Red October crypto app adopts “two-man rule” used to launch nukes
arstechnica.com
arstechnica.com
Since I'm assuming a CloudFlare person is watching this thread, I've been a bit curious about when they plan on releasing that database of SSL certificates they promised almost a year ago.
> Going forward, in addition to releasing the directory of intermediate SSL certificates on Github, we plan on releasing our SSL bundler as a free service so you can package up your SSL certificates as efficiently as possible, even if you're not using CloudFlare. Just one more way we're working to make the web fast and safe.
http://blog.cloudflare.com/what-we-just-did-to-make-ssl-even...
That looks like a very cool project, and they got a decent amount of attention over it. It would be nice to see some follow through on those plans to release it.
Edit: looks like it needs to be cleaned up a bit and then we'll release it. Seeing if we can get someone on the team to take it on and get it out in the next few weeks.
http://en.wikipedia.org/wiki/Secret_sharing
It would reduce the complexity of encrypting the data encryption key multiple times with each pair of keys, and the math behind them is pretty neat.
Red October is based on combinatorial techniques and trusted cryptographic primitives. We investigated using complicated secret primitives like Shamir's sharing scheme, but we found that a simpler combinatorial approach based on primitives from Go's standard library was preferable to implementing a mathematical algorithm from scratch.
Which seems like a reasonable choice for smallish numbers of keys/sharers, especially given the data they're encrypting isn't exactly huge.
Are there good libraries (for any language) implementing shared secrets?
[1] https://blog.cloudflare.com/red-october-cloudflares-open-sou...
[1] http://coresecret.io/ [2] http://eprint.iacr.org/2013/629
I googled around for ssss implementations and bsd license and found one in javascript of all things.
(Please no license flamewar, just stating the facts!)
http://blog.cloudflare.com/red-october-cloudflares-open-sour...
Passwords and keys are great, but their weakness is that they can be shared.
Is a persons biometric signature something that can be legally compelled to be used by a company, if that person quits or go AWOL?
If an employee/agent has ownership of a text keyfile (assuming no company controlled backups exist), the company could look to police/courts about property theft. But biometric seems a bit different.
Biometrics are useful for authentication, but I struggle with a safe use for authorization, per se. Just for the reason you identified.