Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
AlyssaRowan
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
AlyssaRowan
10y ago
Simplifying the protocol, making it easier to analyse (and prove) and especially removing legacy things we know are troublesome is the main goal of the draft TLS 1.3: now already live and rolled out across CloudFlare and Chrome, and which r
32.
▲
by
AlyssaRowan
10y ago
I wouldn't say it's out of context, I was clearly stating my worries when this CA was discussed here a couple of years ago. I think something should be done, but it's not my call of course. Given we do have Let's Encry
33.
▲
by
AlyssaRowan
10y ago
Yes, that is what I was referring to. Of course it doesn't prove anything either way. It's simply one data-point surrounding the app, and its relevance is not clear (after all, I don't know who uploaded the screenshot, alth
34.
▲
by
AlyssaRowan
10y ago
I haven't looked at the APK metadata, but I certainly wouldn't dismiss that out of hand - the author is apparently from the US, but has a Türkçe keyboard on display in a demo screenshot?
35.
▲
by
AlyssaRowan
10y ago
Imagine a voice call, using a variable-bitrate codec, broken into small packets (not necessarily over the internet), of interest to a passive eavesdropper who cannot decrypt the content, but can observe metadata: the timing of packets and t
36.
▲
by
AlyssaRowan
11y ago
Absolutely. What troubles me - partly why I nearly always stay the hell out of discussions like this, the other part being that it seems to induce sealiony arguments I don't care much for - is that an underlying attitude, though well-m
37.
▲
by
AlyssaRowan
11y ago
Quite! Some like big endian, because tradition ('network byte order'); little endian, because simplicity (current CPUs); mostly it's actually just classic bikeshedding¹. Since X25519 and Ed25519 had already been deployed by a
38.
▲
by
AlyssaRowan
11y ago
Indeed. One might be biased, given one was quite... um... vocal in the whole process! I personally feel Curve25519 and Ed448-Goldilocks were very thoroughly discussed, absolutely fine, and they are the final CFRG recommendations. I am quite
39.
▲
by
AlyssaRowan
11y ago
NSA themselves have used Dual_EC_DRBG (which can be distinguished from a PRF even if you don't have the 'backdoor key': it's not just backdoored and slow, it's bad - and they know that). GCHQ behaves even worse an
40.
▲
by
AlyssaRowan
11y ago
Emotionally, it feels to me a little like that one time a stalker bought me flowers and had them delivered to my (then-) home. I mean, yes, in general flowers are nice, but: fuck off! You can't buy my memories: a token of your affe
41.
▲
by
AlyssaRowan
11y ago
Perhaps it's just me, but I find the - repeated - attempted unmasking of a cypherpunk nym adopted with good cause and reason for the creation of a very disruptive technology terribly disrespectful, although perhaps inevitable. "Wh
42.
▲
by
AlyssaRowan
11y ago
I actually ran a chan: so I think I kind of understand, a little bit. The one I ran is small, chilled-out, and pretty social (well, for a chan). Those two particular storms didn't really wash upon our shores much. There were however st
43.
▲
by
AlyssaRowan
11y ago
Yes, exactly. In that case, perhaps using the algorithm described in the same place as one may find the reverser's credo: "what one man can invent, another can discover"? (As can women and others, of course! I've always
44.
▲
by
AlyssaRowan
11y ago
You'll note they don't actually specify any asymmetric quantum-resistant algorithms. I'd guess if they did, NTRU or a derivative would be one they'd consider first: Security Innovation were trying to sell them that at ab
45.
▲
by
AlyssaRowan
11y ago
Firstly, so - the writer is geek_slop? - let me get this straight about you?: · You adopted a girl at some point. · You are not law enforcement, and are not authorised by them in any way. · You disclose, here in this webpage, that you ran a
46.
▲
by
AlyssaRowan
11y ago
This protocol has no forward security; so, poorly by comparison.
47.
▲
by
AlyssaRowan
11y ago
I should perhaps point out that this series is based on somewhat outdated elliptic curve techniques. It's a little easier to explain these operations over, say, Edwards curves, and I believe djb's done a couple of talks at hacker
48.
▲
by
AlyssaRowan
11y ago
And to top it off, what size are his PGP signing keys? http://www.chiark.greenend.org.uk/~sgtatham/putty/keys.html 1024-bit RSA, and 1024-bit DSA. Please see my comment earlier today about why that's Very Bad
49.
▲
by
AlyssaRowan
11y ago
I mean use of RSA-1024 or DSA-1024 anywhere, for any purpose, is really too small for safe use now. By "on your keyrings" I mean that quite a few PGP keys in the wild still use DSA-1024 master signing keys with (often much larger)
50.
▲
by
AlyssaRowan
11y ago
Seconded. Group 14 (2048-bit, ≈112-bit workfactor) or another safe 2048-bit or greater prime (such as ffdhe2048, or ffdhe3072 @ ≈128-bit workfactor) will do fine for now. You don't need to roll your own safe primes. As per the paper: &
51.
▲
by
AlyssaRowan
11y ago
It's not particularly surprising to the IETF TLS Working Group either, which is at least partially why https://tools.ietf.org/html/draft-ietf-tls-negotiated-ff-dhe... exists. Minimum 2048 bits, please note. 10
52.
▲
by
AlyssaRowan
11y ago
Smart cards/hardware tokens try to not make themselves easy targets, and many such microcontrollers have attempts (of varying success) to defend against limited degrees of physical access and make attacks evident. But in any case, gi
53.
▲
by
AlyssaRowan
11y ago
As I've said before: look out for side-channels! The RF/electrical/other emissions from general-purpose CPU cores and their supporting circuitry tend to have major features with good correlations to execution timing and pipel
54.
▲
by
AlyssaRowan
11y ago
Regarding your first point, there's some confusion between active exploits (i.e. botnet infections, etc) and passive intercepts. They are indeed cautious about using exploits and botnet platforms (I don't think that makes any of i
55.
▲
by
AlyssaRowan
11y ago
Directly related, if you've been keeping up: RC4 is considered weak crypto and, now that CVE-2013-2566 has a base score of 4.3 (i.e. more than 4.0) and RFC 7465 has been published forbidding its use, offering or accepting RC4 should be
56.
▲
by
AlyssaRowan
11y ago
Grandparent: Yes, but they are specialised ones, not general-use ones. Parent: Impossible? It's far more nuanced than that. Do you think that's real time that's passing? Redpilling and bluepilling (as it's become known
57.
▲
by
AlyssaRowan
11y ago
It's definitely worth looking into - TextSecure's Axolotl is best-in-class for dealing with text messaging or other scenarios with occasional one-shots. If you want another, simpler transport that works better for more connected
58.
▲
by
AlyssaRowan
11y ago
That's the big blocker - but, without wishing to be too mean to NXP (sorry Joppe!), the A700x MX51 microcontroller used in the YubiKey Neo is pretty old. Really, most crypto chips are at their core: they almost always just make them
59.
▲
by
AlyssaRowan
11y ago
Trusted filters (such as ad blockers, parental censorware, network monitoring) must to be inside the trust boundary to be effective. That is the best way to ensure they are not imposed en masse against people's will. In-path filter
60.
▲
by
AlyssaRowan
11y ago
>The case of a leaker getting her hands on 2 copies is however highly unlikely. I'm not so sure about that. Some groups used to have a general practice of always getting at least two distinct copies from a supplier to avoid burnin
More ›