Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
anomalroil
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
How many GPUs do you need to break SHA-1?
(twitter.com)
1 points
by
anomalroil
10mo ago
|
0 comments
2.
▲
by
anomalroil
1y ago
These precompiles were long overdue, IMO. Good think to see them finally being available on Mainnet, but I wonder if we'll see the migration away from the much weaker BN254 pairing-friendly curve to the stronger BLS12-381 one prior to
3.
▲
No Peeking How to Build a Sealed-Bid Auction with On-Chain Timelock Encryption
(drand.love)
5 points
by
anomalroil
2y ago
|
0 comments
4.
▲
by
anomalroil
2y ago
Depends if you want the RTX 5090 before next year or not, just like the collision :P
5.
▲
On-Chain Randomness Gotchas
(drand.love)
1 points
by
anomalroil
2y ago
|
0 comments
6.
▲
by
anomalroil
4y ago
Too bad you didn't try it with much higher degrees.
7.
▲
Show HN: To stop Pokemon-type related questions, I created a dirty web-app
(poke.wouaib.ch)
1 points
by
anomalroil
4y ago
|
0 comments
8.
▲
by
anomalroil
4y ago
Speaking of Monte Carlo, here's a paper about how using bad randomness can lead to wrong simulation: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC2992609/ (or should I call them _biased_ ones?)
9.
▲
by
anomalroil
4y ago
As you said: Java's Random is not meant for serious cryptographic usage, it's meant to be super fast. You have SecureRandom instead for cryptographic usage, and it's noticeably slower. Interestingly, using fast, but bad rando
10.
▲
by
anomalroil
4y ago
It does but it does not! java.util.Random is not a CSPRNG at all and is terrible, so even tho the nextInt() method is using rejection sampling, it's still producing biased values and also completely fails to be "unpredictable"
11.
▲
by
anomalroil
4y ago
Lemire's technique is really nice, in general a good thing to learn about, since it's a bit mind bending how it's playing with intervals. Sadly last time I benchmarked it in code on x86-64 for cryptographic purposes, it wasn&
12.
▲
by
anomalroil
4y ago
Notice that nowadays, unlike 2 years ago, people usually recommend to use the last technique I presented there in the last paragraph before the Conclusion. Which is to generate a random value that is big enough , so that n-log(p) > 128
13.
▲
Observing Randomness
(drand.love)
3 points
by
anomalroil
4y ago
|
1 comments
14.
▲
by
anomalroil
4y ago
Or rather, observing a network meant to produce randomness in a distributed way.
15.
▲
by
anomalroil
4y ago
It could, and that's why a solid threshold network should have nodes in different locations, jurisdictions, cloud providers, etc. and have a threshold that's high enough to avoid that risk.
16.
▲
by
anomalroil
4y ago
Also, be careful of a "last player attack" when XORing randomness: if your last source could spy on the state of your buffer, or on all other randomness sources, it can trivially craft a string that would XOR to a specific value o
17.
▲
by
anomalroil
4y ago
Yeah, I guess that's a fair way of describing threshold cryptography and a threshold network. There was actually already once a proposal of creating a "timelapse encryption service", by Rabin in 2006 ( https://dash
18.
▲
by
anomalroil
4y ago
Well, Timelock Encryption is "encrypting somewhat towards the future", and as explained in the talk, in 1996 "Timelock puzzles" were proposed by Rivest, Shamir and Wagner as a "proof of work" based system to ac
19.
▲
by
anomalroil
4y ago
That would be a pretty cool way of achieving timelock, sure, but might not be super practical.
20.
▲
by
anomalroil
4y ago
Timelock using trusted third parties was first proposed in 1993 by Tim May, the founder of the crypto-anarchist movement, yeah.
21.
▲
by
anomalroil
4y ago
Almost, the randomness is generated using a BLS signature that also makes it verifiable. And that signature is the decryption key.
22.
▲
by
anomalroil
4y ago
Except for the math part when the slides were frozen, I guess :P
23.
▲
by
anomalroil
4y ago
Yeah, that's not exactly how it works. The drand nodes are publishing random beacons that are signed, that's the only thing the networks does. Publishing public verifiable randomness. But pairing-based cryptography allows us to do
24.
▲
by
anomalroil
4y ago
Onboarding new members on a drand network is fairly easy: there only needs to be a threshold of nodes doing a resharing ceremony and all nodes get new shares and new nodes can be onboarded like that. It's not handled by tlock or timeva
25.
▲
by
anomalroil
4y ago
It works by relying on identity-based encryption to encrypt plaintext that cannot be decrypted until the signature of a specific message is revealed. The League of Entropy is signing its beacons every 30 seconds and so acts as a reference c
26.
▲
by
anomalroil
4y ago
Ahahah, definitively. Where's the challenge otherwise? The PoC was ready since almost 8 months sitting in a branch of drand/kyber, and the Go tlock library since a month or so and it would have been enough if it weren't for t
27.
▲
by
anomalroil
4y ago
This is based on a permissioned threshold network, so as long as there are never a threshold number of nodes that are malicious and as long as there is a threshold number of nodes that continue to operate, the network's liveness and se
28.
▲
by
anomalroil
4y ago
Yeah, it's not exactly how it works, but close. The League's node ran together a distributed key generation that created a secret key for the whole League so that it's sufficient to have only a threshold number of nodes to re
29.
▲
by
anomalroil
4y ago
Yes and no: it's not a blockchain. It's relying on the fact that the drand network is producing distributed, verifiable randomness using a threshold scheme with distributed key generation. So the secret key of the group is never i
30.
▲
Timelock Encryption made possible and easy to use
(github.com)
124 points
by
anomalroil
4y ago
|
65 comments
More ›