HNHacker News
TopNewBestAskShowJobs

paragon_init

187 karma · joined May 29, 2015

Paragon Initiative Enterprises https://paragonie.com

We offer these professional services to businesses:

    - Technology Consulting
    - Web Development
    - Code Audits
    - App Development
    - Application Security
    - Business Intelligence
https://twitter.com/ParagonIE

https://github.com/paragonie

https://facebook.com/paragonie

[ my public key: https://keybase.io/paragonie; my proof: https://keybase.io/paragonie/sigs/93apsjubyvxgJAVQnZ-1O-6uzM6FYuc6en1QMeVuENQ ]

submissionscomments
paragon_init··on We build X.509 chains so you don't have to
> * I shouldn't have to care where the certificates are stored. Just load the os default ones without asking me.

> * I shouldn't have to know what a pem is, and I shouldn't have to open() one.

Agreed, but what you're requesting is separate from the work being discussed in this blog post, and both are actually compatible.

For the PHP community, we made Certainty - https://github.com/paragonie/certainty

You can just...

  <?php
  use ParagonIE\Certainty\RemoteFetch;
  // cURL boilerplate
  $ch = curl_init();
  curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2);
  curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true);

  // Fetch the latest CACert bundle, verify its authenticity, save it locally  
  $fetcher = new RemoteFetch('/path/to/certainty/data');
  $latestCACertBundle = $fetcher->getLatestBundle();
  curl_setopt($ch, CURLOPT_CAINFO, $latestCACertBundle->getFilePath());
Writing a Python client should be relatively straightforward, should anyone want to.

For Python specifically, there may be some value in storing the relevant PEM files into something like SigStore. That could be an easier proposal for the PyCA team to consider.

paragon_init··on ZCash (formerly Zerocash/Zerocoin) technology preview
Hi Zooko,

Has there been any serious discussion about incorporating the results of PQCRYPTO in your protocol so Zcash is still secure and viable (at >= 2^128 security level) after the development of practical quantum computers?

http://pqcrypto.eu.org

paragon_init··on Basic Cryptography Concepts for Developers
Crypto 101 is a ~200 page book that is far richer in detail and examples. It also covers a lot of primitives (one-time pads, hash trees, etc.) that we eschewed for the sake of brevity.

This blog post is digestible in a few minutes. Crypto 101 can occupy a novice for a few hours. Given the hard choice of one of the two, we would encourage anyone interested to read Crypto 101 over our blog post, as they'll walk away with a much more detailed understanding .

paragon_init··on Basic Cryptography Concepts for Developers
If you use bcrypt (which we recommend), you're technically using a variant of BASE64 too.

The title is a reference to a meme ("You wouldn't download a car!") and also a reference to some absurdly bad cryptography, e.g. http://www.cryptofails.com/post/87697461507/46esab-high-qual...

paragon_init··on Basic Cryptography Concepts for Developers
This is an excellent point. Cryptography is not a trivial field to master.

(I've updated the title to read "Basic Cryptography for Developers" instead of "Cryptography for Developers" so as to not accidentally make someone think they know it all.)

paragon_init··on Using Encryption and Authentication Correctly
This was previously shared a few months ago, but we added a little bit more (thanks to feedback from tptacek, et al.).
paragon_init··on Show HN: Polyfill for random_bytes() and random_int() in PHP 5 projects
When PHP 7 is released later this year, PHP users will finally be able to quickly and easily leverage a CSPRNG in their projects.

    random_bytes(int) - Generate a string of random bytes from the OS (e.g.. /dev/urandom)
    
    random_int(int, int) - Generate an unbiased random integer between two integers
We wrote this library so PHP 5.x users can import this in their project and write code that takes advantage of this new PHP 7 API. Particularly random_int(), which is suitable for random string generation (e.g. random password generator).

We cannot declare the 1.0.0 stable release until the PHP team makes a design decision about how to handle errors in their version of the library. We currently throw an Exception; they might decide to return false and raise an E_WARNING error. Until the outcome is known, we're in limbo.

