Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
irungentoo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
irungentoo
11y ago
Your link doesn't work. http://dl.ifip.org/db/conf/aims/aims2009/BocekPHHS09.pdf seems to be the correct link.
2.
▲
Toxcore Development Fundraiser
(indiegogo.com)
2 points
by
irungentoo
11y ago
|
0 comments
3.
▲
by
irungentoo
11y ago
Just build it with asan and you will get all the safety, memory usage and slowness of a memory safe language.
4.
▲
by
irungentoo
11y ago
I made sure to make the packets in Tox as easy to parse as possible which greatly lowers the chances of fatal packet parsing bugs being present. As for the main tool I use to find bugs, it's asan (the clang address sanitizer) which is
5.
▲
uTox – Free, Secure Instant Messaging
(utox.org)
56 points
by
irungentoo
11y ago
|
61 comments
6.
▲
Introducing Toxcoin: The future of distributed applications
(blog.tox.im)
2 points
by
irungentoo
12y ago
|
0 comments
7.
▲
by
irungentoo
12y ago
>Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and stqism) were dealing with money in a shady way and he got suspiciou
8.
▲
by
irungentoo
12y ago
First of all the choice of C is because it was the language I was the most confidant writing secure code in. I'm not going to learn a new language and then right away start try to write secure code with it. Clang has some great tools I
9.
▲
by
irungentoo
12y ago
If you actually read the code you will see that it's true. The parsing is dead simple and written in a way that mistakes are very unlikely.
10.
▲
by
irungentoo
12y ago
You are just some troll trying to kill our project with fabrications and lies. You twist the truth to fit your own agenda. The guy in question tried to damage the project on his way out so yes I grepped our server logs for his ips because I
11.
▲
by
irungentoo
12y ago
endianess doesn't matter when you all you do with it is store it and check if it's equal to another. In all cases where it does matter, the values are converted. Tox has been confirmed working on big endian machines by many people
12.
▲
by
irungentoo
12y ago
Our threat model is an attacker that wants to read and record the contents of conversations between everyone, they have the ability to modify/add/remove and log any packets. We assume they do not have any access to the actual mach
13.
▲
by
irungentoo
12y ago
Tox is distributed meaning there are no central servers. Also, encryption is mandatory.
14.
▲
by
irungentoo
12y ago
The majority of NATs can be hole punched. If you can't hole punch then you will connect to your friend through a couple TCP nodes. They act like relays. TCP nodes are pretty much randomly selected by peers and anyone can host them. Eve
15.
▲
by
irungentoo
12y ago
No. They have to be friends with you.
16.
▲
by
irungentoo
12y ago
Direct connection when possible. Connection routed over one TCP node when direct connections are impossible due to NAT issues.
17.
▲
by
irungentoo
12y ago
Instead of doing things like encrypting ips, peers have temporary DHT public keys. The only way to get the ip of someone from their Tox id is by knowing their public DHT key which they will only send you if they are your friend. How this wo
18.
▲
by
irungentoo
12y ago
Every peer is identified by a curve25519 public key. To add someone as a friend, you add that public key. Connections between friends are encrypted. http://nacl.cr.yp.to/box.html is the crypto used. https://githu
19.
▲
by
irungentoo
12y ago
Fixed. Thank you.
20.
▲
by
irungentoo
12y ago
Tox is distributed meaning it doesn't rely on any central servers.
21.
▲
Tox: A simple, distributed, free, secure Skype replacement. Now alpha with A/V
345 points
by
irungentoo
12y ago
|
139 comments
22.
▲
by
irungentoo
13y ago
> Nonce's are "Numbers used ONCE", they 1) don't need to be secret and 2) ARE NOT encryption keys. We know. Putting the nonces in the handshake along with the session public key was simple. In the NaCl docs it is advi
23.
▲
by
irungentoo
13y ago
>Lossless UDP? Is there a reason not to do TCP? Hole punching. >There is no way to know if the public key is genuine, so the system is very sensitive to MITM. If you want to add someone you need their public key (their id) which is 32
24.
▲
by
irungentoo
13y ago
Since you managed to kill the website: https://github.com/irungentoo/ProjectTox-Core Tox is a completely decentralized secure messaging service which aims to replace skype. It it still in heavy development. So far we h