Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bren2013
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
A Back-Door'ed EC Diffie-Hellman Implementation
(github.com)
1 points
by
bren2013
12y ago
|
0 comments
32.
▲
Fitbit Is Now Officially Profiting from Users’ Health Data
(betabeat.com)
2 points
by
bren2013
12y ago
|
0 comments
33.
▲
by
bren2013
12y ago
> Using key escrow as a method of e.g. password recovery is a security vulnerability. I have no idea what you mean by "security vulnerability" in this case. Key escrows are the primary way asymmetric crypto is used in prac
34.
▲
by
bren2013
12y ago
So what you're saying is, "golden keys" are no less secure than any other form of encryption. People are repulsed when you call it a back door or a "golden key," but "secure golden keys" are simply key esc
35.
▲
by
bren2013
12y ago
> How do we know, and be sure that this is true? Predicting the generator's output reduces to solving the discrete logarithm on elliptic curves, which is incredibly hard unless you chose the private key. Just like in any asymmetric
36.
▲
by
bren2013
12y ago
There is a subfield of cryptography called kleptography, which studies the "secure golden keys" talked about. The DUAL_EC_DRBG is a great example of how "golden keys" can be implemented securely, because the underlying p
37.
▲
Gyrophone: Recognizing Speech from Gyroscope Signals
(crypto.stanford.edu)
17 points
by
bren2013
12y ago
|
1 comments
38.
▲
by
bren2013
12y ago
Then you didn't read the article.
39.
▲
by
bren2013
12y ago
If you think that's the "simple truth," you either didn't read the article, or you have some piece of information you're not sharing with the rest of us. You also know something about the "formalisms of HBC&quo
40.
▲
by
bren2013
12y ago
Is that a question? I don't understand the question. "Put your money where your mouth is" doesn't sound like a rebuttal. I've no idea what you're talking about.
41.
▲
by
bren2013
12y ago
I mean, it is secure against passive adversaries... but that's nit-picking. ChatCrypt has made a large number of mistakes, though, I concur. They don't use HTTPS, it isn't open sourced, and the developer is practically anony
42.
▲
by
bren2013
12y ago
This is also precisely the problem I was trying to avoid by introducing formality. Is it like saying that a tank made of paper sheets is insecure, or is it like saying that a heavily-armored tank is insecure (against a nuclear weapon)? It i
43.
▲
by
bren2013
12y ago
lol, This is exactly what I was trying to stop people from doing! I'm not endorsing or damning it--I'm talking about it sensibly and objectively so people can learn to use it properly. Please read the article again carefully. I
44.
▲
by
bren2013
12y ago
This is an example of the Perfectionist Fallacy I was talking about in the article. You can't verify that someone isn't MiTM'ing with a stolen certificate. You can't verify that the CA hasn't been coerced into forg
45.
▲
by
bren2013
12y ago
No, you don't get to pick your adversaries, but you do get to pick the strongest one you wish to be secure against. Or for that matter, can be secure against. I briefly mentioned Diffie-Hellman key exchanges to provide an example of
46.
▲
User-to-User Encrypted Webmail (Prototype)
(github.com)
1 points
by
bren2013
13y ago
|
0 comments
47.
▲
by
bren2013
13y ago
I said they made an attempt in the right direction from the small bit of code I'd deciphered and outlined some unaddressed problems. I offered a critique of their code--I didn't praise or damn it. I apologize if there was any con
48.
▲
by
bren2013
13y ago
> Xoring the username together is mostly a simple refinement so two passphrases entered for two different contacts or users does not result in the same secrets stored in their profiles. I'm aware of that, but why do you xor the tw
49.
▲
by
bren2013
13y ago
What I've seen so far isn't a complete waste, but I'm still reviewing since I have nothing better to do this morning. So far I've looked at how a crypto-secure schared secret is established with the "original method
50.
▲
by
bren2013
13y ago
https://news.ycombinator.com/item?id=7083272
51.
▲
by
bren2013
13y ago
I didn't feel like signing up for a Blogger account, but I still wanted to drop this here: > My friend, Ray Sidney, with a PhD in mathematics from MIT explained away this nonsense rather succinctly. > infinity + 7 = infinity >
52.
▲
by
bren2013
14y ago
The weakest link in this system is only the actual sharing of torrent files. We didn't focus on candy security only (hard on the outside, soft on the inside). Even if you are trusted, and inside a cluster, you're still limited to active