home.social

#cryptographic — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cryptographic, aggregated by home.social.

fetched live
  1. Nicely played (US citizen) Sam Tunick, passing on your 'duress' PIN!!
    --
    “Imagine a security feature on your smartphone that acts like a digital self-destruct mechanism when you are forced to surrender your device. In a fascinating intersection of cybersecurity and constitutional law, a federal court case in Atlanta is bringing this exact technology into the legal spotlight.The situation unfolded when border agents demanded access to the smartphone of Samuel Tunick, a U.S. citizen returning through Hartsfield-Jackson airport. Tunick was utilizing #GrapheneOS, an advanced, privacy-focused operating system that includes a built-in countermeasure known as a duress PIN. Instead of providing his standard unlock code, he supplied this secondary PIN to the authorities. When entered, a #duress #PIN does not open the phone but instead triggers an immediate and irreversible #cryptographic wipe of all local data.Federal prosecutors have responded by charging Tunick with the intentional destruction of property to prevent a government seizure, marking an unprecedented legal test of anti-forensic security features. Tunick's defense attorneys contend that the device seizure was an unlawful pretext targeting his association with environmental activism.This trial forces the justice system to grapple with the complex reality of modern cryptography and data protection. It raises a profound question about whether employing defensive privacy mechanisms programmed into our personal devices constitutes a legitimate exercise of personal security or a criminal obstruction of law enforcement. The outcome of this clash between digital architecture and border authority could permanently redefine the boundaries of our privacy rights in the modern technological era…”
    H/T @ Prof. Ahmed Banafa
    #CivilDisobedience #firstammendment
    --
    theguardian.com/us-news/2026/j

  2. Nicely played (US citizen) Sam Tunick, passing on your 'duress' PIN!!
    --
    “Imagine a security feature on your smartphone that acts like a digital self-destruct mechanism when you are forced to surrender your device. In a fascinating intersection of cybersecurity and constitutional law, a federal court case in Atlanta is bringing this exact technology into the legal spotlight.The situation unfolded when border agents demanded access to the smartphone of Samuel Tunick, a U.S. citizen returning through Hartsfield-Jackson airport. Tunick was utilizing , an advanced, privacy-focused operating system that includes a built-in countermeasure known as a duress PIN. Instead of providing his standard unlock code, he supplied this secondary PIN to the authorities. When entered, a does not open the phone but instead triggers an immediate and irreversible wipe of all local data.Federal prosecutors have responded by charging Tunick with the intentional destruction of property to prevent a government seizure, marking an unprecedented legal test of anti-forensic security features. Tunick's defense attorneys contend that the device seizure was an unlawful pretext targeting his association with environmental activism.This trial forces the justice system to grapple with the complex reality of modern cryptography and data protection. It raises a profound question about whether employing defensive privacy mechanisms programmed into our personal devices constitutes a legitimate exercise of personal security or a criminal obstruction of law enforcement. The outcome of this clash between digital architecture and border authority could permanently redefine the boundaries of our privacy rights in the modern technological era…”
    H/T @ Prof. Ahmed Banafa

    --
    theguardian.com/us-news/2026/j

  3. #Windows and #Linux users: The deadline to update #SecureBoot keys is near

    The clock is ticking for Windows and Linux users to update #cryptographic keys that protect their systems against firmware-based #UEFI infections, a pernicious form of #malware that loads before operating system and anti-malware protections start.

    Beginning June 24, three certificates that cryptographically verify that each piece of #firmware and software that loads during system #boot will expire. The Microsoft-signed certificates are the linchpins of Secure Boot, a Microsoft-designed chain of trust. Secure Boot checks the digital signatures of all firmware that loads during system startup to ensure it originates from a trusted provider, such as the manufacturer of the #motherboard the system runs on.
    #Microsoft #security

    arstechnica.com/security/2026/

  4. #Windows and #Linux users: The deadline to update #SecureBoot keys is near

    The clock is ticking for Windows and Linux users to update #cryptographic keys that protect their systems against firmware-based #UEFI infections, a pernicious form of #malware that loads before operating system and anti-malware protections start.

