Security News

JSON Libraries Patched Against Invalid Curve Crypto Attack (Threatpost)
2017-03-15 15:46

JSON libraries using the JWE specification to create, sign and encrypt access tokens have been patched against an attack that allows for the recovery of a private key.

Comey Talks Strong Crypto, Silent on WikiLeaks (Threatpost)
2017-03-08 16:02

FBI Director James Comey revived old rhetoric on strong encryption during a keynote at the Boston Conference on Cyber Security. He did not address the leak of CIA hacking tools or Russia during his talk.

New attack sounds death knell for widely used SHA-1 crypto hash function (Help Net Security)
2017-02-24 13:07

SHA-1 is definitely, provenly dead, as a group of researchers from CWI Institute in Amsterdam and Google have demonstrated the first practical technique for generating a collision. What is SHA-1?...