DSDoogal Simpsonindoogal.dev·2d ago · 5 min readHow iPhone's Secure Enclave Stops Brute-Force AttacksTL;DR: Your iPhone protects your 6-digit passcode by combining hardware-bound cryptography with forced validation delays. The Secure Enclave enforces a deliberate 80-millisecond verification lag along10
HFHussain Fakhruddininsultanbyte.com·2d ago · 6 min readQuantumGate–NEC: planning a UAE post-quantum migrationQuantumGate's new collaboration with NEC GCC gives UAE infrastructure operators another route into post-quantum cryptography. The useful part of the announcement is the proposed delivery chain: discov00
DSDoogal Simpsonindoogal.dev·5d ago · 4 min readSHA-256 vs Bcrypt: Why Speed Kills Password SecurityQuick Answer: Standard cryptographic hashes like SHA-256 are built for speed, making them dangerous for password storage. Bcrypt defeats offline brute-force attacks by introducing a configurable cost 20
AArkWardeninarkwarden.hashnode.dev·Sep 30 · 4 min readEncryption Alone Doesn't Stop a Password Guesser. Here's What Does.Most encrypted vault apps ask for a password, run it through a slow hash, and call the file secure. A slow hash only raises the cost of each guess. If someone copies the encrypted file, they can run u00
TOTapbit Officialintapbitofficial.hashnode.dev·Sep 29 · 9 min readHow Seed Phrases Rebuild HD Wallets: Entropy, Checksums, BIP-39, and Derivation PathsA seed phrase looks like a short list of ordinary words. Underneath, it is a portable representation of random data that wallet software can transform into a deterministic tree of cryptographic keys. 00
SGSui Gninneurons-me.hashnode.dev·Sep 27 · 3 min readAudience AlgebraThe problem Encrypting a secret for one person is solved. .me already does it by wrapping a key to that person's public key. Real audiences are rarely one person, though. Sometimes "anyone of us" can 00
MMefistoindiegox.hashnode.dev·Sep 26 · 2 min readDIEGOX: Post-Quantum Security Meets Dual-KEM Plausible DeniabilityMost modern cryptographic tools focus strictly on algorithm strength. However, in real-world threat models, coercion and rubber-hose cryptanalysis remain significant vulnerabilities. DIEGOX is an open00
MSMolly Sohaneyinmollysohaney.hashnode.dev·Sep 25 · 5 min readCTF Writeup: Ways To Lie | Crypto | MetaCTF September 2026 FlashDescription The conservatory archive kept one honest page and ninety nine forgeries. Every copyist who passed through left a version behind, each prettier than the last, and the archivist who could t00
Kkepler-opsinproof-random-api.hashnode.dev·Sep 25 · 5 min readDon't trust the randomness API: verify drand beacons and sampled valuesAgents keep needing a random number that another party can check: picking a reviewer, breaking a tie, sampling a test case, running a small raffle. Math.random() works until someone asks "prove you di00
JJebitokinsharonjebitok.com·Sep 23 · 6 min readOverheard at Breakfast: OSINT - image x Gmail x Gravatar profile & Base64 (TryHackMe)Link to the CTF challenge on TryHackMe: Overheard at Breakfast Concierge Briefing The breakfast terrace is loud this morning, clinking cutlery, espresso machines, the usual chatter. One guest couldn'00