#KerckhoffsPrinciple

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-05

@dazo @MarionDonnelly @murena @e_mydata @red_rooster @georgetakei not to mention #Apple is not only capable but willing to shove in #Govware #Backdoors.

So their claims re: #privacy and #security are "#TrustMeBro!" at best if not blatant lies.

Remember: #AllGAFAMsAreBad and #KerckhoffsPrinciple demands #transparency!

Kevin Karhan :verified:kkarhan@infosec.space
2025-01-22

@ESETresearch @smolar_m thanks for the post and research.

  • Personally, I don't rely on #CensorBoot as I don't trust any #security that violates #KerckhoffsPrinciple, but that's not my decision and being able to attest the security of it or at least have another way to check for it is kinda important.

And yes I refuse to call it "#SecureBoot" because it is not secure by #Microsoft's own admission - otherwise they would've relied on it on the #XboxOne and not just the #Xbox360 !

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-30

@bastibayer nein, weil #Threema ne #proprietär|e +#SingleVendor & #SingleProvider) Lösung ohne #SelfCustody der Keys ist, und damit inhärent unsicher (#KerckhoffsPrinciple)...

Meine Empfehlung ist @monocles / #monoclesChat & @gajim für #XMPP+#OMEMO, ducht gefolgt.von @delta / #deltaChat für echte #E2EE!

Kevin Karhan :verified:kkarhan@infosec.space
2024-08-26

@rysiek also #Telegram - like @signalapp - demand and collect #PII like #PhoneNumbers which ain't possible to acquire anonymoisly in more and more juristictions.

Using #XMPP+#OMEMO by contrast is secure and adding @torproject / #Tor to tunnel it makes it even more anonymous.

  • So don't expect any messenger to cover your 6, but instead go out of your way so that even when held at gunpoint, they can't decrypt comms!

Cnsider every #Messenger that doesn't #decentralize and support #Tor oit of tue box to be insecure!

2024-02-05

@stacksmashing And the cool part of it: It's systemically unfixable!

Note: If #Microsoft doesn't even bother trying to use #BitLocker and #TPM to #CensorBoot the #XboxOne, we can safely assume it wasn't secure to begin with!

youtube.com/watch?v=U7VwtOrwce

Remember: All Cryptogeaphy that violates #KerckhoffsPrinciple is inherently insecure and untrustworthy!

Kevin Karhan :verified:kkarhan@mstdn.social
2023-10-09

@ainmosni @Linux_Is_Best

Yeah but that's just minimally less bad than going full #heads as aftermarket #firmware and requiring all executeables to be signed by the device owners' personal PGP keys...

Also I'd not trust a #blackbox like a #TPM as it violates #KerckhoffsPrinciple and thus must be considered cryptographically shit.

IMHO #TPMs and #Windows11 only act as #CensorBoot...

youtube.com/watch?v=s7WDbnHlc1

Kevin Karhan :verified:kkarhan@mstdn.social
2023-07-24

@md @bmi @bsi #TETRA's #Crypto is so #weak that it's trivial to crack with any modern #GPGPU, because it's #SecurityThroughObscurity makes all the #TEA versions as weak as #CSA on #DVB.

But then again noone pays me to fix it, so it's not my problem.

Spoiler: The proper fix is to abolish all #proprietary shit and demand a fully #OpenSource'd communications system, since everything else violates #KerckhoffsPrinciple and is thus inherently and unfixably insecure by design!

2023-07-24

Hacking police radios: 30-year-old crypto flaws in the spotlight - "Three may keep a secret, if two of them are dead." nakedsecurity.sophos.com/2023/ #kerckhoffsprinciple #vulnerability #cryptography #blackhaty #blackhat #tetra

Kevin Karhan :verified:kkarhan@mstdn.social
2023-05-15

@artikel10ev basically worse than everthing else...

[Or maybe not. cuz #QQ and #WeChat don't bother to lie into users' faces like @protonmail and #WhatsApp do]

Remember #KerckhoffsPrinciple:
#NotYourPrivateKeys = #NotSecureEncryption!

Also all #Singlevendor and/or #SingleProvider and/or non-#FLOSS solutions are inherently & unfixably bad as well as insecure per design!

Kevin Karhan :verified:kkarhan@mstdn.social
2023-05-02

@neil @Em0nM4stodon #Signal as well isn't secure.

NO #SingleVendor / #SingleProvider solution can be secure as they all violate #KerckhoffsPrinciple.
en.wikipedia.org/wiki/Kerckhof

If you can't do #SelfCustody of the #PrivateKeys and don't have 100% control over these, then consider said #encryption to be easily #MITM'd and / or #backdoored.

2022-09-20

A bit back in the book, but #Heinlein once more show that he has no idea about #criptografy.
Especially, like most authors, he has never heard of Kerckhoffs’ principle

The protagonist gets a message with “five-letter code groups, about fifty of them”. And “‘If they can identify the code, it is then just a matter of paying a fee, licit or illicit, to translate it.’”

en.wikipedia.org/wiki/Kerckhof

#cryptography #KerckhoffsPrinciple
#OspalhReads #worldasmyth #CatThruWalls

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst