Posts about security
- How (not) to sign a JSON object
- The PGP problem
- The default OpenSSH key encryption is worse than plaintext
- Factoring the Noise protocol matrix
- Self-compressing pickles
- A child's garden of inter-service authentication schemes
- Gripes with Google Groups
- Nonce misuse resistance 101
- Supersingular isogeny Diffie-Hellman 101
- Introducing Teleport
- Don't expose the Docker socket (not even to a container)
- Today's OpenSSL bug (for techies without infosec chops)
- HTTPS requests with client certificates in Clojure
- Conflicting threat models
- Securing APIs with shims
- On discussing software security improvements
- Securing against timing attacks with Twisted