You are here |
blog.cryptographyengineering.com | ||
| | | |
negativesign.com
|
|
| | | | This one hits close to home. I can't imagine how the NIST staff involved in creating SP 800 (and more specifically, the SP 800-90A Dual Elliptic Curve Deterministic Random Bit Generation...bit) must feel. First of all, given the definition of a deterministic system, the title itself gives me pause. Maybe there's some next-level random number theory described in the standard, but I'm not sure I'd ever want a random number generator to exhibit deterministic behavior. | |
| | | |
littlemaninmyhead.wordpress.com
|
|
| | | | After doing hundreds of security code reviews for companies ranging from small start-ups to large banks and telcos, and after reading hundreds of stack overflow posts on security, I have composed a list of the top 10 crypto problems I have seen. Bad crypto is everywhere, unfortunately. The frequency of finding crypto done correctly is | |
| | | |
gavinhoward.com
|
|
| | | | There is controversy on the NIST's post-quantum selections, and I have some thoughts. | |
| | | |
blog.qasource.com
|
|
| | Read this blog to understand the most important trends in network penetration testing in improving security and why to partner with QASource. |