Re: [cryptography] [Cryptography] Email encryption for the wider public

2014-09-18 Thread Jonathan Thornburg
people) E-mail correct over a poor-quality phone connection is hard enough already! ciao, -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA There was of course no way of knowing whether you

Re: [cryptography] [Cryptography] Steganography and bringing encryption to a piece of paper

2014-07-18 Thread Jonathan Thornburg
attempted decryption. But Room 40 still broke it. A rereading of Kahn The Codebreakers on the era of Nomenclatures and beyond does not offer high hopes of this diary-code staying unbroken if the NSA decides it's worth a few analyst-months and GPU-centuries... ciao, -- -- Jonathan Thornburg [remove

Re: [cryptography] [Cryptography] The Heartbleed Bug is a serious vulnerability in OpenSSL

2014-04-08 Thread Jonathan Thornburg
worth spending any money trying to secure nuclear reactors against tsunami damage. -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA There was of course no way of knowing whether you were

Re: [cryptography] replacing passwords with keys is not so hard (Re: PBKDF2 + current GPU or ASIC farms = game over for passwords)

2013-10-01 Thread Jonathan Thornburg
, -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA There was of course no way of knowing whether you were being watched at any given moment. How often, or on what system, the Thought Police

[cryptography] more oneid stuff 2-factor when smartphone offline scenarios (Re: replacing passwords with keys is not so hard (Re: PBKDF2 + current GPU or ASIC farms = game over for passwords))

2013-10-01 Thread Jonathan Thornburg
logins to online service occur at a place and time where the user doesn't have cellphone reception? Have there been any (well-done) surveys to estimate this? ciao, -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University

[cryptography] XTS mode

2013-09-28 Thread Jonathan Thornburg
somewhere? ciao, -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA There was of course no way of knowing whether you were being watched at any given moment. How often, or on what system

Re: [cryptography] Radiation Emission Controls

2013-07-30 Thread Jonathan Thornburg
in secure facilities anyway. takes a digital-camera -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA on sabbatical in Canada through late August 2013 There was of course no way

[cryptography] backdoors in commercial software

2013-05-18 Thread Jonathan Thornburg
, then Skype is about as (in)secure as a phone conversation, and Skype IMs are about as (in)secure as cellphone SMSs. -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA on sabbatical in Canada

Re: [cryptography] backdoors in commercial software

2013-05-18 Thread Jonathan Thornburg
, -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA on sabbatical in Canada starting August 2012 Washing one's hands of the conflict between the powerful and the powerless means to side

Re: [cryptography] [liberationtech] Cryptography super-group creates unbreakable encryption

2013-02-14 Thread Jonathan Thornburg
gets me an error screen Sorry, you have to enable Javascript in order to use this. I think there's a message here. -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA

Re: [cryptography] non-decryptable encryption

2012-06-19 Thread Jonathan Thornburg
The digit sequence 0.1234567891011121314151617181920212223... (or its equivalent in binary, hex, or your other favorite base) never repeats, but provides no security whatsoever. One-time pads need nonrepeating sequences *which the adversary can't predict*. -- -- Jonathan Thornburg [remove

Re: [cryptography] Master Password

2012-05-30 Thread Jonathan Thornburg
of PC where web browser remembered it, etc. So... it would be a *big* plus to have a way to rollover the master password without having to manually re-visit and re-password each website. -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS

Re: [cryptography] Master Password

2012-05-30 Thread Jonathan Thornburg
/software which *does* grok the letters (e.g., she buys a new smartphone in Germany, which *does* have o-umlaut on its virtual|physical keyboard)? ciao, -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana

Re: [cryptography] [info] The NSA Is Building the Country’s Biggest Spy Center (Watch What You Say)

2012-03-18 Thread Jonathan Thornburg
? Maybe they only plan to brute-force human-provided passphrases used to generate AES keys? -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA Washing one's hands of the conflict between

Re: [cryptography] Bitcoin in endgame

2012-02-23 Thread Jonathan Thornburg
will be idle when their owners are sleeping, and usually when owners are out at school/work/shopping/etc in the daytime), the botnet throughput is only modestly degraded. -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana

Re: [cryptography] Gregory Perry's follow-up to the FBI OpenBSD / OCF backdoors thread (was: Fwd: [gsc] Fwd: OpenBSD IPSEC backdoor(s))

2012-01-15 Thread Jonathan Thornburg
. -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA Washing one's hands of the conflict between the powerful and the powerless means to side with the powerful, not to be neutral

Re: [cryptography] CAPTCHA as a Security System?

2012-01-02 Thread Jonathan Thornburg
, [[...]] According to http://www.nytimes.com/2010/04/26/technology/26captcha.html?hpw the going rate for paying humans to break CAPTCHAs is around $1 per 1000 CAPTCHAS, i.e., around 0.1 cent per CAPTCHA. -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept

Re: [cryptography] How are expired code-signing certs revoked?

2011-12-25 Thread Jonathan Thornburg
some piece of software which knows Alice's private key, and some bit-string (a document). But the legal system wants a binding to Alice's conscious intent, which is a *very* different thing. -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy

Re: [cryptography] this house believes that user's control over the root list is a placebo

2011-06-26 Thread Jonathan Thornburg
this for certificates, but I forget its name... ciao, -- -- Jonathan Thornburg [remove -animal to reply] jth...@astro.indiana-zebra.edu Dept of Astronomy IUCSS, Indiana University, Bloomington, Indiana, USA Washing one's hands of the conflict between the powerful and the powerless means to side

Re: [cryptography] Alleged recovery of PS3 ECDSA private key from signatures

2010-12-30 Thread Jonathan Thornburg
, but there is at least one jailbreak where the crypto was directly broken: the TI-83 series of graphing calculators. The jailbreakers used a distributed factoring project to factor the 512-bit RSA keys burnt into the calculators' ROMs. (I think this counts as breaking the crypto.) -- -- Jonathan Thornburg [remove