@atoponce@fosstodon.org
@atoponce@fosstodon.org avatar

atoponce

@atoponce@fosstodon.org

MSCSIA, cryptography, security, locksport, Linux, programming, mathematics, amateur radio, Buddhism, running, anime, and bibliophilia.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

atoponce, to random
@atoponce@fosstodon.org avatar

Did you know the has its own password, passphrase, and key generator?

For passphrases, instead of using a popular word list like Diceware or EFF, it ships its own.

Do you trust it? 😉

Cc: @schlink

https://github.com/nsacyber/RandPassGenerator

atoponce, to random
@atoponce@fosstodon.org avatar
atoponce, to random
@atoponce@fosstodon.org avatar

I always get a kick out of off-brands in . It's always something I'm looking for.

Here we have a "Macrosoft Winding XO" laptop with a 128-bit DES encrypted password.

Sounds about right.

image/png

atoponce, to random
@atoponce@fosstodon.org avatar

Solid criticism of , specifically how Apple is rolling them out to macOS and iOS users.

TL;DR- passkeys behave like SSH keys, but without the transparency. Further, Apple iCloud can't be trusted to handle them correctly.

https://lapcatsoftware.com/articles/2023/5/1.html

atoponce, to linux
@atoponce@fosstodon.org avatar

Tired: RAID5/6
Wired: RAIDZ1/2/3
Hired: dRAID1/2/3
Mired: Btrfs

atoponce,
@atoponce@fosstodon.org avatar

Good article on why the industry needs triple-parity RAID ("RAID7"):

https://queue.acm.org/detail.cfm?id=1670144

atoponce, to random
@atoponce@fosstodon.org avatar

I just learned that will automatically and correctly clamp any private 32-byte key.

For example:

$ openssl rand -base64 32
tx6Kwv9L17ARq8WOd0M3sjm8gKU8bmdoSeBoGTzyEyY=

Even though the first and last bytes are not properly clamped above, when generating the public key, the wg(8) tool will clamp it. Further, when bringing up the interface, Wireguard will also clamp it.

See https://git.zx2c4.com/wireguard-tools/tree/src/genkey.c and https://git.zx2c4.com/wireguard-linux/tree/drivers/net/wireguard/noise.c (search for "curve25519_clamp_secret")

atoponce, to random
@atoponce@fosstodon.org avatar

I'll take this further. When was the last time you actually burned a CD or DVD?

https://infosec.exchange/@barsteward/110310436841721673

barsteward, to random

When was the last time you actually used a floppy disk?

atoponce,
@atoponce@fosstodon.org avatar

@barsteward 2001. I had a Java development class in university where the professor was adamant about turning homework in on floppy disks.

Even in 2001, my laptop did not have a floppy drive. I tried countering with a USB drive or a ZIP file emailed, but he would have none of it. Floppy, or 1/3 of the points deducted.

atoponce, to linux
@atoponce@fosstodon.org avatar

Be offended all you want, but it's true.

atoponce, to random
@atoponce@fosstodon.org avatar

It's kind of hilarious to me how toxic the word "telemetry" has become. Don't get me wrong, the ad tracking industry has ruined it for everyone. However

Firefox users: Disable telemetry! It's an enemy to your privacy!
Mozilla: We removed a feature no one was using due to a lack of telemetry data.
Firefox users: I use it all the time! Why are you bad at this!

1Password users: I trust AgileBits to safely handle my data.
AgileBits: We added telemetry.
1Password users: Why do you hate my privacy?!

atoponce, to internet
@atoponce@fosstodon.org avatar

Terms of Service gives Jack a 'perpetual' & 'irrevocable' license to all your content.

https://threadreaderapp.com/thread/1651686218319425570.html

atoponce, to linux
@atoponce@fosstodon.org avatar
atoponce, to linux
@atoponce@fosstodon.org avatar

Debian 12 "Bookworm" is scheduled to release the day after my birthday.

https://lists.debian.org/debian-devel-announce/2023/04/msg00007.html

atoponce, to random
@atoponce@fosstodon.org avatar
craigmaloney, to random

I really, really, really wish that Ubuntu / Debian could collate all of the "needs attention" changes between local modified files and maintainer files so things don't grind to a halt at odd intervals.

(Note: Not the opportunity to tell me anecdotes or how other distros do it different / better. Just a rant. Nothing more.)

atoponce,
@atoponce@fosstodon.org avatar

@craigmaloney Do you have an example?

atoponce, to random
@atoponce@fosstodon.org avatar

If your phone has a Qualcomm chipset, it might be spying on you. Unfortunately, this is happening at the firmware level, beneath iOS and Android.

#privacy

https://www.nitrokey.com/news/2023/smartphones-popular-qualcomm-chip-secretly-share-private-information-us-chip-maker

atoponce,
@atoponce@fosstodon.org avatar

@cryptgoat Yeah. It reads like an advertisement for Nitrophone. For the time being, I'm willing to give them the benefit of the doubt, but I'm also holding the article at arms length. I'm curious to see if the domain shows up in my DNS logs.

atoponce,
@atoponce@fosstodon.org avatar

@cryptgoat GrapheneOS has an opinion about the article. TL;DR, it's sensationalized to sell Nitrophones.

https://old.reddit.com/r/privacy/comments/12yii9u/german_security_company_nitrokey_proves_that/jhojlr7/

atoponce,
@atoponce@fosstodon.org avatar

@HistoPol I don't know offhand. If you find something, let me know. I'm curious also.

atoponce, to infosec
@atoponce@fosstodon.org avatar

Unpopular opinion: don't pre-hash bcrypt. It complicates your code and exposes you to foot-guns. Just limit your input to 72 bytes.

https://www.reddit.com/r/cryptography/comments/12zfqua/i_read_that_bcrypt_is_a_slow_enough_hashing/jhs2c0l/

atoponce,
@atoponce@fosstodon.org avatar

@davep Even if you're migrating algorithms, you can do that without pre-hashing. Just update it on next login:

  1. User supplies password.
  2. Service verifies SHA-256 hash.
  3. Service hashes user password with bcrypt.
  4. Service replaces SHA-256 hash with bcrypt hash.
atoponce, to random
@atoponce@fosstodon.org avatar

PSA: KeePass and KeePassXC are different software applications. Please don't refer to KeePassXC as "KeePass".

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

deleted_by_author

  • Loading...
  • atoponce,
    @atoponce@fosstodon.org avatar

    @GossiTheDog Do they run Arch BTW? 🙃

    atoponce, to random
    @atoponce@fosstodon.org avatar

    For those still on Twitter, you can write 2 simple uBlock Origin config lines to hide all Twitter Blue accounts from your timeline, including promoted ads.

    https://twitter.com/netrunnernobody/status/1649863487651303424

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • cubers
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • InstantRegret
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • modclub
  • normalnudes
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • anitta
  • megavids
  • cisconetworking
  • lostlight
  • All magazines