Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Perseids
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
33 ms
·
241.
▲
by
Perseids
12y ago
Note that the MD5 hash appended to the plaintext is probably just an add hoc system to provide integrity protection[1] of the plaintext. The scenario is that Alice sends Bob an encrypted message without a signature and Eve selectively tampe
242.
▲
by
Perseids
12y ago
> Software performance of SHA-3 is unfortunately not very good. The other finalists like BLAKE (or its faster successor BLAKE2), or Skein, are much more viable software contenders (and make excellent tree hashes), and no-one's parti
243.
▲
by
Perseids
12y ago
There was also the proposal to fix the capacity to c=512 among all output sizes and thus reach a security level of 256bit throughout all instances (given the output size is large enough to support the guarantee). Unfortunately this proposal
244.
▲
by
Perseids
12y ago
> To avoid generic preimage attacks, the capacity parameter in Keccak must be 4 times the size of the desired security level Even though I support your conclusion of it being a manufactured controversy, this part of your post is not corr
245.
▲
by
Perseids
12y ago
And after reading the price tag, remember how much value Elsevier added to the document.
246.
▲
by
Perseids
12y ago
What's even worse is that we are not only talking about the privacy laws targeted at corporations - who alone have proven to be difficult, see the discussions between the EU and the US - but about privacy laws targeted against intellig
247.
▲
by
Perseids
12y ago
> Without any legal barriers to such collection, U.S. persons must increasingly rely on the affected companies to implement security measures to keep their communications private. I kind of despair when I read such statements. How is a c
248.
▲
by
Perseids
12y ago
In metric: 25000 feet = 7620m, which approximates to 7.6 km ;) 6000 feet ~= 1800m 1500 feet ~= 450m
249.
▲
by
Perseids
12y ago
> There are some business models that don't work well without it, yes (Spotify's particular model of streaming, for example) I would even argue that Spotify only needs to include DRM to pacify the labels it has deals with. Beca
250.
▲
by
Perseids
12y ago
Maybe you underestimate how many numbers are weeded out just by checking divisibility by 3, 4 and 5? The first check regarding 2 will always return true, as `val` is incremented by 2. The check for divisibility by 3 will cause an abort for
251.
▲
by
Perseids
12y ago
At the top right of the document: """Declassify on: Five years from entry into force of the TISA agreement or, if no agreement enters into force, five years from the close of the negotiations."""
252.
▲
by
Perseids
12y ago
I'd answer in two ways: One, it is already happening. The 10M problem (10 million concurrent open network connection) is solved by getting the Linux kernel out of the way and managing your own network stack: http://highscala
253.
▲
by
Perseids
12y ago
I also view this as information leakage. I keep some of my online pseudonyms completely separated, and stuff like that allows people to link them together, if I was not careful enough to use a separate ssh key.
254.
▲
by
Perseids
12y ago
> In the future I imagine [...] MD5 hash > Even within the tech industry, tooling moves at a glacial pace. Oh the irony...
255.
▲
by
Perseids
12y ago
Something I was always curious about since I first found out about this trick: Why did the book not contain some error correcting codes at the bottom of each page to simplify the scanning process? Would it have somehow lessened the legal pr
256.
▲
by
Perseids
12y ago
> An upper bound is a valid estimation. Most people don't expect upper bounds, though, when talking about estimations. I for one would appreciate a less-than or less-than-or-equal sign when this is truly an upper bound, as it gives
257.
▲
by
Perseids
12y ago
I have just successfully created an account with a bogus email address and was then able to download the PDF without payment. Still Scribd is a PITA, especially since Firefox and Chrome got integrated PDF readers.
258.
▲
The Case Against Sharing
(medium.com)
8 points
by
Perseids
12y ago
|
0 comments
259.
▲
by
Perseids
12y ago
Please excuse my outburst, but this bothers me to no end: > See here for proof of calling out curve225519 vs scrypt http://www.google.com/trends/explore#q=curve25519%2C%20scryp... . (when scrypt isn't even reall
260.
▲
by
Perseids
12y ago
> I'd argue that Haskell actually has a pedagogy problem, because many of its proponents are academics or mathematicians, who are comfortable with that kind of language. Talking about monads, functors, and arrows is a very natural a
261.
▲
by
Perseids
12y ago
>> Dynamic typing makes Python easier to use than C > Overall it is a higher-level language, whereas C is designed for maximum performance. I agree with most of your points, but on this I think you are comparing apples to oranges.
262.
▲
by
Perseids
12y ago
I don't see what you mean with d). For ECDHE_RSA you still need your high value certificate key online to sign your public Diffie-Hellman parameter. Or do want to presign a few thousand of them and use them one after another in normal
263.
▲
by
Perseids
13y ago
> I listen to his weekly Security Now podcast and without failure he is well-prepared, thorough, accurate and correct. Even when he makes a small mistake next week he comes along, specifies the exact mistake and apologises and corrects i
264.
▲
by
Perseids
13y ago
So what about the '*' in C or even better the '.' in so many object oriented language. > The bottleneck when writing code is almost never keypresses. No, it's readability and that often comes with terseness. Ever
265.
▲
by
Perseids
13y ago
As much as I'm a fan of Perfect Forward Secrecy, it does not protect you against MITM with old certificates.
266.
▲
by
Perseids
13y ago
Talking about marketing: Wouldn't this be a great time for one of the not so small IT companies to pull off a publicity stunt within the tech community and donate a few full time developers to improve the openssl codebase? For example
267.
▲
by
Perseids
13y ago
Sorry, let me be more clear: In the courses and books I've seen and read novices don't get taught secure coding techniques as C++ is often introduced as a superset of C and security in general is not of interest to the teacher. Th
268.
▲
by
Perseids
13y ago
RAII is a minimum. You also have to treat any direct and indirect (unchecked) pointer arithmetic as a potential security vulnerability though. For example if you use the [] operator of a vector you can still access memory outside of the all
269.
▲
by
Perseids
13y ago
Other than C there is also C++ and D if you don't want to stray to far from C. The problem with C++ is that even though it is possible to adapt to a memory safe programming style with C++ the concepts are not prevalent in the community
270.
▲
by
Perseids
13y ago
So we don't actually know who the owner is, if the best information we've got is a blockchain lookup?
More ›