“Coding theorists are concerned with two things. Firstly and most importantly they are concerned with the private lives of two people called Alice and Bob.” From 01984, giving an #introduction to #compression and #crypto. #humor
on 02026-07-30my comment summarizing the #NSA’s #history of weakening #crypto, including #DES. Quote
on 02026-06-04#ebook of “American Cryptology during the Cold War, 1945-1989”, DOCID: 523696, REF ID: A523696, a declassified internal #NSA #history, including how they weakened #DES, declassified July 26, 02013. #crypto
Quote originally classified TOP SECRET UMBRA, from p.232 (p.240/271):
> (S CCO) The decision to get involved with NBS was hardly unanimous. From the SIGINT standpoint, a competent industry standard could spread into undesirable areas, like Third World government communications, narcotics traffickers, and international terrorism targets. But NSA had only recently discovered the large-scale Soviet pilfering of information from U.S. government and defense industry telephone communications. This argued the opposite case - that, as Frank Rowlett had contended since World War II, in the long run it was more important to secure one’s own communications than to exploit those of the enemy.
> (FOUO) Once that decision had been made, the debate turned to the issue of minimizing the damage. Narrowing the encryption problem to a single, influential algorithm might drive out competitors, and that would reduce the field that NSA had to be concerned about. Could a public encryption standard be made secure enough to protect against everything but a massive brute force attack, but weak enough to still permit an attack of some nature using very sophisticated (and expensive) techniques? NSA worked closely with IBM to strengthen the algorithm against all except brute force attacks and to strengthen substitution tables, called S-boxes. Conversely, NSA tried to convince IBM to reduce the length of the key from 64 to 48 bits. Ultimately, they compromised on a 56-bit key.
on 02026-06-04#PDF of #DJB’s talk slides about the #NSA’s #history of weakening #crypto
on 02026-06-04#crypto #history: Hellman and Merkle showed in 01977 that #DES #crypto could be broken for about US$5000 per key, already, at the time. #PDF #paper
on 02026-06-04#crypto #history: Hellman and Merkle showed in 01977 that #DES #crypto could be broken for about US$5000 per key, already, at the time. #PDF #paper
on 02026-06-04#DJB’s outline of the #history of the #NSA’s involvement in weakening #crypto, including their reduction of #DES’s key length. #NIST #DSA #DualEC #SIGINT-enabling-project #NISTPQC #FOIA
on 02026-06-04#Filippo Valsorda explains #QC isn’t a threat to 128-bit encryption or hashes because #Grovers-algorithm loses its quadratic speedup when you try to parallelize it. #crypto #security
on 02026-04-24#privacy #human-rights #crypto #news: “by default, #BitLocker recovery keys are uploaded to Microsoft’s cloud, allowing the tech giant — and by extension law enforcement — to access them and use them to decrypt drives encrypted with BitLocker, as with the case reported by Forbes.”
on 02026-01-25“BebboSSH” is an #SSH 2 server and client for #Amiga #retrocomputing. curve25519-sha256, curve25519-sha256@libssh.org, ssh-ed25519, aes128-gcm@openssh.com, chacha20-poly1305@openssh.com, hmac-sha2-256, sha512. “It will work on an unaccelerated Amiga but establishing the connection takes about one minute”. #crypto #security
on 02025-11-26a tiny #SSH server, 42K static stripped. “All AI slop.” Supports “ChaCha20-Poly1305 or Curve25519-donna. Single key exchange: Curve25519. Single host key type: Ed25519. Password authentication only (no public key auth). No compression. No algorithm negotiation (single fixed suite).” Lots of tips for building smaller binaries. #small-is-beautiful #crypto #security
on 02025-11-26#PDF of Zenner’s #crypto dissertation on breaking #LFSRs, with a survey of known attacks. I haven’t read it. #security
on 02025-08-12#Godot has rather anemic #crypto support, just RSA and self-signed X.509 certificates
on 02024-05-20signing #git commits with #ssh keys. #crypto
on 02022-09-16#C++ #SNARKs #crypto an embedded DSL for snarklib
on 02022-02-11#Bunnie’s #Precursor is currently using #VexRiscv on Spartan #FPGA #hardware to defeat #Karger-Thompson #hardware attacks (and other hardware #security problems) but most of the FPGA is devoted to #crypto, mostly cores from #OpenTitan
on 02021-01-24#music about #crypto, spoof of Banana Boat
on 02021-01-24#crypto hash function known attacks
on 02021-01-24use double HMAC verification in #crypto instead of constant-length string compares
on 02017-08-06Successful cryptanalysis of Enigma with recurrent #neural-networks. #crypto #deep-learning
on 02017-08-06#HTTP2 criticisms; why mandatory #crypto didn’t make it in officially, but most client implementations do require it
on 02017-06-20whoa, XTEA #crypto in 504 bytes of machine code on the #AVR! Plus lots of other things — I didn't know you could do AES in 2½K.
