The Limits of Cryptography [#Easterhegg #2014] #crypto #Realness ~ The Limits of Cryptography While recent events have finally made the world at large realize that the exhaustive deployment and use of cryptography throughout the Internet can no longer be deferred, there is now a good chance that people will be given a false sense of security once cryptographic support has been added and enabled. This talk points out the limitations inherent in real-world cryptography, from its underlying principles to its operation, * Preliminaries * What is IT security, and what is touted as "IT security"? * Cryptography 101---a quick refresher * Attack types---another quick refresher * The limits of cryptographic systems/algorithms * Inherent limitations * Methodologic considerations * Cryptography and performance * Cases of inherently broken algorithms * Real world crypto implementations * Inherent problems with hardware implementations * Inherent problems with software implementations * Crypto on real world computers * Crypto on real world operating systems * Crypto and applications * A history of disasters: SSL (part 1) * The problem in front of the screen * Ordinary users vs. cryptography * Presumptuous developers * Paranoia and wannabe paranoia * Cryptography and money: Histories of disasters * Banks and cryptography * SSL (part 2) * Hardware encrypted hard disks * Crypto and sales people * Lethargy (a.k.a. "pragmatism") * The pain principle * The life cycle of a crypto solution * Already deployed implementations * Legal and political aspects * When using crypto legally backfires * Who is liable for broken crypto products? * Further reading Speaker: Benedikt Stockebrand EventID: 5748 Event: Easterhegg 2014 [eh14] by the Chaos Computer Club Stuttgart Location: Kulturhaus Arena; Ulmer Straße 241; 70327 Stuttgart-Wangen; Germany Language: english Begin: Sat, 04/19/2014 20:45:00 +02:00 Lizenz: CC-by-nc-sa
How broken is TLS? [Easterhegg 2014] (by CCCen) ~ How broken is TLS? The most important crypto protocol In TLS sind in letzter Zeit zahlreiche Probleme aufgetaucht, Die BEAST- und die Lucky Thirteen-Attacke, Probleme mit RC4 und Mißtrauen gegenüber Standards aus dem Hause NSA. Wo steht TLS heute und welche Verbesserungen stehen an? TLS (früher SSL) ist das wichtigste und meistgenutzte Verschlüsselungsprotokoll. HTTPS-Verbindungen nutzen wir alltäglich zum Kommunizieren, um Geld zu überweisen oder einzukaufen. Man würde sich daher wünschen, dass TLS ein besonders sicheres Protokoll ist. Doch die Realität sieht anders aus: In den letzten Jahren sind zahlreiche Sicherheitsprobleme bekannt geworden. Das besondere an BEAST, Lucky Thirteen und anderen: Es handelt sich nicht um Softwarefehler, sondern um Fehler im Protokoll selbst. Viele der Probleme waren schon lange bekannt, die Schwäche, auf der die Lucky Thirteen-Attacke basiert, ist sogar im TLS 1.2-Standard selbst beschrieben. Die Probleme von TLS führten teils zu bizarren Situationen: Nachdem immer mehr Schwächen im CBC-Modus von TLS bekannt wurden, empfahlen Sicherheitsexperten einen Umstieg auf RC4. Als dann neue Schwächen in RC4 bekannt wurden, hieß es: Kommando zurück, RC4 ist unsicher, wir verwenden jetzt alle wieder CBC. Im Vortrag werfe ich einen Blick auf die aktueleln Probleme von TLS und mögliche Lösungsansätze. Speaker: hanno EventID: 5744 Event: Easterhegg 2014 [eh14] by the Chaos Computer Club Stuttgart Location: Kulturhaus Arena; Ulmer Straße 241; 70327 Stuttgart-Wangen; Germany Language: english Begin: Sun, 04/20/2014 15:30:00 +02:00 Lizenz: CC-by-nc-sa
© flickr
For those that are hungry for knowledge, these are feasting times. Caches of knowledge are being released all over the place. Cryptome has been releasing a collection of ebooks that are very interesting for /r/evolutionReddit.
Thank you Cryptome!
