Hacker News
- Major cryptography blunder in Java enables “psychic paper” forgeries https://arstechnica.com/information-technology/2022/04/major-crypto-blunder-in-java-enables-psychic-paper-forgeries/ 2 comments
- Major cryptography blunder in Java enables “psychic paper” forgeries https://arstechnica.com/information-technology/2022/04/major-crypto-blunder-in-java-enables-psychic-paper-forgeries/ 38 comments programming
Linking pages
Linked pages
- This 40-second solar eclipse seen from the surface of Mars is sublime | Ars Technica https://arstechnica.com/science/2022/04/nasa-rover-captures-an-amazing-view-of-a-solar-eclipse-on-mars/ 261 comments
- JSON Web Tokens - jwt.io http://jwt.io 221 comments
- Guide to Web Authentication https://webauthn.guide/ 208 comments
- CVE-2022-21449: Psychic Signatures in Java – Neil Madden https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/ 207 comments
- Apple has finally embraced key-based 2FA. So should you | Ars Technica https://arstechnica.com/information-technology/2020/07/apple-has-finally-embraced-key-based-2fa-so-should-you/ 171 comments
- Elliptic Curve Digital Signature Algorithm - Wikipedia https://en.wikipedia.org/wiki/Elliptic_Curve_Digital_Signature_Algorithm 29 comments
- RFC 7519: JSON Web Token (JWT) https://tools.ietf.org/html/rfc7519 10 comments
- Thomas H. Ptacek on Twitter: "Welp. It’s the crypto bug of the year. Mark it down for April. Java 15-18 ECDSA doesn’t sanity check that the random x coordinate and signature proof are nonzero; a (0,0) signature validates any message. Breaks JWT, SAML, &ampampampampampampampampampampampampampampampampampampampampampampampampampampampampampampampampampampampamp;c. https://t.co/t2WgnS0g3A" / Twitter https://twitter.com/tqbf/status/1516570590211153922 6 comments
- A (relatively easy to understand) primer on elliptic curve cryptography | Ars Technica https://arstechnica.com/information-technology/2013/10/a-relatively-easy-to-understand-primer-on-elliptic-curve-cryptography/ 0 comments
- OpenID - Wikipedia https://en.wikipedia.org/wiki/OpenID 0 comments
- Critical cryptographic Java security blunder patched – update now! – Naked Security https://nakedsecurity.sophos.com/2022/04/20/critical-cryptographic-java-security-blunder-patched-update-now/ 0 comments
- https://www.oracle.com/security-alerts/cpuapr2022.html 0 comments
Would you like to stay up to date with Java? Checkout Java
Weekly.
Related searches:
Search whole site: site:arstechnica.com
Search title: Major cryptography blunder in Java enables “psychic paper” forgeries | Ars Technica
See how to search.