Skip to content
I T S S
  • Welcome
  • Hardware
  • Internet
  • Networking
  • Security
  • Data Recovery
  • Support
  • Contact
  • Webmail

A Nice Little Cryptography Primer

By itss | 28/06/2021
0 Comment

Pun Intended.

Category: Technology
Post navigation
← pfSense / Wireguard / Bad Code / Close Call Why Quake3 was so fast : Fast Inverse Square Root →

Recent Posts

  • Hardware Exploits?
  • Why Quake3 was so fast : Fast Inverse Square Root
  • A Nice Little Cryptography Primer
  • pfSense / Wireguard / Bad Code / Close Call
  • Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur)

Slashdot

News for nerds

  • Ring Says New Encryption Limits What It Can Give Police
    by BeauHD on 27/08/2026 at 9:00 pm

    Ring is rolling out a new default encryption system called TAKE, or "Throw Away the Key Encryption," that rotates video keys every five minutes and permanently deletes Ring's copy after 24 hours. The system is designed to preserve cloud features such as smart alerts and AI video search while limiting what Ring can provide under legal process to non-video account information and encrypted footage. The Verge reports: Ring says TAKE uses unique, rotating encryption keys for your footage, stored in a secure enclave and accessible only under strict conditions -- based on the features you enable on your account. Currently, footage captured by Ring cameras is encrypted in transit to the cloud and at rest, and then decrypted for Ring to process for those smart features. With TAKE, the encryption keys change for every five minutes of footage. Ring stores copies of those keys to decrypt the footage, but throws away each copy within 24 hours, "leaving you with the keys and full control of your videos," according to Ring. TAKE was developed using Messaging Layer Security, an open standard from the Internet Engineering Task Force, according to Ring. The company says it is "inspired by the privacy principles of E2EE (end-to-end encryption)," which Ring offers on some of its cameras. However, the two systems work differently. With E2EE, Ring never has the keys and can't process your video for cloud-based features. Both options are available on newer cameras that encrypt on-device, and you can switch between the two. Older cameras encrypt at cloud ingress and only support TAKE. According to a white paper the company published today, Ring's copy of those keys is managed inside an AWS Nitro Enclave, to which Ring's access is restricted by "access controls, cryptography, and hardware isolation." The company claims there is no persistent storage and no way for a Ring employee to access it. The stored keys can only be unlocked by the enclave through cryptographic attestation that proves it's running the exact software image Ring approved. The enclave releases a temporary key when an enabled service requests it. When asked about what happens if Ring is subpoenaed by law enforcement, a spokesperson for the company said: "Where TAKE is enabled, Ring will only be able to provide non-video information (such as basic subscriber information) and encrypted video files in response to the valid legal process. We have updated our Law Enforcement Guidelines to reflect this change." Read more of this story at Slashdot.

  • Claude, Codex, and Hermes Installed Unowned Code Inside Corporate Networks
    by BeauHD on 27/08/2026 at 8:08 pm

    An anonymous reader quotes a report from Ars Technica: Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents [including Claude, OpenAI's Codex, and Nous Research's Hermes]. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware. The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site's content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here. "The trust model is broken," Alon Hertz, one of the researchers, wrote in an interview. "Agents treat vendor docs as ground truth and don't question them -- and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer -- SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today's guards don't cover it." "An agent doesn't distinguish between a page and a command," the researchers wrote Thursday. "Everything it reads is input, and every input is a potential instruction. Which means the entire corpus of published data that agents are now wired to consume has silently become an execution surface -- and almost none of it carries the integrity guarantees we apply to actual code." Read more of this story at Slashdot.

  • Trump Declares National Emergency to Ban Some Foreign Grid Equipment
    by BeauHD on 27/08/2026 at 7:00 pm

    Longtime Slashdot reader dhartshorn writes: Foreign-produced "bulk power" equipment is now effectively banned, and the list of what constitutes such equipment is essentially everything used to make up the grid... much of which we are heavily dependent on foreign sources to supply. In a Wednesday executive order, President Trump said foreign supply of electric equipment "constitutes an unusual and extraordinary threat" to national security. The Hill reports: Under the order, it will be up to Energy Secretary Chris Wright, in coordination with other officials, to determine whether a piece of equipment poses an issue. The order could impact a wide range of equipment, including substations, transformers, batteries used for energy storage, generators, turbines, software and more. It does not lay out specific threats or single out any country by name. [...] Under the last Trump administration, the president put a similar order in place. The new order comes amid several reported cyberattacks on U.S. water systems, which officials suspect have links to Iran, according to The New York Times. Read more of this story at Slashdot.

  • Panic Passes Trump Tariff Refunds Back to Playdate Customers
    by BeauHD on 27/08/2026 at 6:00 pm

    Panic is refunding Playdate customers the 19% tariff charges it passed along while the Trump administration's import duties were in effect, after the Supreme Court ruled the tariffs illegal and the company began receiving refunds from the government. Panic says the money "just [wasn't] ours to keep." Ars Technica reports: In an update posted on the Playdate help site this week, Panic noted that it has finally "begun to receive refunds of the tariffs we paid in the last year" and had consequently "refunded all tariffs charged to customers." In the initial version of that tariff note, Panic explained that it couldn't afford to simply "absorb" the 19 percent tariffs it was being charged to import Playdate hardware made overseas because "our margins on Playdate are low." As such, while the tax was in effect, it was passed along to customers as an explicit subtotal line item at the bottom of all Playdate orders. That's in contrast to companies like Nintendo, which vaguely cited "market conditions" and tariff "uncertainty" in raising the asking price of legacy hardware and some Switch 2 accessories last year. Speaking to Game Developer, Panic co-founder Cabel Sasser said filing paperwork to claw back these taxes and processing tariff refunds for customers took a fair bit of backend work. Still, he said returning that money to Playdate purchasers in the end was a no-brainer. "It's just not our money to keep, and it felt really good to give it back," Sasser said. "That's an easy way to know you made the right decision." "It just felt like the right thing to do," Panic wrote in a refund email message shared on Reddit. Read more of this story at Slashdot.

  • Nvidia Agrees to Acquire Hugging Face For $13 Billion
    by BeauHD on 27/08/2026 at 5:00 pm

    The Information reported on Wednesday that Nvidia has agreed to buy open-source platform Hugging Face for $12.9 billion. "Deal talks began after Hugging Face, an open-source AI platform developers use to collaborate, test and share tools, received acquisition interest from another suitor," reports CNBC, citing the (paywalled) report. Business Insider separately reported the acquisition talks. From CNBC: If completed, the acquisition would put one of the most widely used platforms for sharing and working with open-source AI models under Nvidia's ownership, expanding the chipmaker's reach further into the software and model ecosystem. Siddy Jobe, a fund manager at Eonopolis Exponential Technologies funds, said it made sense for Nvidia to target a company like Hugging Face, as Nvidia has made it clear that it is not looking to discriminate between closed and open-source models. "I think Nvidia is very much a community, a platform-based company, and in that respect, I think Hugging Face fits perfectly within that. There is this five-layer cake from Nvidia, and foundational models are one of them," Jobe told CNBC's Squawk Box Europe on Thursday. "It is clear that Nvidia wants to be integrated in the entire stack vertically, going from energy to foundational models and also to applications," he added. Read more of this story at Slashdot.

  • Operation Bluebird Launches New Twitter
    by BeauHD on 27/08/2026 at 4:00 pm

    An anonymous reader quotes a report from Ars Technica: Operation Bluebird, the Virginia-based startup trying to revive the allegedly abandoned "Twitter" name and logo, announced Monday that it has launched its new social media network: Twitter.now. "We are a small company, we have investors, and we have a product," Stephen Coates, one of Operation Bluebird's cofounders, told Ars. "And we have waited months and months to launch, and we are not going to wait anymore." [...] Twitter.now, still in its nascent stage, only has hundreds of users for the time being. The social media network looks and feels much like the Twitter of old and many of its offshoots -- it has replies and retweets. A new and notable feature is the automated fact-checking tool, a Gemini-based "veracity engine for real-time analysis" ("Vera" for short), which runs on every tweet. Coates has been testing Vera in recent days by posting obviously false messages, like "George Washington was our second president." "Our first goal is to see if we can truly bring back a town square that's safer and less harmful," he said. "We say freedom of speech and not freedom of reach. We want people to say what they want, but we also want to create a platform that's not financially locked into that viral content that's harmful or inaccurate." Operation Bluebird argues that Elon Musk effectively abandoned the Twitter brand and trademarks when he renamed the company X, opening the door for the startup to claim them. X Corp. sued to stop the effort, but a federal judge tentatively ruled in April that X appeared to have relinquished rights to "tweet," the bird logo, and possibly "Twitter" itself, though no written ruling has been issued. Bluebird has taken that as enough of a green light to move forward while emphasizing that its new Twitter is not affiliated with X. "Operation Bluebird, Inc. picked up the name X Corp. walked away from and is rebuilding it on trust, in your browser at twitter.now," it states prominently on its website. "We are not X, and we are not affiliated with X Corp." Read more of this story at Slashdot.

Archives

  • September 2022
  • November 2021
  • June 2021
  • March 2021
  • November 2020
  • October 2020
  • September 2020
  • February 2020
  • January 2020
  • October 2019
  • August 2018
  • July 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2016
  • July 2016
  • March 2016
  • February 2016
  • August 2015
  • May 2015

Categories

  • Innovation
  • Security
  • Software
  • Technology

Tags

backdoor cisco coding json laziness patterns public information announcement security vulnerability
© 2017 IT Sales & Services Ltd
Quality IT solutions in Tanzania since 2010
Iconic One Theme | Powered by Wordpress