses biometrics reliance on cryptographic mechanisms making them harder to deploy securely in many circumstances. Abstract: http://www.hbarel.com/publications.htm Fu

South African Crypto Regulation

2003-08-21 Thread John Young
We offer a recent South African government statement on encryption import and export regulation: http://cryptome.org/za-crypto.htm - The Cryptography Mailing List Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PR

Crypto Hygiene?

2003-08-21 Thread dmolnar
(also posted to sci.crypt in modified form) At Usenix Security, Eric Rescorla pointed out that some of the cryptographic flaws we have seen can be prevented by applying good "crypto hygiene." My questions for the floor -- * What is "good hygiene" ? * Where would I find it written

[Lucrative-L] updated lucrative source now in CVS

2003-08-21 Thread R. A. Hettinga
--- begin forwarded text Status: U From: "Patrick" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Subject: [Lucrative-L] updated lucrative source now in CVS Date: Tue, 12 Aug 2003 13:20:50 -0600 Sender: [EMAIL PROTECTED] Reply-To: [EMAIL PROTECTED] I imported Lucrative source into Source

nCipher edges closer to break even

2003-08-21 Thread R. A. Hettinga
The Register 7 August 2003 Updated: 16:37 GMT nCipher edges closer to break even By Drew Cullen Posted: 05/08/2003 at 14:08 GMT nCipher , the niche crypto-security hardware house, has reduced Q2 operating losses to £500,000 (Q1,

ADMIN: List returning

2003-08-21 Thread Perry E. Metzger
The list should be coming back on the air of the next few days. I'll be approving a large batch of recent posts in a few hours, and then most of the rest next Tuesday. (Don't expect new posts to be approved over the weekend, though I'll do it if I can get to it.) Perry PS I'd say "We apologize fo