on 02017-06-14#USA #privacy #human-rights case of #Francis-Rawls continues; he remains jailed for contempt of court for saying he doesn’t remember the #crypto keys to his disks
on 02017-04-30another tiny public-domain #Keccak #SHA-3 #crypto hash in 120 “lines” of C, derived from a Twitter account, #simplesha3 I think. #smallisbeautiful
on 02017-04-18sbp ported #simplesha3 to #Python 3. #SHA-3 #Keccak #crypto
on 02017-03-22#DJB version of #SHA-3 (#Keccak) as a C Python (2) extension module, called "simplesha3", in 47 lines of C (though several lines, taken from the 9-tweet @tweetfips202, are quite dense and obfuscated.) #crypto #smallisbeautiful
on 02017-03-22first #SHA-1 collision. #security #crypto
on 02017-03-15#PDF #paper “NaCl on 8-Bit #AVR Microcontrollers” requires 23 million cycles to Ed25519-sign, 32 million cycles to verify, 268 cycles per byte for symmetric Salsa20 encryption, 195 cycles per byte for Poly1305 authentication, all in under 18 kB of code and 1.4 kB of stack; all constant-time. #crypto
on 02017-01-14More on #DJB’s Salsa20 and ChaCha20 symmetric ciphers. #crypto
on 02017-01-10Snuffle was #DJB’s demonstration in 1995 that secure hash functions were adequate to securely encrypt data. In 2005 he designed Salsa20, a successor based on a different hash function; in 2008 he designed ChaCha20, using another hash function, which is the current state-of-the-art symmetric cipher used in TLS. #crypto #history
on 02017-01-10SP networks alternate S-boxes with P-boxes. #crypto
on 02017-01-10Explanation of the ChaCha20 #crypto algorithm. #algorithms #toread
on 02017-01-10“The Turkish coup plotters discovered that ByLock was not secure because they had penetrated the Turkish intelligence service.” #ByLock #Turkey #crypto #security #Turkish-coup
on 02016-10-07Nadia, Joshua Fried, and some French guys demonstrate a discrete logarithm against a 1024-bit trapdoored prime field using the special number field sieve. If people are using such a field for DH or DSA, they are vulnerable to such an attack. #crypto #math
on 02016-10-06ChaCha12-256 (without the usual security margin) has about the same #performance as AES-128 on several generations of Intel #hardware, because it’s good at #vectorization of #crypto, and will get faster now that Intel is exposing their 52-bit multipliers as #djb requested in 2002. Also apparently Intel is adding inversion in GF(256).
on 02016-08-11#source-code for a new #post-quantum #crypto implementation: an embedded-optimized ARM assembly implementation of NewHope key exchange, an algorithm using the NTT (Number-Theoretical Transform), with #performance of under 2M clock cycles on the Cortex-M0. By Erdem Alkim, Philipp Jakubeit, and Peter Schwabe.
on 02016-08-03Chelsea #Manning writes from prison to the Hope Conference; urges #AaronSw Day Hackathons to focus on post-quantum #crypto.
on 02016-08-01Michael Hayden opposes FBI director Comey’s position? #toread #politics #human-rights #crypto
on 02016-02-25Donald Trump takes the side of the FBI in the #crypto #human-rights issue with Apple: “I use both iPhone & Samsung. If Apple doesn’t give info to authorities on the terrorists I’ll only be using Samsung until they give info.”
on 02016-02-19Thoughtful post on the #crypto #human-rights issue with Apple.
on 02016-02-19Apple opposes building a backdoored build of the iOS operating system to unlock the San Bernardino shooter’s iPhone. #crypto #human-rights
on 02016-02-17Tim Cook from #Apple fighting for #crypto #human-rights.
on 02016-01-13Whisper’s TextSecure v2 has multiparty #crypto #chat. This talks about the design of its #protocols and covers #mpOTR.
on 02016-01-13outline of #mpOTR #crypto #chat #protocols as of 2011.
on 02016-01-13the first two recipients of the 1st annual Levchin Prize for Real-World Cryptography are Phillip Rogaway and the miTLS team. #crypto #paypal-mafia
on 02016-01-06“SPHINCS-256 is a high-security #post-quantum stateless hash-based signature scheme that signs hundreds of messages per second on a modern 4-core 3.5GHz Intel CPU. Signatures are 41 KB, public keys are 1 KB, and private keys are 1 KB. SPHINCS-256 is designed to provide long-term 2128 security even against attackers equipped with quantum computers.” #djb #crypto #algorithms
on 02016-01-06different threat models in #crypto #security, and some surprising (to me) weaknesses in #AES as it’s usually used. Interesting to note that Bernstein doesn’t seem to be daunted by the NSA backing off on #ECC. In fact, he doesn’t even mention it.
on 02015-11-20Sakura is (mostly) a #crypto tree hashing mode for constructing tree hashes from secure #hash functions. It avoids a #security problem that I don’t understand yet with confusing leaf nodes with internal nodes.
on 02015-08-18