Encryption and Security-related Resources


Crypto Link Farms

Internet2 Security Working Group
          Extensive collection of links to academic, industry, and other security oriented pages.
Anonymity, privacy, security.
Very nicely done collection of links to anonymity, privacy, and security resources.
Bellare - Crypto links
More link farms, conferences, organizations, electronic commerce, IETF, key forfeiture, crypto people.
Cambridge Computer Security Group Links
Huge collections of links to security-related sites - the format is a bit like this list.
Comprehensive list of Public Key Infrastructure (PKI) links
Links to PKI documents, specifications, CA's, and sites with PKI-related useful information.
Coast Security Archive - Category Index
A large archive of security software, publications, and technical information.
COAST Hotlist Contents
Gene Spaffords crypto and security link farm.
Cryptography
PGP, encryption algorithms, legal issues.
Cryptography URL
Encryption standards, FAQ's, and FTP sites.
DSTC Security Related Links
Links to crypto, digital signatures, e-cash, internet backing, smart cards, NT security, PKI, standards.
Email security, cryptography and related stuff
PEM, MIME, and MOSS RFCs, links to CA's, implementations, literature, PGP.
European Cryptography Resources
Recommendations, drafts, papers, new items, official bodies, research, and government meddling.
Firewall Security Jump Page
Links and summaries of a wide variety of firewall products.
Gateway to Information Security Home Page
Links to a large number of security-related sites, books, journals, and related information (imagine this page, but not all lumped together on one page).
Home-Page of Markus Hübner
Security, cryptography, hacking, business on the Internet, security software, satellite hacking.
International Cryptographic Software Pages for Encryption, Decryption, Cryptanalysis, Steganography, and Related Methods
Algorithms, software packages, protocols and standards, books, journals, conferences, newsgroups, mailing lists, crypto links.
Links Related to Terrorism, Intelligence, and Crime
A large number of intelligence, security, law enforcement, disaster planning, terrorism, crime, military, and defense agencies and organizations.
Luca Venuti's Home Page - TPC
Electronic privacy links, organisations, newsgroups.
No Big Brother Page
Links to remailers, anon proxies, crypto and stego software, file wiping tools, privacy and anti-privacy organisations.
NCSA Hot Links
Anti-virus software, firewalls, general security vendors, general infosec links, parental control, privacy, law, and ethics.
Neil's Security and Privacy Resources
Encryption, steganography, special events, research, documents, news, security archives, security organizations.
Network/Computer Security Technology
Current events, security web pages, commercial security tools, newsgroups, mailing lists, FAQ's, incident bulletins, conferences/seminars/workshops.
PGP Resources
Resources related to PGP such as mailer add-ons and front-ends, key servers, and related information.
PGP-Users Mailing List Home Page
PGP-related information, remailers, privacy information, security and crypto links.
Spanish Crypto Resources
Spanish crypto and security-related companies, magazines, and events.
Steganography
Stego papers, references, research groups, related resources.
Strong Cryptography Links on the Internet
Links to crypto companies, universities, newsgroups, books, algorithms, security and crypto tools.
Technical Information - Cryptography
Links to other crypto sites, source code archives, companies and organisations, peope, and reference information.
The Rotherwick Firewall Resource - Point of Attack
Firewall basics, white papers, products, manufacturers, books, papers, training, mailing lists, links to other firewall-related resources.
Tom Dunigan's Security page
PGP, S/Key, Kerberos, crypto API's, secure applications, commercial providers, government agencies, intrusion detection, vulnerabilities.
TSA (Law Enforcement and Intelligence) Links
More links to law enforcement and intelligence agencies.
Uni-GH Siegen - Security-Server
Encryption algorithms, data protection, steganography, ecash, Internet security, viruses, conferences, security standards, newsgroups and mailing lists, RFC, journals.
University of Torino Security Resources
Links to web pages, newsgroups, FTP sites, research labs, papers, conferences, and journals.
Vince Cate's Cryptorebel/Cypherpunk Page
Cypherpunks resources, remailers, digital cash, PGP, and Clipper.
Vinnie's Crypto Links
Crypto overviews and FAQ's, link farms, encrypted comms, e-commerce, crypto libraries.

Crypto FTP Archives

FUNET crypto archive
PGP, symmetric and asymmetric encryption, crypto libraries, papers.
North American Cryptography Archives
Archive of crypto software, only available from the US and Canada.
Oxford Uni crypto archives
DES, SSL, cryptanalysis, documentation, PGP, miscellaneous.
Replay crypto/security archives
Apache, Applied Crypto files, encryption, Java, PGP, remailers, security, voice encryption files.
Tattooman Crypto Archive
Large selection of crypto software, but trapped behind the iron curtain.
University of Hamburg crypto archive
Disk and file encryption, PGP, stego, voice encryption.
University of Oslo PGP archive
PGP and PGP-related software.
UREC archive
French archive of CERT bulletins, dictionaries, PC, Unix, VMS security software (mostly anti-virus and access control rather than crypto).

Crypto Social Issues

" ADD_DATE="889737435" LAST_VISIT="889737144" LAST_MODIFIED="889737144">Crypto AG: The NSA's Trojan Whore?

