❌

Reading view

There are new articles available, click to refresh the page.

Public Report – Keyfork Implementation Review

In April 2024, Distrust engaged NCC Group’s Cryptography Services team to perform a cryptographic security assessment of keyfork, described as β€œan opinionated and modular toolchain for generating and managing a wide range of cryptographic keys offline and on smartcards from a shared mnemonic phrase”. The tool is intended to be run on an air-gapped system and allows a user to split or recover a cryptographic key using Shamir Secret Sharing, with shares imported and exported using mechanisms such as mnemonics or QR codes. These shares can be managed by one or more users, with a defined threshold of shares required to recover the original secret. A retest was conducted in May 2024, which resulted in all findings and notes being marked Fixed.

The review targeted the tagged release keyfork-v0.1.0 of the keyfork repository. Distrust indicated that memory-related (e.g., zeroization) and timing-related attacks were not a concern due to the trusted nature of the hardware and its environment, and as such were not investigated in detail.

Several engagement notes and several low impact findings were uncovered, each of which were promptly addressed by Distrust.

Public Report – AWS Nitro System API & Security Claims Italian

In the last calendar quarter of 2022, Amazon Web Services (AWS) engaged NCC Group to conduct an architecture review of the AWS Nitro System design, with focus on specific claims AWS made for the security of the Nitro System APIs.

The Public Report in Italian this review may be downloaded below:

The original Public Report can be found here in English:

https://research.nccgroup.com/2023/05/03/public-report-aws-nitro-system-api-security-claims

The Public Report in German may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-german/

The Public Report in French may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-french/

The Public Report in Spanish may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-spanish/

Public Report – AWS Nitro System API & Security Claims French

In the last calendar quarter of 2022, Amazon Web Services (AWS) engaged NCC Group to conduct an architecture review of the AWS Nitro System design, with focus on specific claims AWS made for the security of the Nitro System APIs.

The Public Report in French this review may be downloaded below:

The original Public Report can be found here in English:

https://research.nccgroup.com/2023/05/03/public-report-aws-nitro-system-api-security-claims

The Public Report in German may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-german/

The Public Report in Italian may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-italian/

The Public Report in Spanish may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-spanish/

Public Report – AWS Nitro System API & Security Claims Spanish

In the last calendar quarter of 2022, Amazon Web Services (AWS) engaged NCC Group to conduct an architecture review of the AWS Nitro System design, with focus on specific claims AWS made for the security of the Nitro System APIs.

The Public Report in Spanish for this review may be downloaded below:

The original Public Report in English may be found here:

https://research.nccgroup.com/2023/05/03/public-report-aws-nitro-system-api-security-claims

The Public Report in German may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-german/


The Public Report in French may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-french/

The Public Report in Italian may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-italian/

Public Report – AWS Nitro System API & Security Claims German

In the last calendar quarter of 2022, Amazon Web Services (AWS) engaged NCC Group to conduct an architecture review of the AWS Nitro System design, with focus on specific claims AWS made for the security of the Nitro System APIs.

The Public Report in German for this review may be downloaded below:

The original Public Report in English may be found here:

https://research.nccgroup.com/2023/05/03/public-report-aws-nitro-system-api-security-claims

The Public Report in French may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-french/


The Public Report in Italian may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-italian/


The Public Report in Spanish may be found here:
https://research.nccgroup.com/2024/03/04/public-report-aws-nitro-system-api-security-claims-spanish/

❌