Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cortesi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
121.
▲
by
cortesi
14y ago
Drat - this story is just a tad premature. A brand new release of pathod will be out next week, including a publicly accessible pathod instance, pathoc (pathod's evil client-side equivalent), and a huge range of other improvements and bugfi
122.
▲
Introducing pathod: a small, pathological HTTP daemon
(corte.si)
2 points
by
cortesi
14y ago
|
0 comments
123.
▲
by
cortesi
15y ago
Look more carefully at my wording - most of the time, when you hear a news report using wording like "the income of the average family..." (as opposed to "average income"), you're hearing a median value, not a mean. The newsreader probably
124.
▲
by
cortesi
15y ago
People do often use the word "average" when they mean "mean" - but they also often use it when they mean "median". It depends on the context. For instance, when I say "the average family has an income of X" or "the average man is Y cm tall"
125.
▲
by
cortesi
15y ago
Then your maths professors were more lax than mine, who were always careful to distinguish between the general term "average" and specific terms like "mean" and "median". As for the accusation that I'm being arcane - all I can do is point y
126.
▲
by
cortesi
15y ago
Yes, I don't think anyone has disputed that.
127.
▲
by
cortesi
15y ago
Hi there. I think you're interpreting "average" as being equivalent to "mean", but this isn't my understanding of the term. Both the "median" and "mean" are measurements of "averageness". I use "median" when I'm talking directly about figur
128.
▲
by
cortesi
15y ago
I'm the author of this post. It would be interesting to see if one could find some objective way to measure a correlation between defects and stylistic sloppyness. A few years ago, I whiled away some time by extracting a huge amount of data
129.
▲
by
cortesi
15y ago
Unfortunately perfectly legitimate compressed sections are both very entropic and very common, so just an entropy measurement won't be very useful for malware detection. I think there might be some promise in looking at patterns of entropy,
130.
▲
by
cortesi
15y ago
Cheers. :) I'm trying very, very hard to resist the urge to start writing a binary dissection tool based on this. I'm picturing a hex viewer with a space-filling curve navigation pane, with options to switch between different pixel layouts,
131.
▲
by
cortesi
15y ago
I'm working on something like this for the next evolution of the entropy visualizations. I've toyed with compression, but have had nicer results so far with other randomness estimators. I'll do a writeup once I have something to show. For a
132.
▲
by
cortesi
15y ago
Why, hello there Hacker News. Just a note that I've written two follow-on blog posts after this one, developing the idea a bit further. First, using a color function that encodes local entropy to show how crypto keys and other high-entropy
133.
▲
by
cortesi
15y ago
I urge people to think twice before publicizing their UDIDs. Many apps have very serious shortcomings in the way they deal with UDIDs, which means that an attacker armed with your UDID could potentially access accounts and personal informat
134.
▲
Show HN: Netograph, privacy snapshots of the social web
(netograph.com)
3 points
by
cortesi
15y ago
|
1 comments
135.
▲
by
cortesi
16y ago
Browser changes can make things more convenient, but we have all the tools to create secure though somewhat cumbersome host-proof applications today. Yes, the Javascript environment sucks, but it's what we have - dismissing the possibility
136.
▲
by
cortesi
16y ago
So... I'll take it that means you haven't discovered a way to circumvent the verification, and you're just being shrill for effect. Send me a note once you have - I'm always happy to receive constructive criticism.
137.
▲
by
cortesi
16y ago
I welcome peer review, which is why I publish all this stuff, and why I repeatedly ask people to verify my code. If you've actually found a way to circumvent the apphash verification routine, I would be delighted to hear about it and would
138.
▲
by
cortesi
16y ago
I'm as wary of Javascript as anyone - in fact, your first sentence is practically a verbatim quote from my first post on the host-proof idea. However, I don't think that there needs to be a superstitious dread about this - it just means we
139.
▲
by
cortesi
16y ago
Again, you should read more on this issue before you criticize the idea in absolute terms. Yes, verification is necessary, which is why I wrote a browser addon that can do hash-based verification of the application every time the page is lo
140.
▲
by
cortesi
16y ago
This is not correct, on a few fronts. It _is_ possible to secure data with just Javascript (with care), and "host proof" describes a design philosophy that has real meaning - Google the term, and look at excellent commercial projects like C
141.
▲
by
cortesi
16y ago
I agree. I might add "i" as an add-before keybinding in the next release.
142.
▲
by
cortesi
16y ago
Odd. What browser did you use? The other keybindings worked, I take it? I just noticed that cryp.sr had made it to HN - I'll check here for bug reports, or you can just email me at aldo@corte.si.
143.
▲
by
cortesi
17y ago
These things are entirely orthogonal. The "host-proof" paradigm is specifically a web application design paradigm - the question we're asking is "how can we do web apps better". Unless you're able to convince your mom to interact with Faceb
144.
▲
by
cortesi
17y ago
AppHash tries to address this by having something called a "hostile block" in a page. The hash is checked for everything BUT the hostile block, and the hostile block itself is checked to make sure it only contains static variable assignment
145.
▲
by
cortesi
17y ago
The point is that all hosts should be "untrusted", because no host is 100% secure, and no host is controlled by a 100% trustworthy entity. This fact is inconvenient, so it's pretty much ignored in the current generation of web applications.
146.
▲
Host-proof applications: doing it wrong
(corte.si)
8 points
by
cortesi
17y ago
|
0 comments
147.
▲
by
cortesi
17y ago
Hey, as I say in the post - I make no claims whatsoever for the visualisations. They were strictly for fun, and I'm a bit surprised to find them on HN. However... choosing colours along the Hilbert traversal of the RGB cube is good if you w
148.
▲
by
cortesi
17y ago
That's a bit over-zealous - even if I hadn't been the author of the article, noting that Fortuna PRNGs can be thought of as "buffering" entropy would have been worthwhile in this context.
149.
▲
by
cortesi
17y ago
In a nutshell, that's almost what the Fortuna family of PRNGs do. In the JSCrypto implementation, entropy is collected from the mouse movements continuously, and like all Fortuna implementations it uses a clever dance using a block cypher
150.
▲
by
cortesi
17y ago
You can't generalise MITM and injection attacks to "Javascript crypto is bad". There's an idea floating around called "host proof hosting" - or in the Clipperz parlance, "zero-knowledge applications" - that I think could be potentially very
More ›