Re: [cryptography] blinding is in libgcrypt but NOT in gnupg?

2013-08-23 Thread Werner Koch
On Fri, 23 Aug 2013 05:56, j...@spaz.org said: > I found it in libgcrypt. I don't understand why it's not in gnupg. Becuase in GnuPG 2.x all crypto operations are done by Libgcrypt. > It looks to my untrained eye that gnupg and libgcrypt had a common > ancestor, but i'm not sure when that was.

[cryptography] [tor-dev] Global semi-passive adversary: suggestion of using expanders

2013-08-23 Thread Eugen Leitl
- Forwarded message from Paul-Olivier Dehaye - Date: Fri, 23 Aug 2013 03:08:59 +0200 From: Paul-Olivier Dehaye To: tor-...@lists.torproject.org Subject: [tor-dev] Global semi-passive adversary: suggestion of using expanders Reply-To: tor-...@lists.torproject.org Hello, Thank you for w

Re: [cryptography] Reply to Zooko (in Markdown)

2013-08-23 Thread Zooko Wilcox-OHearn
Dear Jon: Thank you for your kind words and your detailed response. I am going to focus only on the issue that I think is most relevant and urgent for your customers and mine. That urgent issue is: what's the difference between the now-canceled Silent Mail product and the products that you are s

Re: [cryptography] Reply to Zooko (in Markdown)

2013-08-23 Thread Zooko Wilcox-OHearn
LWN.net has an article on this topic this week: http://lwn.net/SubscriberLink/564263/d554156d882bfe0e/ Regards, Zooko ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography

Re: [cryptography] Reply to Zooko (in Markdown)

2013-08-23 Thread Nicolas Rachinsky
* Zooko Wilcox-OHearn [2013-08-23 15:21 +]: > But before we get into the nuts and bolts of how to facilitate > verification of end-to-end security, I want to hammer on the first > issue: before going forth to try to improve an issue, we should first > admit to our current customers and to the

Re: [cryptography] Reply to Zooko (in Markdown)

2013-08-23 Thread Warren Kumari
On Aug 23, 2013, at 12:19 PM, Nicolas Rachinsky wrote: > * Zooko Wilcox-OHearn [2013-08-23 15:21 +]: >> But before we get into the nuts and bolts of how to facilitate >> verification of end-to-end security, I want to hammer on the first >> issue: before going forth to try to improve an iss

[cryptography] GB Encryption-Model

2013-08-23 Thread Randolph D.
at least the design of version 0.2 is much better. http://goldbug.sourceforge.net/img/goldbug-encryptionmodel.png but the encryption model looks quite complex. I wounder if it has potentials and impules to the IRC functionality. Best Regards Randolph FWD: > > New Release V0.2 of http://GoldBug.sf.

[cryptography] Snowden Induced Mea Culpas

2013-08-23 Thread John Young
Comsec experts should not be surprised at the Snowden revelations about NSA so far, most of which are venerable. What is surprising is their seemingly exaggerated surprise because many of them worked at or ran firms which were known to be heavily involved with official spying through dual-use tec

Re: [cryptography] urandom vs random

2013-08-23 Thread coderman
On Thu, Aug 22, 2013 at 9:40 AM, Nico Williams wrote: > ... > What I'd like is for the HW RNG source configutation to be made very > clear to users: at boot time, at login time, when source availability > changes, and at critical secret or private key generation times. That > last is difficult wi

Re: [cryptography] urandom vs random

2013-08-23 Thread coderman
On Fri, Aug 23, 2013 at 9:26 PM, coderman wrote: > ... for any recent ubuntu, knoppix, tails, qubes, fedora and slack... i don't use *bsd on baremetal, but should be just as straightforward there. * oh dragonfly... so close! ___ cryptography mailing l

Re: [cryptography] Reply to Zooko (in Markdown)

2013-08-23 Thread coderman
On Fri, Aug 23, 2013 at 9:35 AM, Warren Kumari wrote: > ... > It looks bad for the economy when a company shuts down -- so, the obvious > solution is to simply slap failing companies with secret court orders to stay > in business, making hamburgers or whatever. > > You could extend this to all s