Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ReidZB
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
21 ms
·
151.
▲
by
ReidZB
11y ago
On GitHub, single-commit PRs automatically have their body text set to the body text of the commit. (Annoyingly, GitHub doesn't reflow the body text, so it looks "jagged"...) For multiple-commit PRs, I usually just give some
152.
▲
by
ReidZB
11y ago
From what I recall, the consensus is that the smarter attack is less efficient than brute force overall.
153.
▲
by
ReidZB
11y ago
getrandom(2) uses a CSPRNG under the hood and can be treated as a pre-seeded one. It's unfortunate that it's so recent, though.
154.
▲
by
ReidZB
11y ago
The average guy doesn't have the time to read enough about cryptography to have the sort of knowledge you're wanting. This very article debates an understanding created by incomplete and poor cryptographic knowledge. If there'
155.
▲
by
ReidZB
11y ago
I don't expect there to be a similar community reaction. NIST and the PHC panelists (list at https://password-hashing.net/ ) are two very different bodies. Argon2's internals will likely be altered (with commun
156.
▲
by
ReidZB
11y ago
Typically, cryptographic primitives (like block ciphers, hash functions, KDFs, etc) are written in C. Bugs are caught solely by the use of a sharp mind and careful reading. There are really two reasons for this: (1) optimization is a really
157.
▲
by
ReidZB
11y ago
To be clear, that isn't the final spec. AFAIK, we don't yet know the extent of changes that may be made to Argon2. The email says that Argon2 will be the "basis" for the final winner, which could have some interesting re
158.
▲
by
ReidZB
11y ago
Hmm. I didn't expect this announcement this soon - at least on the public mailing list, the notion of a winner still seemed very far away. Just 18 days ago: https://groups.google.com/forum/#!searchin/crypto-co
159.
▲
by
ReidZB
11y ago
In cryptography, every layer of the stack has a set of possible vulnerabilities associated with it. In the rarest case, primitives (like ciphers and hash functions) are broken; more commonly, the protocol is ill-designed and flawed; but mos
160.
▲
by
ReidZB
11y ago
Even today, auto capitalization fixing (and just auto-formatting code as you type in general) is one of my favorite features of Visual Studio, one that I wish I could have in every IDE/editor. For example, if your class is named FooBar
161.
▲
by
ReidZB
12y ago
Can you link to the source code? In the 2-3 minutes I've spent searching, I can't find it.
162.
▲
by
ReidZB
12y ago
I really dislike when companies say it their product encrypts with "256-bit encryption" or "AES-256". Like you said, that is an incomplete description of an encryption scheme. The choice of block cipher mode can immediat
163.
▲
by
ReidZB
12y ago
There are many large Freenode channels that don't appear to be dying any time soon, like #bash, #archlinux, ##linux, etc. (Though, just because they're large and not dying doesn't mean they're worth hanging out in. :) )
164.
▲
by
ReidZB
12y ago
I'm no IRC expert, but I do know that some IRCds do support sending a scrollback / channel history. For example, InspIRCd's chanhistory module: https://wiki.inspircd.org/Modules/2.0/chanhistory How
165.
▲
by
ReidZB
12y ago
Huh. I didn't know that about Fedora. I admit I don't keep up with the Red Hat world as much as I should. So, apparently systemd has been in production distros for, what, four or five years now? I don't remember the systemd t
166.
▲
by
ReidZB
12y ago
It looks like their domain/project name has changed, but this was discussed on Hacker News recently; the project got a fair bit of flak: https://news.ycombinator.com/item?id=8477659 Maybe the downvoter(s) were some of
167.
▲
by
ReidZB
12y ago
I think Debian has taken a conservative approach. For example, Arch adopted systemd as its default years ago, which means it was already stable enough for daily use years ago (although I think Arch helped pave the way for its adoption b
168.
▲
by
ReidZB
12y ago
It sounds like the site is not rendering correctly for you. The font size itself is (supposed to be) very large, so if you are zooming in, then it sounds like something's wrong. (Mobile device, maybe?) If anything, some folks might pre
169.
▲
by
ReidZB
12y ago
Probably, yes. Upthread, someone looked at the code and suggested that it fell back on a linear congruential generator as an RNG. If that is true, I'd expect the Dieharder tests to fail it.
170.
▲
by
ReidZB
12y ago
If it does use a LCG, then it is totally broken from a cryptographic standpoint: http://security.stackexchange.com/q/4268
171.
▲
by
ReidZB
12y ago
Statistical tests exist, but when it comes to cryptographic security, they are virtually useless. A statistical test attempts to examine a stream of bits and determine if they "look random" from a narrow, naive point of view, ofte
172.
▲
by
ReidZB
12y ago
That isn't what "media conversion" means at all. It is the conversion from one medium to another: for example, from fiber optic (light) to coaxial (electric). This is standard terminology: https://www.google.com&#x
173.
▲
by
ReidZB
12y ago
Nashville, at least, has an insane amount of healthcare tech jobs at the moment. I don't know about the other cities, though.
174.
▲
by
ReidZB
12y ago
I'm using the latest stable release of Firefox (34.0.5) and I see a "Remote DNS" checkbox under my SOCKS proxy configuration. Isn't that the same option in the GUI? No about:config tweaks needed? I would think so, but ev
175.
▲
by
ReidZB
12y ago
I really like Vim for writing LaTeX stuff. It has automatic text wrapping (:set textwidth=80 or whatever width you prefer) and the quick movement/editing commands make writing prose a dream. Being able to sling around words, sentences,
176.
▲
by
ReidZB
12y ago
I've used Arch for years now---on the same install. The only thing that has been unstable about my system is the function of my USB A/D converter (microphone). Other than that, there has never been an upgrade where something broke
177.
▲
by
ReidZB
12y ago
If you'd like to simulate network crappiness on OS X, you can use the Network Link Conditioner from Apple themselves: http://nshipster.com/network-link-conditioner/ I was very impressed with its feature-set (for w
178.
▲
by
ReidZB
12y ago
Thanks for the references! Especially Washington's work. I haven't studied it before, but from a quick glance at the TOC, it looks like it's far more complete than the one cited above.
179.
▲
by
ReidZB
12y ago
Mmm, certainly. Hoffstein et al.'s An Introduction to Mathematical Cryptography is a wonderful text, highly thought of, that really is a better choice than the above link for this sort of thing. Another shorter text is Koblitz's
180.
▲
by
ReidZB
12y ago
The use of AES is orthogonal to the issue of key derivation. In short, when we talk about key derivation, we're speaking of keys in a general sense - irrespective of purpose, they just need to be secure. With that said, if your "
More ›