Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bascule
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
bascule
9y ago
"Works" in a one-off trial or with daily use? What I'm talking about is an unacceptable failure rate in the course of daily usage (by which I mean failures at least once or twice a day, sometimes considerably worse, over the
32.
▲
by
bascule
9y ago
I suppose one notable delta between our environments: OS X (me) versus Linux (you, ostensibly)
33.
▲
by
bascule
9y ago
As a Yubikey fanboi since 2013, who was very excited about the prospect of using it for airgapping GPG and SSH keys circa 2014, 2018 me says: "you almost certainly don't want to do this" Let's start with SSH. It's j
34.
▲
by
bascule
9y ago
I wrote a blog post about this. tl;dr: no, not unless you were using PQ hard algorithms https://tonyarcieri.com/imperfect-forward-secrecy-the-coming...
35.
▲
by
bascule
9y ago
One of them has already fallen victim to a key recovery attack: https://twitter.com/yx7__/status/945283780851400704 Round2 (LWE-based) and SIKE (isogeny-based) are the particularly interesting ones to me. Both sup
36.
▲
by
bascule
9y ago
Changes made to ECMAScript in TC39 and which proposals made it to e.g. stage 3, such as BigInt
37.
▲
by
bascule
9y ago
It's actually closer to 2330 qubits and 126 billion Toffoli gates: https://eprint.iacr.org/2017/598
38.
▲
by
bascule
9y ago
Kind of disappointed to see very little information about the evolution of the language itself, especially in regard to ECMA TC39.
39.
▲
by
bascule
9y ago
Just don't use them (or any linear function, for that matter) for cryptography: https://en.wikipedia.org/wiki/Content_Scramble_System#The_ci...
40.
▲
by
bascule
9y ago
I guess BigInt (i.e. native integer support) is only stage 3: https://github.com/tc39/proposal-bigint It's the feature I'd most like to see added.
41.
▲
by
bascule
9y ago
Neither is ProtonMail. They see all email plaintexts unless you're using end-to-encryption like GPG/PGP. They only encrypt data at rest, and we can only take them at their word that they're even doing that.
42.
▲
Introducing Sequence: a cryptographicaly secure ledger-as-a-service
(blog.chain.com)
2 points
by
bascule
9y ago
|
0 comments
43.
▲
by
bascule
9y ago
As you guessed, my main reason is there aren't standard constructions around SIV modes for ChaCha20Poly1305, although as Brian Smith notes in that thread SIV is a general construction which should be easy to adapt. See my comments in t
44.
▲
by
bascule
9y ago
There are plans to address this in libsodium. Here are some relevant issues: https://github.com/jedisct1/libsodium/issues/361 https://github.com/jedisct1/libsodium/issues/392
45.
▲
by
bascule
9y ago
The plan for online authenticated encryption in Miscreant is to support Rogaway's CHAIN and STREAM constructions: STREAM: https://github.com/miscreant/miscreant/issues/32 CHAIN: https://github
46.
▲
by
bascule
9y ago
It's not a good defense, because a double fault injection attack could bypass the signature verification as well. The only software defense that actually works reliably is preventing duplicate r-values from being generated in the first
47.
▲
by
bascule
9y ago
RFC 8032 already specifies an "Ed25519ph" variant which prehashes the message and therefore facilitates Initialize-Update-Finalize (IUF) APIs: https://tools.ietf.org/html/rfc8032#section-4
48.
▲
by
bascule
9y ago
Have some Erlang: sieve(N) -> sieve(lists:seq(2, N), []). sieve([], L) -> lists:reverse(L); sieve([Prime|T], L) -> sieve([X || X <- T, X rem Prime /= 0], [Prime|L]).
49.
▲
by
bascule
9y ago
As soon as you add an anonymity layer you've basically reinvented Freenet
50.
▲
by
bascule
9y ago
In the end this system is just a PKI, albeit one based on a "privacy preserving" scheme based on bilinear pairings. It has all of the same failings as any PKI. They aren't going to do any better than OCSP. > the entire sys
51.
▲
by
bascule
9y ago
Can you describe which API you're even talking about? This one? /attestation/sgx/v1/report If so, perhaps you missed this: > "The Attestation Service verifies the validity of the platform. It is the
52.
▲
by
bascule
9y ago
Signal allows you to send messages to numbers which are not in your contacts, which by definition implies it can be done without uploading your contacts to your servers. In person you can also exchange "safety numbers" via QR code
53.
▲
by
bascule
9y ago
So you want to completely punt on the "open the app to an empty contact list" problem and force people to perform what's effectively a GPG keysigning party... Call me crazy, but I think that'd be a bad user experience of
54.
▲
by
bascule
9y ago
Who are the two users in this case? How did they discover each other? From the OP: > "Very few people want to install a communication app, open the compose screen for the first time, and be met by an empty list of who they can commu
55.
▲
by
bascule
9y ago
> "It gets worse! The amount of encrypted RAM available to an enclave is limited to 128MB, which isn’t enough to store a large data set of registered users." (So they used ORAM) That's all very neat, but before a 128MB lim
56.
▲
by
bascule
9y ago
This is no different than, say, watching MongoDB for if it loses your writes, and if it does, replaying them. This is definitely a band-aid: a good database doesn't lose writes it acknowledged.
57.
▲
by
bascule
9y ago
The participants in the consensus group are selected via PoW. You would need to control > 1/3rd of them (i.e. 1/3rd of the nodes that have recently won the PoW leader election race/lottery) to cause Byzantine faults.
58.
▲
by
bascule
9y ago
curve25519-dalek is 3X faster than the equivalent Go code (i.e. in the stdlib, authored by agl). This is for a few reasons: Rust has support for 128-bit integers (i.e. u128) which allows for faster arithmetic when operating on what are effe
59.
▲
by
bascule
9y ago
Though many new "blockchain" systems do achieve BFT (perhaps most notably Tendermint, which seems to be passing aphyr's Jepsen tests with flying colors), it's important to keep in mind Bitcoin falls short of achieving it
60.
▲
by
bascule
9y ago
I'll just leave this here: https://underhandedcrypto.com/2017/07/31/2017-runner-up-nevi...
More ›