Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
atoponce
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
atoponce
8y ago
> How is the timing here relevant to attacking shacrypt? By observing the time on the CPU it takes for the password hashing algorithm to complete, you can learn the length of the password. It's a side-channel timing attack. But, as
32.
▲
by
atoponce
8y ago
> Article opens by claiming "DES-Crypt has a core flaw in that, not only was the algorithm reversible ..." > That's not true in any meaningful sense That's exactly right, and when I published the article, I recogni
33.
▲
by
atoponce
9y ago
The MOTD I got in my IRC client: https://ae7.st/pb/?6cb6e86dc5d27158#SKb8x+tKyazabJWuFaGjURqe...
34.
▲
by
atoponce
9y ago
Whelp, goodbye Slack, hello Mattermost.
35.
▲
by
atoponce
9y ago
> all existing HWRNG are relatively low bandwidth The Intel on-die DRNG generator has a cited bandwidth of about 3 Gbps [1]. On my Raspberry Pi 3, it has an on-die generator via BCM-2835. Single threaded testing with dd(1) shows about 1.
36.
▲
by
atoponce
9y ago
> RLY? How on earth can a read from /dev/random be non blocking if it does not have sufficient entropy? In short, to answer your question, I am not aware of any /dev/random that will not block if not sufficiently seed
37.
▲
by
atoponce
9y ago
This is really cool. The fact that I can, basically, carry around a TRNG in my pocket is like, the ultimate nerd. Other than reseeding /dev/urandom, I don't really have any personal need for it, but the discussions that can b
38.
▲
by
atoponce
10y ago
This is also a concern of mine. What will this mean for rooting devices? Will it still be root, or will it be "root" as it an iOS jailbreak?
39.
▲
by
atoponce
10y ago
> The only SipHash security you get is seed hiding. Once you got it, it's insecure. Isn't that the case for every cryptographic primitive? I mean, that's sort of the point of private keys, yes? Once you have the key, you c
40.
▲
by
atoponce
10y ago
Yeah, we need to be pedantic here. Humans picking words at "random" is far different from dice picking words at random. Turns out, human-randomness isn't very random at all.
41.
▲
by
atoponce
10y ago
It doesn't actually. It shows how badly flawed the XKCD comic is. The problem with the XKCD comic is that he advocates creating a passphrase without a random function. Turns out, with no surprise, the resulting passphrases are easy to
42.
▲
by
atoponce
10y ago
You should check out the VPN comparison chart by "That One Privacy Guy" here: https://thatoneprivacysite.net/ . There are many factors to consider, such as cipher suite, jurisdiction, and logging. Even then, don&#x
43.
▲
by
atoponce
10y ago
> So, I agree that NIST has been a force for evil in the world, in the same sense that the IETF has. If that's the core point you're trying to make, we're on the same page. If you are defining "evil" as blind and
44.
▲
by
atoponce
10y ago
As I explained, it's a monoculture in that there are organizations, mostly U.S. government bodies, that will not deploy cryptographic primitives unless it has been standardized by NIST. This means strictly sticking with 3DES, AES, SHA-
45.
▲
by
atoponce
10y ago
Yeah. I'm not claiming they invented AES nor SHA-3. The monoculture stems from government ways of thinking that only NIST approved standards can be used. If it doesn't have the NIST stamp of approval, it can't be deployed in
46.
▲
by
atoponce
10y ago
Yeah, I don't know. Is the package manager switching to it for file integrity? Does the OpenZFS team plan on switching to it for filesystem integrity? I don't know. User "cem" asks the same question: https://r
47.
▲
by
atoponce
10y ago
> I'm not from the crypto community, but putting Skein into FreeBSD seems a very strange choice, especially because it looks to be motivated by the "Schneier" brand. Apart from SHA-3 (which is already there), BLAKE2 would
48.
▲
Bruce Schneier's Skein hashing function is now in FreeBSD
(reviews.freebsd.org)
28 points
by
atoponce
10y ago
|
21 comments
49.
▲
by
atoponce
10y ago
That's because the opening is 17 moves deep when the error is made. You're entering mid game at that point. Ruy Lopez, Queen's Gambit, Sicilian, Dutch, and King's Indian defenses, Stonewall, others, are generally preferr
50.
▲
by
atoponce
10y ago
> An error anywhere during the game can be unrecoverable, that's why it's an error. The opening isn't special, in fact I'm sure an error in the ending is more likely to lead to a loss. Agreed, but a tactical error in
51.
▲
by
atoponce
10y ago
> If you want to look at a userspace CSPRNG done right (or what I believe to be one done right) just take a look at BoringSSL's[1]. BoringSSL just uses /dev/urandom directly. It's not a userspace CSPRNG. And as you po
52.
▲
by
atoponce
10y ago
Yes that's true. GMs are GMs, because they have full and complete mastery of the game- opening, middle, and ending. But that mastery is disproportionate, which is what I was trying to say (and didn't do that great of a job). You m
53.
▲
by
atoponce
10y ago
I played chess religiously as a kid. I attended chess clubs, went to private tutoring, and completed in U.S. Chess Federation tournaments. I even have a few trophies in my room that I'm still proud of. Some time in high school, while s
54.
▲
by
atoponce
10y ago
Okay. I read the whole thread (ugh). Arguments for using the kernelspace CSPRNG basically boils down to this: 1. Kernelspace CSPRNGs generally don't change, are well audited, and are generally accepted to be secure. 2. Userspace CSPRNG
55.
▲
by
atoponce
10y ago
Meh. Operating system CSPRNGs can be slow, whereas userspace CSPRNGs seeded from the OS CSPRNG can be fast, fast, fast. Explain how the OpenSSL RNG is broken, and why it's a bad idea to rely on it.
56.
▲
CloudFlare is using LavaRnd to generate 64-bits of entropy for their Origin CA
(twitter.com)
4 points
by
atoponce
10y ago
|
0 comments
57.
▲
by
atoponce
10y ago
But you don't need to do that. You simply take 256 bits and use them as an AES key. You then generate a stream of bits and write that to disk. Reading the disk afterward is equivalent to breaking AES. Completely agreed. I've alr
58.
▲
by
atoponce
10y ago
Why aren't 800 honest-to-goodness random bits per second enough for all practical purposes? For seeding the system CSPRNG, that's fine. For securely destroying data, such as wiping hard drives, or creating underlying noise for e
59.
▲
by
atoponce
10y ago
I noticed that this hasn't been mentioned yet, so I'll bring it up here. While RF-based noise generators can be influenced by outside sources, using an RTL-SDR with https://github.com/pwarren/rtl-entropy can
60.
▲
by
atoponce
10y ago
Radioactive decay is slow, slow, slow. There are much better performing sources of randmness, such as beam splitting. Further, not all noise is RF-based. Thermal noise, for example, is not influenced by RF intereferrence.
More ›