Possible rigging of Crypto AG hardware by the NSA.
[1997] 1 Web JCLI
Analysis of the UK governments policy on encryption.
Additional Comments of Philip R. Karn, Jr.
Phil Karn rebuts inaccurate and bizarre government claims in congressional testimony (this is an example of the kind of misinformation which government advisors often provide to their governments).
Adopt An MP - Homepage
UK campaign to adopt an MP and enlighten them over problems with crypto restrictions.
Americans for Computer Privacy
Computer privacy issues.
BBC News - Encryption
BBC news stories on encryption, including "UK Government dithers on encryption regulation".
Big Brother Incorporated
Companies which supply surveillance technology to non-democratic regimes.
Brookings Policy Brief No.21.
Brookings Institute study of crypto policy (pro-GAK).
C to English and English to C translator
Translates crypto code into English to allow it to be exported, then translates it back into code afterwards.
CACIB
UK government tactics for deploying GAK.
Canada's export controls
Summary of the Canadian crypto export situation.
Cato Handbook for Congress: Freedom on the Internet and Other Computer Networks
Cato Institute study of crypto policy (anti-GAK).
Centre for Democracy and Technology Crypto Page
CDT information on current US crypto policy
CIPHR'99 Conference: Cryptography & International Protection of Human Rights
Conference on crypto and human rights.
Clipper Roadshow
US government policy laundering on key escrow.
CNET features - digital life - privacy in the digital age
Digital privacy (or more specifically, the lack thereof).
Codex Surveillance & Privacy Page
Surveillance, stalking, privacy invasion, eavesdropping, and anything else related to these categories.
Comments on Encryption Transfers
Comments on new US export regulations.
Comments on Encryption Transfers - HTML
Easier-to-handle HTML versions of the above.
Crime, Terror & War: National Security & Public Safety in the Information Age
The sky is falling! The sky is falling!
Crypto AG
Reports of Crypto AG rigging crypto hardware to allow NSA decryption.
Crypto AG - Der Spiegel (German)
Allegations of intelligence agencies subverting Crypto AG product security.
Crypto-Controls Advisory Services
The one organisation making money out of US export controls.
Crypto Law Survey
A survey of crypto laws in various countries.
Crypto regulation in Europe
The state of crypto regulation plans in Europe as of May 1997.
Cryptography's Role in Securing the Information Society
National Academy of Sciences report on cryptography policy.
Cyberspace Law for Non-Lawyers
Privacy laws and the Internet.
DIE ZEIT Nr. 28/1998 Leichtes Spiel
German news report on NSA industrial espionage leading to $100M loss for German company.
DIE ZEIT Nr. 39 vom 17. 9. 1998: Hintertür für Spione
Another report on Enercon industrial espionage.
Distributing encryption software by the Internet: loopholes in Australian export controls
Examination of legal implications of electronic export from Australia. Conclusion: It's OK.
DTI/UK Encryption Policy
Reply to the DTI Consultation Paper on Licensing of Trusted Third Parties for the Provision of Encryption Services.
E-commerce under threat from encryption deal
The Australian Financial Review on Wassenaar'98.
Echelon: Exposing the Global Surveillance System
Covert Action Quarterly article on wordlwide NSA surveillance.
ECHELON: America's Secret Global Surveillance Network
Free Congress Foundation report on Echelon surveillance system.
EE Times - White Paper
White paper on hackers.
Emerging Japanese Encryption Policy
How Japan, Inc, handles encryption policy (a real contrast to the US governments attitude).
Encryption Policy and Market Trends
Dorothy Dennings 1997 GAK forecast.
Encryption Policy for the 21st Century
Cato Institute study on the future of encryption.
EPIC Cryptography Policy
EPIC information on current US crypto policy.
EPIC Privacy Links
EPIC privacy resources.
export-a-crypto-system sig
Diminuitive crypto hacks (well-known algorithms in a few lines of Perl, Python, or C) and how to use them to poke fun at export laws.
Export Licensing of Intangibles
Commentary on likely effects of UK proposal to license export of intangibles.
Exposing the Global Surveillance System
Extracts from Nicky Hager's book "Secret Power".
FinCen
Big Brother for financial information.
Former Secrets
Declassified US government machinations to ban/restrict crypto.
FUD! Home Page - Crypto legislation
Contents of and discussion over various US crypto bills.
GILC -- Cryptography and Liberty
Survey of encryption policy worldwide.
GNN on Crypto
Global Network Navigator web review: The NSA vs The Net.
Government, Cryptography, and the Right to Privacy
Paper documenting the overt and covert regulation and restriction of cryptography by governments.
Good Privacy Test Sites
Links to sites which show how easy it is to get information on your and your activities on the net.
GR Design Principles
GAK-resistant crypto protocol design guidelines.
Gray Areas Magazine
Essays and articles on the computer underground (and all sorts of other things).
Green light for limited encryption exports
Australia's interpretation of Wassenaar'98.
IFIP TC11 Position on Cryptopolicies
IFIP's (very sensible) position on crypto use and crypto regulation.
Information About PGP & Encryption
Information on the creeping takeover of GAK.
Interception
Technical details on large-scale GSM and ISDN interception techniques.
Internet Privacy Coalition
Attempts to ensure privacy on the internet.
Interview with David Herson - SOGIS
Interview on European crypto policy.
ITAR Civil Disobedience
Click on this form to become an international arms trafficker.
Key Recovery Study
The risks of key recovery, key escrow, and trusted third party encryption.
KRISIS Home Page
GAK/EuroClipper home page.
NSA and Crypto-politics
Huge (1/2MB) writeup on the NSA and crypto politics.
NSA's Influence on New Zealand Crypto Policy
NSA influence on New Zealand export policy.
No Chance for Key Recovery
Paper on key recovery (GAK) vs human and political rights.
PGP 6.0: Cat out of the bag
Wired article showing just how effective US export controls really are.
Phone Tapping
Information and resources on government phone tapping plans.
Privacy, Inc.
Various resources related to the (lack of) privacy, including access to databases and online information search facilities.
Privacy International Home Page
Privacy reports, interntional agreements on privacy and human rights, surveillance technologies, ID cards, privacy-related conferences.
Privacy on the Internet
Zola Times articles on Internet privacy.
Privacy on the Net: Practical Issues
Links and information on various privacy-related issues (cryptography, anonymity, secure communications).
q/depesche
Free crypto campaign logos.
Remailer list
List of anonymous remailers.
Roger Clarke's Privacy Page
Data surveillance and information privacy information publications, and legislation.
Roger Clarke's Public Interests on the Electronic Frontier
Paper discussing various freedoms and rights such as the right to privacy.
Roxen's General Export Application for Strong 128-bit Encrypted Denied
Swedish government refusal of export permit for 128-bit SSL.
RSA as a MIDI file
RSA encoded as a MIDI file. Technically this is a program and therefore unexportable from the US.
Self Incrimination and Cryptographic Keys
Richmond Journal of Law and Technology article on forced disclosure of crypto keys.
Services Available from Offshore Information Services Ltd.
Offshore internet services and accounts in Anguilla.
SOFTWAR Information Security
Declassified papers and resources on Clipper and key escrow, voice and mail encryption software.
Tapping into CALEA
Government surveillance server ("delivers intercepted call content and identifying information... capacity for up to 512 simulatneous call intercepts".
Telekommunikationsgesetz
East German surveillance state-style laws being applied in the unified Germany.
Telepolis Enfopol-Papiere
Documentation relating to EU telecoms surveillance plans (EU-Echelon).
The Age - Computers
DSD meddling in Australian crypto exports.
Threat and Vulnerability Model for Key Recovery
NSA report on why GAK is bad (yes, you read that right).
Tools For Privacy: Version 1
An online book covering threats to privacy, cryptography, PGP, and related issues.
TruePosition Wireless Location System Home Page
Cellular phone tracking.
UK Cryptographic Policy Discussion Group
ukcrypto mailing list archives.
Updated UK Proposals for Licensing Encryption Services
Critique of UK crypto licensing/GAK proposal.
U.S. Electronic Espionage: A Memoir
First exposure of the NSA and Echelon
US Spy Agency Confirms Secret Princess Diana Files
Echelon in action: APB story on NSA building up 1000+ page file on Princess Diana.
Walsh Report
Report on Australian crypto policy, originally suppressed by the government, then released in censored form after a judicial review, finally obtained as the full version by EFA. Provides most interesting reading since the bits they didn't want the public to see are now highlighted in red.
What your Browser is Sending
See what information your web browser is sending to remote servers.

