Re: [cryptography] An appropriate image from Diginotar

2011-09-01 Thread Ralph Holz
Hi, --- @nocombat writes: SSL Observatory: select count(Subject) from valid_certs where Issuer like '%diginotar%' â01 --- They've only issued 700-odd SSL certs? Wow, that's low. OTOH since their gravy train is mainly built around the Dutch government's PKI letter of marque [0], I

Re: [cryptography] *.google.com certificate issued by DigiNotar

2011-09-01 Thread Peter Gutmann
[NB: CC'd to the randombit cryptography list, since this is an interesting point for discussion]. Ian G i...@iang.org writes: What we'll likely see now is a series of breaches at multiple levels to acquire and misuse certs. We've seen compromises in the past, but what makes this new is

Re: [cryptography] Intel Security Driver and AVX CPUs (rdrand)

2011-09-01 Thread David Johnston
On 9/1/2011 5:12 PM, Jeffrey Walton wrote: Hi All, For some time, Intel has offered a Security Driver for Windows [1]. It basically allows us to use the 810 chipset and friends as a PRNG source via a CSP: if(CryptAcquireContext(hProvider, NULL, INTEL_DEF_PROV, PROV_INTEL_SEC, 0)) {