<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://en.zaoniao.it/index.php?action=history&amp;feed=atom&amp;title=Moxie_Marlinspike</id>
	<title>Moxie Marlinspike - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://en.zaoniao.it/index.php?action=history&amp;feed=atom&amp;title=Moxie_Marlinspike"/>
	<link rel="alternate" type="text/html" href="http://en.zaoniao.it/index.php?title=Moxie_Marlinspike&amp;action=history"/>
	<updated>2026-05-15T22:38:27Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.32.0</generator>
	<entry>
		<id>http://en.zaoniao.it/index.php?title=Moxie_Marlinspike&amp;diff=5982&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;{{Infobox scientist | name = Moxie Marlinspike | image = Moxie Marlinspike.jpg | image_size =  | alt =  | caption = Marlinspike in 2013 | birth_date = &amp;lt;!- --&amp;gt; | birth_pl...&quot;</title>
		<link rel="alternate" type="text/html" href="http://en.zaoniao.it/index.php?title=Moxie_Marlinspike&amp;diff=5982&amp;oldid=prev"/>
		<updated>2019-06-17T05:23:07Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Infobox scientist | name = Moxie Marlinspike | image = Moxie Marlinspike.jpg | image_size =  | alt =  | caption = Marlinspike in 2013 | birth_date = &amp;lt;!- --&amp;gt; | birth_pl...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Infobox scientist&lt;br /&gt;
| name = Moxie Marlinspike&lt;br /&gt;
| image = Moxie Marlinspike.jpg&lt;br /&gt;
| image_size = &lt;br /&gt;
| alt = &lt;br /&gt;
| caption = Marlinspike in 2013&lt;br /&gt;
| birth_date = &amp;amp;lt;!- --&amp;amp;gt;&lt;br /&gt;
| birth_place = &lt;br /&gt;
| other_names = &lt;br /&gt;
| death_date = &lt;br /&gt;
| death_place = &lt;br /&gt;
| residence = &lt;br /&gt;
| citizenship = &lt;br /&gt;
| nationality = American&lt;br /&gt;
| fields = [[Computer security]],&amp;amp;lt;br /&amp;amp;gt;[[Software architect]]ure&lt;br /&gt;
| workplaces =&lt;br /&gt;
| patrons =&lt;br /&gt;
| alma_mater = &lt;br /&gt;
| thesis_title = &lt;br /&gt;
| thesis_url = &lt;br /&gt;
| thesis_year = &lt;br /&gt;
| doctoral_advisor = &lt;br /&gt;
| academic_advisors = &lt;br /&gt;
| doctoral_students = &lt;br /&gt;
| notable_students = &lt;br /&gt;
| known_for = [[Open Whisper Systems]] (founder),) is an American [[computer security]] researcher and [[cypherpunk]]. His research has focused primarily on techniques for intercepting communication, as well as methods for strengthening communication infrastructure against interception. Marlinspike is the former head of the security team at [[Twitter]] co-author of the [[Signal Protocol]], and a fellow at the Institute for Disruptive Studies. Marlinspike moved to [[San Francisco]] in the late 1990s. In 2004, Marlinspike bought a derelict sailboat and, along with three friends, refurbished it and sailed around the [[The Bahamas|Bahamas]] while making a documentary about their journey called ''Hold Fast''. the firm made Whisper Systems' apps [[Open-source software|open source]].&lt;br /&gt;
&lt;br /&gt;
Marlinspike left Twitter in early 2013 and founded [[Open Whisper Systems]] as a collaborative open source project for the continued development of TextSecure and RedPhone. At the time, Marlinspike and Trevor Perrin started developing the [[Signal Protocol]], an early version of which was first introduced in the TextSecure app in February 2014. In November 2015, Open Whisper Systems unified the TextSecure and RedPhone applications as [[Signal (software)|Signal]]. Between 2014 and 2016, Marlinspike worked with [[WhatsApp]], [[Facebook]], and [[Google]] to integrate the Signal Protocol into their messaging services.&lt;br /&gt;
&lt;br /&gt;
==Notable research==&lt;br /&gt;
&lt;br /&gt;
===SSL stripping===&lt;br /&gt;
In a 2009 paper, Marlinspike introduced the concept of [[Secure Sockets Layer|SSL]] stripping, a [[man-in-the-middle attack]] in which a network attacker could prevent a [[web browser]] from upgrading to an SSL connection in a subtle way that would likely go unnoticed by a user. He also announced the release of a tool, &amp;amp;lt;code&amp;amp;gt;sslstrip&amp;amp;lt;/code&amp;amp;gt;, which would automatically perform these types of man-in-the-middle attacks. The [[HTTP Strict Transport Security]] (HSTS) specification was subsequently developed to combat these attacks.&lt;br /&gt;
