Re: [Cryptography] Crypto Standards v.s. Engineering habits - Was: NIST about to weaken SHA3?

2013-10-02 Thread Jonathan Thornburg
quot;) centers. Perhaps there's a lesson here: leave carpentry to people who are experts at carpentry. And leave crypto to people who are experts at crypto. -- -- "Jonathan Thornburg [remove -animal to reply]" Dept of Astronomy & IUCSS, Indiana University, Bloomington,

Re: [Cryptography] Credit for Trusting Trust

2013-09-14 Thread Jonathan Thornburg
countermeasure does NOT require hand examination of compiler output -- the tests are (or can be) fully automated even for realistic industrial-strength compilers like GCC (on which Wheeler demonstrated DCC in his thesis). And a tiny historical nit: Wheeler's dissertation was in 2009, not

Re: [Cryptography] Functional specification for email client?

2013-08-30 Thread Jonathan Thornburg
sure that no one else has seen the contents of the email. This probably needs amending to deal with messages addressed to multiple recipients (either cc:, bcc:, or simply multiple to: addresses). -- -- "Jonathan Thornburg [remove -animal to reply]" Dept of Astronomy & IU

Re: [Cryptography] Email and IM are ideal candidates for mix networks

2013-08-28 Thread Jonathan Thornburg
> my public key has been compromised. Maybe it's because you've forgotten the passphrase guarding the corresponding private key? Or because you'd like to do the electronic equivalent of "change my name, start [this facet of] my electronic life over"? -- -- "

Re: [Cryptography] Implementations, attacks on DHTs, Mix Nets?

2013-08-27 Thread Jonathan Thornburg
iption of DNSSEC. Assuming it were widely deployed, would DNSSEC-for-key-distribution be a reasonable way to store email_address --> public_key mappings? -- -- "Jonathan Thornburg Dept of Astronomy & IUCSS, Indiana University, Bloomington, Indiana, USA "There was o

Re: Formal notice given of rearrangement of deck chairs on RMS PKItanic

2010-10-06 Thread Jonathan Thornburg
This message was cryptographically signed but the signature ] [ could not be verified. ] ciao, -- -- "Jonathan Thornburg [remove -animal to reply]" Dept of Astronomy, Indiana University, Bloomington, Indiana, USA "Washing one's hands of the conflict between the power

Re: Is this the first ever practically-deployed use of a threshold scheme?

2010-08-02 Thread Jonathan Thornburg
inor nit... his name was "Lagrange" (one word), not "La Grange" (2 words). See http://en.wikipedia.org/wiki/Lagrange for further details. Lagrange interpolating polynomials are widely used in non-crypto numerical computations (solving differential equations and suchlike). -- -- &q

deliberately crashing ancient computers (was: Re: A mighty fortress is our PKI)

2010-07-28 Thread Jonathan Thornburg
pitch...) > Ultimately though, the only thing that's going to get some people off > IE6 is the machines they are running it off of finally dying, either > due to hardware failure or being so badly owned by worms that the > machine becomes inoperable, at which point it goes into the t

Re: [TIME_WARP] 1280-Bit RSA

2010-07-09 Thread Jonathan Thornburg
| Hanging on in quiet desperation is Oxford University Computing Service | the English way. 13 Banbury Road, Oxford, OX2 6NN, UK | The time is come, the song is over. Tel: +44-865-273200 Fax: +44-865-273275 | Thought I'd something more to say. Finger p...@bl

Re: SHA-1 and Git (was Re: [tahoe-dev] Tahoe-LAFS key management, part 2: Tahoe-LAFS is like encrypted git)

2009-08-25 Thread Jonathan Thornburg
back attacks for as long as in-the-field software still groks the old (now-insecure) versions, so "versioning" is actually more like "Byzantine versioning". -- -- Jonathan Thornburg Dept of Astronomy, Indiana University, Bloomington, Indiana, USA "Washing one's

