Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Dessert Rose
May 17, 2004

awoken in control of a lucid deep dream...

(Thanks for not updating the README, I'd much rather this be left to me)

Adbot
ADBOT LOVES YOU

Dessert Rose
May 17, 2004

awoken in control of a lucid deep dream...
Wonderful. I think we all clearly agree that using emails as salt is the right way to proceed. Leave it to me, I'll work on this pull request and wrap it all in some UI magic! Watch the salt branch.

Dessert Rose
May 17, 2004

awoken in control of a lucid deep dream...
what a pretentious gently caress

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer
i'm incredibly confused by the whole approach they're taking. why is the salt attached to the actual encryption key and not tacked onto the encrypted file like an iv or something?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Dessert Rose posted:

what a pretentious gently caress

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

ultramiraculous posted:

i'm incredibly confused by the whole approach they're taking.

It is good to see your brain is properly functioning

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer
yeah i made the mistake of reading more about it. it's a train wreck top to bottom.

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer
it just hurts to try to piece everything together. it's roll-your-own-key-management that somehow manages to be both lazy and overwrought.

Workaday Wizard
Oct 23, 2009

by Pragmatica
what amazes me about the new wave of roll your own crypto is that no one bothers to write the math on paper/latex

they just plug algos into each other as if they were legos



they could be writing f-1(f(x)) and they have no idea

Miley Virus
Apr 9, 2010

Dessert Rose posted:

what a pretentious gently caress

You're telling me? I really think we're onto something great here.

bobbilljim
May 29, 2013

this christmas feels like the very first christmas to me
:shittydog::shittydog::shittydog:
I read too far down that page. Are they all complete idiots. Could they not just randomly generate the salt evry time and not even show the user????
im so mad about this thing i will never use

bobbilljim
May 29, 2013

this christmas feels like the very first christmas to me
:shittydog::shittydog::shittydog:
When u get that many idiots agreeing with each other it really makes me question my sanity

Pile Of Garbage
May 28, 2007



ChickenOfTomorrow posted:

definitely sounds like an infosec worker to me

cynicism and substance abuse are our core competencies

this but all of it

Toad King
Apr 23, 2008

Yeah, I'm the best

Shinku ABOOKEN posted:

what amazes me about the new wave of roll your own crypto is that no one bothers to write the math on paper/latex

they just plug algos into each other as if they were legos



they could be writing f-1(f(x)) and they have no idea

tbf im pretty sure they wouldn't understand what f-1(f(x)) means anyway

flakeloaf
Feb 26, 2003

Still better than android clock

Shinku ABOOKEN posted:

what amazes me about the new wave of roll your own crypto is that no one bothers to write the math on paper/latex

they just plug algos into each other as if they were legos



they could be writing f-1(f(x)) and they have no idea

encryption legorithm

Cyanide Sandwich
Oct 24, 2010

pr0zac posted:

off chance there are any non-olds in this thread the security team at facebook is doing a scholarship thing for defcon this year

so if you're a student or can convincingly pretend to be a student and want to get a thousand dollars to go to defcon and drink on facebook's dime pm me

i'd love to get in on that but i'm in america's ugly cousin canada

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

flakeloaf posted:

encryption legorithm

VAGENDA OF MANOCIDE
Aug 1, 2004

whoa, what just happened here?







College Slice

pr0zac posted:

i have no power at facebook and simply want that sweet sweet referral moneys

one of the application questions is "Provide an example of an information security project that you're particularly proud of and that relates to your future goals" which "goatseing the twitter wall" would be a quality answer for so api call girl you should probably just apply and figure out how to falsify student documentation later

score

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

flakeloaf posted:

encryption legorithm


Everything is awesome!
Everything is cool when you don't have a clue!
Everything is awesome... when you make crypto scream!

Volmarias fucked around with this message at 15:05 on Jul 24, 2014

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

flakeloaf posted:

encryption legorithm

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

flakeloaf posted:

encryption legorithm

Mods

Wait :lol:

zonar
Jan 4, 2012

That was a BAD business decision!