PDF WARNINGS:
- Aaron Swartz: Oxford Dictionary of Slang
- Aaron Swartz: Postcolonialism Introduction
- Aaron Swartz: End of the World Guide
- Aaron Swartz: Power Sex Suicide
- Aaron Swartz: March of Unreason
- Aaron Swartz: Global Catastrophes Introduction
- Aaron Swartz: Surviving Armageddon
- Aaron Swartz: Emerald Planet
- Aaron Swartz: Magic Universe
- Aaron Swartz: Information Society Theories
- Aaron Swartz: Democracy Inc: Totalitarianism
- Aaron Swartz: Governing Global E-Networks
- Aaron Swartz: Information Arts, Science, Tech
- Aaron Swartz: Wireless Internet Security
- Aaron Swartz: Internet Jurisdiction-Regulation
- Aaron Swartz: InfoTech Moral Philosophy
- Aaron Swartz: Thinking in Action On the Internet
- Aaron Swartz: Who Controls the Internet?
- Aaron Swartz: US-UK Spy Cooperation Post-911
- Aaron Swartz: Government Secrecy in Net Age
- Aaron Swartz: US Telecom Policy in Net Age
- Aaron Swartz: Cybercrime Principles
- Aaron Swartz: Cybersecurity Law and Economics
- Aaron Swartz: Global Transparency Perils-Promise
- Aaron Swartz: Cryptography and Complexity
- Aaron Swartz: Guerilla Open Access Manifesto
- Aaron Swartz: Marketing Rebellion (ie WikiLeaks)
- Aaron Swartz: Munitions of the Mind: Propaganda
- Aaron Swartz: Citizen Spy: TV Spying Propaganda
- Aaron Swartz: Spy Wars, Moles, Deadly Games
- Aaron Swartz: Spying Blind: CIA, FBI, 9/11
- Aaron Swartz: The Culture of Conspiracy
- Aaron Swartz: Norms in a Wired World
- Aaron Swartz: Prison State: Mass Incarceration
- Aaron Swartz: Media, Politics, Network Society
- Aaron Swartz: Internet Scientific Collaboration
- Documents Allegedly Downloaded by Aaron Swartz
- Aaron Swartz: Disposable Women of Global Capital
- Aaron Swartz: Achieving Human Rights
- Aaron Swartz: Constructing Knowledge in Networks
- USA v. Aaron Swartz Terminated
- Aaron Swartz: Managing InfoSys Emotional Intel
- Aaron Swartz: MIT Compile of Cognitive Sciences
- Aaron Swartz: Philosphy and Computing
- Aaron Swartz: Acts of Rebellion
- Aaron Swartz: Media Psychology
- Aaron Swartz: Interrogation-Confession Handbook
- Aaron Swartz: Psychology Law Truth and Lies
- Aaron Swartz: Psychology of Spying Analysis
- Aaron Swartz: Psychiatric Slavery
Other misc:
- O’Reilly donating ebook “Open Government” as a tribute to Aaron Swartz
- 18,592 scientific publications totaling 33GiB, all from Philosophical Transactions of the Royal Society and which should be available to everyone at no cost, but most have previously only been made available at high prices through paywall gatekeepers like JSTOR.
- Library Genesis
- RU Tracker (search Royal Society)
- Links scraped from Twitter hashtag #pdftribute
- Github for research. Searchable paper repository. Easy upload, perhaps with a tweet. Brought to you by a collaboration of the people behind pdftribute.net
- The Papester Collective. Need to get behind a paywall? Send a tweet.
- Open Access in Memoriam. Collecting email addresses for those interested in being a part of open access efforts going forward – based on the #pdftribute hashtag
- Operation Angel: Phase Two
- Also, if anyone is interested in helping build a P2P darknet library on retroshare, i2p and Tor – send me a PM. Basically, the aim is to build an unbreakable body of books and scientific papers accessible to all. But staying with the general eR theme of pushing darknet P2P as the final solution to a free information society.
- I also a very wildcard idea; but looking for someone who is familiar with using bots to submit to reddit.
White House Petitions:
- Remove United States District Attorney Carmen Ortiz from office for overreach in the case of Aaron Swartz.
- Fire Assistant U.S. Attorney Steve Heymann.
- Reform the Computer Fraud and Abuse Act to reflect the realities of computing and networks in 2013.
Open Access Journals:
- arXiv.org – Open access to 812,816 e-prints in Physics, Mathematics, Computer Science, Quantitative Biology, Quantitative Finance and Statistics
- arXiv Bulk Data Access
- arXiv Bulk Data Access – Amazon S3
- Open Access Journals
- DOAJ – Directory of Open Access Journals
- Science Citizen – Doing Science in Public
- DOCUMENTA MATHEMATICA
Book Collections on Tor:
This is far from over and the fight to release information from paywalls to the effective public domain has only just begun.