OpenFortress : Cryptography weblog
Security issues surrounding digital signing and related technical issues. Target audience includes technicians working on such systems. Note that there is a security news track with more general information. Links between the announcements on that track and this one will be made when proper.
More news and weblogs related to OpenFortress
RSS 2.0 news feed for this weblog
Editors should exploit Hashes
Posted on Sun, 10 Apr 2005, 13:55.
Editors of any kind are usually aware that a file has been changed and must
be saved to disk before quitting the editor. On some occasions, this does
not make sense. And it is so easy to avoid...
Read the full article
Repairing Hashes by Wrapping them in Random Data
Posted on Wed, 16 Feb 2005, 16:16.
With the recent fall of sevaral hash algorithms, signing applications face
a serious attack. For some applications, they are left without a
well-researched hash algorithm. This article defines an approach to make
the existing hashes more reliable for signing purposes.
Read the full article
Collission attacks against SHA1
Posted on Wed, 16 Feb 2005, 09:08.
Although not formally confirmed yet, Bruce Schneier published information
that the SHA1 secure hash algorithm is prone to collision attacks.
Read the full article
Symmetric Encryption in OpenPGP under mild attack
Posted on Fri, 11 Feb 2005, 09:21.
Automated OpenPGP systems may have overlooked an issue that turns out
to be open for exploits. With a human in the chain, nothing will happen
but automated traffic handling should caution.
Read the full article
Tightening the PGP Web of Trust with "same person" statements
Posted on Sun, 06 Feb 2005, 16:58.
OpenFortress is investigating PGP's web of trust. One idea that occurred
to us is that it might be advantageous for the Web of Trust if keys of the
same owner can be considered as each other's replacements.
Read the full article
|