pocs/ at master · corkami/pocs
Instant (pre-computed prefix), re-usable & generic (any file pair!) MD5 collisions over different file formats. If someone were a real bastard, and got their hands on a naughty file hash database, this can wreak untold havoc
MD5  hash  collision  cryptography 
27 days ago by asteroza
Cryptology ePrint Archive: Report 2018/962 - Zexe: Enabling Decentralized Private Computation
Interesting use of zcash protocol for arbitrary computation purposes. Might enable a distributed exchange
Zcash  protocol  zero  knowledge  proof  algorithm  cryptography  research  computer  science 
october 2018 by asteroza
Cryptology ePrint Archive: Report 2018/183
zero knowledge proof-of-time for cryptocurrencies, by Bram Cohen (for use by Chia?)
cryptography  algorithm  research  zero  knowledge  proof-of-time  cryptocurrency 
august 2018 by asteroza
Home - Chia Network
Bram Cohen is working on a cryptocurrency using proof of space/time
blockchain  proof-of-space  proof-of-time  cryptography  cryptocurrency 
august 2018 by asteroza
saltpack - a modern crypto messaging format
thin wrapper around NaCl library using MessagePack format, as an alternative to PGP
encrypted  messaging  format  saltpack  cryptography  encryption  messagepack  nacl  PGP  GPG 
may 2018 by asteroza
prosthetic knowledge — FontCode Research from Columbia Computer Graphics...
Using font kerning as a form of steganography, very subtle, but with high rez pictures, can you run the reverse, checking against known fonts to detect possible steg usage, or do you have to allow for enough slop in printing and camera angle that you would get too many false positives?
FontCode  encryption  cryptography  steganography  fingerprinting  font  kerning  glyph  perturbation 
april 2018 by asteroza
Round 1 Submissions - Post-Quantum Cryptography | CSRC
Round 1 candidates for the new NIST post-quantum cryptographic algorithm contest
NIST  contest  post-quantum  post  quantum  encryption  cryptography  algorithm  research 
december 2017 by asteroza
bifurcation/treekeys: Group Keying via Trees
Looks like a PoC of the asynchronous ratcheting tree protocol in Go
encryption  cryptography  e2e  asynchronous  ratcheting  tree  protocol  messaging 
november 2017 by asteroza
BlindHash-Restoring Trust in Passwords
Password hashing security as a service (more like salt as a service), using a 16TB salt and a new blind hashing technique. Functions like a Crypto Anchor.
security  service  password  blind  hash  encryption  cryptography  salt  CryptoAnchor 
november 2017 by asteroza
Home - Hashgraph
Some sort of new distributed ledger with higher transaction throughput compared to bitcoin, doesn't seem to use either Proof of Work or Proof of Stake, and supports byzantine faults. But it seems it trades faster TPS for bad actor security, since this is vulnerable to a 1/3 bad actor ratio, compared to bitcoin's majority bad actor ratio. Also PATENTED so requires a license...
encryption  cryptography  cryptocurrency  bitcoin  blockchain  distributed  ledger  hashgraph  consensus  software 
november 2017 by asteroza
Securing customer data with KMS and Envelope Encryption in Node.js
Interesting pyramid/stacked encryption model to encrypting data with per tenant keys, but the weak point is the AWS KMS stored master key
AWS  cryptography  stacked  envelope  encryption  federated  key  rotation  security  cloud 
october 2017 by asteroza
Black Hat 2017 USA – OpenCrypto: Unchaining the JavaCard Ecosystem | Magic of Se...
Reusing JavaCard security primitives to backport/implement EC crypto where it doesn't currently exist
javacard  elliptical  curve  cryptography  backport  OpenCrypto  security  encryption  research  EMV  smartcard  java  Delicious 
may 2017 by asteroza
"Practical" attack, as in well funded corp or nation state level attack since it needs 110 GPU years...
SHA-1  practical  attack  cryptography  research  security  Delicious 
february 2017 by asteroza
Cryptology ePrint Archive: Report 2017/003
STROBE (similar to BLINKER) crypto framework for building out primitives into useful security constructs for IoT devices
IoT  cryptography  cryptographic  protocol  construct  primitive  framework  security  Delicious 
january 2017 by asteroza
roughtime - Git at Google
with the right inputs, this effectively makes a clockchain...
time  sync  synchronization  security  NTP  research  opensource  software  roughtime  cryptography 
september 2016 by asteroza
Secure Secure Shell
New SSH hardening guides based on Snowden revelations of NSA techniques/targets. Go big, go curvy, or go home.
security  SSH  configuration  guide  howto  tutorial  refence  information  encryption  sysadmin  tips  tricks  reference  hardening  config  linux  cipher  selection  key  DSA  RSA  ECDH  elliptical  curve  cryptography  ECDHE  attack  hacking  guideline  shell  Delicious 
may 2016 by asteroza
[1603.03720] Unexpected biases in the distribution of consecutive primes
Oh snap, random primes not so random. As in a given prime appears to predict attributes of the followng prime. This will not end well...
prime  number  randomness  mathematics  algorithm  research  technology  security  encryption  cryptography  Delicious 
march 2016 by asteroza
Cryptology ePrint Archive: Report 2016/008
Chaum's key escrow mix protocol system, requires unanimous vote of 9 servers to decrypt a message. In a way, a proposed "legal" crypto backdoor...
key  multikey  escrow  network  message  mix  protocol  backdoor  PrivaTegrity  security  cryptography  research  encryption  Delicious 
january 2016 by asteroza
The Untold Story of PKCS#11 HSM Vulnerabilities | Cryptosense
SafeNet Luna HSM's have secret key leakage issues, but that's a protocol issue and not necessarily an implementation issue (though one could argue that it ends up being an implementation error...)
PKCS#11  PKCS11  HSM  security  implementation  secret  key  leak  leakage  protocol  bug  error  encryption  cryptography  Delicious 
november 2015 by asteroza
Password Hashing Competition
Argon2 is like scrypt, but the implementation is simpler to formally analyze
password  hash  algorithm  Argon2  scrypt  cryptography  security  research  Delicious 
november 2015 by asteroza
The Shappening
So, why hasn't a kickstarter happened to crowdsource the $100K or so needed to crack SHA-1 on AWS and permanently put it out to pasture?
SHA1  SHA-1  collision  hash  encryption  crytography  cryptographic  algorithm  software  research  security  hacking  freestart  attack  cryptography  Delicious 
october 2015 by asteroza
