Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Jfreegman
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
Jfreegman
4y ago
Wikipedia is anything but neutral on political topics. Their political bias comes straight from the top with corrupt administration and disproportionate application of their own rules and guidelines. I suggest you watch this interview with
2.
▲
by
Jfreegman
4y ago
There have been 6 releases in the past year, including a major feature merge. https://github.com/TokTok/c-toxcore/releases https://github.com/TokTok/c-toxcore/pull/2269 Tox is devel
3.
▲
by
Jfreegman
5y ago
At the time I read it, I found myself hating the book and its characters, yet unable to put it down. It wasn't until long after I had finished the book that I realized that there were no novels that had ever made me actually feel such
4.
▲
by
Jfreegman
6y ago
>Every password that becomes public knowledge ends up in credential stuffing lists, whether it matches your password policy or not. That's right. And we don't want to produce passwords that are likely to be on those lists. A si
5.
▲
by
Jfreegman
6y ago
Why doesn't it? If that password became public knowledge, then it certainly does exist in lists and tables. Its high entropy is only protective as long as it remains secret. This is why it's important to avoid common patterns, eve
6.
▲
by
Jfreegman
6y ago
You missed my point again, and your tangent on randomness is unnecessary; I have no misconceptions of how randomness works, and it is precisely that understanding that has lead me to these decisions - a pure random password generator produc
7.
▲
by
Jfreegman
7y ago
>No Yes. For example, if a rainbow table contains a match for "a" repeating 500 times, then that password's entropy is a non-factor. Therefore entropy in of itself does not necessarily mitigate rainbow table attacks. Ent
8.
▲
by
Jfreegman
7y ago
Increasing entropy mitigates brute force attacks but not necessarily rainbow table attacks, hence the distinction. If every user had a unique password, rainbow tables would be rendered useless. This is why it's important to reduce the
9.
▲
by
Jfreegman
7y ago
>But you can, apparently, force them to use passwords that meet whatever other weird criteria you choose. No one is forced to use the random password generator, and even if I set a minimum limit they could just chop it up to their liking
10.
▲
by
Jfreegman
7y ago
Small correction: the password that has been seen 12 times is "aaaaA1" (no ! char). But "agkxA1" has still been seen 0 times.
11.
▲
by
Jfreegman
7y ago
>If you use passwords of a small enough size that this would really be a problem (like four digit PINs or your "aaaaA1!" example) then your password isn't delivering adequate security against brute force and so you've
12.
▲
by
Jfreegman
7y ago
I agree that there are risks either way, though like you said, the threat model is a bit different. SpicyPass isn't explicitly for web passwords. It's just a generalized key value store with added security. I use it to store my bi
13.
▲
by
Jfreegman
7y ago
That's a great question, and I wish I was good enough at math to give you a sophisticated answer. But my thinking is that the entropy you might gain by allowing duplicates is negated by the huge set of weak/guessable passwords you
14.
▲
by
Jfreegman
7y ago
The pass source code you linked to is just a wrapper for the unix toolset (and has twice the byte count, not that it matters). Pass has a completely different crypto implementation and security model than SpicyPass. The two are not synonymo
15.
▲
by
Jfreegman
7y ago
Although that sentence refers to the interface and feature-set, not the language on which it's built, I do tend to avoid the more complex features of C++. Is there anything in particular that you find confusing or complex about the cod
16.
▲
by
Jfreegman
7y ago
Third party browser extensions (and cloud syncing) are two things that, while convenient, create potential security holes. I opted for security over convenience with spicypass. I absolutely understand why this might turn some people off, ma
17.
▲
by
Jfreegman
7y ago
Often it just comes down to personal preference. A necessary feature to one person is bloat to another. Git integration for example is not something that meets my criteria for a necessary feature of a password store (think non-developers),
18.
▲
by
Jfreegman
7y ago
According to the libsodium docs: >The string produced by crypto_pwhash_str() already includes an algorithm identifier, as well as all the parameters (including the automatically generated salt) that have been used to hash the password.
19.
▲
by
Jfreegman
7y ago
My motivation for writing spicypass was actually a frustrating struggle I once had trying to get pass to play nicely with my GPG installation. I decided it would be easier (and more fun) to write my own. So one of the main differences is th
20.
▲
Show HN: SpicyPass – A free and open-source minimalist password manager
(github.com)
241 points
by
Jfreegman
7y ago
|
107 comments
21.
▲
Tox DHT network statistics
(toxstats.com)
4 points
by
Jfreegman
11y ago
|
0 comments
22.
▲
by
Jfreegman
11y ago
Far from having comparable resources to billion dollar space and nuclear corporations, FOSS developers often have no funding at all and work entirely in our spare time, for free. Any attempt to accomplish "provably correct" code w
23.
▲
by
Jfreegman
11y ago
Astonex was never banned from any of the public tox IRC channels. He was banned from an invite-only channel for off-topic discussion because he was trolling. The ban did not last very long either, because most of us still like him despite h
24.
▲
by
Jfreegman
11y ago
Also, current benchmarks show Rust to be about ~3x slower than C, making it more comparable to Go or Java.
25.
▲
by
Jfreegman
11y ago
uTox was not originally written by the main toxcore dev. However he and a few other brave volunteers have made a big effort to clean up uTox's code over the past few months. That's why this thread was created now and not 6 months
26.
▲
by
Jfreegman
12y ago
That last comment was by irungentoo, who is the lead Tox dev and the one who wrote the parsing code.
27.
▲
by
Jfreegman
12y ago
I should point out that silentbits is not a Tox dev. He was only expressing his personal opinion on that matter.
28.
▲
by
Jfreegman
12y ago
His last activity on github was 5 hours ago...
29.
▲
by
Jfreegman
12y ago
Currently no, but there is a groupchat rewrite underway and that is one of the planned improvements.
30.
▲
by
Jfreegman
12y ago
Toxic is just one of many clients that are built ontop of Tox. Some clients fill a niche, others (like qTox) are meant for widespread adoption.
More ›