Re: How secure is software X?

2006-05-12 Thread Adam Shostack
Hi David, Very briefly because I'm swamped today: Please consider bringing some of this to Metricon (https://securitymetrics.org/content/Wiki.jsp?page=Welcome) Also there's a project of US DHS/NIST and probably others called SAMATE Software Assurance Metrics and Tool Evaluation http://samate.nis

Re: WMF round-up, updates and de-mystification

2006-01-04 Thread Adam Shostack
On Tue, Jan 03, 2006 at 10:28:40AM +0200, Gadi Evron wrote: | The "patch" by Ilfak Guilfanov works, but by disabling a DLL in Windows. | So far no problems have been observed by anyone using this patch. You This is incorrect. Michael Hennessy has reported problems on the patch-management mailin

Re: Secure Science issues preview of their upcoming block cipher

2005-03-25 Thread Adam Shostack
Really? How does one go about proving the security of a block cipher? My understanding is that you, and others, perform attacks against it, and see how it holds up. Many of the very best minds out there attacked AES, so for your new CS2 cipher to be "provably just as secure as AES-128," all thos

Re: Norton AV 2002 rewriting SMTP, breaking TLS

2002-07-22 Thread Adam Shostack
On Fri, Jul 19, 2002 at 02:40:16PM -0400, Owen, Greg wrote: | > I saw this behavior in Norton AV 2000. After searching their | > web site, I found the information saying that they just plain | > don't support SSL encrypted email. You have to pick, auto-scan | > AV, or encrypted session. | |

STANFORD CONFERENCE ON VULNERABILITY DISCLOSURE: Early Reg to Close Soon! (fwd)

2002-04-22 Thread Adam Shostack
- Forwarded message from "Jennifer S. Granick" <[EMAIL PROTECTED]> - X-Sender: [EMAIL PROTECTED] Date: Wed, 17 Apr 2002 10:05:27 -0800 To: [EMAIL PROTECTED] From: "Jennifer S. Granick" <[EMAIL PROTECTED]> Subject: STANFORD CONFERENCE ON VULNERABILITY DISCLOSURE: Early Reg to Close Soon!

Re: Advisory: PGP 7.0 signature verification vulnerability

2001-01-08 Thread Adam Shostack
Does this work if I put up a fake key on my website? If I put a fake key into the keyservers? How is that different from importing a signed, exported key from disk? Adam On Mon, Jan 08, 2001 at 03:58:58PM +0100, Michael Kjorling wrote: | -BEGIN PGP SIGNED MESSAGE- | Hash: SHA1 | | Pro

Re: Resistance is futile, or what I learned trying to secure the scanner

1999-10-13 Thread Adam Shostack
On Tue, Oct 12, 1999 at 11:17:29AM -0700, David LeBlanc wrote: | I was in the middle of the effort to try and protect ISS' Scanner against | the licensing being cracked, so I've got some unique insight. It took the | crackers about 3 months to crack the 4.0 release of the NT scanner (I was | hono