Daily Archives: December 23, 2009

Takoma Park 2009: the conclusion

Well, it’s been a few weeks of craziness at home and catching up on other work, but I’ve finally wrapped up the Takoma Park 2009 audit. The final step: letting you, dear reader, run the audit all on your own. … Continue reading

Posted in crypto, Takoma Park 2009, voting | Leave a comment

It’s a WRAP followup: maybe the goal was client-side certs?

I’m having some interesting offline followup discussions with folks about oAuth WRAP and my relatively negative reaction to it. One of the comments seems to be that SSL will recreate exactly the security that HMAC signatures were trying to achieve, … Continue reading

Posted in security, web | Leave a comment