&lt;br /&gt;
===SSL implementation attacks===&lt;br /&gt;
Marlinspike has discovered a number of different [[Vulnerability (computing)|vulnerabilities]] in popular SSL implementations. Notably, Marlinspike published a 2002 paper on exploiting [[SSL/TLS]] implementations that did not correctly verify the [[X.509 | X.509 v3]] &amp;quot;BasicConstraints&amp;quot; extension in [[public key certificate]] chains. This allowed anyone with a valid CA-signed certificate for any [[domain name]] to create what appeared to be valid CA-signed certificates for any other domain. The vulnerable SSL/TLS implementations included the [[Microsoft CryptoAPI]], making [[Internet Explorer]] and all other Windows software that relied on SSL/TLS connections vulnerable to a man-in-the-middle attack. In 2011, the same vulnerability was discovered to have remained present in the SSL/TLS implementation on [[Apple Inc.]]'s [[iOS]]. Also notably, Marlinspike presented a 2009 paper, where he introduced the concept of a null-prefix attack on SSL certificates. He revealed that all major SSL implementations failed to properly verify the Common Name value of a certificate, such that they could be tricked into accepting forged certificates by embedding [[null character]]s into the CN field.&lt;br /&gt;
&lt;br /&gt;
===Solutions to the CA problem===&lt;br /&gt;
In 2011, Marlinspike presented a talk titled ''SSL And The Future Of Authenticity'' at the [[Black Hat Briefings|Black Hat]] security conference in Las Vegas. He outlined many of the current problems with [[certificate authorities]], and announced the release of a software project called [[Convergence (SSL)|Convergence]] to replace Certificate Authorities. In 2012, Marlinspike and Trevor Perrin submitted an Internet Draft for [[TACK]], which is designed to provide SSL [[certificate pinning]] and help solve the CA problem, to the IETF.&lt;br /&gt;
&lt;br /&gt;
===Cracking MS-CHAPv2===&lt;br /&gt;
In 2012, Marlinspike and [[David Hulton]] presented research that makes it possible to reduce the security of [[MS-CHAPv2]] handshakes to a single [[Data Encryption Standard|DES encryption]]. Hulton built hardware capable of cracking the remaining DES encryption in less than 24 hours, and the two made the hardware available for anyone to use as an Internet service.&lt;br /&gt;
&lt;br /&gt;
== Traveling ==&lt;br /&gt;
&lt;br /&gt;
Marlinspike says that when flying within the United States he is unable to print his own [[boarding pass]], is required to have airline ticketing agents make a phone call in order to issue one, and is subjected to [[Secondary Security Screening Selection|secondary screening]] at [[Transportation Security Administration|TSA]] security checkpoints.&lt;br /&gt;
&lt;br /&gt;
While entering the United States via a flight from the Dominican Republic in 2010, Marlinspike was detained for five hours; federal agents requested his passwords, and all his electronic devices were confiscated and then returned.&lt;br /&gt;
&lt;br /&gt;
==Speaking engagements==&lt;br /&gt;
&lt;br /&gt;
* [[DEF CON]] 17: &amp;quot;More Tricks for Defeating SSL&amp;quot;&lt;br /&gt;
* In 2016, [[Fortune (magazine)|''Fortune'' magazine]] named Marlinspike among its [[40 under 40 (Fortune magazine)|40 under 40]] for being the founder of Open Whisper Systems and &amp;quot;[encrypting] the communications of more than a billion people worldwide&amp;quot;.&lt;br /&gt;
* In 2017, Moxie Marlinspike along with Trevor Perrin were awarded the Levchin Prize for Real World Cryptography &amp;quot;for the development and wide deployment of the Signal protocol&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Source==&lt;br /&gt;
&lt;br /&gt;
[http://wikipedia.org/ http://wikipedia.org/]&lt;br /&gt;
[[Category:People of the industry]]&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
==See Also on BitcoinWiki==&lt;br /&gt;
* [[Graft]]&lt;br /&gt;
* [[BlockCDN]]&lt;br /&gt;
* [[ETCWin]]&lt;br /&gt;
* [[Bubbletone]]&lt;br /&gt;
* [[E-veksel]]&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
		
	</entry>
</feed>