Showing posts with label Crypto News. Show all posts
Showing posts with label Crypto News. Show all posts

Thursday, October 24, 2013

Security & Hacking: Xavier de Carné's "How I compiled TrueCrypt 7.1a for Win32 and matched the official binaries"

Good paper https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binaries-analysis/ by Xavier de Carné (Twitter @xavier2dc or https://twitter.com/xavier2dc).

If your unfamiliar with the concerns about TrueCrypt, Xavier's "Challenges and implications" section concisely outlines those concerns.

Including the IsTrueCryptAuditedYet? project http://istruecryptauditedyet.com/ which I have blogged http://cliffsesportcorner.blogspot.com/2013/10/psa-truecrypt-audit-project.html

To see all my post on TrueCrypt, or to bookmark to easily check for new posts, click on the Truecrypt label.

Labels can be found at bottom left of every blog post and in Label cloud at left side of Blog.

Additional links from Xavier de Carné's paper:

Wednesday, October 9, 2013

PSA TrueCrypt Audit project

What an interesting day!

Started with comments about Bruce Schneier's article at Wired http://www.wired.com/opinion/2013/10/149481/ where he mentions some concerns about TrueCrypt:
No, I don’t have any inside knowledge about TrueCrypt, and there’s a lot about it that makes me suspicious. But for Windows full-disk encryption it’s that, Microsoft’s BitLocker, or Symantec’s PGPDisk — and I am more worried about large U.S. corporations being pressured by the NSA than I am about TrueCrypt.

Eventually Matthew Green made the following tweet:
. and I are working on a 'Kickstarter' for a proper review of Truecrypt. The terms are a work in progress.

Fundfill link from Tweet above http://www.fundfill.com/fund/4-spzFJdDQk211KJDAUfcOw==#

Draft at http://istruecryptauditedyet.com/

You can follow Kenn White & Matthew Green on Twitter:

I am still very much a noob when it comes to Crypto, but Matthew Green is one of the people I follow to learn.

If your not into Crypto you probably haven't heard of him, this Ars article would be one place to start http://arstechnica.com/security/2013/09/crypto-prof-asked-to-remove-nsa-related-blog-post/

I am sorry to say I don't know much about Kenn White currently, I'd welcome comments or links that correct my ignorance.

Monday, September 9, 2013

Nerd News: "Crypto prof asked to remove NSA-related blog post"

Update:  Matthew Green has received a  kind apology http://cliffsesportcorner.blogspot.com/2013/09/update-on-john-hopkins-university-and.html

**** 

Ars article http://arstechnica.com/security/2013/09/crypto-prof-asked-to-remove-nsa-related-blog-post/

This really upsets me, on several levels.

I consider Matthew Green a mentor, in addition to being (IMVHO) one of the most knowledgeable people in cryptography.

His twitter is @matthew_d_green link https://twitter.com/matthew_d_green & his blog is at http://blog.cryptographyengineering.com/

I also strongly recommend the Resource page of his blog http://blog.cryptographyengineering.com/p/useful-cryptography-resources.html

Monday, August 26, 2013

Updated oclHashcat-plus v0.15

Main link:  http://hashcat.net/oclhashcat-plus/

oclHashcat-plus v0.15 "Added support for cracking passwords longer than 15 characters," lot of other improvements see https://hashcat.net/forum/thread-2543.html for full details.

I am still digging through the changes, and I have been sick, so it will probably take me a while, but it looks like some big improvements have been made.

They have also added support for several algorithms, including TrueCrypt 5.0+, Lastpass, & MacOSX v10.8 that are of particular interest to me.



Tuesday, August 13, 2013

Very interesting NYT article about Snowden, Laura Poitras, & Glenn Greenwald

Longer, more in depth article http://www.nytimes.com/2013/08/18/magazine/laura-poitras-snowden.html?pagewanted=all and a shorter one that is also used in longer article http://www.nytimes.com/2013/08/18/magazine/snowden-maass-transcript.html

Lot of people know who Snowden and Greenwald are now, I think fewer know who Laura Poitras is, sad to say I didn't before seeing this article.

For quick reference about these people see their Wikipedia links:
Lot of things of interest in above links.

Close reading of the NYT's article can provide some useful insights and tidbits to serious security.

I also want to note one comment by Snowden
"I was surprised to realize that there were people in news organizations who didn’t recognize any unencrypted message sent over the Internet is being delivered to every intelligence service in the world. In the wake of this year’s disclosures, it should be clear that unencrypted journalist-source communication is unforgivably reckless. "

Wednesday, October 10, 2012

Crypto News: Embedded Systems Week: Day 1

I started studying computer security seriously last December, because my credit card number got hacked or stolen some how and I wanted to know why & prevent it from happening again.

Learned a lot so far, though still a lot left to learn, still pretty much a Noob when it comes to Crypto, but I keep studying and learning.

The Bristol Cryptography Blog is an excellent source for Crypto news and information, they are covering the "Embedded Systems Week: It consists of three co-located conferences, CASES, EMSOFT and CODES+ISSS."

Day 1 coverage here http://bristolcrypto.blogspot.com/2012/10/embedded-systems-week-day-1-monday.html