Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dkatsura
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
Ask HN: Would you trust encryption at the mobile keyboard layer?
3 points
by
dkatsura
3mo ago
|
2 comments
2.
▲
by
dkatsura
7mo ago
Maker here. If you think this is security theater, please don’t be polite — pick one and attack it: 1. “policy travels with ciphertext” — why is that a bad idea vs external workflow? 2. geo/time gating — useless gimmick or actually val
3.
▲
by
dkatsura
7mo ago
Maker here — adding a concrete detail to make critique easier. Capsule = one file: header (version, KDF/AEAD ids) + encrypted payload chunks + policy tree (AND/OR over time/geo/password/visual). Password path uses A
4.
▲
by
dkatsura
7mo ago
Maker here. Quick challenge for the skeptics: Assume the capsule file leaks (someone forwards/copies it). In your view, does embedding the access policy (time/geo/password/visual key) into the same artifact as the cipher
5.
▲
Show HN: TrueLock – secure messages as encrypted files with unlock rules
(truelock.pro)
3 points
by
dkatsura
7mo ago
|
3 comments
6.
▲
by
dkatsura
7mo ago
Design question: for Windows geo I chose a phone relay (QR challenge/proof) instead of trusting desktop location APIs. Is that the right tradeoff in your view, or would you prefer a different approach?
7.
▲
by
dkatsura
7mo ago
As promised, here’s a minimal sketch. *Capsule format (high-level)* * magic + version * crypto suite id (AEAD) * KDF id + parameters (for password path) * salt / nonces * policy section (time/geo/password/visual, AND
8.
▲
by
dkatsura
7mo ago
If useful, I can post a minimal capsule format sketch (header + policy fields) and a compact threat-model table (what it protects vs. what it does not).
9.
▲
by
dkatsura
7mo ago
Maker here. I’m especially interested in criticism of the threat model. If you try it, I’d love feedback on: which rule is actually useful in practice (time/geo/visual key) what is confusing in setup what would increase trust fast
10.
▲
TrueLock – encrypted capsules with built-in unlock rules
(truelock.pro)
1 points
by
dkatsura
7mo ago
|
5 comments
11.
▲
by
dkatsura
7mo ago
I built TrueLock to share content that opens only under rules, without cloud dependency or a central service. A capsule is one .cfcaps file containing encrypted payload + an embedded unlock policy. The recipient gets one file, and the app c