Crypto Software

ABA JCE
Clean-room JCE implementation.
Advanced Cryptography Tool
Crypto tool using PGP 2.6.3i with triple DES and SHA-1.
AES Algorithm Efficiency
Free-world implementations of the AES algorithms.
Alex Encryption
Encryption based on automata theory (unknown security level).
Ambient Empire
Vigenere cipher cracker, Windows port scanner.
Apache HTTP Server Project
Apache secure web server.
BSAFEeay, a public domain implementation of the BSAFE API
BSAFE API wrapper around SSLeay.
Canadian Cryptographic/cryptanalytic software
Canadian encryption software and companies.
CAP
Cryptographic analysis program (automatically analyse and break simple ciphers).
Cedomir Igaly's SSH Page
Free SSH for Windows.
Cédric Gourio's Java-SSH
SSH client in Java.
CIPE
Crypto IP encapsulation - encrypting IP routers using Linux.
CipherClerk
Software emulation of various historical ciphers
Cisco Systems ISAKMP Distribution
A reference implementation of the IETF's ISAKMP protocol.
CRASHME: Random input testing.
Tests resistance of programs to random input.
Crowds Home Page
Anonymous proxying for web browsing.
cryptix
Cryptix Java crypto library.
cryptlib Information
Encryption library supporting a large number of encryption algorithms, digital signatures, key exctange, key certificates, CA functionality, key databases, smart cards, and secure enveloping.
Crypto Kong
PGP-like program using elliptic curve crypto.
Cryptographic Libraries: A comparison
Comparison of various free (and free-world) crypto libraries.
Cryptographic software
Elliptic curve and RSA public-key encryption software.
Cryptographic tools for Visual Basic
Elliptic curve OLE extension for VB.
Cryptography Blowfish Multi-thread
Command-line Blowfish encrypter.
Cryptonite Java Package
Java crypto library.
Cryptoscan
Scanned US crypto publications available outside the US.
CTC - PGP-compatible encryption software
PGP-compatible C library and Mac application.
Delphi crypto software
Various pieces of crypto software written in, and for, Delphi.
DES in VHDL
DES in VHDL, including a Xilinx-optimised version.
Disk/File Wiping Utilities
Programs to wipe files, free disk space, slack space, the Windows swap file.
Emacs Cryptographic Library and Tools
DES, RC4, IDEA, SHA-1, MD5, and others, in elisp.
Enabling Network Security with SSLeay
Security projects based on SSLeay.
Encrypted PDFs
Code to work with encrypted PDF's (intended mainly for use with Ghostscript).
Engineering Research Home Page
P1363 ECC implementation.
Enigma
PGP-compatible plugin written in Java.
Error Correcting Codes (ECC) Home Page
C source code and information on ECC's (the techniques employed are closely related to encryption techniques).
ESP Reference
Encrypted socket protocol (an open protocol for TCP/IP secure transmissions).
FastCAST's Homepage
P5-optimised code for CAST-128/CAST5.
Fortify for Netscape
Free 128-bit SSL browser proxy,
Frank O'Dwyer's Homepage - Security Code
DES in Java, C++ firewall class library.
Fresh Free FiSSH!
Free SSH client for Win'95 and NT.
Fuzzy Logic: Cryptography
The GNU encryption project.
G10 - A Free PGP Replacement
GPL'd PGP clone.
GInt
Bignum library and sample PKC code.
GMD Security Technology - SecuDE
Security toolkit for RSA, DSA, DES, DH, X.509, PKCS, PEM, X.500, and BYOG.
Hamradio page of Thomas M. Sailer, HB9JNX
All sorts of neat stuff for software decoding of various radio signals.
Heimdal
Non-US Kerberos 5 implementation.
IAIK - Javasecurity Homepage
Java cryptography extensions from the free world.
ICE Home Page
The Information Concealment Engine block cipher.
Immunix: Adaptive System Survivability
Automatic protection against stack-smashing attacks.
International PGP Home Page
How to get PGP, documentation, foreign-language support, PGP-related products and services, and other PGP resources.
Internet Locations for Materials on the Disks for Applied Cryptography
Site #1.
IRDU PGP Page
PGP information, software, key management, key server interface, PGP links.
JCSI
Free-world JCE implementation.
JGSS Package Distribution Page
Kerberos in Java.
jSSL - A free Java SSL implementation.
SSL implementation in Java.
Keytrap Home Page
Dcyphers keyboard sniffer.
kha0S Linux - b/c friends don't let friends s[ug]id
Linux with strong crypto built in.
Lance Cottrell Home Page
Mixmaster remailer publications and soure code.
Linux-PAM
Pluggable authentication modules for Linux.
libch's Homepage
P5-optimised code for various hash algorithms.
LiDIA - Main Page
C++ computational number theory library (great for crypto).
LInteger
C++ bignum library.
Linux FreeS/WAN Project
IPSEC, ISAKMP/Oakley and DNSSEC software for Linux.
Linux Packet Sniffer
IP packet sniffer for Linux.
MD5 Message Digest algorithm in Javascript
Microsoft CryptoAPI
Microsoft's attempt at a cryptograhpy API. This page moves a lot, you may need to try a search from MS's developer pages.
