Chuyển sang chế độ ngoại tuyến với ứng dụng Player FM !
Signal's Post-Quantum PQXDH, Same-Origin Policy, E2EE in the Browser Revisted
Manage episode 382558625 series 2956114
We're back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.
Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc
Links:
- https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/
- https://github.com/superfly/macaroon
- https://cryspen.com/post/pqxdh/
- https://eprint.iacr.org/2023/1390.pdf
"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian)
Chương
1. Issues With Encrypted Jabber Communications (00:00:00)
2. App and Web Security Challenges (00:13:53)
3. Benefits and Limitations of Web Encryption (00:22:26)
4. Benefits and Challenges of Browser-Based Cryptography (00:29:54)
5. Web App Security and Distribution Models (00:35:09)
6. Web Security and Signal Key Exchange (00:48:36)
7. X3DH Protocol and Signal's Key Exchange (00:53:49)
8. Camry Encapsulation Attack and Secure Encryption (01:08:11)
52 tập
Manage episode 382558625 series 2956114
We're back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.
Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc
Links:
- https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/
- https://github.com/superfly/macaroon
- https://cryspen.com/post/pqxdh/
- https://eprint.iacr.org/2023/1390.pdf
"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian)
Chương
1. Issues With Encrypted Jabber Communications (00:00:00)
2. App and Web Security Challenges (00:13:53)
3. Benefits and Limitations of Web Encryption (00:22:26)
4. Benefits and Challenges of Browser-Based Cryptography (00:29:54)
5. Web App Security and Distribution Models (00:35:09)
6. Web Security and Signal Key Exchange (00:48:36)
7. X3DH Protocol and Signal's Key Exchange (00:53:49)
8. Camry Encapsulation Attack and Secure Encryption (01:08:11)
52 tập
Tất cả các tập
×Chào mừng bạn đến với Player FM!
Player FM đang quét trang web để tìm các podcast chất lượng cao cho bạn thưởng thức ngay bây giờ. Đây là ứng dụng podcast tốt nhất và hoạt động trên Android, iPhone và web. Đăng ký để đồng bộ các theo dõi trên tất cả thiết bị.