soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
The software development community has a naysayer problem
https://iain.rocks/blog/the-software-development-community-has-a-naysayer-problem
I have some commentary about this article to share. Before you read my commentary you need to understand the meaning of 'marmaluke'. Really.
"... the entire point of the layered encryption is that you make it a lot harder to know when you’ve cracked the first layer."
We've gone over this idea many years in the past. The gatekeeper community ain't havin' it.
"Security via obfuscation in encryption? We’re done here. ..... “Hiding what you’re doing in encryption doesn’t make it any more secure.”" .... I got this response many times. Many people seem to fail to understand that encryption is literally obsfucating the data. You’re changing the data so people can’t understand it, and it can be un-obfuscated, aka decrypted which is the entire point. ..... The number of people who called this concept security via obscurity is shocking. It’s a new concept, but just because it’s a new idea doesn’t mean the point of it is to be obscure."
The author is right and wrong.
This is not the first time anyone has proposed the idea of chunking up encryption and cascading ciphers. He is mistaken about that claim.
However he is right about 'security through obscurity' and I will explain why.
The parrots love to shout about "Kerkchoff's Principle", which they say is a truism that security through obscurity is either bad or is not security at all. And this is a lie. The reason it is a lie is because that is not what Kerkchoff said. They have inverted Kerkchoff's Principle to read: "You must disclose the algorithms, or else you are playing security dice." This is totally false.
If obscurity of the method had no effect on security, then classified secrets would be pointless. Classified weapons would be pointless. Classified operations would be pointless. Hiding your location from a stalker would be pointless. If obscurity did not boost operational security, then every police detective would call the criminals in advance to let them know they are being investigated. The military would publish battle plans in advance on the six o'oclock news since 'security through obscurity' is bad.
Kerckhoff’s Principle states that security should not be dependent on the secrecy of the cipher but rather on the secrecy of the key. It is not a mandate to declare which cipher is being used. That is just stupid. Yet some 'cryptography experts' define it this way because they don't know what the hell they are talking about.
If I use a basket of ciphers, and choose a random cascade of them in a random order, that random choice is part of the key schedule, and obscuring the choice of ciphers DOES increase the mathematical hardness and security of the ciphertext. This is what the amateur author is instinctively grasping, and his detractors are wrong, and criticizing the wrong things for the wrong reasons. Without realizing it they are doing the bidding of gatekeepers who don't want widespread cascade ciphers because they require much more time and resources to crack. Just have a look at the recent drama at the crypto standards group trying to remove fallback ciphers in KEM system standards. The gatekeepers don't want us using baskets of ciphers. They want everyone using the same standard, singular lock model on every treasure chest.
Yes, satan's little helpers love to shoot everyone down to make them fall in line with the gatekeeper agendas. These marmaluke parrots and popinjays have no idea that their 'thought leaders' are nowhere near as competent as they portray themselves. In order to keep the illusion going, they try to put others down to ensure their idols remain higher than and aloft over the crowd. Singular people are smart. Put a whole crowd of smart people in a [chat] room or forum and they all get dumb really quickly. IQ addition is a lossy operation.
Who cares that an amateur is experimenting and learning? What kind of dinkus tries to shout that down? What kind of maroon always has to jump in with unproductive whataboutery instead of playing along and helping improve the game play? An authoritarian marmaluke, that's what kind. It seems a lot of jackasses who over-rate their own knowledge ... want to use negativity and boundary policing to prevent the curious from exploration.
"This is probably the best example of how bad the software community actually is. It was a bunch of naysayers who GCHQ called “Script Kiddie cybersecurity experts” because they were just parroting things they’ve heard about security without truly understanding them."
He gets it. Don't cave to the naysayer marmaluke parrots. I say more power to the curious. Let them try and fail and try and fail as many times as they have the grit to bear. That is how we learn to walk, run ... and fly.
I do think some of the author's conclusions are mistaken, such as GCHQ finding his idea 'new' or 'useful', since they have actually used these kinds of cascades and segmented, fractionated, and 'railfence' ciphers since WW1. But let him figure that out and give him ideas to arrive at the right conclusions instead of parroting wrote social rules and mores that aren't even being correctly described.
If you are an ideological boundary cop, you are an enemy of basic humanity. Go away thought cop. Let the curious thrive, and live, and die as explorers.
#cryptography #cryptology #ciphers #encryption #naysayers #freethinkers #curiosity #marmalukes #gatekeepers #gatekeeping #math #cybersecurity #security
The problem with modern computational cryptography is that it has no 'empirical' evidence of security. The fact that no one has publicly broken a cipher is not empirical evidence. It is absence of evidence being used as evidence.
If an adversary breaks a function or cryptosystem, he is not going to tell you. Thus using the lack of a public break as evidence is not scientific method.
The security models are based upon 'educated assumptions' within model A or B or C. Nobody has ever proven that a cryptosystem is secure. They are 'assumed' to be secure. Or, they are assumed to be hard in the average case.
Terry Ritter wrote a piece that explains this problem:
In this old Usenet discussion thread, Terry Ritter debunks a lot of the magical thinking endemic in the 'cryptology community':
https://web.archive.org/web/20240922132730/http://www.ciphersbyritter.com/NEWS5/HERDART.HTM
NP-hardness proof is still an open problem. As far as I know, not a single cryptosystem has actually been proven to be NP-hard. Model assumptions using a supposed NP-hard function and proof are two different things.
As for no existing crypto surviving: Vernam's cipher (OTP) is provably information-theoretic secure if keys are not re-used. That avoids the NP-hard problem altogether as it is a different universe of math.
#crypto #cryptography #cryptology #math #maths #ciphers #cybersecurity #encryption
POLL : Have you ever tried to break a cipher?
