Financial CryptographyWhere the crypto rubber meets the Road of Finance...TLShttpd finally to be fixed for general purpose website security- June 6, 2008 Life is slowly improving with that old tired security model called secure browsing. Here's a roundup: Firefox have their new security UI in place whereby you can click on exceptions to store the certificates as accepted and trust by you (being your most important authority). There is an annoying bug where it loses the cache from time to time, and this causes the user to have to re-do the exceptions. That is being pursued in the bug channels, and will be cracked as soon as someone figures out a..https://financialcryptography.com/mt/archives/001058.html BarCampBankLondon: alternative finance workshop- June 6, 2008 Thomas Barker sends this press release: Innovators Gather in the City to Set Shape for Future of Finance Contact: Thomas BarkerEmail: tbarker(at)barcampbank..org LONDON, UK, Monday June 2nd, 2008 - On Saturday July 5th, 2008, one of the most unusual conferences in the financial services industry, BarCampBankLondon (BCBL), will get underway at 9:30 AM near the heart of the City. BCB London follows the success of previous BarCampBanks in Paris, Seattle, San Francisco, New Hampshire and New York...https://financialcryptography.com/mt/archives/001057.html Technologists on signatures: looking in the wrong place- June 3, 2008 Bruce Schneier writes about the classical technology security view and how it applies to such oddities as the fax signature. As he shows, we have trouble making them work according to classical security & tools thinking. In a 2003 paper, "Economics, Psychology, and Sociology of Security," Professor Andrew Odlyzko looks at fax signatures and concludes: Although fax signatures have become widespread, their usage is restricted. They are not used for final contracts of substantial...https://financialcryptography.com/mt/archives/001056.html Case Study 2: OpenSSL's patched-out randomness- June 1, 2008 In the aftermath of the OpenSSL failure due to a vendor patch (which bit the vendor badly...) there has been more analysis. Clearly, early attempts to describe this were flawed, and mine was no exception, as the precise failure was not well described. I did miss out on one important thing, pointed out by Philipp Gring: when doing high-sec apps, it is necessary to mix in different sources, because we should assume that the lower layers will fail. But, while necessary, it is not sufficient. We...https://financialcryptography.com/mt/archives/001055.html |