<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Encryption on Rietta Cybersecurity</title>
    <link>https://rietta.com/tags/encryption/</link>
    <description>Recent content in Encryption on Rietta Cybersecurity</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>1999-2026 Rietta Inc. All Rights Reserved.</copyright>
    <atom:link href="https://rietta.com/tags/encryption/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Generate OpenSSL Elliptic Curve Key Pair from the Command Line</title>
      <link>https://rietta.com/blog/openssl-generating-ec-key-from-command/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/openssl-generating-ec-key-from-command/</guid>
      <description>&lt;p&gt;Back in 2012, I wrote &lt;a href=&#34;https://rietta.com/blog/openssl-generating-rsa-key-from-command/&#34;&gt;Generate OpenSSL RSA Key Pair from the Command Line&lt;/a&gt;, which has gone on to become the single most-visited post on this entire blog. Fourteen years is a long run for a command-line tutorial, and RSA hasn&amp;rsquo;t gone anywhere. But if you&amp;rsquo;re generating a new key pair in 2026, I&amp;rsquo;d point you toward elliptic curve cryptography (ECC) instead of a bigger RSA key.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Shorter SSL/TLS Lifetimes: Business Impact of Monthly Certificate Renewals</title>
      <link>https://rietta.com/blog/shorter-tls-lifetimes-business-impact-of-monthly-renewals/</link>
      <pubDate>Tue, 22 Apr 2025 08:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/shorter-tls-lifetimes-business-impact-of-monthly-renewals/</guid>
      <description>The CA/Browser forum has reportedly approved a measure to reduce the allowed time for certificate validity from 398 to 47 days by March 15, 2029. This change will require users to renew certificates on a nearly monthly basis. This is a manual process that will now have to be done up to 10 times per year, instead of just once. This change will not be evident to most Internet users and businesses.</description>
    </item>
    <item>
      <title>Americans&#39; Access to Strong Encryption is at Risk, an Open Letter to Congress</title>
      <link>https://rietta.com/blog/americans-access-to-strong-encryption-is-at-risk/</link>
      <pubDate>Wed, 03 May 2017 19:34:59 -0400</pubDate>
      <guid>https://rietta.com/blog/americans-access-to-strong-encryption-is-at-risk/</guid>
      <description>&lt;p&gt;Dear Honorable Members of the United States Congress:&lt;/p&gt;&#xA;&lt;p&gt;I work in application security in the cybersecurity field to make software more secure from attack. The cybersecurity threats that face our nation are very important to my wife and me. As Americans, our private data is in great jeopardy because of increased cybersecurity threats. Our infrastructure is prone to being hacked, and major data breaches of both private and government networks are routinely in the news. The best way to prevent these breaches is to increase the use of strong encryption with &lt;em&gt;no backdoors&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The track record of data breaches demonstrates an uncomfortable truth: when sophisticated adversaries want to hack a network, they will ultimately win. Among the few tools known to computer science that can prevent a data breach is strong encryption. This means that there is no backdoor and no backup key. Either the original user needs to enter the password, or the data is un-retrievable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Calls to Ban Effective Encryption Continue Despite Data Breach Crisis</title>
      <link>https://rietta.com/blog/calls-to-ban-encryption-despite-data-breach-crisis/</link>
      <pubDate>Fri, 22 Apr 2016 09:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/calls-to-ban-encryption-despite-data-breach-crisis/</guid>
      <description>&lt;p&gt;The continued calls for the U.S. Congress to ban effective encryption despite the current computer security crisis in which data breaches are regular news is dangerous, shortsighted, and destined to harm all Americans. The two most effective tools that we have capable of helping prevent data breaches are encryption and reducing the attack surface of computer systems that handle sensitive or private data. Under the proposed legal framework, both will be sacrificed for a false sense of safety.&lt;/p&gt;&#xA;&lt;p&gt;The latest installment of Congressional hearings was held by the Energy and Commerce Committee on April 19, 2016, and was titled &lt;em&gt;Deciphering the Debate Over Encryption: Industry and Law Enforcement Perspectives&lt;/em&gt;. The calls for Congress to ban effective encryption are repeated with little variance from the past. Some Members of Congress are expressing frustration that the debate is repeating itself without law enforcement suggesting any particular middle ground that would be workable for the tech community. But what is most chilling is that those in law enforcement continue to demand exceptional access despite years of back and forth and the parade of high profile data breaches both within government and the private sector. We&amp;rsquo;re losing the cybersecurity battle and the government is calling for a ban on one of the most effective tools that computer science has at its disposal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>U.S. Senate Bill Seeks to Ban Effective Encryption, Making Security Illegal</title>