    Beginning June 24, three certificates that cryptographically verify that each piece of #firmware and software that loads during system #boot will expire. The Microsoft-signed certificates are the linchpins of Secure Boot, a Microsoft-designed chain of trust. Secure Boot checks the digital signatures of all firmware that loads during system startup to ensure it originates from a trusted provider, such as the manufacturer of the #motherboard the system runs on.
    #Microsoft #security

    arstechnica.com/security/2026/

  5. Most ask you to trust the company in the middle.

    We're building a where you don't have to.

    Reposts in carry a signature across servers, so anyone can check a post is genuine without a platform vouching for it.

    Small thing, but it's the whole point. 😇

    cloudillo.org/

  6. Happy Birthday, Whitfield Diffie! Diffie received the 2015 #ACMTuringAward for inventing and promulgating both asymmetric public-key cryptography, including its application to digital signatures, and a practical cryptographic key-exchange method.

    Diffie says the counterculture of the 1960’s inspired his interest in cryptography. Watch him explain: youtu.be/d820zuDbYIg

    #ACM #Computing #TuringAward #ComputerScience #Encryption #Cryptography #Cryptographic #Pioneer #AI #Counterculture

  7. Happy Birthday, Whitfield Diffie! Diffie received the 2015 #ACMTuringAward for inventing and promulgating both asymmetric public-key cryptography, including its application to digital signatures, and a practical cryptographic key-exchange method.

    Diffie says the counterculture of the 1960’s inspired his interest in cryptography. Watch him explain: youtu.be/d820zuDbYIg

    #ACM #Computing #TuringAward #ComputerScience #Encryption #Cryptography #Cryptographic #Pioneer #AI #Counterculture

  8. 🎉 Wow, who knew #Kubernetes needed another layer of complexity? Enter #Flox, where you can now enjoy the thrill of pulling hash-pinned packages and living in fear of #cryptographic #hashes, all while pretending your deployments are suddenly faster. 🚀 Because nothing says "cutting-edge" like making your #DevOps life an even bigger nightmare. 😜
    flox.dev/kubernetes/ #complexity #HackerNews #ngated

  9. 🎉 Wow, who knew #Kubernetes needed another layer of complexity? Enter #Flox, where you can now enjoy the thrill of pulling hash-pinned packages and living in fear of #cryptographic #hashes, all while pretending your deployments are suddenly faster. 🚀 Because nothing says "cutting-edge" like making your #DevOps life an even bigger nightmare. 😜
    flox.dev/kubernetes/ #complexity #HackerNews #ngated

  10. @berniethewordsmith The main way to respect is to avoid , end-to-end encrypted content at scale. Focus on:
    - and opt-in tools for local scanning.

    - checks only for data that’s already leaving the private domain.

    - that verify matches without exposing the rest of users’ data.

  11. 🚀✨ Behold, a *groundbreaking* innovation: a "fast" #GUID #generator for Go! Because clearly, generating #random #numbers wasn't #fast enough without #cryptographic #safety. 😅 But hey, who needs actual #software #development when you can fiddle with GUIDs and call it a day! 🔒🎉
    github.com/sdrapkin/guid #groundbreaking #innovation #Go #HackerNews #ngated

  12. 🚀✨ Behold, a *groundbreaking* innovation: a "fast" #GUID #generator for Go! Because clearly, generating #random #numbers wasn't #fast enough without #cryptographic #safety. 😅 But hey, who needs actual #software #development when you can fiddle with GUIDs and call it a day! 🔒🎉
    github.com/sdrapkin/guid #groundbreaking #innovation #Go #HackerNews #ngated

  13. Did you know that #GNU/ #FSF has its own #darknet application and protocol stack?

    What is #GNUnet?

    GNUnet is an
    #alternative #network stack for building #secure, #decentralized and #privacy-preserving #distributed applications. Our goal is to replace the old insecure Internet protocol stack. Starting from an application for secure #publication of #files, it has grown to include all kinds of basic protocol components and applications towards the creation of a GNU internet.

