yon Leveron blog

John's musings on the Interknot cowpath

some new intel 32nm chips to support hardware AES acceleration

Posted by John on 3rd February 2010

(this next bit can affect everything from certain web transactions, to VoIP, to full disk encryption . . .)

AES-NI Performance Analyzed; Limited To 32nm Core i5 CPUs

2:00 AM – 02/02/2010 by Patrick Schmid and Achim Roos

Security is an important topic these days. However, it’s typically only recognized as important by professionals. If security were to suddenly turn into a mainstream selling point, though, then perhaps it’d make more sense for companies like Intel to promote it.

The Advanced Encryption Standard (AES) has already been adopted by the United States government—including the NSA—along with many other institutions. Intel’s 32nm Clarkdale-based CPUs (only the Core i5-600-series, so far) now promise significant performance benefits for AES encryption and decryption via new instructions. Today we’re looking at the real-world benefits of Intel’s AES-NI functionality, comparing a dual-core Core i5-661 with AES New Instructions (AES-NI) to a quad-core Core i7-870, which lacks the new encryption acceleration capability.

Encryption is used much more intensively than you might suspect. Consider Internet sites that hold you sensitive personal information, or utilize sensitive data for transactions. They all use protocols like Transport Layer Security (TLS) or Secure Sockets Layer (SSL). VoIP, instant messaging, and email may also be protected with these protocols. Virtual Private Networks (VPNs) and electronic payments are other popular encryption applications.

However, TLS and SSL are cryptographic protocols for secure communication, while AES is a general-purpose encryption standard. It can be used to encrypt individual files, data containers, archive files, entire drives (including thumb drives), and even multi-drive volumes. AES can be implemented in software, and there are products based on hardware acceleration as well, since encryption/decryption represent a rather significant workload. Solutions like TrueCrypt or Microsoft’s BitLocker, which is part of Windows Vista and Windows 7 Ultimate, are capable of encrypting entire partitions on the fly.

(for the rest of the first page, and all the other pages, hit up Tom’s)

—————-
Now playing: Men At Work – Crazy
via FoxyTunes

  • Windows Live Favorites
  • Technorati Favorites
  • Share/Bookmark

Tags: , , , ,
Posted in Security - Crypto, Tech | No Comments »

SkyDrive Explorer

Posted by John on 12th December 2009

Although not nearly so full featured as Gladinet, not bad for a single-use type scenario . . .


What is SkyDrive Explorer

SkyDrive Explorer is a free, easy-to-use, but very powerful extension for Windows Explorer. With SkyDrive Explorer you can make any every-day operations with your documents from Microsoft Live SkyDrive™ service (read more…) using Windows Explorer, as if they were on your computer.

Moreover you don’t need to install and configure any additional programs or ActiveX components. SkyDrive Explorer will organize the interaction with the online storage itself.

Features

Multifunctional

Multifunctional

With the current 1.4 version you can enjoy the following functionality:

  • View the structure and contents of folders in SkyDrive™;
  • View files information (type, size, creation date in GMT format);
  • Create new root folders and subfolders;
  • Copy files into the storage;
  • Delete files and folders;
  • Copy files from the storage to the computer;
  • Copy folders and subfolders from the storage to the computer keeping their structure;
  • Use Drag & Drop for files operations;
  • Rename files and folders;
  • Create links to SkyDrive™ folders on your computer;
  • Copy URL of the selected object(s) to the Clipboard;
  • Automatic check for the latest version;
  • Bidirectional languages support;
  • Selection of your preferred interface language.

Fast

Perfomance

SkyDrive Explorer allows applying some operations for group of objects that is not possible in web browser. This increases performance of work with SkyDrive™.

Examples of multi-operations are:

  • Renaming objects;
  • Deleting group of objects;
  • Copying folders with subfolders and files from SkyDrive™.

Easy

Easy

You don’t need to know how to work with the SkyDrive™ service in web browser. To work efficiently with your data in SkyDrive Explorer you just use base operations with files and folders in Windows Explorer.

Secure

Secure

SkyDrive Explorer uses the standard Microsoft library for work with Windows Live Id services. Your personal information does not leave this library and even is not passed to SkyDrive Explorer engine. Also, the traffic with online storage goes through HTTPS protocol that protects data from snoopers.

Cross-platform

32/64 bit OS support

SkyDrive Explorer works both in 32- and 64-bit Microsoft® Windows OS. Minimal required OS is Windows XP, and SkyDrive Explorer will successfully work in Windows Vista, Windows Server 2003 and 2008, and Windows 7.

