Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
chaos.social boosted
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
@kubikpixel@chaos.social  Β·  activity timestamp 3 days ago

Simple and for a long time regularly used IT security procedure and yet this is a salting of the keys with nonce:

πŸ§‚πŸ”‘ == more security through nonce

P.S. The problem is that encryptions have to be activated for most services and many fail because they seem to have nothing to hide. Do they really care about your security?

#cybersecurity #encryption #salt #key #emojis #salting #nonce #itsecurity #pqc #itsec #keys #itsecurity #aes256 #aes #privacy #digitalCommunication #nothingtohide #myopinion

  • Copy link
  • Flag this post
  • Block
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
@kubikpixel@chaos.social  Β·  activity timestamp 3 days ago

Simple and for a long time regularly used IT security procedure and yet this is a salting of the keys with nonce:

πŸ§‚πŸ”‘ == more security through nonce

P.S. The problem is that encryptions have to be activated for most services and many fail because they seem to have nothing to hide. Do they really care about your security?

#cybersecurity #encryption #salt #key #emojis #salting #nonce #itsecurity #pqc #itsec #keys #itsecurity #aes256 #aes #privacy #digitalCommunication #nothingtohide #myopinion

  • Copy link
  • Flag this post
  • Block
don't panic boosted
Dirk SchrΓΆdter
Dirk SchrΓΆdter
@dirkschroedter@norden.social  Β·  activity timestamp 4 weeks ago

β€œWe export public money and import long-term dependency.” - This was one of my key messages in my policy keynote at the OpenForum Europe EU Open Source Policy Summit 2026 last Friday in Brussels. Besides addressing why dependencies threaten our governmental action and what state sovereignty means today, I focused particularly on the economic aspect of Open Source. #OpenSource is a #key #driver of #economic #growth. An opportunity that we in Europe should seize.

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš• and 1 other boosted
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
@kubikpixel@chaos.social  Β·  activity timestamp 7 days ago

Carelessness versus craftsmanship in cryptography

Two popular AES libraries, aes-js and pyaes, β€œhelpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. […] The aes-js/pyaes maintainer, on the other hand, has taken a more… cavalier approach.

πŸ”“ https://blog.trailofbits.com/2026/02/18/carelessness-versus-craftsmanship-in-cryptography/

#aesctr #itsecurity #key #javascript #js #iv #pyaes #cryptography #carelessness #aes #cybersecurity #cryptography #itsec #encryption #craftsmanship #reuse #fail

The Trail of Bits Blog

Carelessness versus craftsmanship in cryptography

Two popular AES libraries (aes-js and pyaes) provide dangerous default IVs that lead to key/IV reuse vulnerabilities affecting thousands of projects. One maintainer dismissed the issue, while strongSwan’s maintainer exemplified proper security response by comprehensively fixing the vulnerability in their VPN management tool.
  • Copy link
  • Flag this post
  • Block
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
@kubikpixel@chaos.social  Β·  activity timestamp 7 days ago

Carelessness versus craftsmanship in cryptography

Two popular AES libraries, aes-js and pyaes, β€œhelpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. […] The aes-js/pyaes maintainer, on the other hand, has taken a more… cavalier approach.

πŸ”“ https://blog.trailofbits.com/2026/02/18/carelessness-versus-craftsmanship-in-cryptography/

#aesctr #itsecurity #key #javascript #js #iv #pyaes #cryptography #carelessness #aes #cybersecurity #cryptography #itsec #encryption #craftsmanship #reuse #fail

The Trail of Bits Blog

Carelessness versus craftsmanship in cryptography

Two popular AES libraries (aes-js and pyaes) provide dangerous default IVs that lead to key/IV reuse vulnerabilities affecting thousands of projects. One maintainer dismissed the issue, while strongSwan’s maintainer exemplified proper security response by comprehensively fixing the vulnerability in their VPN management tool.
  • Copy link
  • Flag this post
  • Block

Kakapo Social

Kakapo Social: About Β· Code of conduct Β· Privacy Β· Users Β· Instances
Bonfire social Β· 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct