🦞🌯 Lobster Roll

Thread

On the (provable) security of TLS: Part 1 (blog.cryptographyengineering.com)

Stories related to "On the (provable) security of TLS: Part 1" across the full archive.

On the (provable) security of TLS: Part 1 (blog.cryptographyengineering.com)
The Transport Layer Security (TLS) Protocol Version 1.3 draft (tools.ietf.org)
Introducing transport layer security (TLS) in pure OCaml (openmirage.org)
Not-quite-so-broken TLS: lessons in re-engineering a security protocol (anil.recoil.org)
A TLS library implemented with modern techniques to improve security. These include a memory-safe language, pure functions where possible, type-checking protocol steps, and a DSL for easier parsing. Result is library and runtime with 73-84% of bulk performance of unsafe OpenSSL with 25x less code in...
HTTPS Interception Weakens TLS Security (us-cert.gov)
Security review of TLS1.3 0-RTT (ietf.org)
RFC 8446 - The Transport Layer Security (TLS) Protocol Version 1.3 (tools.ietf.org)
GnuTLS patches huge security hole that hung around for two years – worse than Heartbleed, says Google cryptoboffin (theregister.com)
- https://nvd.nist.gov/vuln/detail/CVE-2020-13777 - https://github.com/0xxon/cve-2020-13777
Test a TLS server on any TCP port, not just HTTPS, for config and security (testtls.com)
Infiltrate the Vault: Security Analysis and Decryption of Lion Full Disk Encryption (eprint.iacr.org)
An Empirical Study into the Security Exposure to Hosts of Hostile Virtualized Environments (taviso.decsystem.org)
Security Analysis and Decryption of OSX Lion Full Disk Encryption (eprint.iacr.org)
Android Security Overview (source.android.com)
Dropbox Has Hired Outside Experts To Investigate Possible Security Breach (techcrunch.com)
German security experts find major flaw in credit card terminals (arstechnica.com)
"The UNIX security model sucks" (apple.slashdot.org)
Dropbox security update & new features (blog.dropbox.com)
How Apple and Amazon Security Flaws Led to My Epic Hacking (wired.com)
When It Comes to Human Rights, There Are No Online Security Shortcuts (wired.com)
Schneier: The Importance of Security Engineering (schneier.com)
New security issue affecting Java SE 7 Update 7 (full JVM sandbox bypass) (seclists.org)
Azimuth Security: Poking Holes in AppArmor Profiles (blog.azimuthsecurity.com)
Critical security flaw in BIND can remotely crash server (kb.isc.org)
Identifying Website Users by TLS Traffic Analysis: New Attacks and Effective Countermeasures (hal.inria.fr)
Virgin Mobile security hole lets anyone log in to your account (kev.inburke.com)
Ruby Security Reviewer's Guide (code.google.com)
Schneier on Security: Master Keys (schneier.com)
Inside Android 4.2's powerful new security system (blogs.computerworld.com)
Security, security! But do you test it? (viva64.com)
Security Incident on FreeBSD Infrastructure (freebsd.org)