ADMIN: your wonderful anti-spam software

2010-07-22 Thread Perry E. Metzger
Researchers at two major institutions are informed that you may have missed a recent short thread about a content delivery network with an EV cert claiming to be valid for a truly vast number of zones, originated by Peter Gutmann. I would name the institutions, but that wouldn't be a kindness. If

Re: A mighty fortress is our PKI

2010-07-22 Thread Chris Palmer
Peter Gutmann writes: > Readers are cordially invited to go to https://edgecastcdn.net and have a > look at the subjectAltName extension in the certificate that it presents. Also, keep your eye on: https://www.defcon.org/html/defcon-18/dc-18-speakers.html#Eckersley -

Re: Encryption and authentication modes

2010-07-22 Thread David McGrew
Hi Florian, can I ask what your interest in AEAD is? Is there a particular application that you have in mind? DJ provided a good summary of CCM and GCM. To add some follow-on to that, RFC 5116 defines an interface to an AEAD algorithm, and a registry of such algorithms. TLS 1.2 ties in

What if you had a very good entropy source, but only practical at crypto engine installation time?

2010-07-22 Thread Thierry Moreau
See http://www.connotech.com/doc_pudec_descr.html . (OK, it's also practical whenever the server needs servicing by trusted personnel.) Then, you care about the deterministic PRNG properties, the secrecy of its current state, and the prevention of PRNG output replays from an out-of-date sav

A mighty fortress is our PKI

2010-07-22 Thread Peter Gutmann
Readers are cordially invited to go to https://edgecastcdn.net and have a look at the subjectAltName extension in the certificate that it presents. An extract is shown at the end of this message, this is just one example of many like it. I'm not picking on Edgecast specifically, I just used th

[gd...@microsoft.com: [fc-announce] Call for papers: Financial Cryptography and Data Security (FC2011)]

2010-07-22 Thread R. Hirschfeld
--- Start of forwarded message --- From: George Danezis To: "fc-annou...@ifca.ai" Date: Wed, 21 Jul 2010 15:56:36 + Subject: [fc-announce] Call for papers: Financial Cryptography and Data Security (FC2011) Financial Cryptography and Data Security (FC 2011), Bay Gardens Beach

Re: A Fault Attack Construction Based On Rijmen's Chosen-Text Relations Attack

2010-07-22 Thread David Wagner
Alfonso De Gregorio wrote: > The last Thursday, Vincent Rijmen announced a new clever attack on > AES (and KASUMI) in a report posted to the Cryptology ePrint > Archive: Practical-Titled Attack on AES-128 Using Chosen-Text > Relations, http://eprint.iacr.org/2010/337 Jonathan Katz wrote: