Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
galadran
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
galadran
7y ago
The latter. The tools in question (Tamarin and ProVerif) use a model of signatures that goes back to 2000/2001 which is around when these key substitution properties were discovered. Consequently, they were missed from the models and b
32.
▲
by
galadran
7y ago
It depends what you consider to be non-repudiation! With key substitution, you have a signature that can verify under multiple public keys. However, each key was either honestly generated and used to sign the message, or was maliciously gen
33.
▲
by
galadran
7y ago
We discuss this exact attack (and blog post) in Section 5.1 of the paper :). IIRC: it was missed by both an academic analysis of LE and a 3rd party audit of their crypto design. Thankfully Andrew spotted it a few weeks before they went live
34.
▲
by
galadran
7y ago
"This scheme also provides nonrepudiation since it proves that Alice sent the message; if the hash value recovered by Bob using Alice's public key proves that the message has not been altered, then only Alice could have created th
35.
▲
by
galadran
7y ago
> What remains open for future work is checking for cross-protocol attacks. [...] I can't see such an attack, but if you can, let me know on Twitter. So we know using the same key for signing and encryption is catastrophic for gener
36.
▲
by
galadran
7y ago
Interesting! Google's Project Zero team investigated WhatsApp's and Facetime's video conferencing last year: "Overall, WhatsApp signalling seemed like a promising attack surface, but we did not find any vulnerabilities i
37.
▲
by
galadran
7y ago
This would be illegal in the EU under the GDPR which would require positive consent from the individuals monitored (simply walking into a space would not be enough). However, individual countries are allowed to alter this aspect of the Regu
38.
▲
by
galadran
8y ago
It's very neat and well worked out, but in hindsight it seems kind of obvious. If the "judge" trusts an "uncorruptible" witness then deniability can't hold. Now if only Intel could actually build a secure TPM!
39.
▲
by
galadran
8y ago
tl;dr - QUIC doesn't have kernel or hardware support (yet). These aren't intrinsic problems with QUIC, they're common to all new protocols.
40.
▲
by
galadran
8y ago
I would highly recommend mailbox.org. Based in Germany, their offering is similar but cheaper than ProtonMail. They are much more flexible as well, and allow for better security. If you want to use the webmail client with javscript PGP (a l
41.
▲
by
galadran
8y ago
> Actually, the boxes can also MitM the entire SSL connection. This just happens to be a much more efficient system. It can easily be turned off without affecting the connection, and it doesn't introduce extra latency. Moreover, thi
42.
▲
by
galadran
8y ago
Sorry if my point wasn't clear. I do mean that there should be DPI software running somewhere external, the point is just that you don't need dedicated hardware to do it. I completely agree doing everything on the endpoint isn
43.
▲
by
galadran
8y ago
The real story here is not about security, it's about markets and profit (as always). Currently, there's a huge market in DPI boxes for inspecting TLS traffic, which are often poorly implemented, tied to expensive support contract
44.
▲
by
galadran
8y ago
NewsGuard gives a red mark for Wikileaks, but a green tick for Fox News. I think we're done here. https://twitter.com/wikileaks/status/1084876278065446913 On NewsGuard's advisory board, 5 of the 7 slots
45.
▲
by
galadran
8y ago
It most definitely isn't. https://en.wikipedia.org/wiki/Nuclear_force
46.
▲
by
galadran
8y ago
Paper: https://arxiv.org/pdf/1712.07962.pdf Not a physicist, but my summary of the author's point would be: If you allow for matter with a negative mass and plug it into a n-body simulation. You seem to get what
47.
▲
by
galadran
8y ago
> The point is, to combine even less powerful elements of each into a package with the functionality Bloomberg describes, it would require amazingly small lithography techniques. I have yet to find someone able to say that adding process
48.
▲
by
galadran
8y ago
> The illicit chips could do all this because they were connected to the baseboard management controller, a kind of superchip that administrators use to remotely log in to problematic servers, giving them access to the most sensitive cod
49.
▲
by
galadran
8y ago
> The crux of your argument seems to be "it is more valuable to be able to point an IOT device at the wrong IP than it is to get UXSS on a machine on that network". That seems obviously wrong to me for any user, technical or no
50.
▲
by
galadran
8y ago
I absolutely agree with you about users already running dnsmasq, but the context here is a malicious developer abusing their position. The actual quality of the software is orthogonal. I still think you are understating the risk of a malici
51.
▲
by
galadran
8y ago
You, and the other commentator, are forgetting that the DNS Server handles all connections, not just those from your browser. Are you confident all the self updating software you use has no vulnerabilities? How about the video games that yo
52.
▲
by
galadran
8y ago
> Do you use a popular browser extension? How confident are you that the creator wouldn’t accept a $10k offer to hand it over only to have it then go rogue on you? What makes the Pi-Hole organization any more trustworthy? (and the softwa
53.
▲
by
galadran
8y ago
This project has so many cryptographic wrong answers, I don't know where to begin. Glaring problems: - The same unchanging aes key is shared between all nodes on a network. Compromise one, compromise all. Additionally a bad node ca
54.
▲
by
galadran
8y ago
Wow! I've seen artists who hand draw in Tolkien's style ( https://www.middleearthsmaps.com/ ) but I never would have thought it could be done so well automatically!
55.
▲
by
galadran
8y ago
I guess we know why Intel tried on that benchmarking restriction. Serving static content from Nginx is a 22% drop on Intel, a 7% drop on AMD. That's huge for cloud providers!
56.
▲
by
galadran
8y ago
That does look a lot better, however: a) its not supported by the stable release b) There are no claims about downgrade resistance. The manual specifies the new transport protocol is used if both clients support it and both have changed the
57.
▲
by
galadran
8y ago
tinc is not a secure choice! Have you seen their documentation? https://www.tinc-vpn.org/documentation/Security.html#Securit... The default cipher is from 1993 and its creator recommends everyone updates. 32 bit MACs a
58.
▲
by
galadran
8y ago
I think you've misunderstood. This setup is not insecure. Wireguard authenticates (or drops) any packets forwarded by udptunnel. Once a packet leaves the Wireguard interface the attacker (or anyone else) can transform it however they l
59.
▲
by
galadran
8y ago
Oh man! If only there was a way to take UDP packets and tunnel them over TCP! Wait a second! http://manpages.ubuntu.com/manpages/xenial/man1/udptunnel.1.... Setup Wireguard on your server as though everything
60.
▲
by
galadran
8y ago
I have a 4TB Hard Drive attached to an OpenWRT router (Rasberry Pi's are also a popular choice). The router exposes a locked down SSH port (SFTP only) through a cheap $5 a month VPS. I also use Jottacloud [1] who provide unlimited (yes
More ›