Re: CSPRNG algorithms

2009-05-01 Thread Jonathan Thornburg
authors' reputations suggest their advice is probably excellent... ciao, -- -- "Jonathan Thornburg [remove -animal to reply]" Dept of Astronomy, Indiana University, Bloomington, Indiana, USA "C++ is to programming as sex is to reproduction. Better ways might technically exist but they're not nearly as much fun." -- Nikolai Irgens

Re: full-disk subversion standards released

2009-02-02 Thread Jonathan Thornburg
of different software encryption schemes -- and compilers to turn them into binary code (which is what the NSA/Intel backdoor ultimately has to key on) that, I think, makes it so much harder for a hardware backdoor to work (i.e. to subvert software encryption) in this context. -- -- "Jonath

Re: full-disk subversion standards released

2009-01-30 Thread Jonathan Thornburg
get a "yes" answer to my question if the encryption is done in hardware, disk-drive firmware, or indeed anywhere except "software that I fully control". -- -- Jonathan Thornburg Dept of Astronomy, Indiana University, Bloomington, Indiana, USA "Washing one's hand

Re: Bitcoin v0.1 released

2009-01-17 Thread Jonathan Thornburg
y major government to monitor all Bitcoin transactions to watch for botnet-to-botnet sending? -- -- From: "Jonathan Thornburg [remove -animal to reply]" Dept of Astronomy, Indiana University, Bloomington, Indiana, USA "Washing one's hands of the conflict betwee

Re: defending against evil in all layers of hardware and software

2008-04-29 Thread Jonathan Thornburg
re passing control to it. If the bootloader is running on malicious hardware I don't think that test can be trusted. :( -- Jonathan Thornburg (remove -animal to reply) <[EMAIL PROTECTED]> School of Mathematics, U of Southampton, England "C++ is to programming as sex is t

Re: Death of antivirus software imminent

2008-01-18 Thread Jonathan Thornburg
cal access to the slave/owned machines. In what way has this stopped (or even slowed) the Storm worm, to name one notorious example? -- -- Jonathan Thornburg (remove -animal to reply) <[EMAIL PROTECTED]> School of Mathematics, U of Southampton, England "Wash

Re: *AEI-SPAM-MARK* Re: Governance of anonymous financial services

2007-03-30 Thread Jonathan Thornburg
is mailing list of nefarious purposes. Rather, I'm asking a serious question about the practicality of anonymous (crypto-enabled) financial services in the 21st century, namely, will governments be willing to allow them to operate?] ciao, -- -- "Jonathan Thornburg -- remove -animal to r

Re: It's a Presidential Mandate, Feds use it. How come you are not using FDE?

2007-01-20 Thread Jonathan Thornburg
e (I haven't seen any problems on an old 486/33 laptop I'm using as a home firewall/router). For laptops (where physical theft is major concern), I think the combination of an encrypting file system and swap encryption gives a pretty good -- and readily configurable -- security/performa

Re: It's a Presidential Mandate, Feds use it. How come you are not using FDE?

2007-01-18 Thread Jonathan Thornburg
files under Matt Blaze's CFS; any of the other open-source {linux,bsd} cryptographic file systems would be reasonable alternatives. -- -- "Jonathan Thornburg -- remove -animal to reply" <[EMAIL PROTECTED]> Max-Planck-Institut fuer Gravitationsphysik (Albert-Einstein-Institut),

Re: It's a Presidential Mandate, Feds use it. How come you are not using FDE?

2007-01-16 Thread Jonathan Thornburg
ware the performance hit is minimal (compared to the cost of the disk access). See http://www.openbsd.org/papers/swapencrypt.ps for a discussion of the security model. ciao, -- -- "Jonathan Thornburg -- remove -animal to reply" <[EMAIL PROTECTED]> Max-Planck-Institut fuer G

Re: It's a Presidential Mandate, Feds use it. How come you are not using FDE?

