Philippe Oechslin

91 posts

Philippe Oechslin

Philippe Oechslin

@tradeoph

Katılım Ekim 2007
150 Takip Edilen232 Takipçiler
Philippe Oechslin
Philippe Oechslin@tradeoph·
@thorsheim @BSidesLV I was looking for a name that was easier to remember than tables-where-the-reduction-function-changes-with-each-column 😀
English
0
0
0
443
Philippe Oechslin
Philippe Oechslin@tradeoph·
@thorsheim @BSidesLV In both cases, if you have a collision within the same color it is merge, if it is in two different colors, it is only a colision. So they have the same coverage. But the rainbow table needs half as many hashes in the worst case and even much less if you're aiming for high prob
English
1
0
0
30
starbuck3000
starbuck3000@starbuck3000·
Question: où obtenir la météo de la veille? (p.ex. températures dans une ville Suisse 1 à 2 jours plus tôt)
Français
4
0
0
406
Philippe Oechslin
Philippe Oechslin@tradeoph·
@smetille @derBeauftragte Très souvent les données son seulement chiffrées au repos. Si les attaquants ont eu accès au compte d'une personne ayant accès aux fichiers, les fichiers auront été déchiffrés automatiquement par le système.
Français
2
0
2
57
Sylvain Métille
Sylvain Métille@smetille·
On peut se demander comment les données ont été déchiffrées...? Le @derBeauftragte n'a pas encore communiqué mais on peut imaginer qu'il va d'office ouvrir une procédure
Français
2
0
2
216
Philippe Oechslin
Philippe Oechslin@tradeoph·
@veorq I've seen it defined as "authenticity of origin and content", e.g. in Matt Bishop's Computer Security, Arts & Science
English
0
0
0
42
JP Aumasson
JP Aumasson@veorq·
beginner crypto question: how to best call signature's security property? "non-repudiation" isnt good – when's the last time you wish you could repudiate a sig? sounds legalese but unusable as evidence it's more a mix of "identity binding" and "content commitment"
English
7
1
12
6.5K
Philippe Oechslin
Philippe Oechslin@tradeoph·
@veorq Beware of the attack of the European Central Bank (seen in the syllabus of a crypto training)
Philippe Oechslin tweet media
English
0
1
4
761
Philippe Oechslin
Philippe Oechslin@tradeoph·
@cynicalsecurity Contrary to v3, NFSv4 not only signs the command but also the parameters. So we can't play funny games with the parameters anymore.
English
0
0
0
0
modulo p SA
modulo p SA@modulo_p_sa·
Hello world !
English
2
0
3
0
Philippe Oechslin
Philippe Oechslin@tradeoph·
@veorq Reminds me of the day I learned that generation parameters are often stored in private keys to make calculations more efficient. Then you can get the public key from the private key and can't swap the roles of the private and public keys. Reality is not like text book crypto.
English
0
0
2
0
JP Aumasson
JP Aumasson@veorq·
loving signature verification instructions that show you how to instantiate a public key object by deriving it from a private key
JP Aumasson tweet media
English
8
9
68
0
Philippe Oechslin
Philippe Oechslin@tradeoph·
@MjHillEditor ..and they only work for unsalted hashes, which no sane system uses anymore. OTOH, our online demo objectif-securite.ch/en/ophcrack cracks 8char windows passwords in 60s avg on a dual proc server. This is equivalent to about 200 dual RTX3090, so we got that going for RT, which is nice.
English
0
0
0
0
Michael Hill
Michael Hill@MjHillEditor·
Starting a new project exploring the various ins & outs of Rainbow Tables. Looking for insight & comment from those with knowledge on the topic. Get in touch for more! #Password #Security
English
3
1
0
0
Philippe Oechslin
Philippe Oechslin@tradeoph·
@MjHillEditor Do not hesitate do DM me if you have any questions about Rainbow tables. The biggest limitations are that the effort is linear in the number of hashes to crack, that they crack a fixed set of passwords and that you can't benefit from GPU because of the large amount of data
English
1
0
1
0