Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cryptbe
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
cryptbe
6y ago
Author here, ask me anything.
32.
▲
by
cryptbe
6y ago
The last vulnerability [1] is super cool, as it allows to decrypt AES-GCM ciphertexts using an AES-CBC padding oracle! The exploit is very efficient and fits in a tweet: 1. Take C = E(K, IV) \xor P from GCM encryption 2. Make a guess of P,
33.
▲
Crypto Vulnerabilities in AWS S3 SDK
(twitter.com)
7 points
by
cryptbe
6y ago
|
1 comments
34.
▲
by
cryptbe
6y ago
It's coming and will be part of 1.4.0: https://github.com/google/tink/issues/358 . We have a test package for Linux with Python 3.7 or 3.8 pip3 install -i https://test.pypi.org/simple/
35.
▲
by
cryptbe
6y ago
Disclaimer: I'm a maintainer of Tink. From a user's point of view, keys are still binary blob. Internally Tink serializes keys using protobuf, but in principle it supports arbitrary key formats via the KeysetReader/KeysetWrit
36.
▲
by
cryptbe
6y ago
Disclaimer: I'm one of the maintainers of Tink. I'm not sure if NaCl itself is production ready, but I'm a great fan of libsodium. If I weren't working on Tink, I'd use libsodium for my personal projects. Did you kn
37.
▲
by
cryptbe
6y ago
Disclaimer: I'm a maintainer of Tink. We've added tons of new features since 2018, including support for two new languages Golang and Python. The team has grown from 4 20% contributors to 5 full-time and countless contributors. Pl
38.
▲
by
cryptbe
6y ago
In less than a week, 77K people have installed the app, according to the official tally published by the developer. The growth rate is 2x-3x every day, faster than COVID-19.
39.
▲
by
cryptbe
6y ago
Thanks, appreciate it! Check out this comment: https://news.ycombinator.com/item?id=22991028 .
40.
▲
by
cryptbe
6y ago
Author here. One interesting aspect that I've learned is the tactics, techniques, and procedures (TTPs) of public opinion brigades, aka Force 47. They tried hard to discrete me. My initial report had an error, that is I didn't kno
41.
▲
by
cryptbe
6y ago
Thanks. I have no strong evidence, but it seems that Force 47 is actively monitoring my blog [1]. I've never got so many personal attacks and smear comments like I did since I published my findings. I bet one of them will cite your com
42.
▲
by
cryptbe
6y ago
I wrote the article. I agreed. It's a bad joke. I have no intention causing harm to this system.
43.
▲
Vietnam's contact tracing app broadcasting a fixed ID
(vnhacker.blogspot.com)
107 points
by
cryptbe
6y ago
|
33 comments
44.
▲
by
cryptbe
6y ago
It's https://vnhacker.blogspot.com . I rarely blog in English. However, right now there's a pretty good post: https://vnhacker.blogspot.com/2020/04/vietnams-contact-traci... .
45.
▲
by
cryptbe
6y ago
Yes, it did. I'm doing crypto at Google.
46.
▲
by
cryptbe
6y ago
DH was invented at Stanford. RSA was allegedly invented at GCHQ.
47.
▲
by
cryptbe
6y ago
This is hands down the best book on applied crypto, especially for people who want to self-learn crypto. I started reading it since version 0.1, but every time I pick it up I learn something new.The fun application section in each chapter i
48.
▲
by
cryptbe
6y ago
Haha I came here to ask the same question. This "SIV" mode is silly and breaks down completely when encrypting more than 2^32 IDs. Your proposal is not only faster, but also safer. AES is a strong pseudorandom permutation, the 000
49.
▲
by
cryptbe
6y ago
>It is, but some libraries do not perform this check. Including TweetNaCl if I recall correctly. I'm not sure why TweetNaCl is even considered a serious crypto library. I guess that it can fit in tweets, but this is an optimization
50.
▲
by
cryptbe
6y ago
You should not implement Ristretto, and continue implementing stuff that you're comfortable with. Crypto is deep. You can get involved at the levels you feel comfortable with.
51.
▲
by
cryptbe
6y ago
If one implements EdDSA, but does not follow RFC 8032, one is doing it wrong on multiple levels.
52.
▲
by
cryptbe
6y ago
I didn't say anything about gatekeeping. It's okay to make mistakes, that's one of the best way to learn. I said if one isn't comfortable with the math, maybe don't try to roll one's own crypto and advertise or
53.
▲
by
cryptbe
6y ago
>Ristretto is nice, terribly complex, and you don't actually need to care about the conceptual complexity. As an implementer, your only job is to execute the explicit formulas in section 5 of the Ristretto website. You do not have t
54.
▲
by
cryptbe
6y ago
tl;dr: the conclusion of the EdDSA part of the article is wrong. EdDSA has its problems, but malleability is not one of them, if one is following RFC 8032. >There are several ways to sign a document with EdDSA, and produce a valid signat
55.
▲
Potential data breach in the Bay Area?
(vnhacker.blogspot.com)
2 points
by
cryptbe
7y ago
|
0 comments
56.
▲
by
cryptbe
9y ago
At Google you can ask your coworkers to write feedback that would be included in your promo package. I wonder why the author didn't ask the developers that they helped to write a few sentences explaining how much time they'd saved
57.
▲
by
cryptbe
9y ago
<shameless plug> If you enjoy these challenges you might want to join my team at Google, to analyze, break, design and implement real-world crypto solutions for products used by billions of people. Aside from short-term projects like
58.
▲
by
cryptbe
11y ago
You meant Matt Cutts? He's still at Google, isn't he?
59.
▲
by
cryptbe
11y ago
Because generating p on the fly is expensive. On the other hand, using a safe prime is fine, even if it was generated by a third party.
60.
▲
by
cryptbe
11y ago
Crypto as I know it doesn't allow performing an authenticated key exchange between two entities without neither a pre-shared secret nor a trusted third party (CA) [1]. Anyone who promises anything like that is either selling snake-oil
More ›