@stf@chaos.social avatar

stf

@stf@chaos.social

https://pitchfork.ist, libopaque, https://sphinx.ctrlc.hu, pysodium, https://klutshnik.info

Look ma, I have my own page in the cryptomuseum for breaking a (legacy) NSA crypto backdoor: https://www.cryptomuseum.com/crypto/philips/px1000/stef.htm

#searchable #cypherpunk

This profile is from a federated server and may be incomplete. Browse more on the original instance.

LukaszOlejnik, to Cybersecurity
@LukaszOlejnik@mastodon.social avatar

My book 'PROPAGANDA: from disinformation and influence to operations and information warfare' treats the subject adequately, comprehensively, broadly, expertly. Information surrounds us. How does information influence work? An expert arrangement of the subject. https://blog.lukaszolejnik.com/propaganda-my-book-on-information-security/

#book #mybook #cybersecurity #propaganda #author #disinformation #informationsecurity

stf,
@stf@chaos.social avatar

@LukaszOlejnik i'm sorry, but when the author says about their own content:

> treats the subject adequately, comprehensively, broadly, expertly.

i have a weird feeling, i mean if this is a quote from an independent expert in the field, that is awesome, but without attribution? really awkward....

tynstar, to opensource
@tynstar@nerdculture.de avatar

Any experienced C developers among my followers? #BoostsWelcome.

Expat, arguably the world's most popular #XML parser, is understaffed and without funding. As #xz has shown, situations like this are dangerous.

Last month, maintainer Sebastian Pipping put up a plea for help at https://github.com/libexpat/libexpat/blob/R_2_6_2/expat/Changes

(I would help myself, but my C skills barely surpass "Hello, World".)

Found via @timbray - https://cosocial.ca/@timbray/112203547801373427

#libexpat
#SoftwareSupplyChainSecurity #OpenSource #OpenSourceMaintainer
#C

stf,
@stf@chaos.social avatar

@guusdk @tynstar @timbray @NGIZero neither sovtechfund nor nlnet fit nicely, both are about new features, not maintenance of mature projects. sadly.

stf, to random
@stf@chaos.social avatar

wow, threshold-sphinx is a thing! just managed to get a password for which the oprf key has been created by a dkg. not that we knew this is possible, sure. but now i have working code doing so! still a lot of work until this can be deployed, but it is very promising start! #sphinx #oprf #threshold #passwordmanager #nlnet #ngi0

stf, to mastodon
@stf@chaos.social avatar

is there a way on to block by a certain user? also is there a way to out retoots of posts that were previously shown already in the timeline?

edit: i suck with tags...

luis_in_brief, to random
@luis_in_brief@social.coop avatar

I have concerns about the scalability of the @sovtechfund approach, but while I'm privately concerned about STF, and other governments are loudly concerned about security, the Germans are Getting Stuff Done, or at least ported to Rust: 🤔https://floss.social/@centricular/111782862734264470

stf,
@stf@chaos.social avatar

@kurtseifried @luis_in_brief @sovtechfund ngi0/nlnet is a better solution, speaking from experience as a grantee

stf, to random
@stf@chaos.social avatar

https://wiby.me/ looks pretty cool to me, it is a searchengine indexing traditional web1.0 content, give it a try.

stf, to rust
@stf@chaos.social avatar

i demand that calc.exe be rewritten in to mitigate against any potential remote code executions and privilege escalations!

stf, to brainfood
@stf@chaos.social avatar

i watched yesterday pt1 of the new dutch #documentary that partly covers also #stuxnet being delivered by a dutch engineer Erik van Sabben. it is a weird docu, it mixes the stuxnet story with the ukraine war, and features also a weird militant cyberpolitician bart groothuis. One detail was interesting though, how someone claiming to be an informant from a dutch spy agency got into contact with the journalist, only to find out what the journalist discovered so far. maybe pt2 will be better...

stf, to random
@stf@chaos.social avatar

although some people are happy about the latest CRA version after the trilogue, Ante from @vrijschrift is not: https://www.vrijschrift.org/serendipity/index.php?/archives/265-EU-Cyber-Resilience-Act-and-the-emergence-of-proto-legislation.html

and i agree.

campuscodi, to random
@campuscodi@mastodon.social avatar

Talks from the 37th Chaos Communication Congress (37C3) security conference, which took place at the end of December in Germany, are available on YouTube.

https://www.youtube.com/playlist?list=PL_IxoDz1Nq2ZaHqsvqyBCrm8EdCTvkIxr

stf,
@stf@chaos.social avatar

@campuscodi why advertise youtube when there is a much better free and privacy respecting service that doesn't leach on everyone? pls use https;//media.ccc.de/c/37c3

stf, to random
@stf@chaos.social avatar

wow, 53.000 hours of volunteer work by angels during by a total of 4000 angels. very impressive. this is how you do an independent event. amazing.

