Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
briansmith
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
briansmith
6y ago
> This problem is compounded by it only being possible to link one version of Ring in to the same program. I am planning to fix this in ring early in 2021 (January)... > Even if you don't depend on Ring directly, Ring could app
32.
▲
by
briansmith
6y ago
I commented on this at https://github.com/briansmith/webpki/issues/130 . This is nothing to be concerned about, for quite a few reasons. I don't expect any compatibility issues with being stricter since G
33.
▲
by
briansmith
6y ago
I spent significant effort writing the name constraint implementation in mozilla::pkix (used by Firefox) and by webpki (used by Rustls) to fix this situation. The result is summarized by Netflix: > The result was that every browser (exce
34.
▲
by
briansmith
8y ago
I received a bug bounty from Mozilla after leaving, in a browser component I previously worked on. I didn't write the vulnerable code though. On the other hand, Google refused to pay me a bug bounty for a bug I found in the same compon
35.
▲
by
briansmith
8y ago
We are continuing the project of replacing C code with Rust code in ring . The pace of that effort is mostly a function of how much work time I have available to spend on ring . Day-to-day ring development happens on Windows and it was
36.
▲
Mundane: Rust cryptography library backed by BoringSSL
(github.com)
120 points
by
briansmith
8y ago
|
30 comments
37.
▲
by
briansmith
9y ago
https://github.com/bluejekyll/trust-dns
38.
▲
by
briansmith
9y ago
NIST did specify a SHA-512/256 that has its own IV, like SHA-384.
39.
▲
by
briansmith
9y ago
I guess 32-bit x86 performance is maybe not the best benchmark. I think people aren't optimizing for that ISA to the same extent as they are optimizing for x86-64, 64-bit ARMv8, or 32-bit ARM. If you care about performance and you don&
40.
▲
by
briansmith
10y ago
You can probably find the same or similar bugs in lots of crypto libraries. I occasionally fix similar issues in ring and BoringSSL so that the BoringSSL/LibreSSL/OpenSSL/ ring community can discover and fix the issues. Ar
41.
▲
by
briansmith
10y ago
Did you file a bug on the rustc issue? I'd like to get that fixed and/or even help get it fixed, by fixing the Rust toolchain.
42.
▲
by
briansmith
10y ago
Rustls doesn't really have to deal with the timing attack issue, because those issues are handled by the underlying crypto library, ring . And, ring wasn't built from scratch. It builds upon all the constant-time crypto code in
43.
▲
by
briansmith
10y ago
Most high-level languages don't provide guaranteed-constant-time behavior at all. That's a big reason why ring uses lots of BoringSSL's/OpenSSL's assembly language code. Also, one of my goals with the ring proje
44.
▲
by
briansmith
10y ago
Hi, I'm the person who started the ring project. There is a lot of assembly language code in ring , and there's still some C code too. The thing to keep in mind is that we started from 100% C and assembly language code. Since A
45.
▲
by
briansmith
10y ago
Out of curiousity, what sort of evidence of safety is the Servo team using to evaluate crypto libraries? I'd love to see the criteria.
46.
▲
by
briansmith
10y ago
> Attacks like downgrade attacks, for example, are not memory unsafety issues. First, this library only implements TLS 1.2 with AEAD cipher suites (AES-128-GCM, AES-256-GCM, and ChaCha20-Poly1305) and perfect forward secrecy (using ECDHE
47.
▲
by
briansmith
10y ago
Here's the effect that this ultimately has, as far as I can see: The most reasonable people, who we would ultimately like to see build something that people use, get discouraged and go work on something else. The most stubborn, unreaso
48.
▲
by
briansmith
10y ago
One can't really learn cryptography without writing code. IMO, people should write code and share it and get feedback on it, and experts should donate some time to help them improve, so that we can have more experts. And experts should
49.
▲
by
briansmith
10y ago
The appeal to expertise is exactly what I'm objecting to. Let's judge things on their technical merits: tests, clarity of code, correctness, etc. I've talked to way too many people that want to make contributions to improve s
50.
▲
by
briansmith
10y ago
I'm not sure what you are trying to say. Are you saying that people should use CPGB? Are you saying that CPGB is better than pcp because you think the author of CPGB is more of an expert than the author of pcp? Did you notice the pcp a
51.
▲
by
briansmith
10y ago
Which statistics are you referring to?
52.
▲
by
briansmith
10y ago
If you're parsing untrusted input, you should try to systemically avoid panics. Easier said than done, but I have started a small framework for protocol parsers called untrusted.rs that helps: https://github.com/briansm
53.
▲
by
briansmith
10y ago
> Since the Rust standard library depends on libc, I'm not sure how one would properly allow the Rust symbols to replace the linked-in libc symbols while still depending on the rest of libc. Maybe it's not an issue? Maybe there
54.
▲
by
briansmith
10y ago
IMO, it would be more interesting to see it done top-down, instead of bottom-up. That is, instead of starting with rewriting `strlen`, why not start with rewriting `getaddrinfo`? That would be a very interesting project because you could wr
55.
▲
by
briansmith
10y ago
This Google Chrome document is worth reading: https://docs.google.com/document/d/1vwx8WiUASKyC2I-j2smNhaJa... In particular, it gets into the heart of the matter: What does the user want to happen when they click
56.
▲
by
briansmith
11y ago
What do you think Rust needs to do to become viable in the embedded world?
57.
▲
by
briansmith
11y ago
In Firefox 4, there was a need to implement the HKDF crypto algorithm in a variety of code bases: Java, Javascript, C using OpenSSL, C using NSS. One team coded three implementations. Later, another team coded an implementation. But, that l
58.
▲
by
briansmith
11y ago
Right now, I don't see any advantage of embedding the DSL into Rust code, when instead I could have the DSL completely separate from Rust, and just use Rust's FFI to access what the DSL compiler generates. One benefit of the FFI r
59.
▲
by
briansmith
11y ago
> Does he mean doing what Galois did [1][2] with tools like CRYPTOL [3][4]? Or something more like this [5] with EasyCrypt and CompCert? Or something simpler like Altran's SPARK crypto [6]? And maybe with protocol-level verification
60.
▲
by
briansmith
11y ago
Integrating with LLVM is almost definitely more work than just porting the simple compiler to multiple architectures. Plus, LLVM is actually the source of the difficulty of writing constant-time code using Rust's official compiler, bec
More ›