Andy_European · @Andy_European
1589 followers · 18201 posts · Server mastodon.online

Before his epic fall, Sam Bankman-Fried was hailed as a crypto genius. Some clients saw smoke and mirrors. 


nbcnews.com/news/epic-fall-sam

#ftx #cryptofail

Last updated 2 years ago

JJM_Digimedia · @JJM_Digimedia
20 followers · 115 posts · Server mas.to

vice.com/en/article/dy7epm/sam

I had totally missed that Bloomberg article mentioned here (bloomberg.com/news/articles/20)
Basically SBF is talking about a combo of bootstrap + psyops + mass histeria (aka ), and of course (because the operation needs *sustained* energy input in order to survive).

#cryptofail #cryptotrading #hodl #fomo

Last updated 2 years ago

Jens Finkhäuser 🌻 · @jens
994 followers · 6119 posts · Server social.finkhaeuser.de
Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

Was pleasantly surprised today by bugzil.la/524403 being resolved. Only to see it immediately followed up by: "Script error. Ignore." So still won't properly protect the database of locally stored passwords, and no plans change this it seems.

#firefox #cryptofail

Last updated 6 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

So somebody built an "unhackable" USB stick that would only unlock with the right iris scan and password. And then a particular USB command makes the device produce the credentials needed to unlock it, as clear text? Fascinating...

twitter.com/statuses/112638166

#cryptofail

Last updated 6 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

Dear @acebit, using AES-ECB is 𝘯𝘰𝘵 "Best possible encryption" - it's pretty broken encryption actually. Maybe you should change the way you describe ? For reference: en.wikipedia.org/wiki/Block_ci 1/5

#passworddepot #infosec #cryptofail #passwords

Last updated 6 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

He didn't check how they derive the encryption key from your password, so I took a quick look. Apparently, uses PBKDF2-HMAC-SHA1 with 1000 iterations (hardcoded). In other words, even with the rest of it all implemented flawlessly you better choose a damn strong password if file encryption should be of any use.

#7zip #crypto #cryptofail

Last updated 6 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

Michal Stanek over at Twitter did a quick look at the crypto behind file encryption. Not entirely surprisingly, what he found wasn't pleasant:

twitter.com/3lbios/status/1087

#7zip #crypto #cryptofail

Last updated 6 years ago