Let's Encrypt: threat or opportunity to other certificate authorities?
Classified in : Homepage, Debian, Command line, Miscellaneous
Let's Encrypt is a certificate authority (CA) that just left beta stage, that provides domain name-validated (DV) X.509 certificates for free and in an automated way: users just have to run a piece of software on their server to get and install a certificate, resulting in a valid TLS setup.
Read more Let's Encrypt: threat or opportunity to other certificate authorities?
Signing party aux 15 ans du Crans
Classified in : Homepage, Auto-hébergement, Debian-FR, April, Pirate-FR
La célébration des 15 ans du Crans comprendra une signing party PGP et accréditation CAcert, le dimanche 20 octobre à 16h30.
XMPPloit explained
XMPPloit is an exploit tool for a so-called “flaw” in the XMPP protocol. It has been published recently under the GPLv3 license, and has received much comment. However, it does not seem anybody took the time to study this attack and explain it.
Goals
XMPPloit is designed to serve as a transparent man-in-the-middle between an XMPP client and its XMPP server, in order to force the client not to encrypt its communications, so that it is possible to read them and modify them on-the-fly.
That allows to force the client to use a clear text authentication mechanism, to display its login and password, and to modify any message it sends or receives.
Documents de vulgarisation de la cryptographie
Suite à ma conférence et séance de signature de clefs de mai, je mets à disposition deux documents :
- La présentation
- C'est une présentation, rédigée pour l'occasion, qui m'a servi de support pour cette conférence. Son contenu est probablement incompréhensible hors de la conférence, et je ne le mets à disposition qu'à titre d'exemple d'utilisation de LaTeX/Beamer.
- Un texte de vulgarisation de la cryptographie
- C'est un document d'une douzaine de pages, que j'avais rédigé il y a quelque temps et que j'ai mis à jour pour l'occasion : il a le même but et à peu près le même contenu que la conférence. Il pourra donc être utile comme rappel à ceux qui y étaient, mais également comme substitut à ceux qui n'y étaient pas.
Signing-party and crypto conference in Paris
- Content: explanations about cryptography, SSL and PGP, then signing-party
- Location: EPN la Bourdonnais, 105 avenue de la Bourdonnais, 75007 Paris
- Date: 2012-05-21 18:45+02:00
- Duration: 02:15
Monday 21st during at 18:45, in Paris, there will be a conference organized by Parinux, where I will explain the principles of cryptography and their application in the SSL and PGP systems. This conference will be followed at 20:30 by a signing-party PGP et CAcert.
For the signing-party, I will ask participants to:
- generate a key pair if you do not already have one;
- send me you public key and register;
- print some copies of your key fingerprint;
- print the list of participants I will send you;
- come with all that stuff and one or two identity documents.
This is a partial translation of the full article I wrote in French, in case foreigners could attend. Sorry for the very late notice…
page 1 of 2 next