Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
FiloSottile
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
FiloSottile
2y ago
You're asking why not apply the formula for adversarially selected candidates even if we are randomly selecting candidates. There is simply no reason to, except "maybe we made a mistake" but then why would we not think we mad
92.
▲
by
FiloSottile
2y ago
Why not do 120 then? We can show that the chance of false negative of 5 rounds is cryptographically negligible, so 5, 60, and 120 are all the same. If the only argument for 60 is that it's more and this is a really important rare opera
93.
▲
by
FiloSottile
2y ago
The number of Miller-Rabin rounds has to be bounded, so if you're not going to base your bound on reaching a cryptographically negligible change of false positives, what are you going to base it on? Should we do 10? 15? The problem wit
94.
▲
by
FiloSottile
2y ago
There's extremely small (like 2⁻²⁰, the chance of winning $50 000 with a $2 Powerball ticket [1]), and then there's cryptographically negligible (like 2⁻¹²⁰, the false negative chance of our primality test). The chance of somethin
95.
▲
by
FiloSottile
2y ago
> Rule of thumb: Want a 1024-bit prime? Try 1024 1024-bit candidates and you'll probably find one. Where probably is 76% [1], which is not that high depending on what you are doing. For example, you wouldn't be ok with Generate
96.
▲
t-a-i: Converts Unix Milliseconds to and from International Atomic Time (TAI)
(github.com)
3 points
by
FiloSottile
2y ago
|
0 comments
97.
▲
A Tour of WebAuthn by Adam Langley
(imperialviolet.org)
1 points
by
FiloSottile
2y ago
|
0 comments
98.
▲
Show HN: An Immutable Alpine Linux NAS with No Rootfs
(words.filippo.io)
16 points
by
FiloSottile
2y ago
|
0 comments
99.
▲
by
FiloSottile
2y ago
We have gotten a liiiiittle more liberal ever since we introduced the new GODEBUG feature flag mechanism. I've been meaning to write a "how to safely update Go" post for a while, because the GODEBUG mechanism is very powerful
100.
▲
by
FiloSottile
2y ago
> You will be forced to lug this broken behavior with you forever Yep, welcome to my life.
101.
▲
by
FiloSottile
2y ago
Hah, I wrote the crypto/rsa comments. We take Hyrum's Law (and backwards compatibility [1]) extremely seriously in Go. Here are a couple more examples: - We randomly read an extra byte from random streams in various GenerateKey fu
102.
▲
by
FiloSottile
2y ago
> Does it know which part of a dependency has a vulnerability and check, if the execution reaches _that_ part? Yes, govulncheck does symbol-level reachability static analysis, and the vulndb is manually annotated with affected symbols fo
103.
▲
by
FiloSottile
2y ago
Hrm, this is what I get for logging in to HN from my phone. It’s possible I am confusing this with one of the other exploitable HTTP/1.1 header parser alignment issues. Maybe this was so widespread that ~everything already handles it b
104.
▲
by
FiloSottile
2y ago
Exactly. Please DO NOT mess with protocols, especially legacy critical protocols based on in-band signaling. HTTP/1.1 was regrettably but irreversibly designed with security-critical parser alignment requirements. If two implementation
105.
▲
by
FiloSottile
2y ago
My age v2 note for padding says “use Padmé, see Colm’s comments” :) I’m not really sold on the UR part of PURBs, though: age wants to avoid asking for a passphrase if the file is not passphrase encrypted, and age-plugin-yubikey wants to avo
106.
▲
by
FiloSottile
2y ago
Identity files can be passphrase encrypted and cmd/age will transparently ask for the passphrase before using them. Is that what you meant? https://github.com/FiloSottile/age?tab=readme-ov-file#passph...
107.
▲
by
FiloSottile
2y ago
Assuming that implementation never skip verifying the second signature, and compare the signing keys, that should be ok.
108.
▲
by
FiloSottile
2y ago
Thanks for sharing, always happy when my projects inspire alternatives addressing different parts of the design space. Here are a few quick comments based on skimming the documentation, let me know if I misinterpreted anything. - signing su
109.
▲
by
FiloSottile
2y ago
_o/ hi all, age author here! age is the one of my projects that grew most organically into an ecosystem. It's always great to see what people build with it. Happy to answer any questions. Here are some previous discussions 132 poi
110.
▲
by
FiloSottile
2y ago
That exist(ed)! c2goasm would compile C and then decompile it into Go asm. https://github.com/minio/c2goasm
111.
▲
age Plugins
(words.filippo.io)
2 points
by
FiloSottile
2y ago
|
0 comments
112.
▲
by
FiloSottile
2y ago
Elligator is a bidirectional map from random bytes to elliptic curve points, which is mainly useful for censorship resistance. Its state-of-the-art protocol integration as far as I know is obfs4 ( https://gitlab.com/yawning&#
113.
▲
by
FiloSottile
2y ago
It appears you’ve not read past the topmost reply to the topmost comment, and left with the wrong impression.
114.
▲
by
FiloSottile
2y ago
The ones you link are the "minimal patches for those can't/don't want to upgrade". The commit I am linking to is taken straight from the advisory. On June 6, 2024, this signal handler race condition was fixed
115.
▲
by
FiloSottile
2y ago
Interestingly, the RCE fix was "smuggled" in public almost a month ago. When PerSourcePenalties are enabled, sshd(8) will monitor the exit status of its child pre-auth session processes. Through the exit status, it c
116.
▲
by
FiloSottile
2y ago
Assuming you’re referring to the birthday bound on blocks ( https://sweet32.info ) that’s a limit on blocks encrypted with a single key. XAES derives large keys per message, so it achieves what are commonly referred to as “better-
117.
▲
by
FiloSottile
2y ago
There is no space for 256 bits: 192 bits is 96 bits from the underlying nonce space, and 96 bits that go into the 128-bit CMAC block (along with the necessary prefix). We could make the CMAC input longer, but then we'd have to run the
118.
▲
by
FiloSottile
2y ago
I don't disagree, actually. I was copying the NIST source document notation with 0¹²⁸ and 0¹²⁰10000111, but it probably does more harm than good. `X` was just me being too clever. (In my defense, `X` is formatted differently from varia
119.
▲
The XAES-256-GCM extended-nonce AEAD
(words.filippo.io)
192 points
by
FiloSottile
2y ago
|
56 comments
120.
▲
Real World Crypto 2024
(latacora.com)
1 points
by
FiloSottile
2y ago
|
0 comments
More ›