GrapheneOS, to privacy
@GrapheneOS@grapheneos.social avatar

Auditor app version 80 released:

https://github.com/GrapheneOS/Auditor/releases/tag/80

See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

Forum discussion thread:

https://discuss.grapheneos.org/d/12676-auditor-app-version-80-released

See https://attestation.app/about and https://attestation.app/tutorial for info about the app and optional monitoring service.

GrapheneOS, to privacy
@GrapheneOS@grapheneos.social avatar

Auditor app version 79 released:

https://github.com/GrapheneOS/Auditor/releases/tag/79

See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

Forum discussion thread:

https://discuss.grapheneos.org/d/12179-auditor-app-version-79-released

See https://attestation.app/about and https://attestation.app/tutorial for info about the app and optional monitoring service.

hko, to linux
@hko@fosstodon.org avatar

The new "Simple standalone Agent for cards" (https://crates.io/crates/openpgp-card-ssh-agent) is now available as a package for Linux, by the way :arch: 😏

This agent offers a frictionless UX when using ssh with keys that are stored on OpenPGP card devices: No more ongoing PIN entry required! 🚀

@dvzrv has once again done amazing packaging and documentation work! 🥳 Thank you 😃

See https://wiki.archlinux.org/title/SSH_keys#OpenPGP_card_ssh-agent for details.

hko, to linux
@hko@fosstodon.org avatar

I just released https://crates.io/crates/openpgp-card-ssh-agent version 0.3.0, a new agent for card users.

This agent makes ssh with OpenPGP card devices friction-less: No more ongoing PIN entry!

This release adds full support for Windows, based on amazing work by @wiktor 🥳

This version supports , and equally.

If anyone with a background in MacOS or Windows packaging is interested in packaging this, we'd love to hear from you!

hko, to rust
@hko@fosstodon.org avatar

I just released https://crates.io/crates/openpgp-card-ssh-agent version 0.2.4, a new agent for card users.

This version comes with substantial updates to the openpgp-card-state dependency (which handles User PIN storage for OpenPGP card devices, see https://codeberg.org/openpgp-card/state).
It now supports selecting different PIN storage backends, including one to store the User PIN directly in the config file.

PIN verification error cases are now handled more defensively

veit, to opensource
@veit@mastodon.social avatar

NetHSM – A hardware security module with open hardware and open source code: «Unlike proprietary HSM products, NetHSM is the first HSM available as open source, which enables independent security audits, easy customization and avoids vendor lock-in. Only open source allows to verify the absence of back doors.»
https://www.nitrokey.com/products/nethsm

fj, to random
@fj@mastodon.social avatar

Thales, TheGreenBow, CryptoExperts, CryptoNext Security, ANSSI, and Inria, have formed the RESQUE (RÉSilience QUantiquE) consortium. With €6 million funding from the French government and EU, the project aims to create hybrid post-quantum VPNs and high-performance hardware security modules.
https://www.thalesgroup.com/en/worldwide/security/press_release/post-quantum-cryptography-six-french-cyber-players-join-forces

hko, to rust
@hko@fosstodon.org avatar

I just released https://crates.io/crates/openpgp-card-ssh-agent version 0.2.3, a new agent for card users.

This version fixes some bugs in the handling of RSA keys.

hko, to rust
@hko@fosstodon.org avatar

I just released https://crates.io/crates/openpgp-card-ssh-agent version 0.2.2, a new agent for card users.

This release shows more output for error cases, both in the log output, and with GUI notifications.

I also published an updated version 0.0.3 of https://crates.io/crates/openpgp-card-state, which contains a low-level CLI tool to help with debugging/development. This version gives more debugging output for error cases.

hko, to rust
@hko@fosstodon.org avatar

I just released https://crates.io/crates/openpgp-card-ssh-agent version 0.2.1, a new agent for card users.

This release should fix build issues (the previous version didn't build on mac).

