3 ms·
A while back I helped a friend (read: dumped a bunch of compute power into it) brute force the SSL keys for Sega's "Phantasy Star Online" Dreamcast game. They
by CursedSilicon 27d ago
A while back I helped a friend (read: dumped a bunch of compute power into it) brute force the SSL keys for Sega's "Phantasy Star Online" Dreamcast game.
They used a similar kind of custom (and flawed) TLS implementation in their game(s) which allowed signing new certificates after brute forcing.
The benefit to this is that users can now play these games without needing to burn a new CD with either the SSL certs swapped, or the code patched to dummy out the checks. A "retail CD" will simply work with private servers now.
I've also been on the other side of the fence, building a "retro internet" service [1] has meant trying to implement ancient SSL/TLS services for things and people that want to use them on the network.
Getting modern OpenSSL (aka what ships in Debian) to even accept these ciphers, let alone keys that short is an uphill battle. Understandably, they're disabled by default and (in Debian at least) the cipher support isn't even compiled into the binary! This requires building a custom OpenSSL to build Nginx against to serve ancient SSL.
Presumably for the OP this kind of work was either outside of their realm of knowledge, or simply "easier" to outsource to the slop machine. Though I hope the machine they're running their demo TLS implementation on is separated completely from their own network. Rolling your own crypto libraries is always a bad idea [2] and I doubt LLM's have "improved" that
[1] https://www.youtube.com/watch?v=cSJsGNIDjtc https://www.youtube.com/watch?v=cSJsGNIDjtc
[2] https://soatok.blog/2025/01/31/hell-is-overconfident-developers-writing-encryption-code/ https://soatok.blog/2025/01/31/hell-is-overconfident-develop...
- smaudet 27d agoFor what it's worth, this comment was better than the article... When you outsource to the slop machine, you don't have anything interesting to say (usually).
- CursedSilicon 27d agoOh, I have *strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob I will say that my projects have a "leading the pack" anti-AI policy [1] [1] https://wiki.cursedsilicon.net/wiki/AI_Policy https://wiki.cursedsilicon.net/wiki/AI_Policy
- jimmaswell 27d ago[flagged]
- CursedSilicon 27d agoI don't recall doing any of that. But thanks for affirming my point? :)
- jimmaswell 27d agoDid I imply you did? I simply said I never see a "pro AI" mob, only an "anti AI" mob.
- CursedSilicon 27d agoLet's flip it, then Is the "anti AI mob" in the room with us right now? If not, why did you feel the need to lament it?
- jimmaswell 27d agoThis entire comment section is almost entirely people bemoaning AI output, calling AI a "slop machine", and you posted your regressive religious screed against it as if it were something to be proud of, seemingly to the approval of others. nearly every comment section with AI involved is like this, and many comment sections where AI is not involved. It deserves pushback.
- wartywhoa23 27d agoPeople are indeed proud of remaining humans and resisting becoming AI corp appendages that are lost in slop at their own expense. Get over it. Your pushback is exactly as religious.
- CursedSilicon 27d agoAh, So. I (and one other person) disagreed with you visibly. Ergo you felt personally called out :) Sounds like a bit of main character syndrome
- throw1234567891 27d agoThe slop machine gives answers to your questions. It hallucinates so it's recommended to verify what it says. Shit in, shit out. If you have no idea whatsoever and can't use other sources to verify claims, well, get a different job I guess.
- wartywhoa23 27d agoWhy use the slop machine then, if you already know or precognize the answer?
- throw1234567891 26d agoBecause you move faster.
- ricksunny 27d ago(I have next to zero knowledge of matters crypto) “Presumably for the OP this kind of work was either outside of their realm of knowledge,” Unnecessary? I don’t even follow the statement’s framing even if I validated the apparent nerdswipe tendency.
- CursedSilicon 27d agoWasn't intended as a "nerdswipe". Wrangling OpenSSL to actually work is a herculean task on a good day. Much less figuring out how to enable ancient crypto protocols within it It's okay to "not know things". Computers are such an incredibly vast field that there's chunks of them that can simply be beyond some of us
- strenholme 27d ago“Rolling your own crypto libraries is always a bad idea” Absolutes like this aren’t absolutely true. It’s interesting because in a related comment, someone claimed that I was “rolling my own crypto” https://news.ycombinator.com/item?id=37368245 https://news.ycombinator.com/item?id=37368245 >>>a few odd coding decisions, such as rolling your own crypto (RNG)<<< Let me give some context here. MaraDNS is a DNS server that’s been around for a very long time, since 2001. There has never been, in those 25 years, any security holes found having to do with the RNG code used by MaraDNS. MaraDNS originally used an AES variant for the RNG; when DJB found cache timing attacks a little over two decades ago, I revised the AES-based RNG code to minimize the impact of such impacts, making the code slower and more complicated. So, about two decades ago, I implemented a new RNG based on RadioGatún, an algorithm which isn’t vulnerable to cache timing attacks and, indeed, has no known attacks which break its cryptographic claims, even though those claims were made over two decades ago. My code has been extensively audited by multiple AI-based security researchers, and while they found two minor issues with the DNS-over-TCP code in the recursive resolver, and a minor issue with the RFC8482 reply in the recursive resolver, no issues have ever been found with the RNG code in MaraDNS (except the issue with possible cache timing attacks I fixed myself after learning about them). [1] In the same time period, OpenSSL has had a large number of security issues, security advisories, and so on. OpenSSL has had countless security holes and patches in the last two decades (Heartbleed, etc.); MaraDNS has had precisely 0 known issues with its RNG code in the same time period. If I had relied on OpenSSL to keep MaraDNS’s cryptography secure, it would had been exposed to many more attacks than it has, since the code I rolled myself ended up being far more secure than using the code in a third party library. Point being, it is possible for someone to roll their own secure RNG. I wouldn’t do so in a corporate context, for the simple reason management often times puts unreasonable time constraints on developers, but for an open source project developed on my own timeline, it can be, in fact it has been very secure. Also: I was never exposed to the Lastpass breach because, instead of using Lastpass, I rolled my own secure website password generator. [2] [1] https://samboy.github.io/MaraDNS/webpage/security.html https://samboy.github.io/MaraDNS/webpage/security.html [2] https://github.com/samboy/PassGen https://github.com/samboy/PassGen
- tptacek 27d agoForget whether you "roll your own" or not, userspace RNGs are a bad idea. The advice to rely on getrandom or urandom is as much about the superior security properties of a kernel RNG as they are about whether you'll fuck up AES somehow.
- eltondegeneres 27d ago> A while back I helped a friend (read: dumped a bunch of compute power into it) brute force the SSL keys for Sega's "Phantasy Star Online" Dreamcast game. Is there anything published online about this? It looks like the Sylverant website still requires patching the game. https://sylverant.net/connecting-to-sylverant/ https://sylverant.net/connecting-to-sylverant/
- CursedSilicon 27d agoI'm not sure why they aren't using it. His github repo is over here https://github.com/patapancakes/dreamconstraint https://github.com/patapancakes/dreamconstraint