MindTerm - A java implementation of SSH
SSH client in Java.
Ming-Ching Tiew Home Page
PGP key manager, PGP netscape plugin, Motif and Win32 file encrypter using cryptlib, cryptlib Java wrappers.
Mozilla Crypto Group
Putting the crypto back into Netscape/Mozilla.
Nautilus Homepage
Speech encryption (with a neat anti-Clipper graphic).
NiftyTelnet
SSH client for the Mac.
Nmap -- Stealth Port Scanner
Stealth scanner using TCP half open scanning, TCP FIN/Xmas/NULL stealth scanning, ftp bounce and IP fragmentation scanning, and OS identification by TCP/IP fingerprinting.
NSBD: Not-So-Bad Distribution
Internet software distribution authenticated with PGP.
Oscar - DSTC's Public Key Infrastructure Project
PKI toolkit.
Package Acme.Crypto
Various Java crypto classes.
Package java.security
Java security package docs.
PC Security Software & Sources
Brief descriptions of various security programs.
PGP, logiciel de cryptographie gratuit et en français (PGP pour les français)
French PGP page.
PGP Tools
PGP function library.
PGPLIB
DLL which implements various PGP functions.
PGPNet Server
A dummy home page for the www.pgp.net domain (incomplete).
Photuris Test Server
Photuris session-key management protocol software and test server.
Private Idaho User's Manual
Documentation for Private Idaho.
PPTP-linux: Point-to-Point Tunneling Protocol
PPTP for Linux (presumably without all of Microsoft's security holes in it).
PS
(Relatively) secure encryption using 40-bit keys (designed to bypass silly French restrictions).
PuTTY: a free Win32 telnet/ssh client
Telnet/SSH client for Win32.
Qualcomm Australia crypto software
sendmail encryption patch, SOBER stream cipher.
RC4 Stream Cipher Library
RC4 ActiveX control.
Reliable Remailer
cpunk/mix remailer for Windows.
RIPEM
RIPEM source code and information.
RSA Free Utilities
RSA key generation and encryption for Linux.
RSAEURO - Cryptography For The World
European RSAREF providing full source-code compatibility with the original.
SCNSM
Win3.1/95/98 non-swappable memory allocator.
ScramDisk - Free Disk Encryption Software
Win95 disk encryption using 3DES, Blowfish, IDEA, MISTY, Square, and TEA.
Secretz
File encryption using elliptic-curve PKC's and Blowfish.
Secure FileSystem Information
The world's best transparent disk encryption software for DOS and Windows (this has nothing to do with the fact the I'm the author :-).
Secure Logging
Secure logging for Unix and Windows.
Security: File wiping
Links to various file wiping utilities.
Sir Winston Rayburn - Crypto/Politico
Various encryption reoutines.
S/KEY Information
Information on the S/KEY authentication system.
Skygate Technology
Windows NT disk encryption.
SMB Scanner
SMB port/machine scanner.
S/MIME Freeware Library
S/MIME freeware library (export-controlled, US only).
SNOW Home Page
Whitespace steganography software.
spDES Encryption Control
ActiveX DES control.
Speak Freely
Very nice Unix and Windows speech encryption software.
Ssh (Secure Shell) Home Page
Very good encrypted, digital-signature-authentication remote access software (replaces the r* utilities, allows X11 and TCP port redirection over the encrypted connection).
SSH/SCP for Windows
ssh/scp port for Win95/NT.
SSLeay and SSLapps FAQ
Very nice, free SSL implementation (like Netscape's SSL, but without the bugs and crippled encryption).
SRP: Secure Password Authentication for the Net
Secure password-based authentication over insecure networks.
Systemics Software Archive
Crypto extensions for perl and Java.
TC TrustCenter TC_PKCS11
PKCS #11 software-only token implementation.
The Cryptography and PGP Page
Classic ciphers, links to crypto sites, explanations of the maths behind PGP and RSA, privacy issues.
Therapy
SSH client for Win32.
Tiny Encryption Algorithm
Description and C source code.
TinyIDEA - 128-bit File Encryption
366-byte IDEA file encryption program.
Tom's Privacy Pages
Patching Navigator and Explorer to use strong crypto.
Transparent Cryptographic File System
Tresor Page
Mac file encryption using IDEA, written in the free world.
Trinux: A Linux Security Toolkit
Floppy-bootable Linux network security toolkit.
TSS PGPWord... Real Security, Real Easy
PGP encryption integrated into Word for Windows.
TTSSH: An SSH Extension to Teraterm
SSH DLL add-on for Teraterm.
Uni-GH Siegen - Security-Server - Kryptographie
Pointers to information on and implementations of a number of conventional, public-key, and hash algorithms.
Unix tools on Windows NT?
ssh port to NT via Cygnus gnu-win32.
Vitas DownLoad area
Windows'95 password (.PWL) viewer.
Wei Dai's Crypto++
C++ class library of cryptographic primitives.
WinPGP(tm) Home Page
Windows front-end for PGP.
Wipe 0.02
Heavy-duty file wiper for Linux.
XPDF additions
Add-on to allow XPDF to decrypt encrypted PDF files.