    Today, the actual use and thus the social requirements for a global network differs widely from those goals of 1970. While the Internet remains suitable for military use, where the network equipment is operated by a command hierarchy and when necessary isolated from the rest of the world, the situation is less tenable for civil society.

    Due to fundamental Internet design choices, Internet traffic can be misdirected, intercepted, censored and manipulated by hostile routers on the network. And indeed, the modern Internet has evolved exactly to the point where, as Matthew Green put it, "the network is hostile".

    We believe liberal societies need a
    #network #architecture that uses the #anti-authoritarian #decentralized #peer-to-peer paradigm and #privacy-preserving #cryptographic #protocols. The goal of the GNUnet project is to provide a Free Software realization of this ideal.
    https://www.gnunet.org/en/index.html

  14. 𝗗𝘆𝗻𝗲 💜 𝗦𝗽𝗵𝗶𝗻𝘅

    SPHINX is a simple, elegant, & unconditionally secure zero-trust password manager. It stores a random numbers, not your password, ensuring the server knows nothing. Free, offline-bruteforce resistant, self-hostable, and extensible.

    Built on a well-studied #cryptographic algorithm by respected experts, SPHINX brings password management into the 21st century.

    𝗜𝗻 𝗳𝗮𝗰𝘁 𝘄𝗲 𝗹𝗼𝘃𝗲 𝗶𝘁 𝘀𝗼 𝗺𝘂𝗰𝗵 𝘁𝗵𝗮𝘁 𝘄𝗲 𝗮𝗿𝗲 𝗵𝗼𝘀𝘁𝗶𝗻𝗴 𝗮 𝗽𝘂𝗯𝗹𝗶𝗰 𝘀𝗲𝗿𝘃𝗲𝗿!

    🔗 sphinx.pm/servers.html

    #PasswordSecurity

  15. 𝗗𝘆𝗻𝗲 💜 𝗦𝗽𝗵𝗶𝗻𝘅

    SPHINX is a simple, elegant, & unconditionally secure zero-trust password manager. It stores a random numbers, not your password, ensuring the server knows nothing. Free, offline-bruteforce resistant, self-hostable, and extensible.

    Built on a well-studied #cryptographic algorithm by respected experts, SPHINX brings password management into the 21st century.

    𝗜𝗻 𝗳𝗮𝗰𝘁 𝘄𝗲 𝗹𝗼𝘃𝗲 𝗶𝘁 𝘀𝗼 𝗺𝘂𝗰𝗵 𝘁𝗵𝗮𝘁 𝘄𝗲 𝗮𝗿𝗲 𝗵𝗼𝘀𝘁𝗶𝗻𝗴 𝗮 𝗽𝘂𝗯𝗹𝗶𝗰 𝘀𝗲𝗿𝘃𝗲𝗿!

    🔗 sphinx.pm/servers.html

    #PasswordSecurity

  16. But cryptography is hard. Until recently, institutions and individuals who need to run #cryptographic operations had to rely on specialists to review the code that their applications is running. Cryptography can protect our privacy and authenticate sources of important information. For #cryptography to work for the people, the people need to understand it.

  17. But cryptography is hard. Until recently, institutions and individuals who need to run #cryptographic operations had to rely on specialists to review the code that their applications is running. Cryptography can protect our privacy and authenticate sources of important information. For #cryptography to work for the people, the people need to understand it.

  18. The #chatmail #fosdem talk from @compl4xx is public. It goes into topics such as

    - why chatmail servers?
    - how to setup a server with your child
    - (avoiding) spam filtering
    - metadata and guaranteed end to end encryption in #deltachat
    - #cryptographic #interoperability for email message routing

    Thanks to attendees for the great energy even if was the last talk on the day and also for questions and conversations afterwards!

    ftp.fau.de/fosdem/2025/k4601/f

  19. The #chatmail #fosdem talk from @compl4xx is public. It goes into topics such as

    - why chatmail servers?
    - how to setup a server with your child
    - (avoiding) spam filtering
    - metadata and guaranteed end to end encryption in #deltachat
    - #cryptographic #interoperability for email message routing

    Thanks to attendees for the great energy even if was the last talk on the day and also for questions and conversations afterwards!

