3 ms·
These are all standard security concerns. Anyone who brings you something similar and does not have a long list like this is in marketing or sales.
by jjguy 9y ago
These are all standard security concerns. Anyone who brings you something similar and does not have a long list like this is in marketing or sales.
- avaer 9y agoIf these are all standard security concerns, doesn't that make this a standard security pastebin? I think the point is that it's an extraordinary claim with unextraordinary evidence.
- true_religion 9y agoDoes anyone remember when the phrase "extraordinary claims require extraordinary evidence" was used regards to truly extraordinary claims? Like room-temperature superconductors. Or cold fusion. Or that aliens were responsible for the birth of human civilization? This is not an extra-ordinary claim. This is the claim of "I made secure software, and I reckon it's pretty good" wrapped up in the extremely ordinary common English-language hyperbole of calling something 'the best' when there is no way to know if it is, or prove it one way or the other.
- bradknowles 9y agoHowever, the use of hyperbole transforms the claim into an extraordinary one. That is, unless you consider hyperbole to now be standard, in which case we have to likewise transform the original material being quoted. Otherwise we're comparing apples to super duper hyper bestest-ever oranges.
- true_religion 9y agoYep, I consider the use of hyperbole to be a standard colloquialism in this case, not a claim that they did an in-depth experimental study of pastebins and have compiled a report for peer review.
- tangent128 9y agoThe vanilla "secure pastebin" is simply an insecure pastebin served over HTTPS. Better, actually-trying-to-be-secure pastebin implementations will encrypt the data with JS before sending it to the server, and later decrypt it with a key that's embedded in the link's URL fragment (which the server never sees). The security evolution here is that both the ciphertext and the code for the webpage to decrypt it are stored on IPFS, which is a content-addressed filesystem. Thus, so long as you access pastes through a trusted (ie, local) IPFS note, the hardbin server operator can't insert code on the webpage after-the-fact to exfiltrate the key or plaintext back to them.
- nickpsecurity 9y agoOr just knocking out risk areas using proven solutions in ways similar to past within parameters the cryptographers state instead of new, fancy stuff. Plus one for a memory safe language low-level enough for preventing leaks. Works more often than the new, fancy stuff.