Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
asharp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
151.
▲
by
asharp
15y ago
It was my understanding, having read the scrypt paper, that scrypt is significantly more secure then bcrypt (hence its existence).
152.
▲
by
asharp
15y ago
Not particularly. An attack that leaves the attacker with password hashes is rare, as opposed to regular "brute force" attacks of various flavours.
153.
▲
by
asharp
15y ago
To be more specific they are dictated by the hashing algorithm and how it is set up. Say you have something like a straight md5/sha256/etc. It's fairly likely that there exist rainbow tables that will insta(for some reasonable value of inst
154.
▲
by
asharp
16y ago
Inject the users public key in as root and have pubkey only logins for root. Now you are both secure and convenient.
155.
▲
by
asharp
16y ago
I believe a similar idea (use hmac(url, password) as a password for websites) is used to great effect by a firefox plugin. Also, please do not use hash(x + y), use hmacs. String concatenation in hashing breaks some of the complexity guarant
156.
▲
by
asharp
16y ago
"You clearly didn't read the link I directed you at." I do believe your tone is rather counterproductive to the purpose of this forum. I did in fact read the article, and I do now agree that you only need to send MD5(username:realm:password
157.
▲
by
asharp
16y ago
The problem is that you can't actually be secure. This applies in all real situations. You can, however, be secure enough (ie. you achieve your security goals), with some thought and planning. There is a difference though. What is expected
158.
▲
by
asharp
16y ago
It seems as though you are correct. http://techcrunch.com/2009/10/13/grooveshark-slips-past-emis... They have signed with some labels and as such can legally play some content. On the other hand, they were recently kicked off android over
159.
▲
by
asharp
16y ago
It depends very much on what you want out of life. Find what you want out of life, then find what you need to get it. Then work towards it. Long story short, there are some tradeoffs involved. If you want a product that can make stupid amou
160.
▲
by
asharp
16y ago
Or using a system of time not correlated to the rotation of the planet. (It is convenient though :( )
161.
▲
by
asharp
16y ago
I believe that the songs they play are properly licensed, much like radio stations. I also believe this cost them a stupidly large amount of money. So I believe your question can be rephrased "Will the cut the studios ask for be insufficien
162.
▲
by
asharp
16y ago
Long story short, Th isn't actually fissable. It is fertile. You have to use something else (like U235/Pu/etc.) to create a stream of neutrons to turn Th into Pa which decays into U233 (iirc). which is then fissable. (and strangely enough,
163.
▲
by
asharp
16y ago
Digest mode has the issue that you need the plaintext password on the server side in order to do the authentication.
164.
▲
by
asharp
16y ago
Salting is a process used in hashing. Hashing converts an input text (ie. a password) into an unintelligible mash of symbols, that cannot be reversed. If they were sending passwords in plaintext, they are not hashing it, as they are able to
165.
▲
by
asharp
16y ago
A slight one if any. If you store passwords plaintext in the database, a simple SQL injection can dump them out. If you store passwords encrypted in the database, you need to get the code of the server software in order to extract the keys.
166.
▲
by
asharp
16y ago
Surely your joking, Mr. Alterego?
167.
▲
by
asharp
16y ago
Most certainly agree. Unfortunately, dropping the range limit from "Anywhere on earth" to "From a nearby mountain" doesn't fill me with all that much confidence.
168.
▲
by
asharp
16y ago
Surprisingly not, mostly due to some very strange bits of the GSM protocol. Basically, as long as you have enough signal such that the victims handset can hear your commands, you can tell it that you are stronger then any other signal, and
169.
▲
by
asharp
16y ago
Make sure you generate everything you need when processing data in one pass. ie. you take the last 100 data points, (or what have you), turn that into your graph. Then work on the next set of points, etc. The key to this is to make sure tha
170.
▲
by
asharp
16y ago
Virtual machines receive very little entropy from their environment, which is a real problem when entropy is required for the generation of cryptographic keys. There have been many attacks based upon vulnerabilities which exist due to misun
171.
▲
by
asharp
16y ago
Why is it taking 17 seconds to load, if the page you are serving them merely contains links?
172.
▲
by
asharp
16y ago
It still has the same problem that you can't "turn them up" to cope with higher demand over longish periods, which makes dealing with them tricky. They are a good step though.
173.
▲
by
asharp
16y ago
Similarly if you look underground you will find a mantle hot with radioactivity.
174.
▲
by
asharp
16y ago
Can you show that the rate of fatality for uranium mining is more then 13630 times the rate of fatality of coal mining per kilogram (or cubic meter)? (Including secondary effects of both) At the end of the day, that specifically is what we
175.
▲
by
asharp
16y ago
From what i've heard, carrier grade nat is stupidly expensive and rather hard to scale nicely at reasonable speeds. It would be fairly easy to implement say ipv6 in china, as it would be a closed system with everybody getting new gear and e
176.
▲
by
asharp
16y ago
The candu reactors are thorium. As was AVR... Last I heard there were reactors in india/china using thorium. All the gen IV reactors I remember are thorium based, however keep in mind that most of the gen IV reactors can be made with uraniu
177.
▲
by
asharp
16y ago
On virtual machines, /dev/urandom contains very little if any entropy. Basically /dev/random takes entropy from the system and feeds it to you. /dev/urandom is a psudorandom number generator that reseeds from entropy as it gets it. Ie. if i
178.
▲
by
asharp
16y ago
Not really. If you take the waste out of a thorium cycle reactor (ie. no fission products with half lifes > 100 hears), burn it down until there is basically nothing left then turn it into glass and stick it underneath solid granite in
179.
▲
by
asharp
16y ago
Sure. Global warming can kill people for tens of thousands of years to come. Newer processes produce no fission products with a half life > 100y. https://secure.wikimedia.org/wikipedia/en/wiki/Thorium_fuel_... Proper reprocessing can
180.
▲
by
asharp
16y ago
I do not believe that is his definition of safe. I believe he is using the standard definition of safe, for a power source, which is expected deaths/Twh.
More ›