Ed25519 is a public-key signature system with several attractive features
Noise is a framework for building crypto protocols. Noise protocols support mutual and optional authentication, identity hiding, forward secrecy, zero round-trip encryption, and other advanced features.
Automate all your cryptographic needs!
Goals
- Zero downtime
- Automatic certificate renewal
- Spam protection
- Updated DNS records
Configure once and always stay up to date.
Use cases
- Renew letsencrypt certicates
- Derive all kinds of data from the signature
- Ensure everything is secure
This text is a collection of observations and complaints about the state of PKI in general, PKCS#11 in particular, and about some software products. Let me preface that the provider of the cryptotoken (and software) that this text is based on has three things in their favor: 1. Their products work, 2. Their support is good, 3. Their products work.
It cannot be stressed enough that spending lots of money on crypto hardware is no guarantee whatsoever that what you get works, or works better, or is better supported.
I2P is an anonymous overlay network - a network within a network. It is intended to protect communication from dragnet surveillance and monitoring by third parties such as ISPs.
Tails ist ein Live-Betriebssystem, das Sie auf auf vielen Computern von einer DVD, einem USB-Stick oder einer SD-Karte aus starten können. Es zielt darauf ab, Ihre Privatsphäre und Anonymität zu bewahren und hilft Ihnen:
- das Internet anonym zu nutzen und Zensur zu umgehen;
alle Verbindungen zum Internet werden zwingend durch das Tor Netzwerk geleitet; - auf dem verwendeten Computer keine Spuren zu hinterlassen, sofern Sie es nicht ausdrücklich wünschen;
- kryptographische Werkzeuge auf dem aktuellen Stand der Technik zu benutzen um Ihre Dateien, E-Mails und Instant-Messaging-Nachrichten zu verschlüsseln.
To bring the world our unique end-to-end encrypted protocol and architecture that is the 'next-generation' of private and secure email. As founding partners of The Dark Mail Technical Alliance, both Silent Circle and Lavabit will work to bring other members into the alliance, assist them in implementing the new protocol and jointly work to proliferate the world's first end-to-end encrypted 'Email 3.0' throughout the world's email providers. Our goal is to open source the protocol and architecture and help others implement this new technology to address privacy concerns against surveillance and back door threats of any kind.
Dark Internet Mail Environment (DIME)
CryptoParty intro video - feel free to use :-)
Hier gibt es ein paar Hinweise, wie man seine openssh-Konfiguration zunagelt. Ich persönlich habe ja für meine Server jeweils in ~/.ssh/config sowas stehen wie:...
You may have heard that the NSA can decrypt SSH at least some of the time. If you have not, then read the latest batch of Snowden documents now. All of it. This post will still be here when you finish. My goal with this post here is to make NSA analysts sad.
TL;DR: Scan this post for fixed width fonts, these will be the config file snippets and commands you have to use.
OTR ermöglicht Ihnen private Gespräche mit IM durch:
- Verschlüsselung
- Kein Unbefugter kann Ihre Nachrichten lesen.
- Authentifizierung
- Es wird sichergestellt, dass ihr Gesprächspartner der ist, den Sie
erwarten.
- Es wird sichergestellt, dass ihr Gesprächspartner der ist, den Sie
- Abstreitbarkeit
- Die von Ihnen gesendeten Nachrichten haben keine digitalen
Signaturen, die von einem Außenstehenden überprüft werden können.
Jeder kann Nachrichten nach einem Gespräch derart verfälschen, dass
diese aussehen, als ob Sie sie versendet haben. Jedoch ist ihr
Gesprächspartner während einer Konversation sicher, dass die
Nachrichten authentisch und unverändert sind.
- Die von Ihnen gesendeten Nachrichten haben keine digitalen
- Folgenlosigkeit (perfect forward secrecy)
- Wenn Sie die Kontrolle über Ihre privaten Schlüssel verlieren, ist
kein vergangenes Gespräch gefährdet.
- Wenn Sie die Kontrolle über Ihre privaten Schlüssel verlieren, ist
RedPhone makes private communication simple. Free, world-wide, end-to-end encryption for your calls, securing your conversations so that nobody can listen in.
For a recent customer setup of Debian/wheezy on a IBM x3630 M4 server we used my blog entry “State of the art Debian/wheezy deployments with GRUB and LVM/SW-RAID/Crypto” as a base. But this time we wanted to use (U)EFI instead of BIOS legacy boot.