Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ReidZB
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
30 ms
·
211.
▲
by
ReidZB
13y ago
These aren't cryptographic hash functions exactly , though, at least not in the sense that a cryptographer would think. I mean, they will fit just about any definition of a cryptographic hash function you can think of, but really it
212.
▲
by
ReidZB
13y ago
I think SHA-2 should be "minor weakness discovered" (if not outright "unbroken"), not "weakened". At the onset of the SHA-3 competition, everyone was nervous about SHA-2: it appeared as though a good attack was
213.
▲
by
ReidZB
13y ago
Yes, I addressed the "glue" thing with the note about authenticating the correct data (notably things like IVs and packet numbers). But given that it uses ssh for the initial setup, I doubt there are any problems to be found with
214.
▲
by
ReidZB
13y ago
It uses ssh to set up the connection, so that setup is fine. The actual traffic is encrypted using AES-128-OCB, which is a great mode of operation. I haven't digged too deeply into their security, but from what the main page says, it s
215.
▲
by
ReidZB
13y ago
Any encryption scheme worth using will not be identifiable by a randomness test. Block ciphers like AES are designed specifically to model pseudorandom permutations (or, rather, this was one of their design goals); being able to distinguish
216.
▲
by
ReidZB
13y ago
StackExchange has a "favorite tags" feature which will highlight specific tags on the front page (and for busier sites, it may even bias its display on them, though I'm not sure about that). There is also an advanced "fi
217.
▲
by
ReidZB
13y ago
Sure. The purpose of a salt in password storage is to prevent the pre-computation of a gigantic rainbow table, which essentially acts as a lookup table. (Rainbow tables use less disk space in exchange for more time per lookup.) Here, the sa
218.
▲
by
ReidZB
13y ago
That's quite unfortunate. The size of the salt doesn't really matter much, so long as it can't be pre-computed before the DB leak. Once the DB is leaked, the salt could be a hundred characters and it wouldn't help much m
219.
▲
by
ReidZB
13y ago
Agreed on the two-factor auth bit: their implementation seems a bit wacky. (At least, their Google Authenticator TOTP implementation. It seemed like their Yubikey implementation was pretty good, but I don't have a Yubikey.) However, th
220.
▲
by
ReidZB
13y ago
FastMail can do this just fine. However, it has a really nifty feature that makes this idea work much better, in my opinion. You can configure FastMail to use "virtual domains" that will reroute b@a.example.com to a+b@example.com.
221.
▲
by
ReidZB
13y ago
Maybe he did! I have no idea. But just in case he didn't, or someone else had the interpretation I had, I just wanted to clarify that a real secret-sharing scheme has some pretty nifty properties.
222.
▲
by
ReidZB
13y ago
If you're generating some truly-random "password", I'd call it a key instead. Just a minor terminological note. Anyway, while that split-the-key scheme works , I wouldn't use it over one of the real secret sharing
223.
▲
by
ReidZB
13y ago
Correct. The NSA suggested changes in the DES S-boxes, which led to many questions. Ultimately, what was discovered is that their changes strengthened DES, not weakened it, as some had feared. You can read more about their involvement here:
224.
▲
by
ReidZB
13y ago
Well, I guess Rijndael is "easier" to brute force in that it's faster than Twofish. But "easier" to brute force doesn't mean a whole lot; AES-192 is easier to brute force than AES-256, but both are so outside t
225.
▲
by
ReidZB
13y ago
Here's the list on gmane: http://news.gmane.org/gmane.comp.security.cryptography.rando... Not sure how to link a particular article in that view. The 'direct link' sends you to an article-only page. But the m
226.
▲
by
ReidZB
13y ago
Not to mention AES-CTR if you want a non-AEAD mode. I think the bias against stream ciphers has something to do with the failure of all stream ciphers submitted to NESSIE, but the eStream project has yielded useful stream ciphers.
227.
▲
by
ReidZB
13y ago
This is a critical distinction. As a concrete example, here's how voting worked in a scheme I once read about. On any one ballot, the order of candidates was randomized. Then the way the scheme worked was that after voting, the voter t
228.
▲
by
ReidZB
13y ago
The International Association for Cryptologic Research (IACR) uses Helios Voting [1], an implementation of a cryptographic voting protocol [2], to vote for its directors. See the 2010 mock election [3,4] or the 2012 vote for the IACR direct
229.
▲
by
ReidZB
13y ago
Valve (or whoever is responsible for the beta keys) was giving out a huge number of keys to some gamers. One of my close friends received 32 (!) beta keys, if I recall correctly, a few months ago. He gave one to everyone in our circle of
230.
▲
by
ReidZB
13y ago
I agree that I wouldn't treat the HAC as a "discovery" reference, for lack of a better term. Like you point out, there are modern-day concerns and constructions that are omitted. But I argue that if you are designing a protoc
231.
▲
by
ReidZB
13y ago
I'm an aspiring cryptographer and this book is hands-down one of the best references for applied cryptography out there today. Don't let the date fool you; cryptography is an area where maturity is well appreciated. It's also
232.
▲
by
ReidZB
13y ago
Cryptography needs problems that are hard on average , not in the worst case. This doesn't fit well with P/NP/NP-complete, which are all about the worst-case difficulty of a problem. For example, see the Merkle-Hellman knaps
233.
▲
by
ReidZB
13y ago
I'm not sure how to parse your comment. > how he becomes a valueable asset for any given intelligence How who becomes a valuable asset? Unless I am misreading this somehow, I don't even know what you're trying to say. &g
234.
▲
by
ReidZB
13y ago
Not relevant to ECC, but if anyone here has spare time and any interest at all in crypto, please contribute to the linked site ( http://crypto.stackexchange.com )! In case anyone doesn't know, StackExchange is a network of Q&
235.
▲
by
ReidZB
13y ago
Turing machines? What do they have to do with privacy?
236.
▲
by
ReidZB
13y ago
I'm not sure how such a feature would work or how useful it would be, for that matter. Maybe the TrueCrypt binary would attempt to decrypt the first X bytes of the partition under the "coercion" password and then check if it matches some kn
237.
▲
by
ReidZB
13y ago
To be more accurate, SHA-224, SHA-512/384, and SHA-512/256 don't suffer from length extension attacks. The rest of the SHA2 family (256 and 512) do. Of course, SHA-256 and SHA-512 are more popular than their truncated variants...
238.
▲
by
ReidZB
13y ago
I was not aware trial accounts are restricted, and I can't find any info online about it, so... So far, though, I have been quite impressed with Fastmail. (I have an enhanced account.)
239.
▲
by
ReidZB
13y ago
Those numbers are for the "ad free" accounts, which are really lightweight anyway. For instance, the ad free accounts only get 100MB of storage for their email anyway, so a 60MB hourly cap is not entirely unreasonable: that's more than half
240.
▲
by
ReidZB
13y ago
When I woke up this morning (and was in a better state of mind), I realized the supplements may have been on the arXiv page but not included in the paper. I was correct. Here [1] is the supplement paper, which I find more useful than the ac
More ›