OpenFortress : Cryptography weblog

Security issues surrounding digital signing and related technical issues. Target audience includes technicians working on such systems. Note that there is a security news track with more general information. Links between the announcements on that track and this one will be made when proper.

More news and weblogs related to OpenFortress

RSS 2.0 news feed for this weblog


Editors should exploit Hashes

Posted on Sun, 10 Apr 2005, 13:55.

Editors of any kind are usually aware that a file has been changed and must be saved to disk before quitting the editor. On some occasions, this does not make sense. And it is so easy to avoid...

Read the full article



Repairing Hashes by Wrapping them in Random Data

Posted on Wed, 16 Feb 2005, 16:16.

With the recent fall of sevaral hash algorithms, signing applications face a serious attack. For some applications, they are left without a well-researched hash algorithm. This article defines an approach to make the existing hashes more reliable for signing purposes.

Read the full article



Collission attacks against SHA1

Posted on Wed, 16 Feb 2005, 09:08.

Although not formally confirmed yet, Bruce Schneier published information that the SHA1 secure hash algorithm is prone to collision attacks.

Read the full article



Symmetric Encryption in OpenPGP under mild attack

Posted on Fri, 11 Feb 2005, 09:21.

Automated OpenPGP systems may have overlooked an issue that turns out to be open for exploits. With a human in the chain, nothing will happen but automated traffic handling should caution.

Read the full article



Tightening the PGP Web of Trust with "same person" statements

Posted on Sun, 06 Feb 2005, 16:58.

OpenFortress is investigating PGP's web of trust. One idea that occurred to us is that it might be advantageous for the Web of Trust if keys of the same owner can be considered as each other's replacements.

Read the full article



 
   ------ 8< ---------- 8< ----------- 8< ------ | OpenFortress*