Miscellaneous Security Items

Random Numbers

Aware Electronics Corp.
PC Geiger counters (great random data sources).
CME's Random Number Conditioning Page
Information on sources of strong random numbers.
Computer Generated Random Numbers
Techniques for analyzing PRNG's.
DIEHARD
George Marsaglia's RNG test suite.
Efficient Generation of Cryptographic Confusion Sequences
A survey of PRNG's for crypto applicatoins.
HotBits: Genuine Random Numbers
Build-it-yourself radioactive-decay based random number generator (perfect for Chernobyl residents).
Ideas for an RNG_DEVICE standard
Proposed standard for random-number generation devices.
Lavarand!
Random number generation using lava lamps.
Noisemaker schematic
Hardware RNG.
Numerical Recipes Home Page
CDROM contains ~1/4GB of random numbers.
ORION RNG
Serial-port hardware RNG.
Protegrity Incorporated
Cryptographically strong random number generator.
Radiation Monitors for PCs
Various random number sources.
Random Number Generation, Taygeta Scientific Inc.
Papers and software for PRNG's.
Random number generators -- The pLab Project Home Page
Theory and practice of random number generation.
Random number generators
Analyses of hardware and software randomg number generators.
Random Number Generators (RNGs)
Web sites and references for RNG information, information on various PRNG's.
Randomness Resources
Resources on secure random-number generation and the problems of insecure random number generation.
RBG1210
Cryptographically strong random number generator.
SG100
Hardware random number generator.
Using and Creating Cryptographic-Quality Random Numbers
Randomness-gathering techniques.
Wayne's Random Noise Generator
PN-junction based hardware RNG sampled using a sound card.
Algorithm benchmarks
Relative speeds of a number of encryption and hash algorithms.
AT&T PathServer
PGP web of trust tracing server.
Bletchley Park Home Page
Visitors guide to Bletchley Park.
Bob Tinsley's Steganography Pages
Steganography papers and ideas.
DigiCrime, Inc.
Online links to digital crime, blackmail services, encryption key cracking, airline rerouting, internet shoplifting, e-cash laundering, alien mind control, etc etc.
GISUM. Information Security
University of Malaga infosec group.
GSM Wizard
GSM-related technical information and secret features of phones. NB: This page repeats the official GSM security info rather than the actual details.
Information on VideoCrypt Hard/Software
JANUS
Anonymity for WWW content providers.
KL7/KWR37 Crypto Units
Descriptions and photos of the KL7 and KWR37.
KuesterLaw Technology Law Resource
Technology and IP law resources.
Matt's Unix Security Page
Unix and Internet security papers, security software, links and miscellaneous items.
Microsoft Security Advisor Program
Microsoft's interpretation of security (see many other links on this page for everyone elses interpretation of Microsoft's security).
NSA Crypto Museum Photos
Payment, Security & Internet References
X9.59 electronic payment-related references.
Prime number verification via ECPP
Bignum prime number verification via a CGI script.
Pseudoprimes/Probable Primes
Papers on primality testing.
Quantum Computation/Cryptography at Los Alamos
Information on quantum computation and cryptography.
RADIOPHONE Top Level
Information on cellular telephony, PCS, and wireless data transfer.
Remailer related Sources
Remailer home pages, remailer techinfo, PGP introduction, PGP keyservers, crypto pages and laws.
S & P Calendar
Calendar of security and crypto conferences.
Securing NIS
Sirene Home Page
Various research projects in computer security.
SourceKey - The Global Source for Key Recovery
GAK/key escrow/trusted third party/whatever centre.
SSL Browser Information
Information on the SSL implementation used by your browser.
Steganography
A paper on steganography.
The Square Page
The Square block cipher and links to implementations.
Toby's Cryptopage
Information and links to historical cryptosystems and encryption machines.
USDS Homepage
Yet another new (and patented) PKC.