#ciphers #cryptology #cryptography #codes #puzzles #cracking #crypto #cryptanalysis
| YES, I have tried and failed.: | 6 |
| YES, I have tried and broken a cipher.: | 18 |
| NO, I have never tried to break a cipher.: | 6 |
This video shows how the BlockChain is far more dangerous than you were told. The big tech big wigs are constructing a system to remove all your private property rights into their cloud. Zero due process. Zero appeal. You will own nothing and be ... a most unhappy robot polisher.
Meet the New Owners (The Dangerous Blockchain)
https://www.youtube.com/watch?v=AAEv0cpZG9k
[copypasta]
Who really owns your property?
And what happens when a private company, a blockchain, and foreign-connected investors get between you and your deed?
In this episode of Plain Meaning, I trace the campaign to replace America's distributed, physical property record system with blockchain technology. And I expose who stands to benefit.
This episode covers:
How America's physical ownership system was deliberately designed to resist central control and why that matters.
Who Senator Bernie Moreno is, what CHAMPtitles does, and why a blockchain entrepreneur now sits on the Senate Commerce Committee
-The real vulnerabilities of blockchain: 51% attacks, garbage-in garbage-out errors, and the $1.5 billion Bybit hack
How companies with deep ties to foreign sovereign wealth funds and Chinese-connected investors can tell anyone who pays what you own and what you've done with it
What happened when West Virginia and Louisiana handed their vehicle title systems to a private company
How Wyoming became the launchpad for nationalizing blockchain property records
#blockchain #crypto #nft #propertyrights #privacyrights #privacymatters
[/copypasta]
OCTADE Project Software : Signed Papers Portal
I am hacking on a cryptographic verification web portal. I seek comments and suggestions on the user interface (UX) and feature set.
Accessibility perspectives might be helpful since this involves slightly complex signatures and verification commands.
The server software automatically hashes and signs all files uploaded to the site. The software also generates 'verification bundles' that users may download to verify signatures using 'gnupg' and 'openssl'.
https://files.octade.net/publications/
Feedback would be helpful for improving the software before I release any source code.
#cryptography #cryptology #signatures #DataIntegrity #verification
#keys #gpg #pgp #openssl #crypto
Syfer Sangraal : Holy Grail of Cryptography in the Arc of the Combinant
DOI : 10.5281/zenodo.22158384
== SUMMARY ==
Embark on the quest for the Syfer Sangraal system, or the holy grail of cryptography hidden in the arc of the combinant. One system to roll them all is the holy grail of cryptography. One algorithm to perform every kind of cryptographic function is the new wine within the Syfer
Sangraal system.
--
OCTADE | https://octade.net
#SyferSangraal #HolyGrail #cryptography #cryptology #crypto #pqc #papers
Syfer Sangraal : Holy Grail of Cryptography in the Arc of the Combinant
https://doi.org/10.5281/zenodo.22158384
Embark on the quest for the Syfer Sangraal system, or the holy grail of cryptography hidden in the arc of the combinant. The Holy Grail of Cryptography is a single, simple algorithm that performs all necessary functions of computational cryptography with provable security sans assumptions in the model. One system to roll them all is the holy grail of cryptography. One algorithm to perform every kind of cryptographic function is the new wine within the Syfer Sangraal system.
#cryptography #cryptology #ciphers #holygrail #SyferSangraal #preprint
[demo] https://files.octade.net/
I drafted a prototype for a PHP server application that automatically hashes and signs files and presents visitors with verification archives containing digital signatures for offline verification. The site allows readers to view, download, hash, and verify signatures of files. Since I occasionally like to publish puzzles and bits of cryptology, I just had to make this to scratch the old itch.
The neat thing about this design is that the current version has zero JavaScript. It uses CSS3 hacks with anchors and URL probing to emulate JavaScript and AJAX functionalities for modal dialogs to present server-side JSON data as HTML text.
When I upload files or documents to the server, the interface automatically presents them to the user in a grid. So now all I have to do is upload files and documents and the server generates the site.
The reader can then click buttons to hash, sign, view, verify, and download files.
GnuPG and OpenSSL Signatures are generated automatically on user demand. The site visitors can download these signatures and the public keys to verify files.
What should I add / change in the application and its interface?
What accessibility components might be warranted?
Should the application parse and present EXIF data, or is that too much?
#PHP #CSS3 #HTML5 #WebDesign #UX #cryptology #cryptography #crypto #signatures #OpenSSL #GnuPG #GPG #PGP #encryption #papers #preprints #documents #SelfHosted #WebLord #WebMaster #WebSerf #NoJS #Apache #CyberSecurity
Rhizome Function Anagram Random Generator
preprint | https://zenodo.org/records/21551292
doi | https://orcid.org/0009-0009-5144-3278
Herein are described principles and a scheme of random number generation styled as, pangrandomonium, or ‘pangrand’. Pangrand is a anagrammatic random number generator that uses rhizome functions as chaotic indexing and shuffling instructions to reorder and sum perfect pangrams. Brief descriptions are given for the principles of pangram summing and rhizome indexing functions, Source code of the random number generator is included herewith. The source code is attached to the PDF file.
Sections:
1. Pangrams (Holoalphabetic arrays) ;
2. Rhizome Functions ;
3. Rhizome Hardness Problems ;
4. Random Generator Methods ;
5. Errata ;
6. Source Code.
#Preprints #Random #Cryptography #RNG #Pangrams #Anagrams #Pascal #Papers #RhizomeFunction #AcademicMastodon #Cryptology #Math #NumberTheory #Papers #Academia #ComputerScience #CompSci #AcademicChatter #OpenScience