Re: [Cryptography] Crypto Standards v.s. Engineering habits - Was: NIST about to weaken SHA3?

2013-10-10 Thread David Mercer
an increase of fraud and financial loss. So in some cases anything less than a whole loaf, which you can't guarantee for N years of time, isn't 'good enough.' In other words, we are screwed no matter what. -David Mercer -- David Mercer - http://dmercer.tumblr.com IM: AIM: M

Re: [Cryptography] Other Backdoors?

2013-10-10 Thread David Mercer
Thursday, October 10, 2013, Phillip Hallam-Baker wrote: > > [Can't link to FIPS180-4 right now as its down] > For the lazy among us, including my future self, a shutdown-proof url to the archive.org copy of the NIST FIPS 180-4 pdf: http://tinyurl.com/FIPS180-4 -David Mercer

Re: [Cryptography] Opening Discussion: Speculation on "BULLRUN"

2013-09-07 Thread David Mercer
ering the domain objectdns.com. Things stalled out there due to my lack of copious free time. David Mercer - http://dmercer.tumblr.com IM: AIM: MathHippy Yahoo/MSN: n0tmusic Facebook/Twitter/Google+/Linkedin: radix42 FAX: +1-801-877-4351 - BlackBerry PIN: 332004F7

Re: [Cryptography] Opening Discussion: Speculation on "BULLRUN"

2013-09-05 Thread David Mercer
fixed there. Don't trust seeds you didn't generate. Think about Amazon AWS instances all spinning up on demand with the exact same init code and prng seed (this example is not the ones i dealt with, butnis perhaps a larger problem). You always have a window after startup where you can predict

Re: Interesting bit of a quote

2006-07-14 Thread David Mercer
ations that need to prove that things weren't altered (or to be able to audit when they are). It is of course quite a lot more expensive to do things that way compared to how the typical IT shop does things. -David Mercer -

Re: browser vendors and CAs agreeing on high-assurance certificates

2005-12-23 Thread David Mercer
onditioned to ignore them or click on Ok in general, that that itself was not the biggest barrier to their (potential) future wide deployment, at least not in relation to other UI issues for their use. -David Mercer Tucson, AZ --

Re: browser vendors and CAs agreeing on high-assurance certificates

2005-12-18 Thread David Mercer
but these ssl examples are directly cut and pasted from live ssl sessions. What a mess, and again, holy water indeed! Ciao, -David Mercer Tucson, AZ - The Cryptography Mailing List Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]

Re: Crypto and UI issues

2005-12-16 Thread David Mercer
On 12/15/05, Ben Laurie <[EMAIL PROTECTED]> wrote: > David Mercer wrote: > Thanks for the apology, but ... ssh is not my fault. Sorry, crosswired openssl and openssh in my brain! > I will agree that something better than just showing you the key would > be cool. Like maybe it

Crypto and UI issues

2005-12-13 Thread David Mercer
(Hopefully this is sent as ascii, as I had previously set my gmail to send in utf-8 encoding, as I often send email in french as well as english. -djm) On 12/11/05, James A. Donald <[EMAIL PROTECTED]> wrote: > It is not my position that inability to sign means that > the chairman of the board is s