Public Key Infrastructure

128i
New Zealand CA.
Analysing State Digital Signature Legislation
Analysis and comparison of various states' digital signature laws.
ARCANVS
CA licensed under the Utah Digital Signature Act.
Australia Post - KeyPOST
Australian CA.
BelSign
Belgium and Luxemburg CA.
BiNARY SuRGEONS: Certification Services
South African CA.
BSI-Projekt Digitale Signatur
Implementation details of the German digital signature law.
C=EE, O=ESTONIAN NATIONAL PCA
Estonian CA.
CA-CERT
Spanish CA.
Carynet Security Certificate Authority
Asian(?) CA.
Center for Standards Public Key Infrastructure (PKI) Standardization Home Page
DISA information pages on the Internet PKI.
Certificates Australia
Australian CA. GAK alert: This CA escrows all encryption keys.
Certificates shipped with Netscape
Extracting certs from Netscape's .db files.
Certification Authority Survey (DGXV Project)
List of CA's worldwide.
certifikacni stranka DATANETu
Czech DATANET CA.
CERTISIGN
Brazilian CA.
Columbia Certification Authority
Columbia University (not country) CA.
Columbian Draft Proposal of Law on Electronic Commerce
Columbian draft digital signature legislation.
CompuSource Certificate Authorities Home Page
South African CA.
Digital Signature Guidelines
American Bar Association digital signature guidelines, available as WordPerfect and Word documents.
Digital Signature Trust (DST) Home Page
CA licensed under the Utah Digital Signature Act.
Dunkel Certification Authority
German CA.
European Framework for Digital Signatures And Encryption
Proposed EC framework for digital signatures and encryption.
Florida Digital Signatures - Final Report
Final report on the Florida digital signature guidelines.
European ICE-TEL Project
PKI for Europe
Gatekeeper
Australian PKI project.
Global Trust Register
Global trust register for public keys in molecular form.
GlobalSign - Trust On The Net
European CA.
Government Public Key Authority
Australian government PKI project.
GTE CyberTrust Home
GTE CA.
IAIK - ICE-TEL Information Service
Austrian CA.
IBM Registry and World Registry
IBM CA and PKI products.
ICAT Home Page
Japanese CA.
ICE-TEL
Portuguese CA.
ICE-TEL Certification Infrastructure
European CA.
IKS Zertifizierungsinstanz
IKS CA.
Individual Network
IN certification authority.
Installing certificates and root keys in Internet Explorer and IIS
Instructions on installing certificates into MSIE.
Inter Clear - The UK's first Certificate Authority
UK CA.
Introducing SSL and Certificates using SSLeay
Nice introduction to cryptographic techniques, certificates, SSL, and SSLeay.
Internet PCA Registration Authority
IPCA public key.
IPS Seguridad
Spanish CA.
Keyserver.de
Web-based PGP keyserver.
KeyTrust
German KeyTrust CA (part of the MailTrusT initiative).
Keywitness Canada
Canadian CA.
Legislating Market Winners
Paper which examines problems with existing PKI legislation.
MA.US/ITD/LEGAL
Massachusetts digital siganture and online commerce guidelines and information.
MC Home Page
The meta-certificate group (an alternative to X.509/PKIX-type certificates).
Object Identifiers Registry
Large collection of ASN.1 object identifiers.
OCSP++   -   An On-line Certificate Status Protocol
Modification of OCSP to provide a more workable system.
OnWatch Service - Public Key & Security Ref.
Bell Sygma CA.
OpenLDAP
Free LDAP server/client (update of UMich software).
OpenPathCA
Siemans CA toolkit.
Payment, Security & Internet References, Lynn Wheeler
Account authority digital signature (AADS) and X9.59 electronic payment standard information.
PGP Keyserver Interface
WWW interface to the PGP keyservers.
PGP Public Key Server
One of several web-based PGP key servers.
PGP Public Key Server for Yashy-hack and PGP-Users
Web interface for PGP key server.
PKAF
Australian PKI initiative.
Politecnico di Torino: ICE-TEL
Italian CA.
Public Key Authentication Framework: Tutorial
A tutorial on PKI.
Public Key Infrastructure
NIST's PKI information page - interoperability guidelines, PKI panels and overviews, PKI documents.
Public-Key Infrastructure (PKIX) home page
Home page of the PKIX working group.
Public-Key Infrastructure Standards
Slides from a talk on PKI standards and work in progress.
Regole tecniche per la formazione [...], anche temporale, dei documenti informatici
Italian digital signature law.
Roger Clarke's PKI Position Statement
PKI position statement including links to papers on the dangers of a PKI becoming a SurveillanceI.
SACA Home Page
South African CA.
SEIS
Secure Electronic Information in Society (SEIS) project in Sweden.
SI-CA
Slovenian CA.
Signet ID Home Page
Australian CA.
Singapore Controller of Certification Authorities
Singapore digital signature and CA legislation.
SIRCA
Securities Industry Association CA.
SISCER
Spanish CA.
SoftForum Certifying Center
Korean CA (all text is in Korean).
SPKI Certificate Documentation
Documentation and links for SPKI certs.
SPKI Requirements
Simple public-key infrastructure requirements.
SSLeay Certificate Cookbook
Cookbook for setting up a simple CA and working with server and client certs.
SSLeay PKCS#12 patch FAQ
Guide to hacking things so Netscape and MSIE will recognise certs generated by other software.
Structured Arts
X.509-related services.
Summary of Digital Signature and Electronic Signature Legislation
McBride Baker & Coles summary of worldwide digital signature legislation.
Swisskey AG
Swiss CA.
TC TrustCenter Certification Authority and Security Provider
German CA.
Telecom Italia Certification Authority
Italian CA (in Italian).
Time-Stamping
Links to information on timestamping research, protocols, papers, and patents.
TradeAuthority
General CA.
UK Academic PCA
UK CA.
UNI-C PCA
Danish CA.
UNINETT Certification Authority - UNISA
Norwegian CA.
United Nations - Electronic Signatures
UN draft articles on electronic signatures.
VeriSign, Inc.
Major worldwide CA.
Verisign CRL's
Verisign's CRL repository.
Verisign Repository
Information on digital ID's and certificates, certificate practices, and FAQ's.
VRK/PRC: Fineid specifications-HST määritykset
Finnish PKI profile (in Finnish)
Weaving a Web of Trust
Trust management on the WWW.
WebVision Developers Corner
CA toolkit and guide ("low-budget CA").
World Wide Wedlin CA
Swedish CA.
X.500 Directory Standard
Links to X.500-related information, standards, and references.
X.500 Registration Authorities
The number of these has doubled recently... a second one has been discovered in Petropavlovsk-Kamchatsky.
X.509 Sample Certificates
Various sample certificates including oddball fields and types.
X9F Taxonomy and Glossary - Lynn Wheeler
Definitions of crypto, PKI and financial services-related terms.

