# digital signatures

Published articles for digital signatures.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## HTTP Message Signatures with curl

DevFeed: [HTTP Message Signatures with curl](<https://devfeed.tech/articles/http-message-signatures-with-curl-18900.md>)

Original publisher: [Read original article](<https://daniel.haxx.se/blog/2026/07/27/http-message-signatures-with-curl/>)

Author: Daniel Stenberg

Published: 2026-07-27T06:55:03Z

Content type: release

Language: en

Sources: [Daniel Stenberg](<https://devfeed.tech/sources/daniel-stenberg.md>)

Topics: [cURL](<https://devfeed.tech/topics/curl.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [curl](<https://devfeed.tech/tags/curl.md>), [curl-and-libcurl](<https://devfeed.tech/tags/curl-and-libcurl.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [ed25519](<https://devfeed.tech/tags/ed25519.md>), [experimental](<https://devfeed.tech/tags/experimental.md>), [git](<https://devfeed.tech/tags/git.md>), [hmac](<https://devfeed.tech/tags/hmac.md>), [http](<https://devfeed.tech/tags/http.md>), [production](<https://devfeed.tech/tags/production.md>), [release](<https://devfeed.tech/tags/release.md>)

### AI overview

curl experimentally supports HTTP Message Signatures based on RFC 9421, allowing users to sign selected HTTP request components with ed25519 or hmac-sha256 through new command-line and libcurl options. The feature must be explicitly enabled, is discouraged for production use, and is planned for curl 8.22.0.

### Source excerpt

The recently published RFC 9421 describes how to do HTTP Message Signatures, and starting just now, curl experimentally supports them. Message Signatures The specification describes this as a mechanism for creating, encoding, and verifying digital signatures or message authentication codes over components of an HTTP message. It is a way to verify that selected parts ... Continue reading HTTP Message Signatures with curl ->

## New Chainguard Academy course: Securing the AI/ML Supply Chain

DevFeed: [New Chainguard Academy course: Securing the AI/ML Supply Chain](<https://devfeed.tech/articles/new-chainguard-academy-course-securing-the-ai-ml-supply-chain-13172.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-chainguard-academy-course-securing-the-ai-ml-supply-chain>)

Published: 2024-07-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [developers](<https://devfeed.tech/tags/developers.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [pytorch](<https://devfeed.tech/tags/pytorch.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

Chainguard is launching a hands-on, self-paced Chainguard Academy course on securing the AI/ML supply chain. The course covers supply-chain components, cyberattacks, regulations, standards, risk-mitigation tools, vulnerability scanning, SBOMs, digital signatures, provenance, and Chainguard AI Images such as PyTorch.

### Source excerpt

Learn to secure your AI/ML supply chain with Chainguard's new course, designed to help you mitigate risks and build safer AI/ML systems.

## Top 5 takeaways from KubeCon NA 2023: SSCS, Wolfi and more

DevFeed: [Top 5 takeaways from KubeCon NA 2023: SSCS, Wolfi and more](<https://devfeed.tech/articles/top-5-takeaways-from-kubecon-na-2023-sscs-wolfi-and-more-13296.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/top-5-takeaways-from-kubecon-na-2023-sscs-wolfi-and-more>)

Published: 2023-11-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubecon-na](<https://devfeed.tech/tags/kubecon-na.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sscs](<https://devfeed.tech/tags/sscs.md>), [wofli](<https://devfeed.tech/tags/wofli.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard reviews five takeaways from KubeCon North America 2023, focusing on the event's growth, the rising awareness of software supply chain security, and the shift toward implementing security tools and processes within software development. The article also highlights SBOMs, digital signatures, attestations, Wolfi, and related cloud-native topics.

### Source excerpt

Chainguard's breakdown of KubeCon NA 2023: Top five highlights in software supply chain security, Wolfi, and more.

## From U2F to passkeys

DevFeed: [From U2F to passkeys](<https://devfeed.tech/articles/from-u2f-to-passkeys-36608.md>)

Original publisher: [Read original article](<http://www.imperialviolet.org/2023/07/23/u2f-to-passkeys.html>)

Author: Adam Langley

Published: 2023-07-23T00:00:00Z

Content type: article

Language: en

Sources: [ImperialViolet](<https://devfeed.tech/sources/imperialviolet.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Security](<https://devfeed.tech/topics/security.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [protocol](<https://devfeed.tech/tags/protocol.md>)

### AI overview

This article gives a chronological account of how standards developed from U2F into passkeys. It explains U2F's security-key and JavaScript API standards, the risks of bearer tokens such as passwords and cookies, and how digital signatures can authenticate users without disclosing a private key.

