Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dadrian
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
91.
▲
by
dadrian
2y ago
The next version of Chrome introduces a whole UI for this at chrome://certificate-manager.
92.
▲
by
dadrian
2y ago
Multi-perspective issuance corroboration is required starting in March of 2025 for CAs following the CAB/F Baseline Requirements https://cabforum.org/working-groups/server/baseline-requirem...
93.
▲
by
dadrian
2y ago
Raise rates.
94.
▲
by
dadrian
2y ago
I'll admit hostile was perhaps too harsh, however looking back to the late 2010s, it seems clear that the attitude was: - C ABI is good enough for any compatibility - "Rewrite it Rust" / RESF - Prioritize language propos
95.
▲
by
dadrian
2y ago
This is the exact attitude I am referring to. Also, Rust already uses LLVM.
96.
▲
by
dadrian
2y ago
Rust had to be dragged kicking and screaming into integration with other languages, and its C++ compatibility is a joke compared to Swift. It's absolutely true that you need integration and compatibility to enable iterative improvement
97.
▲
by
dadrian
2y ago
Nah, it's like how the existence of Star Trek influences future development of technology. Did Mickens call it, or did the Mossad get the idea from Mickens?
98.
▲
by
dadrian
2y ago
Of course D&D is not an accurate picture of the medieval era. There's magic in D&D! There was not magic in the medieval era. What are we even doing here?
99.
▲
by
dadrian
2y ago
It's unclear that NSO group is interested in gaining access to iCloud accounts or Photos, nor is it clear that this entrypoint is something that would meet the bar or be useful for signals intelligence, since it requires sending a cale
100.
▲
A new path for Kyber on the web
(security.googleblog.com)
2 points
by
dadrian
2y ago
|
0 comments
101.
▲
by
dadrian
2y ago
I agree that simpler is better than more complex, but you're not saying what is wrong with the current approach. I gather you're upset about certificates (who isn't annoyed with X509?), but ultimately all you're saying i
102.
▲
by
dadrian
2y ago
I'm confused as to why you think you can replace all the things in TLS that provide security with some sort of magical SecureConn function. TLS is the secure connection, so much so that your code example is exactly what happens in Gola
103.
▲
by
dadrian
2y ago
What do you think secure by default means?
104.
▲
by
dadrian
2y ago
Do not attempt to compete with SCWpod.
105.
▲
by
dadrian
2y ago
DJB and Tanya operate as a unit. Saying Lange agrees with DJB is like citing Clark as support of Lewis.
106.
▲
by
dadrian
2y ago
Of the SCW hosts, I'm actually the NSA plant. You got me.
107.
▲
by
dadrian
2y ago
And if there's one thing the cryptocurrency brand of cryptographers can do, it's come up with new ways to take out loans!
108.
▲
by
dadrian
2y ago
Hybrid kyber is actually enabled by default in Chrome on desktop, you don't need to go to chrome://flags to enable it.
109.
▲
by
dadrian
2y ago
They're not mutually authenticating, they're origin-bound (making them non-forwardable on the remote side) and channel-bound (meaning the authenticating action is guaranteed to be for the same device as the user action). However,
110.
▲
by
dadrian
2y ago
They are harder to implement than ECC.
111.
▲
by
dadrian
2y ago
It's not clear to me that this is something that should be genericized, nor that providing a generic HPKE to IETF WGs and then tweaking it as needed is any less work than just composing the correct primitives for each WG use case. As i
112.
▲
by
dadrian
2y ago
Bottom of https://tldr.fail
113.
▲
by
dadrian
2y ago
I don't see TLS adopting anything other than the current hybrid or a pure Kyber, but Bas would know better than me. Signatures are very difficult to do hybrid in a way that's not strippable. I think lattices are in the realm of bo
114.
▲
by
dadrian
2y ago
Unlikely that signatures will ever be hybrid. Fairly likely we move off of hybrid for key exchange once NIST finishes standardization.
115.
▲
by
dadrian
2y ago
It's a joke, because it's about migrating off of pre-quantum asymmetric cryptography.
116.
▲
by
dadrian
2y ago
> I don’t know why OP brought in MTU and packet sizes since that doesn’t really apply here. It does apply. TCP exposes streams as the API, but the underlying data is still sliced into packets of size up to the MTU.
117.
▲
by
dadrian
2y ago
There's a difference between FIPS approved algorithms, which are actually pretty broad and well-selected these days, and FIPS validated implementations, which are at best a PITA and often actively harmful. Very rarely do you actually n
118.
▲
by
dadrian
2y ago
LDAP is a UofM innovation. Tim Howes, a Peter Honeyman student, wrote his dissertation about it, and then went on to found Loudcloud with Ben Horowitz.
119.
▲
by
dadrian
2y ago
UofM popularized the use of Kerberos in academic settings. IIRC, Dug Song added support for Kerberos to SSH, and some other people in Honeyman's group (CITI) connected Kerberos to Andrew File System (AFS). But we'd have to ask hon
120.
▲
by
dadrian
2y ago
Massive failure by Silicon Valley to have given us Juicero, but failed to have invented the battlecow.
More ›