Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
floody-berry
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
floody-berry
11y ago
Why would something need to happen to me to point out exploitation? Uber and Airbnb make money off people breaking the law. They exploit hundreds of thousands of people wanting to make a little extra money so that they can make a lot. They
2.
▲
by
floody-berry
11y ago
Companies like Uber are much worse than that. They're a glorified web app profiting off of hundreds of thousands of people who do all the work and bear all the risk while the only people getting rich are the scum at the top and their r
3.
▲
by
floody-berry
11y ago
Yes, how does he go from DUAL_EC_DBRG being backdoored to using the same few elliptic curves being an issue? It's not accurate or productive to lump e.g. Curve25519 or Goldilocks448 in with DUAL_EC_DBRG and issues with 1024-bit DH prim
4.
▲
by
floody-berry
11y ago
Yeah, a made-up term that was ripped off from http://en.wikipedia.org/wiki/Zero-knowledge_proof because it sounded high-tech, yet has nothing to do with ZKP and merely means "you encrypt everything client-side and
5.
▲
by
floody-berry
11y ago
Would you want to ride in a car with failing brakes?
6.
▲
by
floody-berry
12y ago
Why would I want to read books about people that fall under your definition of 'success'? Do I have to read about and fetishize war profiteering too? Just follow the money, right? Jobs over Wozniak? Zuckerburg over Borlaug?
7.
▲
by
floody-berry
12y ago
> This isn't really the mentality and behavior of successful people Thinking you know what traits do and don't make someone 'successful', or that everyone shares your definition of 'success', is probably als
8.
▲
by
floody-berry
12y ago
You mean hotels would like to be glorified web directories with hundreds of thousands of 'employees' who provide the rooms, do all the work, are solely on the hook for the vast number of laws and regulations they're breaking,
9.
▲
by
floody-berry
12y ago
When Rijndael was chosen as AES, it was ~3 years old and was broken for 6-7 rounds out of 10 with 128 bit keys, and 7-8 rounds out of 14 with 256 bit keys. Chacha20 is 7 years old now and is broken for 7 rounds out of 20, with the attacks o
10.
▲
by
floody-berry
12y ago
> There are many people out there literally asking you to introduce your product to them so they can become your customers No, they aren't, but not a surprise that automated spam is a big hit on HN.
11.
▲
by
floody-berry
12y ago
yescrypt has ROM capabilities [1], which function like your large file idea. [1] https://password-hashing.net/wiki/doku.php/yescrypt#read-onl...
12.
▲
by
floody-berry
12y ago
You can choose to be black, jewish, or gay?
13.
▲
by
floody-berry
12y ago
Unless they did a study with various presentations and found this version resulted in higher numbers, I doubt they have any clue how much it 'helped', or if it helped at all short of just being _something_ to toss up with their re
14.
▲
by
floody-berry
12y ago
Remove selection bias or straight up marketing spam from authors and the willingness of many users to believe anything someone who claims they're making money says and HN would be a lot emptier. One can dream..
15.
▲
by
floody-berry
12y ago
Going off the comments here, "pretentious, over-priced twat" is quite real and worth being.
16.
▲
by
floody-berry
12y ago
Advocating table based implementations that are not secure is not taking it seriously. Providing implementations that are not secure is not taking it seriously. They may have taken it more seriously than had they designed it in 2001, but it
17.
▲
by
floody-berry
12y ago
Grøstl's round 3 specification document mentions 3 'strategies' for constant time implementations: AES-NI, vperm (AVX/XOP/NEON), or bitsliced (which they estimate "only a 50% overhead" for vs tables). Yet
18.
▲
by
floody-berry
12y ago
ChaCha also got a lot of review in the form of BLAKE, whose security margin was roughly consistent with the existing cryptanalysis of ChaCha. AES-128-CTR with AES-NI is ~0.8-1.2cpb on Haswell/Ivy Bridge/Bulldozer Chacha20 is ~1.1c
19.
▲
by
floody-berry
12y ago
Are there actually many alternatives at this time? SHA-3, and more recently CAESAR, still received submissions based on AES. Grøstl (one of the SHA-3 submissions borrowing from AES) was a top 5 candidate. Constant time, side-channel free al
20.
▲
by
floody-berry
12y ago
From his previous article on his "startup" / "business": > In my online game hacking history to that point, I'd had seven dupe methods patched across four different games, but never had an account closed. He
21.
▲
by
floody-berry
12y ago
e.g., in Diablo 2, duped items were known to "poof" or disappear if you were not careful. There is no way to tell if an item is legitimate or not, leading to the obvious situation of oblivious players buying or trading for a dupe
22.
▲
by
floody-berry
12y ago
Do you have an example of this happening?
23.
▲
by
floody-berry
12y ago
Er, do you think only a select few people need to know assembler then?
24.
▲
by
floody-berry
12y ago
(her)
25.
▲
by
floody-berry
12y ago
Adding an annotation for qhasm where stack variables/registers would be zero'd at the end of the function if they still contained sensitive data would be great. What I'd really like to see is qhasm put on github along with th
26.
▲
by
floody-berry
12y ago
Not ARM64, but "Tonc: Whirlwind Tour of ARM Assembly" [1] is what I'm repeatedly referring to while learning ARM. Pretty confusing coming from x86, but it's starting to make sense and my ARM is getting slightly less awfu
27.
▲
by
floody-berry
12y ago
Cryptographic doesn't mean slow. If you generate in to a large enough buffer (1-2kb is good), Chacha8 is anywhere from ~1.5 cycles/byte (SSSE-3, Wolfdale) to ~0.5 cycles/byte (AVX2, Haswell). Even unoptimized implementations
28.
▲
by
floody-berry
12y ago
Relying on as won't work with Visual Studio It's easier to update an external assembler than the system assembler. A lot of distros don't ship with updated binutils so you can't reliably compile for newer CPU extensions
29.
▲
by
floody-berry
12y ago
NASM or Yasm are both good. NASM has really powerful macro support, and Yasm is a NASM clone/rewrite. Yasm additionally supports GAS syntax (if you're in to that), although its documentation for non-NASM features is a bit lacking.
30.
▲
by
floody-berry
12y ago
You might have a point if they were treated in America http://www.cbsnews.com/news/how-soon-can-a-vaccine-or-treatm... > Last week, several vials of an experimental drug serum called ZMAPP were transported to Liberi
More ›