Over the years, I ve discovered many techniques in learning how to design as-safe-as-possible, misuse-resistant cryptographic libraries for some fairly complex primitives, which I d like to share in the hopes that we can continue to progress the state-of-the-art in cryptography towards greater safety at decreased cost to both cryptographers and security engineers. Time permitting, I hope to…
tl;dr: This vulnerability affects GnuPG and several plugins and wrapper libraries, including Vinay Sajip s python-gnupg which I rewrote many years ago after finding a shell injection vulnerability in his code. His code is vulnerable to SigSpoof; mine isn t. Markus Brinkmann, a NeoPG developer, wrote about a recent signature spoofing vulnerability in GnuPG which carried over into several downstream…
Content Warning: rape, sexual assault, whistleblower retaliation Sarah Jeong s recent article, Vulnerabilities and exploits: what happened when the infosec community outed its own sexual predators , discusses some positive cultural changes in North America since the outings of serial rapists Jacob Appelbaum and Morgan Marquis-Boire. This post is not about those positive changes. This post is about…
tl;dr: This vulnerability is quite serious, but it doesn t affect the Tor network any more than it affects the rest of the internet. In particular, the Tor-specific attacks mentioned in the paper will not work as described. Recently, an excellent paper , entitled Off-Path TCP Exploits: Global Rate Limit Considered Dangerous, was published by Yue Cao, Zhiyun Qian, Zhongjie Wang, Tuan Dao, Srikanth…
It feels rather sardonic to say this now, openly, after two years spent alternating between trying to inhibit my rage and convince myself that I hadn t been hurt, followed by seeking out other victims, in order to develop the collective capacity to defend ourselves and to have the simple ability to speak out in a manner which would be heard and not discarded. I m Forest . Here s my story, as…
Obligatory Disclaimer: Personal or political views presented within this post absolutely do not reflect those of my employer(s), client(s), and/or legal counsel. In the final week of November 2015, a Special Agent from the Federal Bureau of Investigation, Mr. Mark Burnett, knocked on the door of my family s home and left his card, with an additional phone number penciled in. All my family members…
Previously, Matthew Garrett and I came up with an new idea for a method of local attestation. Local attestation here means: authenticating the computer that the user possesses a valid hardware token and authenticating to the user that the computer is executing the intended code, and that said code has not been tampered with. The idea is to use some NFC -enabled smart wearable device, something…
Teufelsberg — Devil s Mountain in English — is a derelict NSA listening post from the Cold War era on the outskirts of Berlin. Abandoned in the 1990s, the geodesic radio towers once abused for surveillance, now serve a much better use for street artists and German vampire films .
This is some text to get the table of images to appear only after the jump. Hackity hack. This is some text to get the table of images to appear only after the jump. Hackity hack. This is some text to get the table of images to appear only after the jump. Hackity hack. This is some text to get the table of images to appear only after the jump. Hackity hack. This is some text to get the table of…
The TSA agent had just finished running their fingers through my hair, and begun to pat down my shoulders and outstretched arms. So do you live in Washington D.C.? they asked. I shook my head, no. They asked what I was doing in the capitol. I responded, in my politest, most innocent, most mousy-little-girl voice: I m just going to talk to some of our nation s senators about my work. The TSA agent…
Using coreboot to directly initialise a Linux kernel payload UPDATED : (2014-01-13) To include corrections and additional comments from Peter. The idea behind this is to build on top of the Thinkpad hardware modifications which I mentioned in one of my last posts, and which were discussed by Peter Stuge in his recent 30c3 talk, Hardening Hardware & Choosing a #goodBIOS . Pretty much all of this…
UPDATED : 23 June, 2014 ( originally published on 5 April, 2013 ) For a long time, I couldn t figure out what Twitter was for. I m not sure I ve figured that out yet. It seems convenient for posting links to the physics and cryptography whitepapers I read, and then receiving the internet standard inane feedback from people I ve never even heard of. At one point, because I couldn t figure out what…
I recently agreed to be the maintainer for Tor s BridgeDB both the codebase and the server running the website. The poor thing needs a lot of ♥♥♥ . One of the things we want to do is start signing emails from the BridgeDB email responder. As StrangeCharm and others have been complaining that I know to much about GnuPG I blame writing this python module and that I keep that knowledge all in my…
Last week, I went to China, for the first and possibly the last time. Later, when I feel like complaining, I ll blog about the negative things, like the evidence that someone had broken into mine and another Tor developer s hotel room. As well as the tale of being followed by multiple plainclothes people through the streets of Kowloon, again with another Tor developer, down alleys, in and out of…
One of the first times I met up with Moxie while travelling, we met at a dive bar in San Francisco s Mission District, packed with hipsters. I had nineteen years, a modified state ID card, and just hitchhiked into town. We sat at the bar, and both ordered well gin and tonics. I had a proposal, the sort of get-rich-quick scheme it seems that only 18th century pirates and lazy hacker-squatters are…