Tag: cryptography
-
UKโs secret Apple iCloud backdoor order is a global emergency, say critics
The UK seems to be strongarming Apple to weaken the security of its consumer products, which is fucking stupid. Weakened and backdoored encryption in mainstream products doesn't help catch smart criminals. But it does help smart criminals to catch regular folks.
-
The eldest is really getting into her WW2 studies at school, so I arranged a trip for her and a trip to the ever-excellent Bletchley Park for a glimpse at the code war that went on behind the scenes. They're clearly looking forward to the opportunity to look like complete swots on Monday.
Alt
Dan sits on a padded bench in a cinema-style room, pointing his thumb at the two children sitting on a row in front of him.
Bonus: I got to teach them some stories about some of my favourite cryptanalysts. (Max props to the undersung Mavis Batey!)
-
Length Extension Attack Demonstration (Video)
This is a video version of my blog post, Length Extension Attack. In it, I talk through the theory of length extension attacks and demonstrate an SHA-1 length extension attack against an (imaginary) website.
The video can also be found on:
YouTube
-
Length Extension Attack Demonstration
Hash length extension attacks aren't necessarily intuitive without a little understanding of how vulnerable hashing algorithms work. Using SHA1 as an example, I've put together a step-by-step demonstration with a focus on teaching the underlying principles behind the vulnerability.
-
Finally got around to implementing a super-lightweight (~20 lines of code, 1 dependency) Spring '83 key generator. There are plenty of others; nobody needs this one, but it's free if you want it:
https://github.com/Dan-Q/spring83-keygen -
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective
Moxie Marlinspike "acquires" a Cellebrite UFED and hacks it, with all the delight and sarcasm you'd expect. Dan partially-translates.
-
Spy's Guidebook Reborn
When his 7-year-old asks Dan to print some crib from Usborne's Spy's Guidebook, he goes one step further and reimplements the cipher in Javascript.
-
Basilisk collection
Blackle Mori's "Basilisk collection" is an amazing piece of alternate history science fiction, presented in the style of a Wikipedia article. Dan explains why it's so good and encourages you to read it.
-
Endpoint Encabulator
Dan shares his latest digital project, the Endpoint Encabulator, with an explanatory video.
-
Displaying ProtonMail Encryption Status in Thunderbird
Dan releases his first Thunderbird plugin, for improving integration with ProtonMail Bridge.
-
Third-party libraries and security issues
A month or so ago Chris Ferdinandi recommended that developers avoid third-party libraries for security reasons. Dan partially-agrees, but feels the need to explain where and why he disagrees too.
-
G7 Comes Out in Favor of Encryption Backdoors
From a G7 meeting of interior ministers in Paris this month, an "outcome document":
Encourage Internet companies to establish lawful access solutions for their products and services, including data that is encrypted, for law enforcement and competent authorities to access digital evidence, when it is removed or hosted on IT servers located abroad or โฆ -
Enigma, the Bombe, and Typex
How to guides
How to encrypt/decrypt with Enigma
We'll start with a step-by-step guide to decrypting a known message. You can see the result of these steps in CyberChef here. Let's say that our message is as follows:
XTSYN WAEUG EZALY NRQIM AMLZX MFUOD AWXLY LZCUZ QOQBQ JLCPK NDDRW F
And that we've been told โฆ -
Evaluating the GCHQ Exceptional Access Proposal
...
In a blog post, cryptographer Matthew Green summarized the technical problems with this GCHQ proposal. Basically, making this backdoor work requires not only changing the cloud computers that oversee communications, but it also means changing the client program on everyone's phone and computer. And that change makes all of those systems less secure. Levy and โฆ -
Quantum Computing and Cryptography
Quantum computing is a new way of computing -- one that could allow humankind to perform computations that are simply impossible using today's computing technologies. It allows for very fast searching, something that would break some of the encryption algorithms we use today. And it allows us to easily factor large numbers, something that wouldโฆ
...
โฆ






