Tarnkappe.info · @tarnkappeinfo
2422 followers · 4834 posts · Server social.tchncs.de
Cadu Silva :vgold: · @cadusilva
393 followers · 1281 posts · Server bolha.one

🔖 VocĂȘ deveria parar de usar certificados do tipo

Os SSL protegem a conexão entre seu usuårio e seu site, mas um dos mais usados hoje em dia são do tipo RSA. Eles são pesados e vulneråveis, mas ainda estão aí por uma falsa crença sobre compatibilidade.

Se vocĂȘ puder mudar seus certificados para (), seu site demandarĂĄ menos recursos, estarĂĄ protegido e contarĂĄ com um algoritmo bem menos vulnerĂĄvel.

Nem precisa usar a configuração chamada "dual-stack", oferecendo certificados RSA e ECC ao mesmo tempo para os navegadores dos usuårios.

Veja a compatibilidade dos certificados ECC:

đŸ–„ïž Sistemas operacionais:
▫ Apple OS X: OS X 10.6
▫ Microsoft Windows: Windows Vista
▫ Red Hat Enterprise Linux 6.5
▫ iOS: iOS 7.x
▫ Android OS: 3.x
▫ Microsoft Windows Phone: 7.x

🌐 Navegadores:
▫ Apple Safari: 4
▫ Google Chrome: 1.0
▫ Microsoft Internet Explorer: 7
▫ Mozilla Firefox: 2.0

EntĂŁo a menos que vocĂȘ receba visitas de pessoas com sistemas operacionais muito antigos, nĂŁo faz sentido o gasto computacional e vulnerabilidades dos certificados SSL do seu site.

Considere na próxima renovação passar a gerar certificados ECC.

🔗 Para saber mais: alto.win/V2TPa

#ïžâƒŁ

#ssl #rsa #certificados #ecc #ecdsa #mastoadmin

Last updated 2 years ago

Heath Stewart · @heaths
174 followers · 391 posts · Server fosstodon.org

Full and support is now available in github.com/heaths/azcrypto for . I'm consider AES support, but still researching AES in . The APIs I'm familiar with in are significantly different so it may be a while, and AES is limited to anyway.

#rsa #ecdsa #azure #keyvault #golang #csharp #managedhsm

Last updated 2 years ago

Heath Stewart · @heaths
173 followers · 389 posts · Server fosstodon.org

Since the for 's philosophy is thin, mostly generated clients - which I don't disagree with - I built a client atop it much like I helped drive in our other SDK languages and wrote for the SDK for .NET: github.com/heaths/azcrypto

It's very early in development right now - supporting only sign and verify - but is an MVP enough to get some feedback from my team or anyone else who may be interested.

#azuresdk #golang #cryptography #azure #keyvault #ecdsa

Last updated 2 years ago

Soatok Dreamseeker · @soatok
3353 followers · 5239 posts · Server furry.engineer
StĂ©phane Bortzmeyer · @bortzmeyer
8176 followers · 78183 posts · Server mastodon.gougere.fr

Among the choices: or ? The later is not mandated by the RFCs.

#ecdsa #ed25519 #dnssec

Last updated 2 years ago

Dominik Schilling 🌊 · @dominik
117 followers · 17 posts · Server indieweb.social

changed their RSA SSH host key which can be the reason why any secure Git operations suddenly starting to fail.

Remove current key:
ssh-keygen -R github.com

Get new key:
ssh -T git@github.com
Confirm with yes after verifying the fingerprint with docs.github.com/en/authenticat.

Might be a good opportunity to switch to or keys.

Official announcement: github.blog/2023-03-23-we-upda

#ed25519 #ecdsa #github

Last updated 2 years ago

Julien M. · @julm
550 followers · 5341 posts · Server framapiaf.org


> : A Tale of a Novel Attack and Tears
> So, since we aren’t sipping Mojitos on a beach in some exotic location, you can tell we didn’t gain access to ’s wallet, but we recovered the private key of some wallets showing that the attack works. We only scratched the surface by looking at , , and some connections.
research.kudelskisecurity.com/
grc.com/sn/sn-914-notes.pdf

#tls #ethereum #satoshi #bitcoin #ecdsa #polynonce #cryptography #infosec

Last updated 2 years ago

nano · @nano
21 followers · 504 posts · Server social.xcess.one
Tarnkappe.info · @tarnkappeinfo
1993 followers · 4267 posts · Server social.tchncs.de
Gregory Fabre · @gregofabre
21 followers · 66 posts · Server piaille.fr
Irve · @irve
210 followers · 944 posts · Server est.social

