Go offline with the Player FM app!
Nate Lawson: Part 1
Fetch error
Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on November 11, 2025 16:14 ()
What now? This series will be checked again in the next day. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.
Manage episode 340700091 series 2956114
We bring on Nate Lawson of Root Labs to talk about a little bit of everything, starting with cryptography in the 1990s.
Transcript:
https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/
References
- IBM S/390: https://ieeexplore.ieee.org/document/5389176
- SSLv2 Spec: https://www-archive.mozilla.org/projects/security/pki/nss/ssl/draft02.html
- Xbox 360 HMAC: https://beta.ivc.no/wiki/index.php/Xbox_360_Timing_Attack
- Google Keyczar HMAC bug (reported by Nate): https://rdist.root.org/2009/05/28/timing-attack-in-google-keyczar-library/
Errata
- HMAC actually published in 1996, not 1997
- "That was one of the first, I think hardware applications of DPA was, was, um, satellite TV cards." Not true, they first were able to break Mondex, a MasterCard smart card
"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian)
59 episodes
Fetch error
Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on November 11, 2025 16:14 ()
What now? This series will be checked again in the next day. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.
Manage episode 340700091 series 2956114
We bring on Nate Lawson of Root Labs to talk about a little bit of everything, starting with cryptography in the 1990s.
Transcript:
https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/
References
- IBM S/390: https://ieeexplore.ieee.org/document/5389176
- SSLv2 Spec: https://www-archive.mozilla.org/projects/security/pki/nss/ssl/draft02.html
- Xbox 360 HMAC: https://beta.ivc.no/wiki/index.php/Xbox_360_Timing_Attack
- Google Keyczar HMAC bug (reported by Nate): https://rdist.root.org/2009/05/28/timing-attack-in-google-keyczar-library/
Errata
- HMAC actually published in 1996, not 1997
- "That was one of the first, I think hardware applications of DPA was, was, um, satellite TV cards." Not true, they first were able to break Mondex, a MasterCard smart card
"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian)
59 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.