Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hxtk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
hxtk
1y ago
In general, this theoretical problem is called the Kolmogorov Complexity of a string: the size of the smallest program that outputs a the input string, for some definition of "program", e.g., an initial input tape for a given univ
92.
▲
by
hxtk
1y ago
It sounds like you have constructed a way to encrypt data such that it can only be decrypted by someone who has the same (secret) key and (non-secret) associated data that was used to encrypt it, or else decryption fails. As you said, same
93.
▲
by
hxtk
1y ago
It sounds like the source of confusion is in terminology. I would consider AES-CBC+HMAC to be an AEAD construction, and I would consider whatever "secret key" you pass into HMAC along with the ciphertext to be the "associated
94.
▲
by
hxtk
1y ago
It sounds like you are assuming that if the data were modified, decryption would fail catastrophically and you'd end up with garbage. This is precisely the point of AEAD: providing cryptographic guarantee that decryption will fail cata
95.
▲
by
hxtk
1y ago
A usual example I use (because it reflects how I tend to use AEAD in applications) is to assume the server (and only the server) has the keys for something like data-at-rest encryption. Application level logic decides whether the server is
96.
▲
by
hxtk
1y ago
Yes, in fact, one construction of the AEAD primitive is to use AES-CTR with HMAC to "bolt on" authentication after the fact (AES-CTR on its own is an unauthenticated stream cipher). You can find an implementation of AES-CTR-HMAC (
97.
▲
by
hxtk
1y ago
Suppose you have a server with its own encryption key, and a key-value database full of encrypted data (secured by this root keyset) associated with a user. Even if I gain access to the database, if the keys are managed securely, I can'
98.
▲
by
hxtk
1y ago
A lot of the hardest problems in practical cryptography come down less to the abstractions around literally encrypting and decrypting things and more around the secure management of key material to ensure that the application supports thing
99.
▲
by
hxtk
4y ago
I've had great experience with migrating C/C++ projects at work to use Bazel, at least in the sense that a couple of hours' work yields me a fast, correct, reproducible build and has usually sped up incremental build times by
100.
▲
by
hxtk
4y ago
I do web backend stuff. A coworker of mine writes Go according to MISRA C style and this is the main thing that's always annoyed me: it seems like half the codebase is comments justifying deviations, like explicitly commenting when we
101.
▲
by
hxtk
4y ago
Others have mentioned statically linked binaries. I thought I'd mention I actually use Bazel to build most of my docker images, and unlike Docker itself, Bazel rules_docker builds reproducible (i.e., same digest) container images by de
102.
▲
by
hxtk
4y ago
I can't comment on Nix, but I work on a project that uses recursive Makefiles and build containers to make the builds (almost) hermetic. I dread running builds because it takes like ten minutes to run `make all`. I spent like four hour
103.
▲
by
hxtk
4y ago
It seems as though a lot of people view it as hypocritical, e.g., generics for me but not for thee (dated example since there are now generics for everyone). The fact that they needed to make a map a part of the language in order to allow i
104.
▲
by
hxtk
4y ago
It ceased to exist. Redhat stopped supporting the version that was equivalent to RHEL8 and kept CentOS stream for developers targeting RHEL 8 to use. This came with some changes to open up the developer license program for RHEL so that it c
105.
▲
by
hxtk
4y ago
Not defined as part of the standard, but before compilers got as smart about their optimizations, it was easier to have behavior that was technically undefined but could be reasoned about in practice. Now that compilers know cleverer optimi
106.
▲
by
hxtk
4y ago
Ah, I see, it sounds like you're talking about how you'd implement that in other languages that don't have a solution as a trivial property of the type system. I'd missed that before.
107.
▲
by
hxtk
4y ago
> However you would also probably want a language with some syntactic sugar that let users use your special string type easily otherwise the burden on users will be too high In the instance under discussion in that section of the book I&
108.
▲
by
hxtk
4y ago
The book "Building Secure and Reliable Systems" from Google's series on SRE actually talks about two examples of this in C++ and Go which forbid using anything but string literals in the query string of an SQL API. In Go, the
109.
▲
by
hxtk
4y ago
First of all, I think it'd probably help to link the publication I'm using as my primary source [1]. The certificate is indeed stored in a TPM: > Desktops and laptops use an X.509 machine certificate and a corresponding private
110.
▲
by
hxtk
4y ago
The way that Google handles it, at least based on their publications about BeyondCorp is that endpoints are authenticated cryptographically by TLS certificates backed by their TPM chips. When someone tries to connect to a service, instead o
111.
▲
by
hxtk
4y ago
I've certainly seen "most" used to mean "almost all", and it appears as though you're feeling a little annoyed to see it used that way because you consider it misleading. I've also frequently seen "mo
112.
▲
by
hxtk
4y ago
It's part of the `arg` macro.
113.
▲
by
hxtk
5y ago
I haven't heard anything about not using enough rounds, so it's possible that my information is just out of date. My understanding is that AES-128 was chosen to be resistant against classical attacks, and AES-256 was chosen to ach
114.
▲
by
hxtk
5y ago
At the time that you made your comment, I think it had the potential to be accurate for a lot more people because at that time my understanding is that the outage was ongoing. With the incident now resolved, I have the benefit of hindsight
115.
▲
by
hxtk
5y ago
> “it’s a lot of work” should never be a reason for not securing an system. It is, though. Software bugs are almost entirely optional: we could just formally verify every piece of software with a mathematical proof. Computer software wou
116.
▲
by
hxtk
5y ago
Netfilter (the kernel backend for the deprecated {ip,arp,ip6,eb}tables and the newer nftables) supports allow/deny by ipsets, and you can configure some DNS resolvers such as dnsmasq to populate an ipset from a DNS name. This has a few
117.
▲
by
hxtk
5y ago
I'm not under the impression that GP means to suggest you personally have any obligation to donate time to OSS by virtue of being an employee at a large company. Something I believe we agree on is that it is in the interest of large te
118.
▲
by
hxtk
5y ago
> I feel like there's always something odd about some of these taught communication techniques, where I feel like there's a reason these communication styles don't come naturally to us, and there is a bit of a manipulative
119.
▲
by
hxtk
5y ago
Another useful feature is some part of my environment (I've used it in Gnome 3 on both Fedora and Arch, but it doesn't work in RHEL; I'm honestly not sure what part of my stack is providing the feature) lets me pres Ctrl+Shif
120.
▲
by
hxtk
5y ago
Your choices are already being shaped in that way. That's why, for example, modern residential roads are designed with shorter sight distances, narrower lanes, speed bumps/humps, and more roadside shrubbery compared to their count
More ›