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

pr0zac posted:

i have no power at facebook and simply want that sweet sweet referral moneys

one of the application questions is "Provide an example of an information security project that you're particularly proud of and that relates to your future goals" which "goatseing the twitter wall" would be a quality answer for so api call girl you should probably just apply and figure out how to falsify student documentation later

I wish I could have put something that cool on mine, maybe I should have said I know the person who goatse'd the Twitter wall at RSA

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

flakeloaf posted:

encryption legorithm

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

bobbilljim posted:

When u get that many idiots agreeing with each other it really makes me question my sanity

this but everything pop-culture-related since like 1999

i'm old

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe

quote:

I think the fundamental problem is that we're trusting the user to handle key management period. Copying and pasting or transcribing 44+ character psuedorandom strings is the underlying shortcoming of the architecture, IMO.

Doing it once per recipient is annoying. Doing it once per recipient per use is broken.

It's almost like practical identity management and practical key management is the big security user experience problem we've been trying to solve for the last 30 years!

flakeloaf
Feb 26, 2003

Still better than android clock


mom won't buy me the useful bricks library so i have to make my own

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i posted this on FD a while ago but here's an interesting search

https://canary.pw/search/?q=GrenXParta

you can see when viewing 'related' that there are a lot of copycat 'dumps'

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

cool, you should now kill yourself, and please don't attempt to make any more cryptography software

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this was shared on #yossec



https://github.com/kaepora/miniLock/commit/9185536eebd1120a8889d86968b3ff3afc8df997

spankmeister
Jun 15, 2008






L

O


fuckin


L

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
ugh this encryption LEGO piece only comes in a 4x4 square and doesn't fit my bitchin' cat spaceship. I know, I'll just use a few 1x4 home brew pieces, put em here... and here and it'll work just fine :smuggo:

flakeloaf
Feb 26, 2003

Still better than android clock

BeOSPOS posted:

ugh this encryption LEGO piece only comes in a 4x4 square and doesn't fit my bitchin' cat spaceship. I know, I'll just use a few 1x3 home brew pieces, put em here... and here and it'll work just fine :smuggo:

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


Glorious

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.
ugh just make a trusted platform module that communicates via nfc and can be implanted in the user's forehead

duh

Pile Of Garbage
May 28, 2007



not so muchh a fuckup, just really kind of dumb, mlmp. the following is the mechanism which SamoaNIC use to obfuscate the contact email address on their website:

from index.dhtml:
code:
<script src="/decrypt.js" type="text/JavaScript" language="JavaScript"></script>

<script language="JavaScript"> 
<!--
document.write('<A HREF="mailto:'+ decrypt('ozcvyzuw@usmbs.au','wolqtnzfcvgumyhxibarspkjde') + '">' + decrypt('ozcvyzuw@usmbs.au','wolqtnzfcvgumyhxibarspkjde') +  '</A>');
-->
</script>
and here's decrypt.js:
code:
function decrypt(str, crypto) {

	//return str.length;
	var newstr = '';
	
	for (i = 0; i < str.length; i++) {
		if ((str.charAt(i) >= 'a') && (str.charAt(i) <= 'z')) {
			newstr = newstr + crypto.charAt(str.charCodeAt(i) - 0x61);
		}
		else {
			if ((str.charAt(i) >= 'A') && (str.charAt(i) <= 'Z')) {
				newstr = newstr + crypto.charAt(str.charCodeAt(i) - 0x41).toUpperCase();
			}
			else {
				newstr = newstr + str.charAt(i);
			}
		}
	}

	return newstr;
}
those samoans must really hate spam. it would probably help if that same email addy that they are going so far to obfuscate wasn't listed as the abuse contact on their whois records..

Wayne Knight
May 11, 2006

cheese-cube posted:

not so muchh a fuckup, just really kind of dumb, mlmp. the following is the mechanism which SamoaNIC use to obfuscate the contact email address on their website:

eh, seems like an effective way to stop an automated tool.

heh, automated tool

vOv
Feb 8, 2014

obfuscating your e-mail ityool2014 and not just letting your anti-spam software deal with it seems kind of silly

Adbot
ADBOT LOVES YOU

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind

why do Girl Scout cookies have a NIC

  • Locked thread