    ftp.fau.de/fosdem/2025/k4601/f

  20. → Chinese researchers break #RSA encryption with a #quantum computer
    csoonline.com/article/3562701/

    “In a potentially alarming development for global #cybersecurity, Chinese researchers have unveiled a method […] to #crack classic #encryption, potentially accelerating the timeline for when quantum computers could pose a real #threat to widely used #cryptographic systems”

    “data being encrypted today could be at risk if adversaries are stealing it with the intention of decrypting it in the future”

  21. → Chinese researchers break #RSA encryption with a #quantum computer
    csoonline.com/article/3562701/

    “In a potentially alarming development for global #cybersecurity, Chinese researchers have unveiled a method […] to #crack classic #encryption, potentially accelerating the timeline for when quantum computers could pose a real #threat to widely used #cryptographic systems”

    “data being encrypted today could be at risk if adversaries are stealing it with the intention of decrypting it in the future”

  22. Scientists in #China use #quantum computers to crack military-grade #encryption — quantum attack poses a "real and substantial threat" to #RSA and #AES. According to a report published by the SCMP, the researchers utilized a #DWave #quantumcomputer to mount the first successful quantum attack on widely used #cryptographic algorithms.
    tomshardware.com/tech-industry

  23. Scientists in #China use #quantum computers to crack military-grade #encryption — quantum attack poses a "real and substantial threat" to #RSA and #AES. According to a report published by the SCMP, the researchers utilized a #DWave #quantumcomputer to mount the first successful quantum attack on widely used #cryptographic algorithms.
    tomshardware.com/tech-industry

  24. #YubiKeys Are a #Security Gold Standard—but They Can Be Cloned

    Security researchers have discovered a #cryptographic flaw that leaves the #YubiKey 5 vulnerable to attack.
    #privacy

    wired.com/story/yubikey-vulner

  25. #YubiKeys Are a #Security Gold Standard—but They Can Be Cloned

    Security researchers have discovered a #cryptographic flaw that leaves the #YubiKey 5 vulnerable to attack.
    #privacy

    wired.com/story/yubikey-vulner

  26. @jpl - Good points, but specifically your last point is indeed rather concerning. Thankfully, there is RADIUS over #TLS, which is probably anyway a good idea. Perhaps this will be an incentive to prioritize the deployment of RADIUS over TLS, which enforces modern #cryptographic #security guarantees.

  27. @jpl - Good points, but specifically your last point is indeed rather concerning. Thankfully, there is RADIUS over #TLS, which is probably anyway a good idea. Perhaps this will be an incentive to prioritize the deployment of RADIUS over TLS, which enforces modern #cryptographic #security guarantees.

  28. Acoustic Attacks: An Emerging Threat

    Recent research has unveiled a new frontier in #cryptographic #vulnerabilities: acoustic attacks.

    These side-channel attacks exploit the sound or vibrations produced during cryptographic operations to infer sensitive information.

    Notable examples include:

    1. Acoustic Cryptanalysis: Extracting RSA keys by analyzing sound patterns during decryption
    2. Keynergy: Inferring key codes from the sound of key insertions in pin tumbler locks

  29. #Cryptographic #Research 🔐

    • Circuit complexity
    • Elliptic curve cryptography
    • Lightweight cryptography
    • Pairing-based cryptography
    • Post-quantum cryptography
    • Privacy-enhancing cryptography

  30. invites you to join co-located event "Logos Assembly Brno" with Logos core contributor Vaclav Pavlin. Join the discussion topics technical and philosophical – from the ethos of the to the latest in research – in relaxed surroundings with food, drinks, and stimulating discussions.

    📍Students Club, @FIT_VUT
    🗓️ June 13, 6:00PM

    👆Registration is required: pretalx.com/devconf-cz-2024/ta

  31. #DevConf_CZ invites you to join co-located event "Logos Assembly Brno" with Logos core contributor Vaclav Pavlin. Join the discussion topics technical and philosophical – from the ethos of the #cypherpunks to the latest in #cryptographic research – in relaxed surroundings with food, drinks, and stimulating discussions.

