#NonRepudiation

tuxwise πŸ‡ΊπŸ‡¦tuxwise@mastodon.de
2024-12-10

(15/N) Two more threat types defined:

Undesirable non-repudiation or repudiation

#Repudiation (plausible denial) of what somebody has said / done / known / possessed becomes impossible because an adversary has managed to collect enough evidence to establish undesirable non-repudiation. In other words: the adversary can prove beyond reasonable doubt that "it" happened.

Alternatively, #NonRepudiation (proof beyond reasonable doubt) cannot be established because an adversary has managed to suppress or destroy enough evidence to gain the option of repudiation (plausible denial). In other words: the adversary can plausibly deny "it" happened.

Detecting

An adversary can check for the presence or absence of specific data items, which are tell-tale indicators for something else.

(to be continued)

Start of this thread:
mastodon.de/@tuxwise/113503228

#ThreatModeling #4D

tuxwise πŸ‡ΊπŸ‡¦tuxwise@mastodon.de
2024-12-09

(14/N) Having familiarized ourselves with categories of adversaries, their main goals and their respective, overall "modus operandi", let's look at the types of threats posed by them.

Again, it pays to focus on types of threats: We don't want to become mainly alert-triggered, but proactive. There are several frameworks we can borrow ideas from, most notably the LINDDUN framework that is geared toward threats to privacy, and can be extended a bit to cover more ground.

First, our list of threat types:

Our definitions of these, for our context:

Linking

An adversary can figure out connections and relationships between formerly isolated items of interest.

Identifiying

An adversary can link items of interest directly to a natural person.

(to be continued)

Start of this thread:
mastodon.de/@tuxwise/113503228

LINDDUN:
linddun.org/

#ThreatModeling #4D

Jesse Alexander, WB2IFS/3wb2ifs@mastodon.hams.social
2024-02-11

Look. y'all can't just say you want #diversity in #hamradio and not make it safe for the diversifiers. πŸ€ͺ I like how @PrideRadioGroup and OMIK are using #digital comms that inherently support #nonrepudiation--you have to sign up & use your callsign or no talkie for you.πŸ‘

2023-01-27

re:Boot ~ Creating an AWS Account: ACM.142 Complications led me to create a new AWS account from scratch for my next experiment
~~~~~
by Teri Radichel | Jan 27, 2023
#cloudsecurity #aws #account #root #mfa #nonrepudiation #bestpractices #cybersecurity

medium.com/cloud-security/re-b

Solinvictus :vm:dminca@mastodontech.de
2022-06-19

"Replace CAPTCHAs with Private Access Tokens" -- could this be the future?

developer.apple.com/videos/pla

#nonRepudiation #security

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst