{"id":30523,"date":"2015-04-14T19:46:02","date_gmt":"2015-04-14T23:46:02","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/this-open-source-personal-crypto-key-vault-wants-two-things-to-make-the-web-safer-and-your-donations.php"},"modified":"2015-04-14T19:46:02","modified_gmt":"2015-04-14T23:46:02","slug":"this-open-source-personal-crypto-key-vault-wants-two-things-to-make-the-web-safer-and-your-donations","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/cryptography\/this-open-source-personal-crypto-key-vault-wants-two-things-to-make-the-web-safer-and-your-donations.php","title":{"rendered":"This open-source personal crypto-key vault wants two things: To make the web safer &#8230; and your donations"},"content":{"rendered":"<p><p>    An open-source hardware project aimed at making the internet \"a    little bit safer\" needs an influx of cash to continue its work.  <\/p>\n<p>    The Cryptech effort was created following     revelations from NSA whistleblower Edward Snowden that the    US government and its pals are exploiting     standards and weak    crypto algorithms to gain access to citizens' private    correspondence and documents.  <\/p>\n<p>    In response, a group of engineers decided there needed to be an    open-source hardware engine that could provide strong and    reliable encryption and decryption for email, plus    public-private key cryptography for all sorts of things from    digitally signing messages and files to DNSSEC.  <\/p>\n<p>    \"Recent revelations have called into question the integrity of    some of the implementations of basic cryptographic functions    and devices used to secure communications on the Internet,\"    the team    wrote earlier this year.  <\/p>\n<p>    \"There are serious questions about algorithms and about    implementations of those algorithms in software and    particularly hardware.  <\/p>\n<p>    \"The algorithmic issues are in the domain of the heavy math    cryptography folk. But we must also deal with the    implementation issues. We therefore are embarking on    development of an open-source hardware cryptographic engine    that meets the needs of high-assurance internet infrastructure    systems that use cryptography.  <\/p>\n<p>    \"The open-source hardware cryptographic engine must be of    general use to the broad internet community, covering needs    such as secure email, web, DNS, PKIs, etc.\"  <\/p>\n<p>    Cryptech's goal is to develop an inexpensive ARM-powered    Hardware    Security Module (HSM) that can store cryptokeys and act as    a signing engine to establish the authenticity of digital    content.  <\/p>\n<p>    The idea is you store a secret key in the module, which is    designed to never intentionally (and, ideally, never    accidentally) disclose that key. Rather, you tell the module    to, for example, sign some data using that secret key; people    can use your public key and that signature to verify that    particular data really came from you, and has not been tampered    with in transit.  <\/p>\n<p>    The Cryptech HSM will use USB to communicate with your    computer. To avoid attacks on the USB controller spreading to    the HSM's CPU, the USB connection is terminated at the on-board    single-purpose controller chip, which sends commands and data    and receives a reply from the CPU over a serial bus. This means    if you're able to compromise the USB chip, you can't directly    access the main processor's memory to extract the secret keys.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more:<br \/>\n<a target=\"_blank\" href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2015\/04\/14\/cryptech_donations\" title=\"This open-source personal crypto-key vault wants two things: To make the web safer ... and your donations\">This open-source personal crypto-key vault wants two things: To make the web safer ... and your donations<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> An open-source hardware project aimed at making the internet \"a little bit safer\" needs an influx of cash to continue its work. The Cryptech effort was created following revelations from NSA whistleblower Edward Snowden that the US government and its pals are exploiting standards and weak crypto algorithms to gain access to citizens' private correspondence and documents. In response, a group of engineers decided there needed to be an open-source hardware engine that could provide strong and reliable encryption and decryption for email, plus public-private key cryptography for all sorts of things from digitally signing messages and files to DNSSEC<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1600],"tags":[],"class_list":["post-30523","post","type-post","status-publish","format-standard","hentry","category-cryptography"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/30523"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=30523"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/30523\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=30523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=30523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=30523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}