      <link>https://rietta.com/blog/feinstein-burr-encryption-bill/</link>
      <pubDate>Fri, 08 Apr 2016 10:11:33 -0400</pubDate>
      <guid>https://rietta.com/blog/feinstein-burr-encryption-bill/</guid>
      <description>&lt;p&gt;The anticipated Feinstein-Burr &lt;em&gt;Compliance with Court Orders Act&lt;/em&gt;, an anti-security bill, would&#xA;&lt;a href=&#34;https://www.scribd.com/doc/307378123/Burr-Encryption-Bill-Discussion-Draft&#34;&gt;require the provision of data in an intelligible format to a government pursuant to a court order&lt;/a&gt; (scribd.com). A draft copy was&#xA;uploaded by The Hill reporter &lt;a href=&#34;https://twitter.com/Cory_Bennett&#34;&gt;Cory Bennett&lt;/a&gt;, though whether&#xA;it has been submitted officially within the Senate is &lt;a href=&#34;https://motherboard.vice.com/en_ca/read/leaked-burr-feinstein-encryption-bill-is-a-threat-to-american-privacy&#34;&gt;not yet clear&lt;/a&gt; (vice.com).&lt;/p&gt;&#xA;&lt;p&gt;This bill essentially says you can not have any conversation or data exchange that the government can not access if it wants to.&#xA;It is the legal culmination of what the FBI has been lobbying Congress for years. If Feinstein-Burr&#xA;becomes law, it will be illegal to deploy strong encryption &lt;em&gt;without key escrow&lt;/em&gt; maintained by each company. Cryptographers and computer scientists near-unanimously assert key backup systems are insecure at scale.&lt;/p&gt;</description>
    </item>
    <item>
      <title>It is not just one iPhone, the FBI wants a future where it is impractical to deploy strong encryption without key escrow</title>
      <link>https://rietta.com/blog/its-not-just-one-iphone/</link>
      <pubDate>Wed, 16 Mar 2016 09:01:11 -0400</pubDate>
      <guid>https://rietta.com/blog/its-not-just-one-iphone/</guid>
      <description>&lt;p&gt;Crypto War II, the first crypto war having taken place in the 90s with the clipper chip, is in full swing with hostilities started back up a few years ago when FBI Director James Comey and others started lobbying congress and giving public speeches about how being unable to unlock some devices and communications makes it hard to do their job. It has been an unrelenting full public relations assault on practical strong encryption.&lt;/p&gt;&#xA;&lt;p&gt;Ultimately FBI Director James Comey wants a future where it is illegal or impractical to deploy strong encryption &lt;em&gt;without key escrow&lt;/em&gt;, which is a key backup system that the great consensus of cryptographers and computer scientists assert is insecure at scale. As a statesman he never comes out and says this directly, but it is the only conceivable outcome to what he is demanding of tech companies before congress and the actions that the FBI has taken in court.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How To Protect Against the POODLE SSLv3 Vulnerability</title>
      <link>https://rietta.com/blog/how-to-protect-against-the-poodle-sslv3-vulnerability/</link>
      <pubDate>Thu, 16 Oct 2014 09:21:22 -0400</pubDate>
      <guid>https://rietta.com/blog/how-to-protect-against-the-poodle-sslv3-vulnerability/</guid>
      <description>&lt;p&gt;The &lt;acronym title=&#34;Padding Oracle On Downgraded Legacy&#xA;Encryption&#34;&gt;POODLE&lt;/acronym&gt; SSL vulnerability marks the third major security flaw discovered this year that impacts the security of millions of websites.&lt;/p&gt;&#xA;&lt;p&gt;The attack works by forcing the connection to downgrade from the newer TLS protocol to the 18 year old SSL 3 protocol, which is obsolete and insecure, and then utilizing a weakness to calculate small strings of data from the encrypted communication, such as session cookies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Raspberry Pi crypto key management project!</title>
      <link>https://rietta.com/blog/raspberry-pi-crypto-project/</link>
      <pubDate>Thu, 02 Oct 2014 21:20:16 -0400</pubDate>
      <guid>https://rietta.com/blog/raspberry-pi-crypto-project/</guid>
      <description>&lt;p&gt;A few months ago I bought a &lt;a href=&#34;http://www.raspberrypi.org/&#34;&gt;Raspberry Pi B&lt;/a&gt; to experiment with, but sadly my day job as a Ruby developer keep me busy enough that it just sat on the shelf unused until this last weekend. For those not yet in the know, the Raspberry Pi is an excellent little complete computer system on a small circuit board that uses very low power and looks like this:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://rietta.com/images/posts/2014/10/raspberry_pi_b_first_boot.jpg&#34; alt=&#34;My Raspberry Pi booting for the First Time!&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction to OpenPGP: Decrypt this Message</title>
      <link>https://rietta.com/blog/the-openpgp-encrypted-message-exercise/</link>
      <pubDate>Mon, 07 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/the-openpgp-encrypted-message-exercise/</guid>
