Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bascule
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
26 ms
·
181.
▲
by
bascule
11y ago
Anyone (not saying Gutmann) who thinks djb's algorithms have been adopted due to "rampant fanboyism" missed the years of debates about elliptic curves that happened on the IRTF CFRG mailing list (primarily involving Microsoft
182.
▲
by
bascule
11y ago
I can't speak to the people who designed JOSE/COSE or their motivations, but to me every design decision they made is either ignorant or actively opposed to past problems with similar standards. ASN.1 would perhaps be the main mot
183.
▲
by
bascule
11y ago
See also his Security Charlatans page on Attrition.org: http://attrition.org/errata/charlatan/kimble/
184.
▲
by
bascule
11y ago
No color cycling? That's like Fractals 101...
185.
▲
On the dangers of a blockchain monoculture
(tonyarcieri.com)
195 points
by
bascule
11y ago
|
63 comments
186.
▲
by
bascule
11y ago
There's a fundamental problem with client certs as currently implemented in browsers as well as the <keygen> tag: these certificates aren't origin-bound and violate the same-origin policy. The method of authorizing client ce
187.
▲
by
bascule
11y ago
If you want a crash course on capabilities, I'd suggest Ben Laurie's paper "Access Control (v0.1)": http://www.links.org/files/capabilities.pdf
188.
▲
by
bascule
11y ago
Yes, Capability Myths Demolished describes the "revocable forwarder" pattern, which uses a proxy to delegate access in a revokable manner. Macaroons on the other hand are nice because they don't need a proxy to solve this pro
189.
▲
by
bascule
11y ago
No, secure ciphers like AES are not vulnerable to known plaintext attacks
190.
▲
by
bascule
11y ago
I've been meaning to blog about Xanadu myself. Nice to see it being talked about.
191.
▲
by
bascule
11y ago
Most other chat systems require user consent before sharing presence information
192.
▲
by
bascule
11y ago
Perhaps you'd like to define what a blockchain means outside the context of Bitcoin? Is SCP a Blockchain? Is Hyperledger? Is Tendermint? Is every database that uses a replicated log a blockchain? Are Certificate Transparency logs block
193.
▲
by
bascule
11y ago
If you're looking for an HTTP library with an advanced timeout API that doesn't use Timeout/timeout.rb (but instead uses an asynchronous I/O layer), check out http.rb: https://github.com/httprb/http
194.
▲
by
bascule
11y ago
The Bitcoin blockchain, as implemented today: - Takes over 10 minutes to come to consensus - Cannot handle the transaction volume of a reasonably large retail company - Loses accepted transactions!!! (blockchain forks, orphan blocks, etc) F
195.
▲
by
bascule
11y ago
> Where does he say that? He says, "security still isn’t a first class concern for most programmers", and puts it in the "No" column. He put it in the "Maybe" column for 2015. Try searching for "Securit
196.
▲
by
bascule
11y ago
To reiterate, because you missed my original point: The author thinks we're doing okay at security, and capabilities failed. We aren't doing okay at security, and capabilities are still a promising solution. The solutions where ca
197.
▲
by
bascule
11y ago
I would put the author in the "doesn't know what he's talking about camp" in regard to capabilities. The same could probably be said regarding the claim that distributed computing works and that maybe we're ok at se
198.
▲
by
bascule
11y ago
HMAC tolerates collisions in the underlying hash function. That said, stop using SHA1.
199.
▲
by
bascule
11y ago
So they basically reinvented this? https://github.com/codahale/sneaker
200.
▲
by
bascule
11y ago
HyperDex Warp does lightweight multi-key transactions: http://hyperdex.org/warp/
201.
▲
by
bascule
11y ago
The section on security is just... bonkers. First it starts by talking about how ZeroMQ security is an "afterthought", linking to an article that should hopefully convince even people with casual security backgrounds this isn'
202.
▲
by
bascule
11y ago
That change was reverted: https://bugs.ruby-lang.org/projects/ruby-trunk/repository/re... It remains an open issue: https://bugs.ruby-lang.org/issues/9262
203.
▲
by
bascule
11y ago
Defining instance-specific behavior of any kind is catastrophic to method caching. JRuby has a hierarchical method cache so it can clear only what's needed, but MRI does not: http://jamesgolick.com/2013/4/14&#
204.
▲
by
bascule
11y ago
It's an idea as old as Xanadu, which predates the web by decades: http://www.xanadu.com/ But see also: - BitTorrent's Project Maelstrom - GNUnet - Tahoe-LAFS - MaidSafe - MojoNation, the technology that inspired B
205.
▲
by
bascule
11y ago
This is a neat hack, but beyond that, I'm not sure what the practical usage is. If '.authorized_keys` can be modified by the user, then one-time access is easily escalated to many-time access. If not, they can still leave a proces
206.
▲
by
bascule
11y ago
Data remanence is a really hard problem. Are you sure this lives up to your claims that "the file is completely deleted without a trace"? How are you storing them? Do they ever hit e.g. an SSD in plaintext?
207.
▲
by
bascule
11y ago
That's not really what the confused deputy problem is about. Instead, a confused deputy has too much authority, and is being asked to "switch hats" and pretend to have the authority of a user/caller. Confused deputies ar
208.
▲
by
bascule
11y ago
The recent OS X DYLD_PRINT_TO_FILE local privilege escalation vulnerability was a classic confused deputy: https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_fi...
209.
▲
by
bascule
11y ago
Hopefully they'll be able to address this then: http://i.imgur.com/3VAMerv.png (from https://twofactorauth.org/ )
210.
▲
by
bascule
11y ago
Their UI is a carbon copy of WhatsApp
More ›