The fly in this ointment is that the testers (of whatever stripe) are being trusted to reveal all the flaws that they find. One way of assuring that is flaw injection, but it's imperfect, because you can never prove that failure to find the flaw was deliberate. The same problem applies to

On Jan 9, 2004, at 8:06 PM, Rich Salz wrote: dave kleiman wrote: Because the client has a Certificate Revocation Checking function turned on in a particular app (i.e. IE or NAV). I don't think you understood my question. Why is getting overloaded *now.* What does the

2004-04-01 Thread R. A. Hettinga,,SB108079540145771406,00.html The Wall Street Journal April 1, 2004 COMMENTARY The 'Privacy' Jihad By HEATHER MAC DONALD April 1, 2004; Page A14 The 9/11 Commission hearings have focused public attention again on the intelligence failures

Hello, I have put on-line an implementation of an Eric Filiol's Moebius Statistical Analysis of Symmetric Ciphers and Hash Functions, if anyone might need such a thing. It is a part of a package of utilities for testing cryptographic hash functions (Maurer's universal statistical test,

By popular demand, I've created a moderated alternative to the UKCrypto mailing list. See for the charter and subscription information. This is intended to be complementary to the cryptography (because its about the UK) and ukcrypto