Tag Archives: Security

Progress on the Discrete Logarithm Problem

A team of French mathematicians and computer scientists have developed a new algorithm that makes substantial progress on certain types of discrete logarithms. The general discrete log problem is given a and b from a finite field find n also … Continue reading

Posted in General | Tagged | Leave a comment

Tor Best Practices

Over at Digital Era there’s a nice post on Tor best practices. While the Tor protocol and software are reasonably secure, you can’t use them blindly. The most recent example of what happens when you do is demonstrated by Eldo … Continue reading

Posted in General | Tagged , | Leave a comment

Phone Tracking

Matt Blaze over at Exhaustive Search has an interesting post on how law enforcement agencies track phone calls. Blaze is discussing law enforcement targeting individuals in support of criminal investigations not the wholesale dragnet surveillance of the type that the … Continue reading

Posted in General | Tagged , | Leave a comment

SSL and the NSA

If you’re a crypto-nerd or even have a passing interest, you might enjoy Matthew Green‘s post speculating on how the NSA breaks SSL. We know, courtesy of Edward Snowden’s leaked documents, that they’ve had some sort of success with SSL … Continue reading

Posted in General | Tagged , | Leave a comment

GPG/PGP Best Practices

The Privacy and Authenticity Outreach Workgroup of we.riseup.net have published an excellent list of OpenPGP Best Practices. Most Irreal readers, I trust, have already installed and configured GPG/PGP even if most of their usual correspondents haven’t. I’ve written before that … Continue reading

Posted in General | Tagged | Leave a comment

Building Password Lists

A little while ago Ars Technica published an interesting article on how password crackers build their lists of trial passwords. The TL;DR is that they scan Wikipedia, Project Gutenberg, news websites, song lyrics, IRC logs, Twitter, and other sources of … Continue reading

Posted in General | Tagged | Leave a comment

NIST and Keccak

I’m a bit of a crypto nerd—though far from a practitioner or expert—so I’m on NIST‘s SHA-3 mailing list. The mailing list’s main purpose was to keep the contestant teams and other interested observers up to date on the competition. … Continue reading

Posted in General | Tagged , | Leave a comment

More Password Advice

Stavros Korokithakis has a nice post on choosing and securing passwords. Although his recommendations won’t come as news to Irreal readers, the post is still worthwhile because he explains the reasons behind his recommendations. Even more useful—especially for your Aunt … Continue reading

Posted in General | Tagged | 3 Comments

Password Contains Invalid Characters

Nick Selby tweets a pro tip: what to do if your site delivers the error message “Password contains invalid characters”. It’s funny, of course, but like most things we find funny, it contains the germ of truth. Now, can we … Continue reading

Posted in General | Tagged | 1 Comment

Safe Password Hashing

I have written several times about the absolute necessity to properly hash passwords. The tricky part is that properly. It’s a bit subtle to get it right. Happily the folks over at Defuse Security have an excellent guide that Tells … Continue reading

Posted in General | Tagged | 1 Comment