BitLocker Group Policy settings (Windows 10) | Microsoft Docs
Controlling whether Bitlocker offloads encryption to an SSD with SED flags. Which is kinda important after several SSD models were found to be doing YOLO encryption...
windows  BitLocker  encryption  offload  SSD  SED  GPO  AD  group  policy  software  hardware  acceleration 
november 2018 by asteroza
Intra - Apps on Google Play
Google sponsored DNS-over-HTTPS DNS query funnel/VPN app
security  privacy  DoH  DNS  HTTPS  name  query  encryption  android  app  software 
october 2018 by asteroza
LAteral Movement Encryption technique (a.k.a. The "LAME" technique)
I wonder why let's encrypt didn't isolate the internal IP range DNS entry SSL certificates to a child CA cert that enterprises could explicitly distrust, which would quash this in a heartbeat.
internal  IP  range  SSL  TLS  certificate  letsencrypt  lateral  movement  encryption  security  hacking  pentesting 
september 2018 by asteroza
experimental anonymous comms network that is trying to be traffic analysis immune, particularly near endpoints which are under local adversarial organization control (aka corp networks)
privacy  anonymity  encryption  anonymous  communications  protocol  research  software 
august 2018 by asteroza
e2e post-quantum MQTT for m2m IoT? Normally hype-tastic, but it's got real security pros. Are MQTT topics encrypted too?
MQTT  e2e  encryption  security  PQE  M2M  post-quantum  IoT 
june 2018 by asteroza
SCION Internet Architecture
Interesting, but still have misgivings about treating core providers as trusted.
e2e  encryption  network  internet  protocol  design  networking  architecture  standard  specification  concept  security 
june 2018 by asteroza
Open Quantum Safe
early testing of post-quantum encryption, including a patched fork of openSSL to play with
OpenSSL  post-quatum  encryption  algorithm  library  testing  programming  development  security  QA  softare  networking  PQE 
june 2018 by asteroza
Firefox Send
One time file send service. File lives on server for 24hrs or one download, whichever comes first. Uses clientside encryption so network DLP with SSL stripping won't easily catch it.
mozilla  firefox  selfdestruct  link  file  upload  sharing  service  encryption  DLP  bypass  security  hacking  pentesting 
may 2018 by asteroza
saltpack - a modern crypto messaging format
thin wrapper around NaCl library using MessagePack format, as an alternative to PGP
encrypted  messaging  format  saltpack  cryptography  encryption  messagepack  nacl  PGP  GPG 
may 2018 by asteroza
th-wilde/veracrypt-w10-patcher: Windows 10 media patcher for upgrading VeraCrypt encrypted systems
When doing a big upgrade of windows 10, things go bad because it uses an image install basis, and that image lacks the veracrypt driver. This script will patch the image before the update starts so update can finish cleanly while still upgrading while encrypted
veracrypt  windows  10  update  image  driver  patch  script  sysadmin  tips  tricks  security  encryption 
may 2018 by asteroza
mindedsecurity/shhlack: Slack message encryptor/decryptor for desktop app and browser
E2E for Slack, so your boss or Slack can't decrypt private messages. Also makes e-discovery more of a pain too...
e2e  encryption  security  Slack  instant  message  IM  chat  privacy 
may 2018 by asteroza
Riot – Riot – open team collaboration
A fork is now the official E2E IM client of the french government, but not for those pesky peasant citizens...
e2e  IM  instant  message  chat  france  matrix  riot  communication  encryption  messaging  opensource 
april 2018 by asteroza
prosthetic knowledge — FontCode Research from Columbia Computer Graphics...
Using font kerning as a form of steganography, very subtle, but with high rez pictures, can you run the reverse, checking against known fonts to detect possible steg usage, or do you have to allow for enough slop in printing and camera angle that you would get too many false positives?
FontCode  encryption  cryptography  steganography  fingerprinting  font  kerning  glyph  perturbation 
april 2018 by asteroza
Round 1 Submissions - Post-Quantum Cryptography | CSRC
Round 1 candidates for the new NIST post-quantum cryptographic algorithm contest
NIST  contest  post-quantum  post  quantum  encryption  cryptography  algorithm  research 
december 2017 by asteroza
So You Want to Build a P2P Twitter with E2E Encryption?
Interesting demo of end to end encryption on a peer to peer twitter clone
e2e  P2P  gun.js  encryption  chat  IM  client  demo  proof-of-concept 
december 2017 by asteroza
bifurcation/treekeys: Group Keying via Trees
Looks like a PoC of the asynchronous ratcheting tree protocol in Go
encryption  cryptography  e2e  asynchronous  ratcheting  tree  protocol  messaging 
november 2017 by asteroza
Using tor would essentially hide the endpoint from clearnet public access, while potentially being able to penetrate firewalls. IoT safe remote access, or botnet C&C usage comes to mind. Interesting proof-of-concept though.
tor  WAMP  websocket  pubsub  remote  encrypted  P2P  RPC  networking  security  encryption 
november 2017 by asteroza
BlindHash-Restoring Trust in Passwords
Password hashing security as a service (more like salt as a service), using a 16TB salt and a new blind hashing technique. Functions like a Crypto Anchor.
security  service  password  blind  hash  encryption  cryptography  salt  CryptoAnchor 
november 2017 by asteroza
cryfs/cryfs: Cryptographic filesystem for the cloud
Uses authenticated blocks, so you can't attack a block/file. Truecrypt uses unauthenticated blocks, which means any attacker can put garbage blocks in, and the user only detects it as a (silent) data corruption. But it uses GCM, so as block/nonce reuse probability goes up (and it will happen!), it gets progressively easier to break the GCM, getting even worse if some plaintext is known.
cloud  file  encryption  cryFS  filesystem  opensource 
november 2017 by asteroza
CryFS: A cryptographic filesystem for the cloud
Uses authenticated blocks, so you can't attack a block/file. Truecrypt uses unauthenticated blocks, which means any attacker can put garbage blocks in, and the user only detects it as a (silent) data corruption. But it uses GCM, so as block/nonce reuse probability goes up (and it will happen!), it gets progressively easier to break the GCM, getting even worse if some plaintext is known.
cloud  file  encryption  cryFS  filesystem  opensource 
november 2017 by asteroza
Home - Hashgraph
Some sort of new distributed ledger with higher transaction throughput compared to bitcoin, doesn't seem to use either Proof of Work or Proof of Stake, and supports byzantine faults. But it seems it trades faster TPS for bad actor security, since this is vulnerable to a 1/3 bad actor ratio, compared to bitcoin's majority bad actor ratio. Also PATENTED so requires a license...
encryption  cryptography  cryptocurrency  bitcoin  blockchain  distributed  ledger  hashgraph  consensus  software 
november 2017 by asteroza
Securing customer data with KMS and Envelope Encryption in Node.js
Interesting pyramid/stacked encryption model to encrypting data with per tenant keys, but the weak point is the AWS KMS stored master key
AWS  cryptography  stacked  envelope  encryption  federated  key  rotation  security  cloud 
october 2017 by asteroza
