Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jlund
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
jlund
12y ago
The server side is currently relaying messages for the in-progress iOS and Chromium clients. That's functionality that exists today, even though the clients are still under development. The TextSecure server is an elegant and important
62.
▲
by
jlund
12y ago
Full disclosure: I wrote that Support Center article. The comment I was replying to made it sound as though TextSecure's infrastructure is almost entirely Google-based. It is not, and that's what I meant when I said "This isn
63.
▲
by
jlund
12y ago
This isn't entirely true. A detailed explanation is available in the Open WhisperSystems Support Center [1] and several solutions are in the works. Google's GCM push messaging framework is used only for message delivery; the TextS
64.
▲
by
jlund
12y ago
There were some capacity issues when the new version of TextSecure was first released. The SMS code is used to verify ownership of a number before it can be used for Push messaging.
65.
▲
by
jlund
12y ago
This is already in progress [1]. [1] https://github.com/TheBlueMatt/textsecure-chrome
66.
▲
by
jlund
12y ago
An iOS version is in progress and should be released in the next few months [1]. The TextSecure servers are not hosted in Google's data centers. Google's GCM push messaging framework is used to deliver messages to Android users,
67.
▲
by
jlund
12y ago
GCM payloads are fully encrypted. Google would be able to tell that you are a TextSecure user who is receiving a message, but they cannot tell who the message is coming from nor can they look at its contents (obviously).
68.
▲
by
jlund
13y ago
They actually claim to be using NaCl now.
69.
▲
by
jlund
13y ago
Every single US citizen is complicit? Man, I would hate to be this jaded. Some of us are fighting against mass surveillance as hard as we possibly can. This is as silly as saying that all of the people who live in North Korea are brutal dic
70.
▲
by
jlund
13y ago
You can read about the key exchange here. "Prekeys" are an extremely clever idea: https://whispersystems.org/blog/asynchronous-security/ Fingerprint verification protects against MITM attacks. The applic
71.
▲
by
jlund
13y ago
No, because you can still verify a user's fingerprint after the handshake has been completed. That's something that you'd want to do with traditional, non-asynchronous OTR as well.
72.
▲
Fighting DISHFIRE: The State of Mobile, Cross-Platform, Encrypted Messaging
(missingm.co)
2 points
by
jlund
13y ago
|
0 comments
73.
▲
Show HN: Docker. Chrome. PulseAudio.
(github.com)
2 points
by
jlund
13y ago
|
0 comments
74.
▲
by
jlund
13y ago
No. Verizon only allows pre-approved devices to appear on their network, regardless of whether you are prepaid or postpaid. They do this by checking the IMEI identifier of the device. If it's not one of theirs, it won't work. Thei
75.
▲
by
jlund
13y ago
Businesses use RSA VPN dongles, and the stories that are starting to surface now are more about economic espionage. "Follow the money" is a slippery slope.
76.
▲
by
jlund
13y ago
Wickr is closed source. TextSecure is where it's at. Hopefully the iOS release comes out soon.
77.
▲
by
jlund
13y ago
Valve is making their own distribution.
78.
▲
by
jlund
13y ago
Google Play Music All Access (great name!) requires Flash in order to play any music. Unlike Spotify, they do not have a native Linux client. If you abhor Flash for security and performance reasons, GPMAA is much worse on Linux than Spoti
79.
▲
by
jlund
13y ago
Recent Blackberry versions also have an Android compatibility layer.
80.
▲
by
jlund
13y ago
git-annex is explicitly designed to avoid putting file contents under version control because git doesn't handle large files (like videos) very well. It seems like this system is running headlong into that problem. I'm probably go
81.
▲
by
jlund
13y ago
This is apples and oranges because she doesn't allow her latest releases to appear on streaming services.
82.
▲
by
jlund
13y ago
The Debian OpenSSL bug was and is highly embarrassing, yes, but the fact that the source was open was absolutely instrumental in its discovery. It's also difficult to find a better example of the right way to react to such a bug.
83.
▲
by
jlund
13y ago
Cash is really easy to use and is accepted everywhere. There's no similarly elegant solution for mobile connectivity if you want to stop revealing metadata information.
84.
▲
by
jlund
13y ago
I hope that Mozilla and Ubuntu are more successful in keeping binary blobs under control on their hardware. It will probably mean avoiding Nvidia and Qualcomm hardware though. Whether or not this is even realistic or possible is an interest
85.
▲
by
jlund
13y ago
It sounds like they treat people the same way all of us treat EC2 instances.
86.
▲
Identical Droplets in the DigitalOcean: Regenerate your Ubuntu SSH Host Keys now
(missingm.co)
285 points
by
jlund
13y ago
|
106 comments
87.
▲
by
jlund
13y ago
That's better than nothing, I suppose, but unless the source is open it's still impossible to trust the proprietary binary.
88.
▲
by
jlund
13y ago
I think it's safe to say that the primary reason people complain about the lack of BT Sync source code is because it is currently difficult (if not nearly impossible) to audit its security.
89.
▲
by
jlund
13y ago
I recently wrote this: http://missingm.co/2013/06/ansible-and-salt-a-detailed-compa...
90.
▲
Do record labels get off on being withholding?
(missingm.co)
1 points
by
jlund
13y ago
|
0 comments
More ›