Thomas Ptacek

@sockpuppet.org

Full of passionate intensity.

If I was participating in a cryptography standards group and said something that caused an academic cryptographer to vocally question their support of formal methods, I would immediately take a 3 year sabbatical from computers and go work at Whole Foods or something.

Oh, ChiSec is tonight, bunch of security nerds hanging around at a bar, Kaiser Tiger on Randolph/Ogden, 7PM. No RSVPs, just show up, look for the table of nerds. Has been pretty well attended lately.

This is a fucking incredibly great bug. Ask Claude to demonstrate it for you; it'll one-shot it. For ECC signatures (at least), WolfSSL thinks a 1-byte SHA2 hash is just as good as a 32-byte hash.

Bild

None of you are giving me enough credit for not participating on the TLS working group mailing list. You're welcome. Everything I don't do, I don't do it for you.

People who hope to apply Daniel Bernstein's rules-lawyering tactics at IETF, which were honed in the DNS WGs (where he was probably in the right), would do well to remember that those tactics have consistently failed. They've merely won him standing to complain about the IETF.

Given how i am only a) a beneficiary of air travel (thanks for all the miles so far) b) A non-avionics-expert reader of the EUROCAE WG-128 RTCA/DO-254 drafts c) A spectator usually attending this type of debate with popcorn I hope my comments are useful...

For a lot of years I was in the habit of criticizing cryptography designs that used asymmetric constructions because RSA is much more complicated and hard to get right than symmetric crypto. But the real problem is that it's against the law to authenticate an RSA key.