stf, to random
@stf@chaos.social avatar

Hugo Landaus talk Adventures in Reversing Broadcom NIC FW is definitely a recommendation to watch.

stf, to random
@stf@chaos.social avatar

@cstross so good omens 3 announced, murderbot also going on the screen. when will we see bob and mo?

stf, to random
@stf@chaos.social avatar

there is some drama in land, apparently the opengpg standard is contested by gnupg author werner koch, who forked the standard into librepgp: https://blog.pgpkeys.eu/critique-critique.html

SecurityWriter, to random

deleted_by_author

  • Loading...
  • stf,
    @stf@chaos.social avatar

    @nf3xn @simonzerafa @SecurityWriter there is, it is called the Do Not Track setting, which the marketing maffia neutered

    stf, to random
    @stf@chaos.social avatar

    austrian public broadcaster is on the fediverse, in case you are into monitoring int'l news: https://orfodon.org/@ORFodon/111375092254666650

    Bing_Chris, to random
    @Bing_Chris@mastodon.social avatar

    Will the US ever truly compete with china on cyber and have the NSA create a song?
    https://youtu.be/kbBKPqOh6DU?si=VAtW_WsTIF3EQARy

    (^just discovered this amazing video from the launch of the cyberspace administration of china)

    stf,
    @stf@chaos.social avatar
    frameworkcomputer, to random
    @frameworkcomputer@fosstodon.org avatar

    Framework Laptop 16 can play games.

    Framework 16 playing pong on side led lights.

    stf,
    @stf@chaos.social avatar

    @frameworkcomputer and when will you have a keyboard with a trackpoint?

    stf, to random
    @stf@chaos.social avatar

    hey @lcamtuf i just found this https://groups.google.com/g/muc.lists.bugtraq/c/CH1RVi3TWZo from wikipedia, as the first mention of the artwork: :(){ :|:&};: - did you come up with this? if not do you know more about its history?

    stf,
    @stf@chaos.social avatar

    @lcamtuf interesting, thank you!

    fj, to random
    @fj@mastodon.social avatar

    Elon Musk has floated solving the DSA compliance problem by simply removing the app from the European Union, which only counts for 9% of daily active users.

    That would create a very segmented social media landscape with X and Threads not being able available to EU users. https://www.businessinsider.com/elon-musk-considering-taking-twitter-x-out-of-europe-dsa-2023-10?r=US&IR=T

    stf,
    @stf@chaos.social avatar

    @fj good riddance!

    gregeganSF, to random
    @gregeganSF@mathstodon.xyz avatar

    Take a 14-gon in the hyperbolic plane and join up its edges. The resulting surface is known as Klein’s quartic curve.

    KQC has 336 symmetries: any chosen one of the small triangles is taken by some symmetry into each of the 336 such triangles!

    More at:

    https://www.gregegan.net/SCIENCE/KleinQuartic/KleinQuartic.html

    A 14-gon in the hyperbolic plane wraps itself into a 3-dimensional shape, a 3-holed torus with tetrahedral symmetry. The 14-gon is divided into 56 coloured triangles (some split across the boundary of the 14-gon, until its edges join up), each of which is divided into six triangles, for a total of 336 small triangles.

    stf,
    @stf@chaos.social avatar

    @gregeganSF eldritch

    stf, to debian
    @stf@chaos.social avatar

    woohooo good news! thanks to the awesome @joostvb and some help from @NGIZero libopaque is about to be included in (and all dowstream distros, like , , and https://ftp-master.debian.org/new/libopaque_0.99.2-1.html

    it only has to pass the ftp NEW queue manual review.

    Electrospaces, to random
    @Electrospaces@mastodon.social avatar

    Mathematician Daniel Bernstein warns that the NSA may be weakening post-quantum encryption algorithms:
    https://archive.ph/zFlVi

    stf,
    @stf@chaos.social avatar

    @Electrospaces so is kyber512 a good algo? sure it is. Is it a good standard algo? possibly not if we are being strict with the original rules of the selection, it fails to be as secure as aes128 - by how much? the jury is still out there... the original rule was to be as secure, not almost as secure... also it is patented. based on those parameters it would not qualify.

    other algorithms in the selection have other benefits and other drawbacks, it's all going to be some compromise.

    stf,
    @stf@chaos.social avatar

    @Electrospaces and finally and this is my speculation:

    • does the nsa influence towards kyber because like with DES back in the days it was hardening the S-Boxes against differential cryptanalysis?
    • or is it the NSA that was weakening DES to 56 bits, and the NSA now knows something that weakens LWE-based (of which kyber is one) cryptographic algorithms?

    i guess no FOIA request will reveal this.

    but the fact that after bullrun the nsa is covertly meddling with nist is not looking peachy.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • ngwrru68w68
  • megavids
  • cubers
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • lostlight
  • All magazines