### Source excerpt

(This post is nearing 8 000 words. If you want to throw it onto an ereader there's an EPUB version too.) Introduction Over more than a decade, a handful of standards have developed into passkeys--a plausible replacement for passwords. They picked up a lot of complexity on the way, and this post tries to give a chronological account of the development of the core of these technologies. Nothing here is secret; it's all described in various published standards. However, it can be challenging to read these standards and understand how it's meant to fit together. The beginning: U2F U2F stands for "Universal Second Factor". It was a pair of standards, one for computers to talk to small removable devices called security keys, and the second a JavaScript API for websites to use them. The first standard of the pair is also called the Client to Authenticator Protocol (CTAP1), and when the term "U2F" is used in isolation, it usually refers to that. The JavaScript API, now obsolete, was generally referred to as the "U2F API". The goal of U2F was to eliminate "bearer tokens" in user authentication. A "bearer token" is a term of art in authentication that refers to any secret that is passed around to prove identity. A password is the most common example of such a secret. It's a bearer token because you prove who you are by disclosing it, on the assumption that nobody else knows the secret. Passwords are not the only bearer tokens involved in computer security by a long way--the infamous cookies that all web users are constantly bothered about are another example. But U2F was focused on user authentication, while cookies identify computers, so U2F was primarily trying to augment passwords. The problem with bearer tokens is that to use them, you have to disclose them. And knowledge of the token is how you prove your identity. So every time you prove your identity, you are handing another entity the power to impersonate you. Hopefully, the other entity is the intended counterparty and

## Introducing "Speranza": Enhancing software signing with privacy and usability

DevFeed: [Introducing "Speranza": Enhancing software signing with privacy and usability](<https://devfeed.tech/articles/introducing-speranza-enhancing-software-signing-with-privacy-and-usability-13121.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-speranza-enhancing-software-signing-with-privacy-and-usability>)

Published: 2023-05-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pii](<https://devfeed.tech/tags/pii.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard Labs introduces Speranza, a research project for usable, privacy-friendly software signing. The article explains how it aims to improve software supply chain security while addressing the usability problems of long-lived cryptographic keys and the privacy risks of exposing maintainers' identities or metadata. It also discusses potential applications in open source package repositories and enterprise deployments of Sigstore.

### Source excerpt

Chainguard Labs announces, "Speranza: Usable, privacy-friendly software signing," to help balance usability and privacy for software signing techniques.

## It all started with a commit: Celebrating 6 years of Distroless

DevFeed: [It all started with a commit: Celebrating 6 years of Distroless](<https://devfeed.tech/articles/it-all-started-with-a-commit-celebrating-6-years-of-distroless-13129.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/it-all-started-with-a-commit-celebrating-6-years-of-distroless>)

Published: 2023-04-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [bazel](<https://devfeed.tech/tags/bazel.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [debian](<https://devfeed.tech/tags/debian.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [distroless-containers](<https://devfeed.tech/tags/distroless-containers.md>), [go](<https://devfeed.tech/tags/go.md>), [java](<https://devfeed.tech/tags/java.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [python](<https://devfeed.tech/tags/python.md>), [release-engineering](<https://devfeed.tech/tags/release-engineering.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [verify](<https://devfeed.tech/tags/verify.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article commemorates six years of Distroless, describing its goal of creating more secure and efficient container images by removing non-essential components. It covers the Bazel-based build tooling, language runtimes, Kubernetes adoption, vulnerability-management benefits, and later integration with Sigstore for container signing and authenticity verification. It also introduces the subsequent development of Chainguard Images.

### Source excerpt

The goal of Distroless is to provide a more secure and efficient way to package and run software in containers by using only essential components.

## The role of attestations in a secure software supply chain

DevFeed: [The role of attestations in a secure software supply chain](<https://devfeed.tech/articles/the-role-of-attestations-in-a-secure-software-supply-chain-13269.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-role-of-attestations-in-a-secure-software-supply-chain>)

Published: 2023-04-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [Docker Verified Publisher](<https://devfeed.tech/topics/docker-verified-publisher.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-attestations](<https://devfeed.tech/tags/software-attestations.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article explains how attestations support software supply-chain policy enforcement. It describes attestations as signed claims from identified speakers about code or build results, allowing deployment systems to verify policy requirements without repeating expensive or impractical checks.

### Source excerpt

Chainguard Enforce enables policy enforcement using attestations. Learn how to use these principles to create and enforce secure supply chain policies.

## New SLSA++ Survey reveals real-world developer approaches to software supply chain security

DevFeed: [New SLSA++ Survey reveals real-world developer approaches to software supply chain security](<https://devfeed.tech/articles/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security-13183.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security>)

Published: 2023-03-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [openssf](<https://devfeed.tech/topics/openssf.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [report](<https://devfeed.tech/tags/report.md>), [rust](<https://devfeed.tech/tags/rust.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

A joint survey by Chainguard, the Eclipse Foundation, the Rust Foundation, and OpenSSF examined how developers, open source maintainers, and security practitioners adopt software supply chain security practices. Among nearly 170 respondents, centralized build services showed relatively strong adoption, while consistently signing built artifacts was less common, with 25% reporting that their team always did so. Respondents generally considered the surveyed practices helpful.

### Source excerpt

Findings on software supply chain security practice adoption from our joint survey with OpenSSF, Rust, and Eclipse with questions derived from SLSA requirements.

