Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ReidZB
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
21 ms
·
181.
▲
by
ReidZB
13y ago
This is also what the math-related Stack Exchange sites use. (Ex: Math SE, Crypto SE, Physics SE, ...). For example, see the home page of the Math SE: http://math.stackexchange.com/
182.
▲
by
ReidZB
13y ago
> only asymmetric systems based on DLP and IFP will be compromised due to the efficiency of Shor's algorithm. Quantum computing has larger implications than that. For instance, AES with 128-bit keys will need to be phased out since
183.
▲
by
ReidZB
13y ago
I'm not the OP, but: Securely-encrypted data is supposed to be indistinguishable from truly-random data --- this is the widely-used definition of security for encryption. If laws are in place requiring that a user reveal any decryption
184.
▲
by
ReidZB
13y ago
Ah! Of course. You're right. I've never used an absentee ballot, so it completely slipped my mind. This is actually why Helios voting (which is end-to-end auditable) doesn't prevent coercion either: your voting is done '
185.
▲
by
ReidZB
13y ago
The typical US voting system allows coercion? When I voted, I went into a publicly visible booth, recorded my vote, pressed submit, and went about my business. I suppose I could have been forced to take a picture with a cellphone, but I cou
186.
▲
by
ReidZB
13y ago
Such a scheme has a huge flaw: it allows extortion/coercion. Suppose I am a mob boss and I wish to become (insert position here). I send my goons to inform you that voting for me is a wise decision because I can offer you protection
187.
▲
by
ReidZB
13y ago
Checksums offer no security. An attacker can alter them right after altering the image. Now if the images were signed, it would be a different story...
188.
▲
by
ReidZB
13y ago
Keyczar --- and other cryptographic libraries, mostly --- don't solve the issue of protocol design. They do let you choose the primitive you want, but it's still up to you to pick a mode of operation, make sure you use authenticat
189.
▲
by
ReidZB
13y ago
I feel like it's quoted from somewhere else, but the reference escapes me. At any rate, it's a great quote. People who try the iterated design approach are especially frustrating. It ends up becoming a game of whack-a-mole with vu
190.
▲
by
ReidZB
13y ago
Yes! This is exactly what I was going to post. The article's recommendation to read Applied Cryptography and the HAC to "learn the theoretical background" left me dejected, since neither is particularly that great in the
191.
▲
by
ReidZB
13y ago
I haven't had time to delve into the details of this attack, but I do want to note that adding randomization usually doesn't do much for security in these situations. Essentially, randomization usually just increases the numbe
192.
▲
by
ReidZB
13y ago
If you do that and only that, you open yourself up to related-key attacks. A better approach would be to use a well-known scheme like the Merkle–Damgård construction.
193.
▲
by
ReidZB
13y ago
I'd think "ordinary usage" would be by cryptographers and other cryptography-related personnel, not laypeople. Most of the people around where I live don't even know what cryptography is, and it's hit-and-miss wheth
194.
▲
by
ReidZB
13y ago
Well, this is highly tangential, but if you're talking about LaTeX formatting, \epsilon is not generally what you want for the "element of" symbol. Instead, use \in. The biggest difference is that \in is a binary operator and
195.
▲
by
ReidZB
13y ago
Sorry for my late response. 3DES has a block size of 64 bits, or 8 bytes. Unlike a hash function where the whole input affects the whole output (the strong avalanche criterion and whatnot), in ECB mode encryption, data is only changed on 8-
196.
▲
by
ReidZB
13y ago
I am assuming that the DB server cannot decrypt. If the DB server has decryption permissions, and it is compromised, then there's little need in encrypting the passwords anyway as an attacker will simply decrypt them by hand. (They may
197.
▲
by
ReidZB
13y ago
You're right --- had they used something other than ECB mode. For example, if they used CBC mode with a proper IV, assuming the key is not stolen or compromised , the passwords would be quite secure. The issue becomes verifying the pa
198.
▲
by
ReidZB
13y ago
I'm afraid you've exhausted the limits of my precomputed benchmarks. :) I don't know the answer offhand, but I would suspect that hardware-accelerated AES-GCM would win. It certainly does in single-threaded, "one-session
199.
▲
by
ReidZB
13y ago
Oh, yes - definitely. I just picked Salsa20 as an example because I already had benchmark data for my machine, and I am familiar with it. But even TLS 1.2 won't help because 1.2 doesn't include ciphers that are screaming-fast wit
200.
▲
by
ReidZB
13y ago
Yes. GnuTLS does: http://www.gnutls.org/manual/gnutls.html#Encryption-algorith... Anyway, TLS is in a tough spot. It's such a widely adopted standard, with so many implementations, that making radical changes is e
201.
▲
by
ReidZB
13y ago
There are two solutions: use hardware with the AES-NI instruction set, which makes AES blazing fast, or alternatively use a better stream cipher like Salsa20. On my machine, which has an Intel i5-3570k, Salsa20 is about 25% faster (edit: th
202.
▲
by
ReidZB
13y ago
I'm not sure exactly what you're talking about. When the initial constants for Dual_EC_DRBG were generated, the NSA had the opportunity to generate them in such a way that they would be able to predict all future outputs after obs
203.
▲
by
ReidZB
13y ago
Randomness tests mean extremely little for cryptographic PRNGs [1]. Passing a statistical test basically just means that your RNG isn't horribly, awfully broken. Such tests mean almost nothing in terms of cryptographic security. A st
204.
▲
by
ReidZB
13y ago
If I had to design a system to break TLS (and I had the authority of a secretive government agency), selected MITM attacks would be exactly what I would use. Large-scale MITM attacks, i.e. ones against a huge section of the population, real
205.
▲
by
ReidZB
13y ago
That's the thing, though: this article doesn't say that the NSA did generate the Dual_EC_DRBG constants with a backdoor in mind. It just says that internal memos suggest and appear to confirm that they did. That is, the article
206.
▲
by
ReidZB
13y ago
I suppose that was a bit presumptuous of me. My apologies. The whole spiel has made several rounds on HN, though [1], and Ars reported again on the matter about a week ago [2]. But I do acknowledge that doesn't necessarily mean much...
207.
▲
by
ReidZB
13y ago
When I saw 'new details' (edit: this was referring to an old title), I was hoping that the backdoor in Dual_EC_DRBG was either confirmed or denied ... in reality, there's not much new here. The NYT confirmed that their previo
208.
▲
by
ReidZB
13y ago
Honestly, I think the potential advent of efficient fully-homomorphic encryption is potentially one of the largest effects we could ever see on privacy-related computing. The possibilities are absolutely staggering. Imagine, for example,
209.
▲
by
ReidZB
13y ago
Well, in complexity theory (which theoretical cryptography uses heavily), an efficiently computable function is one that has a polynomial-time algorithm to compute it. I mean, wouldn't you say that scrypt is efficient to compute? For i
210.
▲
by
ReidZB
13y ago
You're correct. See the original scrypt paper by Percival [1], halfway down page 13, for a description of the categories. The table itself is at the top of page 14. [1] https://www.tarsnap.com/scrypt/scrypt.pdf
More ›