Linux Cryptography

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Cryptography News

FIPS 140-1: Security Requirements for Cryptographic Modules

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Federal Information Processing Standard 140-1(FIPS 140-1) is entitled "Security Requirements for Cryptographic Modules". It's a standard that describes government requirements that hardware and software products should meet for Sensitive, but Unclassified (SBU) use. The standard was published by the National Institute . . .

Pols ooh, aah over e-signatures

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

As a result of a landmark "e-sign" law that took effect in the United States on Sunday, businesses and consumers may now close mortgages, sign life insurance and seal contracts with the click of a mouse. "This is going to revolutionize . . .

US backs Rijndael for data scrambling

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A scrambling technique scripted by two Belgians has been chosen as the proposed US government standard to protect sensitive data and help spur the digital economy, the Commerce Department said Monday. The selection of the Rijndael (pronounced "Rhine-doll") . . .

Commerce Dept. To Announce Crypto Standard

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The National Institute of Standards and Technology (NIST), an agency of the US Commerce Department's Technology Administration, will announce its choice for the Advanced Encryption Standard (AES) at 11:00 a.m. EDT today. The announcement, which will be broadcast on the Web . . .

E-Signatures Out Of The Gate

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Electronic signatures carry full legal weight beginning Sunday, ushering in a new era for commerce over the Internet. Digital signatures carry the promise of reducing the cost of business and making it more efficient, spurring the growth of e-commerce.. . .

AES ANNOUNCEMENT: Monday, October 2, 2000

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It appears the winner of the new encryption standard to replace DES will be announced on Monday. "The National Institute of Standards and Technology (NIST) has been working with industry and the cryptographic community to develop an Advanced Encryption Standard (AES). . . .

Royal Mail Delivers Digital Signatures

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The Royal Mail, Britain's postal service, is to offer free digital signatures to all citizens in a bid to improve consumer acceptance of e-business. From later this year, consumers will be able to collect software on a free CD-ROM from any . . .

Quantum crypto secrets from Japan

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Mitsubishi and Hokkaido University have completed a latest round of experiments in quantum cryptography over optical fibres. The two organisations say that their quantum cryptographic system is a success, and could have important implications for optical fibre networks already in use.. . .

Cool Tool of the Week -- cryptcat

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Cryptcat is the standard netcat enhanced with twofish encryption. Cryptcat allows you to pipe data from one host to another using encryption. "Netcat is a simple Unix utility which reads and writes data across network connections, using TCP . . .

SSH Techniques

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

We've already seen one of the primary uses of ssh: it allows you to open up a terminal session to a remote system. By using "ssh" instead of telnet or rsh, you get the same ability to type commands on remote . . .

New Linux-Crypto Mailing List

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A new mailing list, dedicated to all Linux Crypto topics has just opened. It is This email address is being protected from spambots. You need JavaScript enabled to view it.. Thanks go to all at nl.linux.org for allowing me to host this mailing list using their majordomo, esp. to Rik van Riel.. . .

Discussing SSL and Certificates

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This document is a bit dated, but a good discussion of SSL. The Secure Sockets Layer protocol provides one means for achieving these goals and is the subject of this article. This document introduces SSL by reviewing cryptographic techniques and by . . .

GnuPG 1.0.3 Now Available

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

GnuPG is a complete and free replacement for PGP. Because it does not use the patented IDEA algorithm, it can be used without any restrictions. GnuPG is a RFC2440 (OpenPGP) compliant application. This version comes with RSA support and the new . . .

Mozilla Network Security Services (NSS)

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. These libraries provide the security foundation for a variety of server products from iPlanet E-Commerce Solutions, including iPlanet Certificate Management System, . . .

Introduction to Encryption

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Encryption is the process of converting data from one form (what would be considered to be readable either through plaintext or through some specific viewer like MS Word) into ciphertext. The actual process that takes place during this conversion widely varies, . . .

Good-bye Bandits, Hello Security

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Over the last year or so, we've heard a lot about how software patents, which became legal in the U.S. in 1981, stifle innovation. James Bessen and Eric Maskin conducted a study showing that ``far from unleashing a flurry of new . . .