Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dakami
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
dakami
11y ago
You're right. HMAC keys, from the internal hash perspective, are always one block long. So if the key coming into HMAC is less than blocksize, it's zero padded to blocksize. And if the key coming into HMAC is length greater tha
32.
▲
by
dakami
11y ago
You're right. I'm specifically referring to his attacks. I'm curious if you can find any references to the key expansion / hashing collision before Solar Designer started talking about it a little while ago. If they
33.
▲
by
dakami
11y ago
Yeah, a message less than blocksize bytes is padded with 0's, and a message greater than blocksize bytes is hashed to blocksize bytes. It "follows" just as much as Little MAC, is about as security relevant, and is no less cl
34.
▲
by
dakami
11y ago
It's novel in that I wasn't able to find anyone else who had posted a colliding HMAC pair, and the couple papers people have found have sniffed around but hadn't quite gotten to the point of "Oh, yeah, compensate for ipa
35.
▲
by
dakami
12y ago
Heh, I'm one of the authors of the report. You can pick it up at http://whiteops.com/botfraud .
36.
▲
by
dakami
13y ago
Also it's an opinion piece because I don't work for Wired.
37.
▲
by
dakami
13y ago
Duct tape and bailing wire, all the way down.
38.
▲
by
dakami
13y ago
What's the global supply differential of Gold to Iridium?
39.
▲
by
dakami
13y ago
If you have a technology (Money) and it doesn't work, it's buggy. You've never had your credit card declined?
40.
▲
by
dakami
13y ago
(Author here) It disappears in Iraq. What, you think they're gonna burn it for warmth? Those bucks are coming back.
41.
▲
by
dakami
13y ago
Eponysterical.
42.
▲
by
dakami
16y ago
Oh, hi Tom :) Was WONDERING why you were so quiet.
43.
▲
by
dakami
16y ago
Neither DNSSEC or DNSCurve are interesting if they're securing just IP addresses. So we both need code on the client, to link into certificate validation stacks and the like. The difference is, when DNSSEC has code on the client, it can st
44.
▲
by
dakami
16y ago
Er, DJB and I are both presuming endpoints will validate -- we're both end-to-end security people. And that's fine, it ain't 1983 anymore, and a device that can handle TLS can handle both DNSCurve and DNSSEC (remember, the crypto construct
45.
▲
by
dakami
16y ago
Man, it's 2011, not 1983. If a device can run TLS, it can run DNSSEC.
46.
▲
by
dakami
16y ago
For the record, I thoroughly doubt I was the first person to find that poisoning bug. I sure as hell wanted to be the last one. (I'm much prouder of getting DJB's fix in, than I am of finding the bug in the first place. The former took two
47.
▲
by
dakami
16y ago
If you'll notice, that's glue for ns0, ns1, and ns2. This information from the parent is just there to say "here's where to go to resolve information from the child". It's not the actual IP addresses for all the child data, like www.wikime
48.
▲
by
dakami
16y ago
Phreebird isn't production code. I've been telling people to use it for internal testing only -- and I've even got that into various articles. What it does do is show what DNSSEC is capable of -- it's a way to separate fundamental limitati
49.
▲
by
dakami
16y ago
Is this a really bad problem?
50.
▲
by
dakami
16y ago
Agreed completely that the form factor doesn't work for everything. The hope is that I can knock out a few annoying buggy cases for you.
51.
▲
by
dakami
16y ago
http://en.wikipedia.org/wiki/Jesse_Gelsinger
52.
▲
by
dakami
16y ago
Gene therapy makes me nervous every since it killed that random kid. Looks like there's some checksumming going on?
53.
▲
by
dakami
16y ago
Actually, I'm exposing all the internal settings, precisely because color blindness is more of a spectrum disorder than something you either have or don't have. It's fairly rare to find someone who the second image doesn't massively help, s