[Noisebridge-announce] BAHA at 2pm Sunday, talkin' bout web crypto

travis+ml-noisebridge-announce at subspacefield.org travis+ml-noisebridge-announce at subspacefield.org
Fri Oct 8 07:19:53 UTC 2010

Been a bit busy with work, so recycling an older-but-good talk.

Had a person at OWASP Austin say this was the best talk they'd
seen there.  Slides here for the lazy, or overachievers:


I'll cover many real-world vulns in crypto in recent web apps (not in
SSL).  We'll learn many ways not to do crypto.

The length-extension attack I discussed here was later used to break
Flickr's API.

I'll also cover the PKCS#7 Padding Oracle attack, which was used to
break millions of ASP.NET apps a decade or two after it was first

So bring your crypto questions, inane questions, insane questions,
questionable questions, and Missy Elliot lyrics, and we'll see if
we can make them topical.

"It's not like I'm _encrypting_, it's more that I've
 suddenly developed a massive entropy deficiency"