## Ultimate Go: Advanced Engineering Episode 13

DevFeed: [Ultimate Go: Advanced Engineering Episode 13](<https://devfeed.tech/articles/ultimate-go-advanced-engineering-episode-13-22202.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2023/01/ultimate-go-advanced-engineering-episode-13.html>)

Published: 2023-01-11T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Algorithm](<https://devfeed.tech/topics/algorithm.md>), [Security](<https://devfeed.tech/topics/security.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [API](<https://devfeed.tech/topics/api.md>), [Transactions](<https://devfeed.tech/topics/transactions.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [data-stamping](<https://devfeed.tech/tags/data-stamping.md>), [digital-signature](<https://devfeed.tech/tags/digital-signature.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [go](<https://devfeed.tech/tags/go.md>), [go-blockchain](<https://devfeed.tech/tags/go-blockchain.md>), [hash](<https://devfeed.tech/tags/hash.md>), [hexademical](<https://devfeed.tech/tags/hexademical.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [keccak256](<https://devfeed.tech/tags/keccak256.md>), [salt](<https://devfeed.tech/tags/salt.md>), [security](<https://devfeed.tech/tags/security.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

This video tutorial explains how to add a salt value to transaction hashes, implement the keccak256 algorithm in Go, and use transaction stamping in a blockchain. It also discusses digital signatures and related security issues.

### Source excerpt

Introduction In episode 12, Bill laid out his strategy to handle data hashing on his blockchain. The first step he took was to create a package to handle the cryptographical aspects of his blockchain. After that, he wrote a hash function that met the requirements outlined in his strategy. This function took transaction data as a parameter and returned a hexadecimal representation of the hash. To implement this function, Bill imported packages from the Go standard library and Ethereum API.

## Comparing Four Passwordless SSH Authentication Methods

DevFeed: [Comparing Four Passwordless SSH Authentication Methods](<https://devfeed.tech/articles/ssh-authentication-methods-which-is-best-29610.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/comparing-passwordless-ssh-authentication-methods/>)

Author: sakshyam.shah@goteleport.com (Sakshyam Shah)

Published: 2022-02-11T00:00:00Z

Content type: comparison

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [ssh](<https://devfeed.tech/topics/ssh.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [blog](<https://devfeed.tech/tags/blog.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This article compares four passwordless SSH authentication methods: key-based, certificate-based, host-based, and out-of-band authentication through a custom PAM module. It explains how SSH key authentication works and discusses its setup, scalability, rotation, and stolen-key considerations.

### Source excerpt

This blog post compares four different passwordless authentication methods for SSH: SSH keys, certificates, host-based, and PAM modules.

## The Asset Trap

DevFeed: [The Asset Trap](<https://devfeed.tech/articles/the-asset-trap-36999.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-asset-trap/>)

Author: Adam

Published: 2020-12-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [solarwinds](<https://devfeed.tech/topics/solarwinds.md>), [digital signatures](<https://devfeed.tech/topics/digital-signatures.md>), [email](<https://devfeed.tech/topics/email.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [email](<https://devfeed.tech/tags/email.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [systems](<https://devfeed.tech/tags/systems.md>)

### AI overview

This commentary uses the SolarWinds attack to explain an asset-focused threat-modeling trap. It argues that defenders should consider assets attackers want, such as DKIM keys, which can be used to forge emails that pass validity checks, and recommends rotating those keys regularly.

### Source excerpt

As we look at what's happened with the Russian attack on the US government and others via Solarwinds, I want to shine a spotlight on a lesson we can apply to threat modeling.

## Introducing Elliptic Curves

DevFeed: [Introducing Elliptic Curves](<https://devfeed.tech/articles/introducing-elliptic-curves-40341.md>)

Original publisher: [Read original article](<https://www.jeremykun.com/2014/02/08/introducing-elliptic-curves/>)

Published: 2014-02-08T10:00:14Z

Content type: tutorial

Language: en

Sources: [Jeremy Kun](<https://devfeed.tech/sources/jeremy-kun.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Programming](<https://devfeed.tech/topics/programming.md>), [Algorithms, Complexity](<https://devfeed.tech/topics/algorithms-complexity.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [cryptography](<https://devfeed.tech/tags/cryptography.md>), [diffie-hellman](<https://devfeed.tech/tags/diffie-hellman.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [elliptic-curves](<https://devfeed.tech/tags/elliptic-curves.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [implementing](<https://devfeed.tech/tags/implementing.md>), [nsa](<https://devfeed.tech/tags/nsa.md>), [python](<https://devfeed.tech/tags/python.md>), [rsa](<https://devfeed.tech/tags/rsa.md>)

### AI overview

An introductory tutorial series on elliptic curves and elliptic curve cryptography. It explains the motivation for ECC, its relationship to RSA and cryptographic security, and plans implementations covering finite fields, key exchange, encryption, and digital signatures.

### Source excerpt

With all the recent revelations of government spying and backdoors into cryptographic standards, I am starting to disagree with the argument that you should never roll your own cryptography. Of course there are massive pitfalls and very few people actually need home-brewed cryptography, but history has made it clear that blindly accepting the word of the experts is not an acceptable course of action. What we really need is more understanding of cryptography, and implementing the algorithms yourself is the best way to do that.