48 Dirty Little Secrets Cryptographers Don't Want You to Know

The Hackers that Cracked Cryptocat. This team could audit the bitmessage security paradigm. At the 9:30 mark begins an overview of how Cryptocat was broken. https://youtu.be/iZa_XKpj9X4?t=9m30s Description: Over the past year, more than 10,000 people participated in the Matasano crypto challenges, a staged learning exercise where participants implemented 48 different attacks against realistic cryptographic constructions. In the process, we collected crypto exploit code in dozens of different languages, ranging from X86 assembly to Haskell. With the permission of the participants, we've built a "Rosetta Code" site with per-language implementations of each of the crypto attacks we taught. In this talk, we'll run through all 48 of the crypto challenges, giving Black Hat attendees early access to all of the crypto challenges. We'll explain the importance of each of the attacks, putting them into the context of actual software flaws. Our challenges cover crypto concepts from block cipher mode selection to public key agreement algorithms. For some of the more interesting attacks, we'll step-by-step the audience through exploit code, in several languages simultaneously. For More Information Please visit : - http://blackhat.com

Thanks for this Infos. I know Nadim (Cryptocat core dev), I've talked IRL with him several times in Paris. He's clever, he's a good engineer / hacker, but he is only specialized in cryptography & software dev and has very little knowledge of digital electronics and the influence electronics has on cryptography, but also Nadim, like most privacy apps developpers, refuses to admit that as long as privacy software run on hardware fully backdoored at all level, but also at OS level, but also with all those zerodays in most applications waiting to me used by NSA & friends, well, it's almost like doing nothing. This is why I am working on the BitMessage Secure Station.

I am watching development on this with interest. The serial port security vector is a good idea.