    📍Students Club, @FIT_VUT
    🗓️ June 13, 6:00PM

    👆Registration is required: pretalx.com/devconf-cz-2024/ta

  32. #PuTTY #SSH client flaw allows recovery of #cryptographic #private keys

    bleepingcomputer.com/news/secu

    > A vulnerability tracked as CVE-2024-31497 in PuTTY 0.68 through 0.80 could potentially allow attackers with access to 60 cryptographic signatures to recover the private key used for their generation.

  33. #PuTTY #SSH client flaw allows recovery of #cryptographic #private keys

    bleepingcomputer.com/news/secu

    > A vulnerability tracked as CVE-2024-31497 in PuTTY 0.68 through 0.80 could potentially allow attackers with access to 60 cryptographic signatures to recover the private key used for their generation.

  34. #PuTTY #SSH client flaw allows recovery of #cryptographic #privatekeys
    The vulnerability (CVE-2024-31497) was discovered by Fabian Bäumer and Marcus Brinkmann of the Ruhr University Bochum and is caused by how PuTTY generates #ECDSA nonces (temporary unique cryptographic numbers) for the NIST P-521 curve used for SSH authentication. The main repercussion of recovering the private key is that it allows unauthorized access to SSH servers or sign commits as the developer.
    bleepingcomputer.com/news/secu

  35. #PuTTY #SSH client flaw allows recovery of #cryptographic #privatekeys
    The vulnerability (CVE-2024-31497) was discovered by Fabian Bäumer and Marcus Brinkmann of the Ruhr University Bochum and is caused by how PuTTY generates #ECDSA nonces (temporary unique cryptographic numbers) for the NIST P-521 curve used for SSH authentication. The main repercussion of recovering the private key is that it allows unauthorized access to SSH servers or sign commits as the developer.
    bleepingcomputer.com/news/secu

  36. The important role #OpenSSL plays in securing the Internet has never been matched by the financial resources devoted to maintaining it.
    The open source #cryptographic #software library secures hundreds of thousands of Web servers and many products sold by multi-billion-dollar companies,
    but it operates on a shoestring budget.
    OpenSSL Software Foundation President Steve Marquess wrote in a blog post last week that OpenSSL typically receives about $2,000 in donations a year
    and has just one employee who works full time on the open source code.

    Given that, perhaps we shouldn’t be surprised by the existence of #Heartbleed, a security flaw in OpenSSL that can expose user passwords and the private encryption keys needed to protect websites.

    OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code.
    Chief among them is probably the #Linux operating system #kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies.
    Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.
    That’s never been the case with OpenSSL, but the Linux Foundation wants to change that.
    ⭐️The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects⭐️
    —with OpenSSL coming first.
    Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit 💥at least $100,000 a year for at least three years💥 to the “#Core #Infrastructure #Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.
    To be clear, the money will go to multiple open source projects
    —OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million.
    The initiative will identify important open source projects that need help in addition to OpenSSL.

    arstechnica.com/information-te

  37. The important role #OpenSSL plays in securing the Internet has never been matched by the financial resources devoted to maintaining it.
    The open source #cryptographic #software library secures hundreds of thousands of Web servers and many products sold by multi-billion-dollar companies,
    but it operates on a shoestring budget.
    OpenSSL Software Foundation President Steve Marquess wrote in a blog post last week that OpenSSL typically receives about $2,000 in donations a year
    and has just one employee who works full time on the open source code.

    Given that, perhaps we shouldn’t be surprised by the existence of #Heartbleed, a security flaw in OpenSSL that can expose user passwords and the private encryption keys needed to protect websites.

    OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code.
    Chief among them is probably the #Linux operating system #kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies.
    Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.
    That’s never been the case with OpenSSL, but the Linux Foundation wants to change that.
    ⭐️The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects⭐️
    —with OpenSSL coming first.
    Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit 💥at least $100,000 a year for at least three years💥 to the “#Core #Infrastructure #Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.
    To be clear, the money will go to multiple open source projects
    —OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million.
    The initiative will identify important open source projects that need help in addition to OpenSSL.

    arstechnica.com/information-te