      <description>If you have been following the news in light of the revelations of the NSA domestic surveillance program, which is probably unconstitutional in the United States but in practice is being permitted by the courts, then you should know something about the encrypt everything movement and Google&amp;rsquo;s End-to-End project, which is to add OpenPGP to the Chrome web browser. If this is new to you, this fun challenge will help you get started with what you need to decrypt a message with GnuPG!</description>
    </item>
    <item>
      <title>Secure Passwords &amp; Passphrases</title>
      <link>https://rietta.com/blog/secure-passwords/</link>
      <pubDate>Mon, 25 Nov 2013 17:40:00 +0000</pubDate>
      <guid>https://rietta.com/blog/secure-passwords/</guid>
      <description>Sometimes when someone sees me type my long password to log into my laptop, I get asked about why I use such a long password. I always sigh a little. Deep down inside, I reflect on how there is not a concise, easy, actionable answer that will help that person practice better password security. My laptop password is better than most, but even it would be potentially susceptible to long, sustained offline attacks.</description>
    </item>
    <item>
      <title>OpenSSL: Encrypt Data with an RSA Key with PHP</title>
      <link>https://rietta.com/blog/openssl-encrypt-data-with-rsa-key-with/</link>
      <pubDate>Thu, 13 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/openssl-encrypt-data-with-rsa-key-with/</guid>
      <description>Web application security is built upon a series of interconnected building blocks.&#xA;This post is part of Rietta&amp;rsquo;s ongoing coverage of encryption. Browse the Encryption tag for the rest of the series.&#xA;Last year, I wrote about how Generating an RSA Key from the Command Line in OpenSSL could support encrypting or validating data in an unattended manner (where the password is not required to encrypt). A few weeks before that, I posted about how to Encrypt a File with a Password from the Command Line using OpenSSL.</description>
    </item>
    <item>
      <title>What is Protected Personally Identifiable Information? Do I really have to hash users&#39; passwords?</title>
      <link>https://rietta.com/blog/what-is-protected-personally/</link>
      <pubDate>Thu, 05 Apr 2012 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/what-is-protected-personally/</guid>
      <description>This post is part of Rietta&amp;rsquo;s ongoing coverage of encryption. Browse the Encryption tag for the rest of the series.&#xA;The Short Answer The legal answer depends on which Federal, State, and local laws apply to your company. And I am not a lawyer. However, for companies whose nexus is in Georgia, where my company is located, the Georgia General Assembly has given some guidance in the data breach law.</description>
    </item>
    <item>
      <title>Generate OpenSSL RSA Key Pair from the Command Line</title>
      <link>https://rietta.com/blog/openssl-generating-rsa-key-from-command/</link>
      <pubDate>Fri, 27 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/openssl-generating-rsa-key-from-command/</guid>
      <description>&lt;p&gt;While &lt;a href=&#34;https://rietta.com/blog/openssl-encrypt-file-with-password-from/&#34;&gt;Encrypting a File with a Password from the Command Line using OpenSSL&lt;/a&gt;&#xA;is very useful in its own right, the &lt;em&gt;real power&lt;/em&gt; of the OpenSSL library is its&#xA;ability to support public key cryptography: encrypting or validating data in&#xA;an unattended manner, where the password protecting the private key is never&#xA;needed by the process doing the encrypting or validating.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OpenSSL: Encrypt a File with a Password from the Command Line</title>
      <link>https://rietta.com/blog/openssl-encrypt-file-with-password-from/</link>
      <pubDate>Mon, 09 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/openssl-encrypt-file-with-password-from/</guid>
      <description>Do you know how to use OpenSSL to protect sensitive information in storage instead of just in transit across the network? In fact, your can use the OpenSSL command line too to encrypt a file on your Mac OS X, Linux, or FreeBSD based computer. Support for the library are included by default in PHP and Ruby. So there is no reason not to use it to add additional security to your web applications.</description>
    </item>
    <item>
      <title>Authentication Without Encryption for Ham Radio</title>
      <link>https://rietta.com/blog/authentication-without-encryption-for/</link>
      <pubDate>Mon, 17 Aug 2009 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/authentication-without-encryption-for/</guid>
      <description>In April 2004, I gave a talk for the Atlanta Radio Club about the possibilities for authenticated digital communication for amateur radio applications. I published the document on my Georgia Tech website at that time. Since I no longer have an account at Georgia Tech, I am re-posting the document here.&#xA;Authenticating on a Ham Internet The FCC regulations for amateur radio, part 97, rule that encryption cannot be used to obscure the meaning of communications.</description>
    </item>
  </channel>
</rss>