Security Agencies and Organizations

Ajax U.S. & International Government Military, Intelligence & Law Enforcement Agency Access
Links to intelligence and law enforcement agencies, defence agencies and laboratories, military and other government agencies.
An interview with the NSA
Description of a job interview with the NSA.
ASSIST
Automated System Security Incident Support Team (US DoD CERT).
AUSCERT - Australian Computer Emergency Response Team
CERT Australia home page.
Biometric Consortium
Biometrics standards, publications, and other information.
Bundesamt fuer Sicherheit in der Informationstechnik
The German version of the NSA.
Canadian Security Forum
Canadian computer security information.
Cerulean Technology - Law Enforcement Links
CESG Home Page
CESG (aka GCHQ) home page (pretty meagre).
CERT Coordination Center
Computer Emergency Response Team home page.
Codes and Codewords
Codes and codewords used in military projects.
Communications Security Establishment Official Page
The Canadian CSE's official web page.
Communications Security Establishment Unofficial Page
The Canadian CSE's unofficial web page, which is much more interesting than the official one.
Computer and Network Security Group
Politecnico de Torino computer and network security group.
Covert Action Quarterly
Articles on covert action and surveillance.
CRIS at WPI
WPI cryptography and information security research lab.
Crypto Drop Box
American Cryptogram Association home page.
CSIS - Main Menu
Canadian Security Intelligence Service.
Cypherpunks Home Page
The cypherpunks archive via HTTP. PGP, remailers, crypto papers, clipper, and pointers to further information.
Cypherpunks Tonga
Cypherpunks Tonga - various cypherpunks projects and work in progress.
DefenseLINK News Overview
US Department of Defence news releases, with an extensive archive of older material.
DoD classified spending for FY 1997
US classified military programs spending for 1997.
Defence Signals Directorate - Information Security Branch
The Australian NSA subsidiary.
GCHQ Homepage
The home page shows satellite SIGINT gear... most appropriate.
Ground Truth: Intelligence and Related Facilities
Spy bases worldwide.
IEEE Cipher Newsletter Archive
Archives of the IEEE cipher newsletter containing a great deal of general news on crypto issues.
IFIP TC11 homepage
IFIP security in information systems technical committee home page.
Info-Sec Super Journal
An online InfoSec journal.
Intelligence and Counter-Intelligence Link Farm
Spying, US intelligence agencies, DoD, air force, navy, army, foreign intelligence agencies, whistleblowers, online intelligence archives, military intelligence, weapons technology transfer, industrial espionage, security companies.
Intelligence Zone
Assorted intelligence-related links and information.
International Association for Cryptologic Research
IACR home page.
L0pht Heavy Industries
Hacking central, and a great source of information on security problems.
Menwith Hill US Spy Base
CND's Menwith Hill page.
NAIS Online Newsletter
National Association of Investigative Specialists newsletter. Information of interest to investigators, video surveillance, search and seizure, privacy techniques, legal issues.
National Computer Security Association
National Counterintelligence (NACIC) Home Page
Information on economic espionage.
National Security Agency High-Performance Computing Projects
Various high-performance computing projects sponsored by the NSA.
National Security Agency
The NSA's home page.
National Security Agency Unofficial Page
The NSA's unofficial home page (much more interesting than the official one).
National Security Archive Home Page
Archives, electronic briefing books, declassified documents, related information.
NSA: America's Fortress of Spies
The Baltimore Sun's six-part series on the NSA.
NIST Computer Security Resource Clearinghouse
NIST computer security resources.
NIST Computer Security Publications
NIST computer security publications.
NZ Intelligence Agencies
NZ Intelligence agencies.
Pine Gap
US spy base in Australia.
Preparing for the 21st Century
GPO appraisal of the US intelligence community
Project on Intelligence Agency Reform
Lots of information on intelligence agencies which their home pages will never tell you.
SAS- und Chiffrierdienst der DDR
Crypto devices used by East Germany.
Secret Kingdom
Various spook agencies in the UK.
Security Resource Net
Intelligence, corporate and computer security, counterterrorism, personal security, legislation, news bulletins, upcoming events.
Seven Locks Software
Security news and information, software, online discussion forums, products and services, calendar of security events, firewalls, viruses, security courses and policies.
SPAWAR Information Systems Security Office Homepage
Space and Naval Warfare Systems Command information.
Wullenweber or CDDA Antennas
Wullenweber antennas as used by the NSA.

