Some notes the Debian OpenSSL PRNG bug and DHE

2008-08-22 Thread Eric Rescorla
Some colleagues (Hovav Shacham, Brandon Enright, Scott Yikel, and Stefan Savage) and I have been doing some followup work on the Debian OpenSSL PRNG bug. Perry suggested that some cryptography readers might be interested in our preliminary analysis of the DHE angle, which can be found here:

RE: The MD6 hash function (rough notes)

2008-08-22 Thread Clausen, Martin (DK - Copenhagen)
See his presentation slides here http://people.csail.mit.edu/rivest/Rivest-TheMD6HashFunction.ppt. M -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Hal Finney Sent: 21. august 2008 19:26 To: cryptography@metzdowd.com Subject: The MD6 hash function

Re: The MD6 hash function (rough notes)

2008-08-22 Thread Dustin D. Trammell
On Thu, 2008-08-21 at 10:26 -0700, Hal Finney wrote: Ron Rivest presented his (along with a dozen other people's) new hash, MD6, yesterday at Crypto. ---8---(snip)---8--- He also presented a number of cryptanalytic results. There is provable security against differential cryptanalysis, by

Re: The MD6 hash function (rough notes)

2008-08-22 Thread Dustin D. Trammell
On Thu, 2008-08-21 at 10:26 -0700, Hal Finney wrote: Ron Rivest presented his (along with a dozen other people's) new hash, MD6, yesterday at Crypto. The slides for this presentation are available from Ronald's website: http://people.csail.mit.edu/rivest/Rivest-TheMD6HashFunction.ppt --

DNS cache poison attacks in the wild

2008-08-22 Thread Perry E. Metzger
There have been other earlier reports, but the neat thing about this one is that the attackers went for the DNS record for the ISP's own crappy that domain doesn't exist, here, have some ads instead web page. http://securitylabs.websense.com/content/Alerts/3163.aspx Hat tip: Bill Squier --