2007-01-16 Thread Jonathan Thornburg
arate keys for separate categories of information (eg one key for my tax forms, a different key for company-confidential project stuff, a different key for old love letters, still another one for My Secret Plan For World Domination, etc etc). These might all live on the same laptop, but they probabl

Re: Can you keep a secret? This encrypted drive can...

2006-11-06 Thread Jonathan Thornburg
For smaller files the hit is truly negligible -- when I tried this test on 64K files there was no difference in times between (a), (b), and (c) within the timing noise. ciao, -- -- "Jonathan Thornburg -- remove -animal to reply" <[EMAIL PROTECTED]> Max-Planck-Institut fue

Re: Crypto hardware with secure key storage

2006-05-22 Thread Jonathan Thornburg
support. In particular, OpenBSD (http://www.openbsd.org) supports a number of crypto boards/boxes, detailed on their crypto page (http://www.openbsd.org/crypto.html). They provide nice documentation, in particular they have _very_ good man pages. ciao, -- -- "Jonathan Thornburg -- remove -animal

Re: thoughts on one time pads

2006-01-27 Thread Jonathan Thornburg
k... but in practice that takes a specialized "oven" (I seriously doubt my home oven gets hot enough), and is likely to produce toxic fumes, and leave behind a sticky mess (stuck to the surface of the specialized oven). ciao, -- -- Jonathan Thornburg <[EMAIL PROTECTED]> Max-Plan

Re: [spam]::Re: [Clips] Banks Seek Better Online-Security Tools

2005-12-13 Thread Jonathan Thornburg
in to deciding to not leave your house because you "can't be sure" someone won't shoot you dead. Well, in certain places that's basically what people do. For example, many foreign people in Bhagdad don't venture out of the "green zone". My point is that when

Re: [Clips] Banks Seek Better Online-Security Tools

2005-12-05 Thread Jonathan Thornburg
ame reason. [I don't particularly trust buying things online with a credit card, either, but there my liability is limited to 50 Euros or so, and the credit card companies actually put a modicum of effort into watching for suspicious transactions, so I'm willing to buy (a few) things online.]

Re: gonzo cryptography; how would you improve existing cryptosystems?

2005-11-08 Thread Jonathan Thornburg
re kernel modes. So far as I know, in this regard cfs is unique among cryptographic filesystems. ciao, -- -- Jonathan Thornburg <[EMAIL PROTECTED]> Max-Planck-Institut fuer Gravitationsphysik (Albert-Einstein-Institut), Golm, Germany, "Old Europe" http://www.aei.mpg.de/~jth

Re: [Forwarded] RealID: How to become an unperson.

2005-07-06 Thread Jonathan Thornburg
ust how reliably could he have spotted a fake passport? ciao, -- -- "Jonathan Thornburg -- remove -animal to reply" <[EMAIL PROTECTED]> Max-Planck-Institut fuer Gravitationsphysik (Albert-Einstein-Institut), Golm, Germany, "Old Europe" http://www.aei.mpg.de/~jthor

Re: Security is the bits you disable before you ship

2005-03-25 Thread Jonathan Thornburg
arder to find bugs of any sort, including security ones) snprintf() call: #define N_LINE 999 static char line[N_LINE]; len = snprintf(line, N_LINE, "%ul , %ul\r\n", rp, lp); snprintf() first appeared in 4.4BSD and is now in C99, so any modern system should support it by now

Re: Linux-based wireless mesh suite adds crypto engine support

2004-09-30 Thread Jonathan Thornburg
ives 3DES protected 100Mbit Ethernet * Next by Date: linux-ipsec: IP Sec w/ dynamic IP addresses ? * Prev by thread: Re: linux-ipsec: Intel IPSEC accelerator gives 3DES protected 100Mbit Ethernet * Next by thread: Re: linux-ipsec: Intel IPSEC accelerator gi