Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
AlyssaRowan
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
61.
▲
by
AlyssaRowan
12y ago
With TLS, it's not safe not to! Let me explain: Diffie-Hellman requires the group order to have at least one large prime factor: if it has only small prime factors, Silver–Pohlig–Hellman could recover keys, and that'll make you
62.
▲
by
AlyssaRowan
12y ago
Agreed there: if Signal won't do SMS, they shouldn't be catching SMS intents, or they might get invoked when, for example, there's no data. (Of course, there's scope for disagreement here. SMS and particularly MMS are h
63.
▲
by
AlyssaRowan
12y ago
I don't know - anyone got time to review the source? - but if they're only doing SMS, they might not need it; after all, SMS is already 'push', and it was only needed for push notifications for the data channel.
64.
▲
by
AlyssaRowan
12y ago
The underlying reasons are actually pretty sensible. Signal (as it will be) can't deliver encryption via SMS on iOS due to platform restrictions. Neither can tablets or computers normally send SMS messages. (To say nothing of metadata
65.
▲
by
AlyssaRowan
12y ago
No, I find that pretty damn hard to believe. Especially considering where it's coming from. You don't accidentally do anything with an unconstrained CA key chained from the public root: that is a serious piece of data that c
66.
▲
by
AlyssaRowan
12y ago
Although in those, they targeted using pretty close selectors and the payload was browser exploits with a very advanced dropper from what is essentially a big, supported modern malware construction kit. GCHQ used the same technique, but lev
67.
▲
by
AlyssaRowan
12y ago
And of course, by the time we got to the Pentium Pro - and more or less everything ever since - we ended up with a hybrid pipelined superscalar design which takes advantage of the legacy of support (and, compared to VLIW, tight instruction
68.
▲
by
AlyssaRowan
12y ago
A Cortex-M0+ core - which is a really tiny microcontroller - can do TLS 1.2 just fine (using the AES-CCM AEAD instead of the AES-GCM AEAD helps somewhat, apparently: I've not tried to implement it myself, so I'm not clear precis
69.
▲
by
AlyssaRowan
12y ago
The actual detail/technology, more or less. There's nothing China did this last couple of weeks that the Five Eyes' QUANTUM setups aren't already tooled to do: QUANTUMINSERT can be used to inject the JavaScript, just cha
70.
▲
by
AlyssaRowan
12y ago
No, you don't need a HTTP request to upgrade: it's done as part of the TLS negotiation with ALPN. No extra round trips, and TLS 1.3 will probably go even faster. If you're not using TLS, despite things like the China QUANTUM
71.
▲
by
AlyssaRowan
12y ago
It does not. Duplicity can use it, however, which does client-side encryption for you, as mentioned above. Well, duplicity can usually use it. You may have connection problems, because hubic.com is TLS version-intolerant; it'll only
72.
▲
by
AlyssaRowan
12y ago
That's odd, they substituted the (Double) Gloucester and Cheshire cheeses - are they not possible to obtain in the US? Looks like a tasty recipe. We might try that (although a member of the Household is lactose-intolerant, so I'd
73.
▲
by
AlyssaRowan
12y ago
Make that cheesecake and I'm in. No-one who runs a server which only accepts RC4 (!!) with no forward security, and SHA1 signatures, in 2015 , should be giving security advice. My daily driver browser has RC4 entirely disabled. This
74.
▲
by
AlyssaRowan
12y ago
I feel like I want to test what happens if you put values like "", false, " ", 0, an empty array, etc etc etc in front of ??. Because, you know, this is PHP.
75.
▲
by
AlyssaRowan
12y ago
Yes, as long as you have a sound random source (whitened via a good CSPRNG, if you're not using real dice), and a correct unbiased bijective mapping to the wordlist (not just a biased modulo), then it is secure. A friend of mine alread
76.
▲
by
AlyssaRowan
12y ago
Well, Zendo is not open source, and it uses "one time pads" - classic signs of snake-oil cryptography (Vernam ciphers are information-theoretic secure if done properly - but impractical for almost every use case, because they re
77.
▲
by
AlyssaRowan
12y ago
The optical method is also quite smart, if you happen to, say, have an activity LED wired to a bus without much of a filter in between. LEDs switch faster than you might have thought¹. This kind of thing is intelligence-agency home turf; th
78.
▲
by
AlyssaRowan
12y ago
I wouldn't say that's true, but I am unable to comment further.
79.
▲
by
AlyssaRowan
12y ago
Longer than a year. RLD released a proper after 424 days. Inquisitive minds wanting more information should be directed to StarForce.RE.Tools.ReadNFO-RELOADED - http://www.glop.org/files/rld-sfrt.rar (sorry for the h
80.
▲
by
AlyssaRowan
12y ago
Check the bottom of the screen (you may have to look carefully). You're looking for something like Sign in without a Microsoft account (not recommended) -> Local account - there's a similar flow when creating a new user. It
81.
▲
by
AlyssaRowan
12y ago
Hmm. Could be the mailbox communication for VPU<->CPU communication timing out? BCM should be able to repro and fix that. They could also be able to make enabling HYP mode less of a hack. As for the lack of an accessible GIC, the VPU
82.
▲
by
AlyssaRowan
12y ago
I'm not sure what he's alluding to. It may be that they've done simple loudness normalisation instead of one of the more preferable, advanced techniques, like ReplayGain 1.0, R128, or BS.1770 (/ReplayGain 2.0)?
83.
▲
by
AlyssaRowan
12y ago
It's kind of confusing. BULLRUN/EDGEHILL projects are umbrella cover terms: Secure Communities of Interest regarding general access to NSA/GCHQ (respectively) efforts to defeat network communication technologies such as TLS a
84.
▲
by
AlyssaRowan
12y ago
So's NULL, but that doesn't mean you should use it.
85.
▲
by
AlyssaRowan
12y ago
No! I know I mentioned this just yesterday - in the thread in https://news.ycombinator.com/item?id=9207824 - but this is yet another new attack. And they're going to keep coming, and there are passive attacks… Like I
86.
▲
by
AlyssaRowan
12y ago
Really: no. There is nothing "very sudden" about RC4 exhibiting biases indicating it is weaker than it should be: ask any cryptographer. The break that's about to be disclosed in March is simply a new practical twist on a wea
87.
▲
by
AlyssaRowan
12y ago
On the world wide web, jumping to Hulu, an explicitly US-only site that blocks all of the rest of the world, is a bad decision overall. I guess everyone else will be pirating that new series if they want to watch it. He's made that
88.
▲
by
AlyssaRowan
12y ago
…how about a new twist on an old partial plaintext recovery attack that can actually steal passwords in the wild, given a cute name and a logo, being demonstrated in 11 days at Black Hat Asia 2015? I think that might help speed things along
89.
▲
by
AlyssaRowan
12y ago
Or at least, on other peoples' subdomains.
90.
▲
by
AlyssaRowan
12y ago
Misconfiguration. All RC4 ciphersuites are explicitly forbidden by RFC, and considered a severe vuln by CVE. https://tools.ietf.org/html/rfc7465
More ›