Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Perseids
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
32 ms
·
211.
▲
by
Perseids
12y ago
I can't really see the usage scenario. If you want to transmit data securely between A and B, use public key cryptography and the internet [1]. If you want to protect data at rest, use full disk encryption. If you want protect the data
212.
▲
by
Perseids
12y ago
> But well, I'm an optimist and I assume there are doing this for the right reasons. Even if the laws were made with good intentions, they are not implemented by perfect human beings. If you get on the US No-Fly list just because of
213.
▲
by
Perseids
12y ago
> Generally the key you would give them is for, and limited to, the resources that they cache/reverse proxy That got me wondering: Why don't attackers then only DOS the dynamic pages? Those that can't be migrated easily, l
214.
▲
by
Perseids
12y ago
> Session reuse makes this somewhat less of a pain, as the keyserver need not be queried for repeated https connections. If a DOS is actively attacking the bandwidth of the keyserver, none of the attacking connections will reuse old sess
215.
▲
by
Perseids
12y ago
> When you create an SSL connection in Europe to a west coast server there are a number of round trips. If those can be avoided you can cut the latency of the transaction. That is a good thing too. Note that this will at most cut the con
216.
▲
by
Perseids
12y ago
Actually the SNI extension is sent in the clear. That's one of the things TLS 1.3 is supposed to fix. (See e.g. http://www.ietf.org/mail-archive/web/tls/current/msg10484.ht... for a discussion abo
217.
▲
by
Perseids
12y ago
The use of SHA1 with HMAC, inside as well as outside of the context of SSL is still acceptable, yes. Even against a nation state attacker. The reason attacks on HMAC(k,m)~=SHA1(k||SHA1(k||m)) are much more difficult than general collision
218.
▲
by
Perseids
12y ago
You have it kind of backwards. Not these sites or their certificates are vulnerable, but the certificate signing process itself is. And by extension all browsers that accept SHA1 certificates anywhere are. To clarify, what the attack does i
219.
▲
by
Perseids
12y ago
> I actually suspect that large sites like Facebook, etc will maintain multiple certs at the different levels and dynamically serve the best one up that the client can support. How would you do that? When the TLS connection is establishe
220.
▲
by
Perseids
12y ago
You can easily make the converse point and claim that SHA2 has a higher probability to resist future cryptanalysis than SHA3, given that SHA2 has already had a lot more research than SHA3, but is still not broken. "Old" is a featu
221.
▲
by
Perseids
12y ago
I believe I use the standard Firefox cookie policies and I have to explicitly allow a bunch of domains in NoScript to see anything on the blogspot site. I do use Ghostery, though.
222.
▲
by
Perseids
12y ago
Some numbers: - Public key encryption: 2048bit RSA can achieve up to about 200k encryptions per second on a high end cpu [1]. ElGamal-like encryption schemes using elliptic curve cryptography can get to about 100k encryptions [2]. - Public
223.
▲
by
Perseids
12y ago
> on C11 […] you can use the memset_s function How is the case for modern C++? Are there `vector` or smart pointer alternatives that reliably zero the memory in the destructor?
224.
▲
by
Perseids
12y ago
>> We can't expect people to use password managers (they're complicated and then centralize everything into a single point of failure). > What about you load a site, get an HTTP 401 response, your browser sends back an au
225.
▲
by
Perseids
12y ago
> Der Energiewende Off topic: I'm always a bit mystified as to why people try to use German articles in English texts when they obviously don't know the gender of the word. "Wende" (turn) is female and you thus use &q
226.
▲
by
Perseids
12y ago
> The USPTO is not horribly understaffed. They have other issues. One of the main issues is actually that the patent examiners are union, and the union is not really on board with them being asked to do significantly more work (IE search
227.
▲
by
Perseids
12y ago
Neither the IP address nor the MAC address contain enough entropy to make that secure. Even assuming they were completely random, 32 and 48 bit keys can be bruteforced in no time. Additionally the MAC address contains mostly static or easil
228.
▲
by
Perseids
12y ago
> I would see this slogan (consciously playing on the Eastern complex, to be sure) as somewhat offensive in its coarseness. What was it really saying? 1000 years of European history and heritage doesn't matter and you are disqualifi
229.
▲
by
Perseids
12y ago
> FWIW I did not downvote you in this thread (I actually upvoted you.) I'm just informing you of the principle -- downvote for disagreement is totally cool on HN. I disagree. From what I've come to expect from the voting behavi
230.
▲
by
Perseids
12y ago
> People are also often referring to the United Kingdom as "England" (disregarding the existence of Scotland and Wales) More to the point, when I use "England" instead of "United Kingdom" I disregard the sep
231.
▲
by
Perseids
12y ago
Nice comparison, though I hate it when graphics look like they were drawn to scale, but actually aren't. (The Google indexed pages bar would have to be more than 10 times larger.) More on topic: Whether you can compare the index sizes
232.
▲
by
Perseids
12y ago
Remember that this is not about browsers, but about the TLS libraries the calendar software uses. For instance Java only supports SNI since version 7.
233.
▲
by
Perseids
12y ago
True. But how you deal with it makes quite a difference. Imagine a greater president than Bush spinning it like this (I'm not good enough with rhetoric to make it a compelling speech though): "Today America mourns. Today we were a
234.
▲
by
Perseids
12y ago
> Similarly, I'd like to ask how you would explain the statistical ridiculousness of terrorism to the families of the thousands of people that died in the twin towers. I'm sure they'd be fascinated to hear it. Seriously?
235.
▲
by
Perseids
12y ago
> The third paragraph of section 5 states that the attack is inapplicable on hashes with truncated output. They actually refer to the large internal state size that makes the generic attack infeasible (for a state size of n bit you need
236.
▲
by
Perseids
12y ago
Re: Length extensions Tldr: The length extension property of the Sha2 family has nothing to do with collisions. If you are afraid of future cryptanlytic breakthroughs regarding the collision resistance of Sha2 use the concatenation of SHA-2
237.
▲
by
Perseids
12y ago
> he thinks he can no longer write apps for Android, whereas it is obvious to me that you can put a .apk file up for download anywhere you want, and get paid by means other than Google Wallet. And how many people will find and buy such a
238.
▲
by
Perseids
12y ago
True, but inertia and backwards compatibility is hell of an opponent. IPv6 turned 10 years old recently and we are still far away from universal deployment. TLS 1.2 only got more traction once BEAST - a proof of concept for a paper that was
239.
▲
by
Perseids
12y ago
> Although the design questions are fascinating, the bigger issue that we need somewhere to store all of the nuclear waste. It's actually sitting in a variety of temporary facilities right now that aren't as safe as WIPP or Yuc
240.
▲
by
Perseids
12y ago
> by contrast most suburban homes have a ~40 year lifecycle Living in Germany this is kind of mind-boggling for me. Does that mean each generation has to practically rebuild the houses of its parents? > Much cheaper and easier if its
More ›