This library has not been subject to a paid audit by a security team, but it has been reviewed by several prominent members of the PHP community (and a few security/crypto folks outside of PHP land).

I believe it to be more secure than any other PHP implementation of these features. That said, more review and scrutiny would be greatly appreciated! :)

paragon_init··on A call to PHP's mt_rand generates only odd numbers
It might be worth noting that 'sarciszewski was the author of that remark.
paragon_init··on A call to PHP's mt_rand generates only odd numbers
Agreed. It's a red flag for "expect more exploitable issues to be found around the corner" and can result in biased distributions, but it by itself does not break a RNG.
paragon_init··on Using Encryption and Authentication Correctly
Encrypt-Then-MAC just makes sense. If the first thing you do when you receive a blob of encrypted data is check that it's authentic (in constant-time!), the attack surface is greatly reduced.
paragon_init··on Using Encryption and Authentication Correctly
I think that's why the statement was "be careful with" rather than "don't"
paragon_init··on Things to Know When Making a Web Application in 2015
If you build something open source and it gets incredibly popular, security researchers will also probably come to you. This creates its own problems, of course. (Can't have problems without PR.)
paragon_init··on PHP 7.0.0 Beta 1 Released
Awesome. We're looking forward to developing with PHP 7. :)
paragon_init··on Using Encryption and Authentication Correctly
https://www.imperialviolet.org/2014/06/27/streamingencryptio...

Thomas's answer probably has to do with the risks of decrypting a stream and being unable to authenticate it first. (See also: the Cryptographic Doom Principle.)

paragon_init··on Things to Know When Making a Web Application in 2015
If you are a business, then definitely yes. But the average self-taught developer will not have the resources available to hire a security consultant.

Instead of throwing money at the problem, you can instead choose to teach yourself more about the subject. We maintain a curated list on Github for people interested in learning about application security for this very reason.

https://github.com/paragonie/awesome-appsec

But if you're a company and your operating budget is in the millions of dollars hire a security consultant!

paragon_init··on Using Encryption and Authentication Correctly
CTR saves you the trouble of padding your plaintext before encrypting, thus eliminating an entire class of cryptography attacks (i.e. padding oracles). The security margins of CBC and CTR are otherwise similar.

GCM is far more preferred to either CBC or CTR because it's less for the implementer to screw up.

NaCl's ChaCha20-Poly1305 is even better, because it's fast and constant-time.

'cperciva made the CTR+HMAC recommendation here: http://www.daemonology.net/blog/2009-06-11-cryptographic-rig...

Properly authenticated encryption that uses CBC+HMAC-SHA2 with PKCS7 padding is probably okay, but new developments should prefer AEAD modes above all else, and CTR+HMAC-SHA2 if no AEAD modes are available.

(The kind folks in ##crypto on freenode have pointed out to me that CTR also allows random-access decryption, where CBC mode does not. We haven't ever implemented this feature and cannot comment on it.)

paragon_init··on Using Encryption and Authentication Correctly
We've implemented your recommendations. Glad to hear you liked our post even without the suggested improvements.
paragon_init··on Anonymous Reddit without servers
Happy to see that it's open source, too.

https://github.com/nehbit/aether-public

paragon_init··on Show HN: A Curated List for Application Security
Yep, and it probably deserves its own Show HN entry from the author. I bet it would get a lot of positive attention.
paragon_init··on Show HN: A Curated List for Application Security
Yes, curated lists can become burdensome. We try to stay on top of change requests and are always looking for more material to add.
paragon_init··on Show HN: A Curated List for Application Security
Thanks for the removal recommendation. Would you prefer that we remove the statements crediting your Amazon reading list as well?
paragon_init··on The Easy Way to Prevent SQL Injection in PHP Applications
Thanks for pointing this out. We're always looking for ways to improve our open source projects and will make the necessary improvements.

EDIT: Done. :)