Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bluegate010
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
1.
▲
by
bluegate010
3y ago
Some prior art from 2006: https://www.flightglobal.com/darpa-and-nasa-demonstrate-worl... Video: https://youtu.be/F-Y7fhIasjM
2.
▲
by
bluegate010
3y ago
Another talk about LMS / SPHINCS+: https://www.youtube.com/watch?v=lZ1PnJml1CY
3.
▲
by
bluegate010
3y ago
Not a stupid question. CDIs are groovy for minting secrets that are bound to the exact firmware that's running, but are a bit less ergonomic out of the box when it comes to keeping long-lived secrets around across a firmware update. Fi
4.
▲
by
bluegate010
3y ago
https://www.smbc-comics.com/comic/critical
5.
▲
by
bluegate010
6y ago
It sounds like, unless someone is an owner or maintainer of a critical open-source project, the blog post isn't necessarily calling for that person's deanonymization. For projects that are both critical and owned/maintained b
6.
▲
by
bluegate010
6y ago
From the second link: > It is conceivable that contributors, unlike owners and maintainers, could be anonymous, but only if their code has passed multiple reviews by trusted parties. It is also conceivable that we could have “verified”
7.
▲
Building a Titan: Better security through a tiny chip
(android-developers.googleblog.com)
149 points
by
bluegate010
8y ago
|
50 comments
8.
▲
by
bluegate010
8y ago
Many of us on the Asylo team share your reservations about DRM. However, the capability to run software in a not-entirely-trustworthy environment leads to many positive possibilities. For instance, you could imagine a world in which custome
9.
▲
by
bluegate010
8y ago
Asylo is not tied to EPID; the framework aims to abstract away any unique behavior specific to TEE implementations, and provide a common backend interface that developers can code against. The goal is to allow developers to easily migrate t
10.
▲
by
bluegate010
8y ago
Thanks for the helpful feedback. To answer your question: Asylo is currently x86 specific and provides a simulated enclave backend. We plan on evaluating additional enclave technologies going forward, with the goal of supporting those which
11.
▲
by
bluegate010
9y ago
A couple practical benefits of Titan is that we can use it in many different environments where traditional secure boot is not available. For example, we're using it in both servers and in our custom networking card. In addition, tradi
12.
▲
by
bluegate010
9y ago
Titan is one of the tools we use to protect against tampering, even down to the bootloader.
13.
▲
by
bluegate010
9y ago
If the flash chip holding the boot firmware isn't really a flash chip, then indeed this could present an issue. However, since Titan interposes between flash and the PCH/BMC, it can observe the bytes actually being served.
14.
▲
by
bluegate010
9y ago
Titan is just one of several measures we take to harden our stack, and helps us be confident in the software we run. It's a good point though, there are no absolutes in security.
15.
▲
by
bluegate010
9y ago
The log signing prevents undetected tampering after-the-fact; the goal is to make it readily apparent when log messages are altered or deleted, even by parties with root access.
16.
▲
by
bluegate010
9y ago
Both the Titan chip and all software that runs on it are designed entirely in-house, so we have full control over the stack. And we do have physical tampering countermeasures in place.
17.
▲
by
bluegate010
9y ago
With Titan we know exactly how it is designed and how it'll behave. Titan is also platform-agnostic; it can work in many environments that Secure Boot cannot. Secure Boot also doesn't get us nifty features like tamper-evident logg
18.
▲
by
bluegate010
9y ago
We've actually got Titan earring swag we'll hopefully start distributing at upcoming recruiting / customer events, so images may start cropping up in short order. Why earrings? See the Titan announce video[0]. [0] https:
19.
▲
by
bluegate010
9y ago
Spicy raisin bars, an old family recipe. And a cucumber.
20.
▲
by
bluegate010
9y ago
Hey HN, I'm one of the engineers on the team behind Titan, feel free to AMA.
21.
▲
by
bluegate010
10y ago
This site exemplifies something that really annoys me with Google's material design framework. On my 13" screen, I can see a grand total of four items at a time: https://i.imgur.com/6YJxj0b.png I really wish they&
22.
▲
by
bluegate010
10y ago
Off-topic, but The Guardian's article landing page really needs to be cleaned up: http://i.imgur.com/3LGXU7g.png I can't make heads or tails of what I'm supposed to pay attention to.
23.
▲
by
bluegate010
11y ago
I just recently had weeks of headaches over getting my server's email sent to spam. After setting up a brand new domain, with SPF, DKIM, etc., I woke up one morning to find my domain wasn't resolving. Eventually I learned it was b
24.
▲
by
bluegate010
11y ago
> If your keys are not protected by a passphrase Looks like the private key can be leaked regardless of the use of a passphrase, but you'd get the encrypted form that would need to be cracked offline.
25.
▲
by
bluegate010
11y ago
An issue with passwordless is its vulnerability to passive attack. From perusing the source code, it looks like they authenticate users based on a token and uid embedded in a link sent to the user's email address. If that link is inter
26.
▲
by
bluegate010
11y ago
We haven't reached out to Mailvelope/Gmail developers, nor have we opened a usability dialogue with the OpenPGP community. We're still in the process of getting these results published. Your experience with that community is
27.
▲
by
bluegate010
11y ago
For those who value security enough to take the pains to learn the system, yes, it's useful. For your average netizen, we feel a progressive approach would be more effective. Start out with a key escrow service and if the user wants mo
28.
▲
by
bluegate010
11y ago
Interesting; I'd really like to hear what issues you have with that scorecard.
29.
▲
by
bluegate010
11y ago
Yes, we probably would have gotten better usability scores if we developed our own PGP client with a better UX and tutorials. We selected Mailvelope because it was rated highly on the EFF's secure messaging scorecard [1] and we were ex
30.
▲
by
bluegate010
11y ago
That's the exact line of thinking our lab has been on. Security<-->usability is a tradeoff, and PGP seems to sit too far on the secure end of the spectrum to be useful to most users. We're working on a way to deliver progres
More ›