Re: [cryptography] True Random Source, Thoughts about a Global System Perspective

2011-01-25 Thread Sandy Harris
Thierry Moreau thierry.mor...@connotech.com wrote: Only NIST (with the help of NSA and participants in a circa 2004 symposium) advanced the true random source standardization effort, with the main outcome being NIST SP-800-90. Neither the financial industry (ANSI) nor the European digital

Re: [cryptography] True Random Source, Thoughts about a Global System Perspective

2011-01-25 Thread Peter Gutmann
Thierry Moreau thierry.mor...@connotech.com writes: So, here are a few highlights of my recent findings. I found that too many notions deserved a description of rationales, and hence a draft-in-progress document is just stalled. The problem here is that the debate rapidly goes from engineering

[cryptography] A REALLY BIG MITM

2011-01-25 Thread Peter Gutmann
This isn't one of those namby-pamby one-site phishing MITMs, this is a MITM of an entire country: http://www.theatlantic.com/technology/archive/2011/01/the-inside-story-of-how-facebook-responded-to-tunisian-hacks/70044/ For those who don't want to read the whole thing, the solution was duuhh, we