Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Perseids
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
181.
▲
by
Perseids
12y ago
While DNSSEC certainly deserves a lot of criticism, I think some of the points are unfair. > Had DNSSEC been deployed 5 years ago, Muammar Gaddafi would have controlled BIT.LY’s TLS keys. (DNSSEC's, and thus) DANE's security ca
182.
▲
by
Perseids
12y ago
> Edit: On reflection, I think the parent is saying that there was never a proof published that Dual_EC_DRBG is reducible to a hard problem, and without that we cannot even say whether Dual_EC_DRBG is as secure as other PRNGs that can be
183.
▲
by
Perseids
12y ago
Whatever justifications the NSA comes up with, the crux with Dual_EC_DRBG remains: Either they are as malicious as is now publicly believed and those points were indeed generated with an included backdoor. Or they are stupid enough to endor
184.
▲
by
Perseids
12y ago
Plus, for the majority of recordings it is the only way to get lossless copies. And to reply to the usual criticism in advance: No I don't hear the difference between 320kbit MP3 and lossless, but I want to be future proof for the time
185.
▲
by
Perseids
12y ago
Do you actually get a pure HTML5 reader on any of your links? For me, each of them requires flash: "To view this page in ReadCube Web Reader ensure that Adobe Flash Player version 10.0.0 or greater is installed."
186.
▲
by
Perseids
12y ago
I understand that it would be bad to introduce whitespace-only changes, but why would whitespace at the end of the line that doesn't break the 80 character limit be a problem otherwise? Sure, git colors them red in its diffs, but that
187.
▲
by
Perseids
12y ago
I don't see the relevance of the quote. It only states the changes and not why other changes were not made.
188.
▲
by
Perseids
12y ago
You can use that argument, but then you get other inconsistencies. For example, why didn't they use the same super[1] fuel of the shuttles to also get them into earth orbit and use the extra capacity to add fuel for even more launches
189.
▲
by
Perseids
12y ago
Thanks for those articles, btw. They provide interesting data points in the (somewhat endless) safety debate.
190.
▲
by
Perseids
12y ago
Ok, ignore the part about nuclear safety. My point about shooting down drones vs. actual improving safety still stands. If the stability of your power network is important to you, then do something about those attack vectors, i.e. build mor
191.
▲
by
Perseids
12y ago
The absurdity of nuclear plant safety: The risk of a disasters is "completely negligible", but fly a model plane or drone above a plant and all hell breaks loose. You can't have it both ways: Either scenarios with attackers
192.
▲
by
Perseids
12y ago
If, like me, you have wondered about the strange form of the accretion "disk" shown around the black hole, here [1] is a video, showing that it is actually still a disk, which is distorted by gravity though. Btw, little of the sci
193.
▲
by
Perseids
12y ago
Also, in contrast to their website, their Youtube channel only contains educational videos and no promotional material. They also have a German channel [1], which unfortunately is not up to date with the English one, though. If you like thi
194.
▲
by
Perseids
12y ago
> First off, because you simply don't have that ability in SHA-2 or SHA-3. If you're designing a new system, don't use MD5 or SHA-1; Then don't mention MD5 and SHA1 in the first place. The sooner they leave everyone&#
195.
▲
by
Perseids
12y ago
I disagree with your threat model. Why do you think that the ability to create two colliding functions with basically arbitrary content does not endanger the end user. E.g. (1) I write (or copy) a useful function f1, (2) create an evil func
196.
▲
by
Perseids
12y ago
Fair point. I didn't recognize you had such a high level view of "system". But this raises the question whether one can really call these laws " cryptography export restrictions". Because, sure, cryptography is inv
197.
▲
by
Perseids
12y ago
You should take a look at the [encryption] tag on stack overflow. There is a lot of really depressing stuff there. Implementing low level cryptographic algorithms is hard - I'd say near impossible to get right - if you apply high sta
198.
▲
by
Perseids
12y ago
> 1) Are you supplying a turn-key end-to-end system to the client? > So, you may disagree with the goals of this regulation, but it's certainly not a joke you make it out to be. It remains a joke, when you consider how much reall
199.
▲
by
Perseids
12y ago
True, but that is a common (though difficult) requirement of well written crypto libraries and not directly related to misuse-resistance.
200.
▲
by
Perseids
12y ago
Too bad. But thanks for your reply anyway :)
201.
▲
by
Perseids
12y ago
If you are looking for one specific output, this bunch of inputs is as large as 2^159 on average before you find the preimage (which is far too large to bruteforce with the meager earthly energy resources). The current fear regarding this c
202.
▲
by
Perseids
12y ago
Apparently Sha1: http://csrc.nist.gov/groups/ST/toolkit/documents/dss/NISTReC... - Appendix 4-7 Which is fine, given that even today Sha1's preimage resistance is not practically broken.
203.
▲
by
Perseids
12y ago
The seed itself was never claimed to be verifiably random. Instead, because it uses a (cryptographically secure) pseudo random generator to produce the curve parameters out of a public seed, the curve parameters are said to be "verifia
204.
▲
by
Perseids
12y ago
> It's secure because it was designed from the ground up to be secure at an implementation level, and (critically) to be misuse-resistant. Ok, interesting. Do you happen to have an example at hand? I don't see where there is ro
205.
▲
by
Perseids
12y ago
The thing is, /dev/urandom is not even limited by the entropy counter when there is no entropy in the system at all. That was the reason for the RSA factor collisions: The software just used /dev/urandom during boot ti
206.
▲
by
Perseids
12y ago
But why? Would you be afraid to use libreSSL, because the AES implementation wasn't done by Rijmen and Daemon (inventors of AES)? Generally one feature of the Bernstein designs are that they are reasonable simple to implement securely
207.
▲
by
Perseids
12y ago
They could use certificate pinning [1] (and really, there is no reason for an app author not do so, except for the additional work) which would thwart all man-in-the-middle attacks. The end-point is still open through the analog gap (phot
208.
▲
by
Perseids
12y ago
> global cyber intelligence war I'm really starting to take an issue with declaring all this stuff as "cyber war" or "cyber warfare" (here and everywhere else in this thread). It's not a war if there is no
209.
▲
by
Perseids
12y ago
The radar discussion in the video is pretty good itself. It begins at 30min 31sec: http://youtu.be/uU3pmXvnc0k?t=30m31s .
210.
▲
by
Perseids
12y ago
That's why I was writing about a "messenger" specifically. I was thinking about someone you can trust, if need be, yourself. If this messenger assures you the key wasn't spied upon, you can use the key. If you can't
More ›