Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gcommer
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
121.
▲
by
gcommer
12y ago
Just a reminder that BTSync is closed source and the protocol it uses has not been released. Better FOSS versions exist - the best one that I know of (and which I currently use) is http://syncthing.net/
122.
▲
by
gcommer
12y ago
I agree that HMAC is the better option, but I don't see any reasonable scenario where length-extension is actually relevant for this application. Also, I think that truncating actually improves security: An attacker who knows n (door_i
123.
▲
by
gcommer
12y ago
Yeah, they did. But you can get it back with Classic Theme Restorer[1], which has the "Small buttons on navigation toolbar" option. [1] https://addons.mozilla.org/en-US/firefox/addon/classicthemer...
124.
▲
by
gcommer
12y ago
If you want to shrink the top chrome, you can right click on it (getting the menu to choose toolbars), hit customize, then check "Use small icons". With this option, FF is thinner than chrome both fullscreen and floating. Edit: Ac
125.
▲
by
gcommer
13y ago
From the article: > On the other hand AD744 has higher noise (3x) and higher offset voltage (0.5mV vs 0.1mV).
126.
▲
by
gcommer
13y ago
Why not distribute that as the code in the repo instead of the compressed version?
127.
▲
by
gcommer
13y ago
I don't know if clef does this, but for SQRL (similar, but uses QR codes, is open source, and doesn't rely on a 3rd party), it relies on the fact that the website URL will be embedded in the QR code (along with a signature) and th
128.
▲
by
gcommer
13y ago
Actually, it is just the opposite. According to wikipedia, SRP was carefully designed to avoid any current patents, and according to this stanford page[1], it is available commercially and non-commercially under a royalty-free license, alon
129.
▲
by
gcommer
13y ago
The image that you're supposed to scan will also be a link with some custom procol (like clef://...), which then gets handled by the Clef app.
130.
▲
by
gcommer
13y ago
I think that depends on the adversary. Against the NSA there might not be a major difference (depending on your email provider), but SMS is probably more secure in the typical case, as it is much more common for your run of the mill script
131.
▲
by
gcommer
13y ago
Actually, Clef was already developed and launched before SQRL was even announced. SQRL does, however, have many benefits over Clef, though the typical user interaction is similar.
132.
▲
by
gcommer
13y ago
The author of this quiz could have made this a great learning opportunity by linking to the appropriate sections in ECMA-262[0]. For example, question 15 makes a lot more sense when you read "ToBoolean" (Sec 9.2) which shows that
133.
▲
by
gcommer
13y ago
In those scenarios, client side crypto isn't even applicable to begin with. If the service requires trusting the server with sensitive information, then the best we can hope for is to secure the transport of the data, which is done wit
134.
▲
by
gcommer
13y ago
Even if we could reliably deliver open source crypto libs, the website could still serve up code that didn't use the libraries correctly.
135.
▲
by
gcommer
13y ago
The best open source alternative I've heard of so far is clearskies ( https://github.com/jewel/clearskies ). The implementation isn't complete yet, but it started right with a clear, open protocol definition ba
136.
▲
by
gcommer
13y ago
The point anon1385 is trying to make about JavaScript clients is that they can be changed at any time by the web service provider, where as open source clients can be 'verified' once by the open source community and then can'
137.
▲
by
gcommer
13y ago
Assuming that the web service is doing proper client side authentication most of the time (which, with enough effort, can be verified), and then gets coerced into sending compromised JS at some point in the future - we still have better sec
138.
▲
by
gcommer
13y ago
You may be interested in the defensive js ( http://www.defensivejs.com/ ) project which seeks to securely isolate JavaScript code from maliscous javascript being injected on the page. It also provides a verified crpyto librar
139.
▲
by
gcommer
13y ago
Philosophically I may agree, but in this case "perfect secrecy" is a mathematically defined term with a specific definition. Basically, it is mathematically impossible for any encryption scheme to ever provide better data secrecy
140.
▲
by
gcommer
13y ago
Are you familiar with the one time pad (OTP)? http://en.wikipedia.org/wiki/One-time_pad As long as the key is securely shared between the two parties, this scheme provides perfect secrecy, and the proof of this is triv