When Textbook RSA is Used to Protect the Privacy of Hundreds of Millions of Users
rsa  security  kryptographie 
february 2018 by th
Cryptology ePrint Archive
The Cryptology ePrint Archive provides rapid access to recent research in cryptology. Papers have been placed here by the authors and did not undergo any refereeing process other than verifying that the work seems to be within the scope of cryptology and meets some minimal acceptance criteria and publishing conditions.
december 2017 by grenzreiter
The ROBOT Attack - Return of Bleichenbacher's Oracle Threat
ROBOT is the return of a 19-year-old vulnerability that allows performing RSA decryption and signing operations with the private key of a TLS server.
In 1998, Daniel Bleichenbacher discovered that the error messages given by SSL servers for errors in the PKCS #1 1.5 padding allowed an adaptive-chosen ciphertext attack; this attack fully breaks the confidentiality of TLS when used with RSA encryption.
We discovered that by using some slight variations this vulnerability can still be used against many HTTPS hosts in today's Internet.
december 2017 by grenzreiter
Designing an Authentication System: a Dialogue in Four Scenes
kerberos  security  kryptographie 
june 2017 by th
You Wouldn't Base64 a Password! Cryptography Terms and Concepts for Developers
There's a ton of bad programming and security advice on the Internet. Some of the advice is bad because the author is misinformed, some because it emphasizes precision over clarity and most people wind up lost in the jargon.
kryptographie  programmieren 
december 2016 by grenzreiter
Welcome to cryptography — Cryptography 1.6.dev1 documentation
cryptography is a Python library which exposes cryptographic recipes and primitives. Our goal is for it to be your “cryptographic standard library”. If you are interested in learning more about the field of cryptography, we recommend Crypto 101, by Laurens Van Houtven.
python  kryptographie 
november 2016 by grenzreiter

