Show more

We have computed the very first chosen-prefix collision for SHA-1. To put it in another way: all attacks that are practical on MD5 are now also practical on SHA-1.

We have reduced the cost of a collision attack from 2^64.7 to 2^61.2, and the cost of a chosen-prefix collision attack from 2^67.1 to 2^63.4.

Demo: The legacy branch of GnuPG (version 1.4) is vulnerable. We have created two PGP keys with different UserIDs and colliding certificates.

sha-mbles.github.io/

I decided to start the new year with some PCB Layout. Can you tell what it is? I am not sure if it is a good or a bad thing if you can recognize the footprint, but you are definitely in good company I recognize them pretty much instantly on other boards. :)

Microphones are vulnerable to laser attack - lightcommands.com/
Smarter Every Day demonstrates controlling devices via laser, even through a window. youtube.com/watch?v=ozIKwGt38L

Setup is summarized at osmocom.org/projects/retro-bbs - feel free to connect yourself with analog or ISDN lines to the patch panel (its labelled) in my absence.

Show thread

0.5.2 is released!

Roughly 40 or so additional devices (or whole device series) supported, improved USB HID support via HIDAPI, Bluetooth/BLE support (Linux-only for now, via BlueZ), and tons of improvements and bugfixes.

sigrok.org/blog/libsigrok-052-

wanted! I'm looking for video editing software for Linux. Does anyone have experience with this?

"Zuckerberg won't speak to the Guardian, so they built a bot trained on hundreds of thousands of his words and interviewed that instead. The result is golden." theguardian.com/technology/201

(RT @allytibbitt@twitter.com)

@uint8_t "because of decisions made in the 1930s", HDMI and EDID are worse than you can imagine: mjg59.dreamwidth.org/8705.html

now supports the MASTECH MS6514 2-channel, USB-based thermometer.

It supports K,J,T,E,R,S,N thermocouple types.

Full teardown and protocol docs available in the wiki.

sigrok.org/blog/mastech-ms6514

recently gained and support.

Currently only a based, ( only) backend is implemented. Contributions for other OSes welcome!

Supported devices so far: 121GW, , some DMMs with Bluetooth cables.

sigrok.org/blog/bluetooth-and-

0.5.3 is released!

New decoders: lin, x2444m, ds2408, cc1101, enc28j60, pca9571, seven_segment, amulet_ascii, tdm_audio, signature, nes_gamepad, flexray, ir_rc6, ieee488, hdcp.

Total PDs supported in this release: 109.

sigrok.org/blog/libsigrokdecod

The sale of the .ORG registry to Ethos Capital would erode the safeguards nonprofits and NGOs have against arbitrary censorship and price gouging. Sign on to the petition to #SaveDotOrg. eff.org/deeplinks/2019/12/we-n

Do not use the Android clipboard for passwords, logins, card numbers, or any kind of sensitive data.

With Android, the clipboard can be read anytime by any app. No permission needed. And the app can then send your data to someone else. If you want to see this, fetch the Clip Stack app from Fdroid, it shows you the clipboard history, and lets you access previous content.

f-droid.org/de/packages/com.ca

How to fight back against Google AMP as a web user and a web developer markosaric.com/google-amp/

I did a detailed privacy check of the Tiktok app and website. You can read my article æt Süddeutsche Zeitung. Tiktok commits multiple breaches of law, trust, transparency and data protection. Here are the technical and legal details
Long thread⤵️

Show more
Fosstodon

Fosstodon is an English speaking Mastodon instance that is open to anyone who is interested in technology; particularly free & open source software.