Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
brl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
brl
17y ago
After trying to learn Haskell on and off for a couple of years and miserably failing to be able to write a useful program with it, I'm moving on to Scala which pretty much rules.
92.
▲
Cryptanalysis of Caesar Cipher
(anagram.com)
2 points
by
brl
17y ago
|
0 comments
93.
▲
by
brl
17y ago
I'm not sure how you could use the birthday paradox to brute force a block cipher. You have a message you want to decrypt, and you don't know the key. A brute force attack is trying all the possible keys (2^128 for AES-128) and on average
94.
▲
by
brl
17y ago
They describe that the attack depends on "minimizing the number of active S-boxes in the key-schedule" and that AES-192 is harder to attack than AES-256 because the key schedule has "better diffusion". I'm guessing that they don't mention A
95.
▲
by
brl
17y ago
Maybe I'm not interpreting the results correctly, but does this mean that published attacks place AES-256 in a weaker position than AES-128?
96.
▲
by
brl
17y ago
No, and I'm not sure about it. The way that Tor uses certificates does not seem to be very well documented or I would have a stronger theory about how it could be done without causing an unacceptable level of false positives on regular SSL
97.
▲
by
brl
17y ago
The way Tor uses TLS/SSL is unique enough that it seems very possible to automatically classify Tor traffic. I don't think this is really happening in Iran, but nobody knows for sure. My comment was misleading and what I really meant to sa
98.
▲
by
brl
17y ago
They could identify connections into the Tor network by analyzing handshake traffic and it seems that this may be exactly what is currently happening.
99.
▲
by
brl
17y ago
"One simple approach would be a certificate server which allowed any site to request a certificate and verify it owned the domain in question but putting a response to a challenge in a URL on that domain on a web server on a random port bel
100.
▲
by
brl
17y ago
I'm not so happy that NSN sold lawful interception gear to Iran, but I don't think lawful interception should exist at all in any country. Every government that spies on it's citizens is an 'oppressive regime' in my opinion. If law enforce
101.
▲
by
brl
17y ago
Godwin!
102.
▲
by
brl
17y ago
I'm not sure NSN did anything wrong here. http://www.nokiasiemensnetworks.com/global/Press/Press%20rel...
103.
▲
by
brl
17y ago
Whoah, if you include the first part of that monograph you have a 230 page explanation of how to add two fractions together. I'm really enjoying the writing so even though I already understand how to add fractions (at least I think so!),
104.
▲
by
brl
17y ago
Yes, I suppose that's a unique implementation risk for CTR and in that case Kragen's concerns about XOR are valid as well since you've got a stream cipher with a short period. I was more thinking about how the cipher input has a predictable
105.
▲
by
brl
17y ago
It's probably as superstitious as your XORophobia but the counting part of CTR has always made be a bit uncomfortable.
106.
▲
by
brl
17y ago
> Edit: a theory that involves infinities. Asymptotic analysis of the computational complexity of algorithms.
107.
▲
by
brl
17y ago
Have you seen this: http://vimperator.org
108.
▲
by
brl
17y ago
http://www.ksrevenue.org/faqs-abcdrugtax.htm No personal checks are allowed!
109.
▲
by
brl
17y ago
That's not part of the license conditions. You are quoting the preamble which has almost zero legal importance.
110.
▲
by
brl
17y ago
If you could go back and change your decision, would you decide not to use LSD?
111.
▲
by
brl
17y ago
> I pity those that feel you need drugs to accomplish, because that's just not true. How would you know? As somebody who has never used drugs you are unqualified to argue from experience about how they affect creativity and performance
112.
▲
$134.5 billion in US treasury bonds seized from Japanese smugglers
(asianews.it)
4 points
by
brl
17y ago
|
0 comments
113.
▲
by
brl
17y ago
Yeah, sorry. I was thinking about it from the perspective of a 13 year old who has never touched a computer taking his new Vic-20 out of the box and hooking it up to the TV for the first time. Programming was a natural thing to attempt to
114.
▲
by
brl
17y ago
RSA quickly becomes a lot less elegant once you start patching in all the cracks. What I mean is that if you give an otherwise competent developer who is not a cryptographer a description of the elegant version of the RSA algorithm and ask
115.
▲
by
brl
17y ago
I guess I'm not so much dissing RC4 as pointing out a ridiculous double-standard. Almost every application of RC4 depends on correlation immunity while most applications of SHA-1 do not require collision resistance. That said, I don't thin
116.
▲
by
brl
17y ago
I need to correct something here. The temporary RSA key generation is never used for ephemeral DH, but rather for the situation where RSA key exchange is requested and only a signing key is available. The server does not even verify an exp
117.
▲
by
brl
17y ago
I love getting down-modded especially when I don't expect it or think I don't deserve it. It gives me instant feedback on how my written communication is being interpreted. So I go back and try to figure out why people hate what I wrote.
118.
▲
by
brl
17y ago
> This sounds like a good thing until you realize that such monitoring has no privacy implications at all If you don't have forward secrecy then there is the possibility that an adversary can silently sniff your traffic for as long as t
119.
▲
by
brl
17y ago
> Nobody should be using RC4. I don't think this opinion gets enough play. A collision attack on SHA-1 is published which is still 'academic' enough that nobody has actually produced a single collision and Debian thinks it's worth re-k
120.
▲
by
brl
17y ago
The relative cost of the symmetric bulk encryption algorithms (RC4 vs AES here) is irrelevant compared to the expense of the key exchange/agreement and authentication. The first ciphersuite uses the most common option where the server sends
More ›