However, we're still exploring how secret storage works on non-Linux platforms. Expect a bumpy ride if you try it.
(If you do delve into debugging on mac or windows, we'd love to hear from you!)

hko, to rust
@hko@fosstodon.org avatar

I just released https://crates.io/crates/openpgp-card-ssh-agent version 0.2.0, an agent for card users.

It contains exciting UX changes: after one-time initial setup, no user interaction is required.

The User PIN for cards is persisted in platform-specific secret storage. For all users whose threat model allows persisting PINs on the host (presumably most), this removes pin entry.

Required touch confirmation on the card (if enabled) is signaled with desktop notifications.

kushal, to python
@kushal@toots.dgplug.org avatar
hko, to rust
@hko@fosstodon.org avatar

I just released version 0.4.2 of the https://crates.io/crates/openpgp-card low level library, and version 0.2.1 of the https://crates.io/crates/openpgp-card-sequoia wrapper.

These releases add support for cards that are configured to use "KDF mode" for PIN presentation.

Thanks to the reporters in: https://codeberg.org/openpgp-card/openpgp-card-tools/issues/43 (and to Gniibe for providing me some insights into KDF-use in Gnuk).

akaei, to Halloween

Happy !! 🎃 Ashika and I are both secretly big fans of , so we thought it’d be cute to try dressing up as Sharpay and Ryan this year!! Granted, we didn’t have all the materials, but I think we did a pretty good job 😌🎶

🎨 and ⌨️: @/commanderrcat (:twitter: :insta:)

nrohluap, to Cybersecurity
@nrohluap@ioc.exchange avatar

Started my career in cybersecurity over a dozen years ago. First assignment: fly to a client site and help deploy network HSMs. Which I had zero knowledge about.

Read the manuals on the two-hour flight. Landed as an expert 😜 Helped for two weeks, with a successful engagement and a happy client.

Today I was handed a new-to-me Yubico HSM2, and had three hours to perform and document how to stand up a new MSCA offline root with it using ECC.

Task completed 30 minutes early.

Now heading to a meeting with client to repeat the process in their environment.

Some things never change.

shaft, to random French
@shaft@piaille.fr avatar

Totally missed that information : a new for the root zone was generated during Root KSK Ceremony 49 last April. It's still a RSA 2048-bits key and it's keytag is 46211 if I read the log correctly

KSK Rollover incoming ! (in 2-3 years ^^)

https://www.iana.org/dnssec/ceremonies/49

shaft,
@shaft@piaille.fr avatar

Ah! This rollover is delayed because the manufacturer of the used by IANA (and Verisign) for the KSK management will cease production of the devices used

"There is a strong likelihood we will seek to generate a new KSK on a new HSM platform once operationalized, which will cause us to abandon the recently generated KSK"

https://mm.icann.org/pipermail/root-dnssec-announce/2023/000160.html

hko, to random
@hko@fosstodon.org avatar

Over the last half year, I've spent time with PKCS and PIV hardware security devices. In particular, using such devices in the context.

Entry points for results of this work:

One particular focus was building CI testing infrastructure (including https://gitlab.com/hkos/virtual-piv/), to make future work on these codebases easier (and hopefully fun).

@sovtechfund]

hko, (edited ) to random
@hko@fosstodon.org avatar

I added a bit of documentation to my repository of "virtual PIV hardware tokens": https://gitlab.com/hkos/virtual-piv/

(These virtual cards are useful for CI-testing of software that uses PIV devices.)

GrapheneOS, to random
@GrapheneOS@grapheneos.social avatar

We currently sign our factory images releases with the signify tool from OpenBSD. It provides tiny signatures that are easy to verify on any distribution with signify in their repositories. This is much less important than in the past because you can verify the completed install.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • kavyap
  • DreamBathrooms
  • normalnudes
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • osvaldo12
  • ngwrru68w68
  • ethstaker
  • JUstTest
  • everett
  • Durango
  • Leos
  • cubers
  • mdbf
  • khanakhh
  • tester
  • modclub
  • cisconetworking
  • anitta
  • tacticalgear
  • provamag3
  • lostlight
  • All magazines