All Articles
A COSE_Sign1 object is not its signing input.
Four transmitted fields become a different CBOR structure before signature verification.
Verification is not authorization.
A valid signature answers a narrower question than most applications need to decide.
127 bytes.
An IEEE 802.15.4 calculation begins with 127 octets. After framing and link security, only 81 may remain.
Random-looking is not unpredictable.
Statistical appearance cannot establish cryptographic unpredictability when generator state is small, duplicated or recoverable.
The handshake has a budget of fourteen kilobytes.
Post-quantum authentication can cross transport limits before application data begins. The real budget is measured in bytes, flights, fragments and buffers.
Twenty-six years from break to scheduled retirement.
SHA-1’s long retirement measures inventory, artifact lifetime and the unreachable tail of deployed systems more than cryptanalysis.
Entropy arrives late.
Correct algorithms can still generate related keys when identical devices ask for randomness before their environments have diverged.
Removing a member creates a new epoch.
Messaging Layer Security makes membership part of shared cryptographic state. A removal takes effect when the remaining group commits and derives a new epoch.
A random output can carry a proof.
A verifiable random function produces a unique, random-looking output and evidence anyone can check. It proves origin and uniqueness, not fairness in deciding which outputs are revealed.









