[Cryptography] Crypto Bug Tool site set up incorrectly

Henry Baker hbaker1 at pipeline.com
Tue Dec 20 09:29:26 EST 2016


FYI --

https://tech.slashdot.org/story/16/12/19/2120237/google-releases-tool-to-find-common-crypto-bugs

https://www.onthewire.io/google-releases-project-wycheproof-crypto-test-suite/

"Your connection is not secure"

"The owner of www.onthewire.io has configured their website improperly.  To protect your information from being stolen, Tor Browser has not connected to this website."

https://github.com/google/wycheproof

Google has released a new set of tests it uses to probe cryptographic libraries for vulnerabilities to known attacks.  The tests can be used against most kinds of crypto algorithms and the company already has found 40 new weaknesses in existing algorithms.  The tests are called Project Wycheproof, and Google's engineers designed them to help developers implement crypto libraries without having to become experts.

---
I'd find this site more believable if their own certificates were configured properly.

Chrome, Firefox and Tor Browser all tell me that "www.onthewire.io" is not configured properly.



More information about the cryptography mailing list