—————-
Now playing: Grateful Dead – Good Lovin’
via FoxyTunes



  • Windows Live Favorites
  • Technorati Favorites
  • Share/Bookmark

Tags: ,
Posted in Tech | No Comments »

SSL Certificate Tester – Let us test / check your web site certificate

Posted by John on 15th August 2009

Techie alert – sometimes it is helpful to see how your web site’s SSL certificate SSL_Lock looks from other folks / outside.  These tools may help.

SSL Checker – SSL Certificate Verify.

SSL Certificate Tester – Check Certificates.

SSL Certificate Checker – CodeFromThe70s.org

I did not include gimped tools from the Thawte / Verisign company, as they only check their own certs.

These tests are done over the ‘net so may not be suitable for internal / LAN type sites.  But they also don’t require anyone to have tech knowledge, or make you use an openssl binary to connect manually from the command line.  Nor do they require you to bug anyone, asking if they can browse to it successfully, heh.  By all means, as always if you have a good link for other resources, just comment and I’ll add it.

J.

P.S.  For simple encryption without needing to verify anything but domain ownership, it’s pretty hard to beat Godaddy.  If you are interested in cheap, non business class, I’d recommend you scout out any of the $12.99 per year promo discount codes for them; they were already significantly cheaper than most other folks at $30 per year, but $13 is better.  Yep.  A company I dealt with last month paid on the order of $200 per cert, in bulk prepaid lots no less (!) for effectively the same cert from one of the original vendors.  That’s just not necessary in 2009 folks.

Forward looking folks : Check the https website cert that the entire WordPress.Com site is running on.  It’s a Standard SSL Wildcard, and it costs them under $200 per year to secure thousands of subdomains such as https://datasecurityclass.wordpress.com/2009/03/30/ihors-ssl-topic/ WordPress corporate (not .org, .com) felt it was fine to go with the Standard, and I agree.

It’s not so much that it costs less per year than the “Deluxe” SSL Wildcard, but if you check, the Deluxe has a max 3 year lifespan; their cert is good for 5 years total.  In essence, they got 5 years of SSL capability (trusted by that same 99.3% of browsers as other folks tout) for actually tens of thousands of sites, for $900 or less.  I get no commission from GoDaddy, but I think there’s a reason they’re beating the heck out of the rest of the industry in new SSL cert issuance.


In EV land, 2 years is the max, and there is no wildcard option due to tighter security requirements (as well as simple business sense, ahem).  EV makes great sense if you’re taking credit card orders on a screen; that should hopefully only be one website.

  • Windows Live Favorites
  • Technorati Favorites
  • Share/Bookmark

Tags: , ,
Posted in Security - Crypto | No Comments »

Web hosting companies

Posted by John on 14th August 2009

There are a lot of options out there when you’re about to choose a web host.

On the low end, where I live (for my personal sites, at least!) nearly all are “oversold”. If they weren’t, you really would not like the pricing. A related example : shop around, check with any internet pipe provider, and ask them what a guaranteed, non-shared pipe the size of your home broadband would cost per month. Be prepared for some sticker shock.

Green Web Hosting! This site hosted by DreamHost. Low cost and good for many users, i.e. casual – this is where I plug my current personal web host.

A step up in price, and potentially performance : Grid model http://mediatemple.net/webhosting/gs/

As soon as I find some good comparison article out there, I’ll no doubt link it.  So far in 10 months time, I’ve been pretty happy at Dreamhost, with multiple users and domains all in that same < $10 per month package.

DH does offer free web hosting for non-profit groups, which I think is nice of them.  Additionally, GoDaddy offers SSL certs for free to open source projects. They’re who I bought the plain-but-functional SSL cert for this domain through (you’ll notice that you are on a secure site, if you register with this blog; during login, etc. you will be on ’secure’ pages).

General disclaimer : pretty much any link to any sales site, web hosts included, gives the referrer (your blogger, in this case) some form of payout just for bringing you to their door.  A yup, I admitted it.

Random additional “General” blog topic : http://blogs.law.harvard.edu/philg/2009/08/07/cash-for-clunkers/ was pretty interesting. I’m definitely not driving my 13 year old vehicle much these days.

  • Windows Live Favorites
  • Technorati Favorites
  • Share/Bookmark

Tags: , , , , ,
Posted in General, Tech | No Comments »