Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
CiPHPerCoder
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
61.
▲
by
CiPHPerCoder
4y ago
Not really. Systems thinking is broader in scope and responsibility. You're going to have to cross the rubicon eventually (unless all the software projects that hire you fail gloriously before they achieve any significant scale, I gues
62.
▲
We Need Non-Interactive Post-Quantum KEMs
(scottarc.blog)
1 points
by
CiPHPerCoder
4y ago
|
0 comments
63.
▲
by
CiPHPerCoder
4y ago
How does one measure "better" when it comes to philosophy or spirituality? The notion that priests and monks should be holier than the common folk strikes me as very Abrahamic. This forms a hierarchy in the mind. I'm not a
64.
▲
by
CiPHPerCoder
4y ago
You're begging the question. Why should monks and priests be a model, rather than a reminder of human nature?
65.
▲
by
CiPHPerCoder
4y ago
Correct. The strpos() check just prevents the IV from containing ::
66.
▲
by
CiPHPerCoder
4y ago
There's this 2009 paper http://www.cs.rice.edu/~dwallach/pub/crosby-timing2009.pdf
67.
▲
by
CiPHPerCoder
4y ago
> Do you think it is better than nothing? No. This is security theater , and it stands as an obstacle to security. They were better off with plaintext. > I could set my bar higher, but for living in the real world and that a higher b
68.
▲
by
CiPHPerCoder
4y ago
> To me, it's probably good enough. Your bar should be a little higher. > I mean any sophisticated adversary will use the traditional methods of bribery and coercion with violence to obtain intelligence and influence the course o
69.
▲
by
CiPHPerCoder
4y ago
The vulnerability here is that their application-layer cryptography is vulnerable to adaptive chosen-ciphertext attacks, not that a passive observer could sniff packets and see plaintext.
70.
▲
by
CiPHPerCoder
4y ago
https://www.php.net/manual/en/errorfunc.configuration.php#in... I don't know what their PHP configuration is set to in production. As a rule, I don't test systems that require me to send packets. I only
71.
▲
by
CiPHPerCoder
4y ago
The blog post is written in conversational English. It is not meant to be a technical, formal paper about their protocol. If you're going to get hung up on that, that's entirely your problem, not mine. Yes, their fucking thing is
72.
▲
by
CiPHPerCoder
4y ago
> Okay, then we need to tell people where to get this professional training. I posted a link to a Getting Started guide in my comment above. Once you've exhausted those resources, your best bet is to join a cryptography team at a te
73.
▲
by
CiPHPerCoder
4y ago
> > Using either of the two methods, with the HMAC check completely bypassed, you’ve reduced the security of this construction to unauthenticated AES-CBC mode, which is vulnerable to a Padding Oracle Attack. > Well was this particu
74.
▲
by
CiPHPerCoder
4y ago
It's both. The strpos() check is what you're describing, but openssl_random_pseudo_bytes() accepts an optional second by-reference argument and sets it to true or false depending on the behavior of RAND_pseudo_bytes(). https:
75.
▲
by
CiPHPerCoder
4y ago
I agree. This was just a write-up I promised the Twitter thread. https://twitter.com/CiPHPerCoder/status/1538574970011500546
76.
▲
by
CiPHPerCoder
4y ago
> We need to stop saying don’t roll your own and start teaching it with good examples and good explanations. I 100% agree with this statement, in isolation. But in context, I have to wonder if something in the post sounded like I was tel
77.
▲
by
CiPHPerCoder
4y ago
The main value-add is to replace passwords entirely.
78.
▲
by
CiPHPerCoder
4y ago
What about it is sexualized to you, exactly? I'm not saying your POV is wrong. I'm asking you to explain it. EDIT: Since you edited your comment, I'll edit mine. > I wouldn't open this blog at work. I certainly wouldn
79.
▲
by
CiPHPerCoder
4y ago
I don't see anything sexualized here. This appears to be a depiction of Red Riding Hood, a fairy tale character that's very frequently introduced to young children in America.
80.
▲
by
CiPHPerCoder
4y ago
> This isn't, like, per se a vulnerability; they're not saying it is. "Defeating" is a really poor choice of verb in the title for a post that isn't claiming a vulnerability.
81.
▲
by
CiPHPerCoder
4y ago
BIKE also stands for Bit-flipping Key Encapsulation https://bikesuite.org
82.
▲
by
CiPHPerCoder
4y ago
That was fixed already. https://wiki.php.net/rfc/named_params
83.
▲
by
CiPHPerCoder
4y ago
I will always say VR, I will never say "metaverse". Their branding move was bold, yet unconvincing.
84.
▲
by
CiPHPerCoder
5y ago
I define it as religion for nerds who think they're too smart/clever for religion. To expand on that, see other critical comments e.g. https://news.ycombinator.com/item?id=30830690
85.
▲
by
CiPHPerCoder
5y ago
Enter the prisoner's dilemma
86.
▲
by
CiPHPerCoder
5y ago
Yes, it's a firehose. I'm sure you can find a security vendor willing to offer a curated list somewhere.
87.
▲
Line Goes Up – The Problem with NFTs (and “Web 3”)
(nfts.io)
3 points
by
CiPHPerCoder
5y ago
|
1 comments
88.
▲
by
CiPHPerCoder
5y ago
https://gossamer.tools :)
89.
▲
by
CiPHPerCoder
5y ago
I took things a different direction: https://paragonie.com/blog/2017/07/chronicle-will-make-you-q...
90.
▲
by
CiPHPerCoder
5y ago
I wish Spotify would let us hide his podcast from the front page of their app, at least. I have no interest in his podcast. Let me remove it.
More ›