Security Books, Journals, and Bibliographies, and miscellaneous short publications

ACM Transactions on Information and System Security
(Just a call for papers at the moment).
Aegean Park Press
Historical books on cryptography, intelligence, military history, and related topics.
An Analysis of Security Incidents on the Internet 1989-1995
PhD thesis analysing 4,300 Internet security incidents.
An Electronic Pearl Harbor? Not Likely
Article debunking various Infowar myths.
An Introduction to Cryptography
Online book on cryptography (only the initial section is complete).
ATDL
US army field manuals, schools, strategies and systems.
Authentication, Key Agreement, and Key Exchange Protocols
Bibliography of key agreement protocols with links to authors and online papers.
Bibliography of Molecular Computation and Splicing Sytems
Bibliography on molecular computing, including attacking encryption systems using molecular computers.
Block Cipher Lounge
List of block ciphers, characteristics, and known attacks.
Block Cipher Lounge - AES
Current state of attacks on AES proposals
Brown Computer Science S/Key access
Information on the S/Key authentication protocol.
CAST Encryption Algorithm
Publications pertaining to the CAST encryption algorithm.
CEE VAR News
Central and East European Secure Systems Strategies (online security journal).
CHACS Publications
Centre for high-assurance computer systems publications.
Charles Blair's Notes on Cryptography
Number theory, public-key encryption, RNG's.
Code Signing for Java Applets
Howto for Java code signing for Netscape and MS products.
Collection of Computer Science Bibliographies
About 1000 CS bibliographies with around 800,000 references.
Communication Theory of Secrecy Systems
Scanned images of Shannon's classic communications security paper from the Bell Systems Technical Journal.
Computer Science Technical Reports Archive Sites
Links to sites which distribute CS tech reports.
Computer Services : Administrator's Pages : NT stuff
Installing a student-proof NT setup.
Computer Virus Handbook
Seven Locks' online virus handbook.
Computer Virus Myths treatise
Comprehensive collection of virus myths, hoaxes, and vendor press releases.
Counterpane Homepage
Bruce Schneier's "Applied Cryptography" information.
Credit Card Transactions: Home Page
Overview of CC terms and mechanisms, including discussion of various online CC processing methods.
cryp.to -- The Cryptographic WWW Server
Various PGP developers list archives.
Crypt Newsletter Homepage
Various reports from the computer underground on hacking, security, viruses, hackers, and related issues.
Crypto Glossary
Terry Ritter's crypto glossary (long).
Cryptography
Good overview of cryptography, digital signatures, certificates, and trust management.
Cryptography and Number Theory for Digital Cash
Introduction to crypto and number theory for digital cash.
Cryptography: some important points for beginners
Crypto FAQ for beginners.
Cryptologia.
Cryptosystems Journal Home Page
CSL Bulletins
NIST Computer Science Laboratory bulletins
CSPP - Reports
Computer Systems Policy Project reports, including several covering encryption and e-commerce.
CuD "Computer Underground E-Publications - Top Level" Archive
Cypherpunks Archive Index
Cypherpunks mailing list archive.
Cypherpunks Archive
Searchable archive of the cypherpunks mailing list.
Cypherpunks HyperArchive
Cypherpunks mailing list archive.
Dabbling in Cryptography
1970's cryptanalysis of the M-209.
Data Encryption Page
Overview of encryption and encryption algorithms, links to further information.
Data Security by Design
Designing buildings to thwart electronic eavesdropping.
Dave's Crypto Index
Collection of misc.papers and publications on crypto algorithms and implementations.
David Kahn Interviews
Transcripts of interviews with David Kahn
David Wagner's Crypto Posts
General cryptography, cryptanalysis, computer security.
DDJ, December 1998
DDJ issue on computer security including Twofish, Panama, e-commerce protocols, and smart cards.
des-coding List Archive
Archive of the des-coding mailing list.
dp6 and the 7th USENIX security symposium
Writeup and photos from the 7th Usenix security symposium.
e$ Home Page
The e$ mailing list, information on digital cash clearing, digital bearer bonds, financial cryptography, and related topics.
[E-CARM] E-Commerce and Rights Management
E-commerce mailing list and archives.
ECC FAQ
Elliptic curve cryptography FAQ.
ECS 153 Winter 1998, Robust Programming
Tutorial on robust programming.
EIT Creations: Secure HTTP
Information on the SHTTP protocol.
Electronic Surveillance
Large archive of documents on electronic surveillance.
Elliptic Curve Cryptography
Tutorial on elliptic curve crypto.
Elliptic Curves and Cryptology
Elliptic curve bibliography.
Elliptic Curve Tutorials
Tutorial on elliptic-curve crypto.
Encryption News Resource Page
Encryption and security-related news stories.
Enigma and Its Decryption
Details on the Enigma machine and software simulators.
Enigma and the Turing Bombe
Description of the Bombe and bombe simulator.
Enigma bibliography
Entrust Whitepapers
Entrust white papers and tutorials on security, encryption, certification.
EPFL - LSE - Project CrySTINA
Papers and information on the Cryptographically Secured Telecommunications Information Networking Architecture.
Evaluation of Micropayment Schemes
HP tech report evaluating various micropayment schemes.
Finding the Key
Economic Strategy Institute study on crypto markets and policy.
Firewalls mailing list
Firewalls mailing list archives.
Foundations of Cryptography by Oded Goldreich
Fragments of a book (4 of 10 chapters exist).
Frog Encryption Algorithm
Design and source code for the Frog AES submission.
GSM Network Security
Description of GSM network security and encryption considerations.
Hack-Tic Magazine Archive
1989-1994 Hack-Tic magazine archive (scanned images, in Dutch).
Handbook of Applied Cryptography
Information on the book (well worth getting).
Heise News - Ticker
News ticker which often carries crypto and security-related stories (in German).
Historical Crypto Links
Links to sites containing information on Enigma, Purple, Magic, and other WWII-era crypto.
History of Computer Security
Computer security papers from the 1970's.