Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
e79
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
e79
6y ago
[removed]
32.
▲
by
e79
6y ago
SSSS is Shamir’s Secret Sharing Scheme. Sort of. Different apps may use different finite fields. The math should be the same as long as you’re computing everything modulo the same integer. It is also possible that some apps may encode share
33.
▲
by
e79
6y ago
While SSSS provides information theoretic security, there are a couple of security gotchas. One example is that it leaks the length of a secret unless padding is used. In practice this isn’t usually an issue, since many applications (like t
34.
▲
by
e79
6y ago
Priority access services like 911 are handled very differently. For example, I can’t place any normal outbound calls with my T-Mobile sim, but calling 311 in NYC works fine.
35.
▲
by
e79
6y ago
On the other hand, fuzzing is only as “correct” as your coverage, properties/assertions, corpus synthesis, etc.
36.
▲
by
e79
6y ago
It doesn’t surprise me at all that bugs were found in SMT Checker. I recently wrote a blog post on how Solidity’s model checker works, and stumbled across several bugs while attempting to write simple example contracts. I didn’t even need a
37.
▲
Exploring the formal verification built into the Solidity compiler
(aon.com)
9 points
by
e79
6y ago
|
0 comments
38.
▲
Software Foundations
(softwarefoundations.cis.upenn.edu)
3 points
by
e79
6y ago
|
0 comments
39.
▲
by
e79
6y ago
This dismisses theorem proving as too difficult to use for existing systems. My experience with old, complex systems is that they’re often old, complex and not very well understood anymore. Theorem proving is all about producing a specifi
40.
▲
by
e79
6y ago
Out of curiosity, are there known pros and cons to each approach? I’ve been experimenting with Z3’s CHC engine and Coq for modeling programs. I don’t know enough about both yet to fully understand how they compare.
41.
▲
Shamir’s Secret Sharing Scheme
(ericrafaloff.com)
14 points
by
e79
8y ago
|
0 comments
42.
▲
by
e79
9y ago
I'm not so sure about that. Comparing the vulnerable source code to the original (which you can find here https://github.com/ethereum/dapp-bin/blob/master/wallet/wall... ) tells a totally differ
43.
▲
by
e79
9y ago
Great article. I recently wrote a tool to help find bugs like this: https://ericrafaloff.com/introducing-the-solidity-function-p...
44.
▲
by
e79
9y ago
Manual code review would have likely helped. A tool like this maybe? https://ericrafaloff.com/introducing-the-solidity-function-p...
45.
▲
Introducing the Solidity Function Profiler
(ericrafaloff.com)
1 points
by
e79
9y ago
|
0 comments
46.
▲
by
e79
9y ago
The vulnerability was extremely simple, as suggested by the three keyword-long patch. I've written about this and other Solidity/EVM bugs from a technical perspective, if anybody is curious: - https://ericrafaloff.com&#
47.
▲
by
e79
9y ago
Yes, although my understanding is that the transition will be gradual. PoW rewards will gradually decrease while PoS rewards gradually increase, facilitating the tranisitioon without all miners jumping ship. Miners who are invested in Ether
48.
▲
by
e79
9y ago
One thing that emojis cannot convey is unconscious body language. There are many subtle communications that can bear influence in empathy, love, trust (or distrust-- i.e. catching someone in a lie). Unconscious body language isn't req
49.
▲
by
e79
9y ago
It has already surpassed $10,000. What started off as a joke very well could make the creator hundreds of thousands of dollars. Don't believe me? These tokens are now trading publicly on exchanges. They're no longer useless, as yo
50.
▲
by
e79
9y ago
I suspect that in reality, this would be far more complicated than your comment gives credit for. How do you determine what coins have been through a mixer? By looking at tx inputs and going back all the way to when those coins were mined i
51.
▲
by
e79
9y ago
Writes to boot sector? Care to elaborate? Sources?
52.
▲
Analyzing the ERC20 Short Address Attack
(ericrafaloff.com)
4 points
by
e79
9y ago
|
0 comments
53.
▲
Running Your Own Private Ethereum Network
(ericrafaloff.com)
4 points
by
e79
9y ago
|
0 comments
54.
▲
by
e79
9y ago
Does each session run in an isolated container? Because I wonder, what's stopping an attacker from exhausting system resources, messing with other users stuff, etc.?
55.
▲
by
e79
9y ago
[Removed rant in which I was trying to explain my frustration about investors having ill effects on the usability of such protocols by driving up associated fees. Unless you can mine coins, you are stuck dealing with a volatile market as an
56.
▲
by
e79
9y ago
You should also make sure providers like Google don't fall back to less secure account recovery methods. I blogged about this here, after I realized that I was still vulnerable even while using real 2FA: https://ericrafaloff
57.
▲
by
e79
9y ago
Looking at this more closely, this takes arbitrary buffers of data and uses syscalls such as mlock to prevent paging memory to disk, as well as cleans up at the end by zero'ing out the buffers for you. Has this been audited in any way?
58.
▲
by
e79
9y ago
The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer.
59.
▲
XSS via DOM-Based Open Redirect
(ericrafaloff.com)
2 points
by
e79
10y ago
|
0 comments
60.
▲
The Power of Go Generators
(ericrafaloff.com)
1 points
by
e79
11y ago
|
0 comments
More ›