Kas mulle tundub, vĂ”i on meie uued id-kaardid, mis ECDSA allkirja kasutavad, suhteliselt lihtsasti lekkiva privaatvĂ”tmega? St allkirjastamistarkvara poolt rĂŒnnatav, kui nonce on kontrollitav vĂ”i vĂ€ga halb.

research.kudelskisecurity.com/

#idkaart #ecdsa

Last updated 2 years ago

tkteo · @tkteo
38 followers · 1167 posts · Server infosec.exchange

sharing via infosec.exchange/@nhamiel

"In this blog post, we tell a tale of how we discovered a novel attack against ECDSA and how we applied it to datasets we found in the wild, including the Bitcoin and Ethereum networks. Although we didn’t recover Satoshi’s private key (we’d be throwing a party instead of writing this blog post), we could see evidence that someone had previously attacked vulnerable wallets with a different exploit and drained them. We cover our journey, findings, and the rabbit holes we explored. We also provide an academic paper with the details of the attack and open-source code implementing it, so people building software and products using ECDSA can ensure they do not have this vulnerability in their systems.

How Bad Is It?
In simpler words, what our attack means is that every time an ECDSA signature is generated, the signature itself gives us a relation between the nonce and the private key. If the nonces are truly randomly generated, this should never be a problem because the chance that a number of nonces picked at random fit on a low-degree polynomial recurrence relation is negligibly small.

But there is a catch: nonces are usually output by a pseudorandom number generator (PRNG) rather than being really random, and PRNGs are deterministic algorithms with relatively low complexity.

research.kudelskisecurity.com/

#encryption #ecdsa #ellipticcurve #algorithm #algorithms #bitcoin #ethereum

Last updated 2 years ago

Nathan Hamiel :2001: · @nhamiel
247 followers · 215 posts · Server infosec.exchange

Introducing , a novel attack against . Today we release the paper, a story of how we ran it against datasets like , and code so you can run the attack yourself and verify your systems aren’t vulnerable. We only scratched the surface. Enjoy. research.kudelskisecurity.com/

#polynonce #ecdsa #bitcoin

Last updated 2 years ago

Nathan Hamiel :2001: · @nhamiel
246 followers · 214 posts · Server infosec.exchange

We are dumping a bunch of research next week. I'm excited. New attack against as well as stuff and some new vuln disclosures. Is Satoshi's wallet safe??? Well, obviously, since I’m posting this and not buying Lambos for my friends and family, you get the picture. 😜

#ecdsa #ai

Last updated 2 years ago

Sherman Chow ✅ · @sherman
1 followers · 5 posts · Server mastodon.acm.org
Camille - stature de tragĂ©dien · @djayroma
297 followers · 12930 posts · Server framapiaf.org
NuSkooler · @NuSkooler
38 followers · 257 posts · Server toot.community

l33t.codes/2023/02/22/Have-My- An attempt to explain things with less lingo and with some examples.

InfoSec people can punch me if you like.

#crypto #cryptography #ecdsa #pki #somethingsomethingsec

Last updated 3 years ago

Thomas Luzat · @luzat
13 followers · 19 posts · Server infosec.exchange

Auch wenn noch nicht gebrochen ist: Wieder ein paar Zertifikate auf umgestellt. Der Support ist schon ziemlich ordentlich, nur eine reine Let's Encrypt-ECDSA-Chain könnte Probleme bereiten. Trust Stores werden viel zu selten aktualisiert.

Gleichzeitig von certbot auf lego umgestellt, womit viele DNS-Provider (bspw. fĂŒr WIldcard-Zertifikate) unterstĂŒtzt werden: go-acme.github.io/lego/install Leider nur begrenzt als Paket verfĂŒgbar (und in Debian bspw. stark veraltet und beschrĂ€nkt); andererseits kann ich mir dafĂŒr jetzt snapd auf einem System fĂŒr certbot sparen.

#rsa #ecdsa

Last updated 3 years ago

Dennis Hoppe · @dhoppe
23 followers · 67 posts · Server hachyderm.io

Finally AWS ACM offers SSL certificates based on ECDSA, but I still do not understand why they support different key algorithms for ALB and Cloudfront. For example Cloudfront only supports ECDSA with 256-bit keys.

#aws #acm #cloudfront #ecdsa

Last updated 3 years ago