Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kkl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
kkl
10y ago
As far as I know almost all browser security warnings are overridable. The only one that comes to mind that does not have a click-through option is when a HSTS-enabled site fails a validation check.
32.
▲
by
kkl
10y ago
I do not think your analogy applies here. Finding 8 critical-risk bugs in a project from an audit is bad news. It is highly suggestive that the codebase is riddled with flaws. Smoke, fire, yadda yadda.
33.
▲
by
kkl
10y ago
LG G2 to a Nexus 5X.
34.
▲
by
kkl
10y ago
My Signal phone audio issues went away after I upgraded hardware. Not a great solution (obviously) but something worth noting.
35.
▲
by
kkl
10y ago
I am bummed that you got the impression that you felt ignored for not having security expertise. I am not certain when you applied but I know our focus lately has been on senior engineers so that likely contributed to our response. Regardle
36.
▲
by
kkl
10y ago
Praetorian | Austin, Texas | REMOTE (For principal and staff positions) Praetorian is different. We are a collective of highly-technical engineers focused on helping our clients solve their most difficult security problems. Rather than brea
37.
▲
by
kkl
10y ago
Praetorian | Austin, Texas | REMOTE (For principal and staff positions) Praetorian is different. We are a collective of highly-technical engineers focused on helping our clients solve their most difficult security problems. Rather than brea
38.
▲
Why PKCS#1v1.5 Signature Should (Also) Be Put Out of Our Misery
(cryptosense.com)
1 points
by
kkl
10y ago
|
0 comments
39.
▲
by
kkl
10y ago
Nope! Whatever language your prefer.
40.
▲
by
kkl
10y ago
Praetorian | Austin, Texas | REMOTE Praetorian is different. We are a collective of highly-technical engineers focused on helping our clients solve their most difficult security problems. Rather than break things over and over, our goal is
41.
▲
by
kkl
10y ago
Considering: * Golang's TLS stack is far less complex in comparison to other projects. * Golang's TLS stack is written in a "safe" language. * Golang's TLS stack is written by individuals with lots of experience in
42.
▲
Executing non-alphanumeric JavaScript without parentheses
(blog.portswigger.net)
123 points
by
kkl
10y ago
|
19 comments
43.
▲
by
kkl
10y ago
If you don't believe `tptacek maybe you will believe James Kettle: http://blog.portswigger.net/2016/05/web-storage-lesser-evil-...
44.
▲
Encrypted Email Obstacles and Experiments
(moderncrypto.org)
1 points
by
kkl
10y ago
|
0 comments
45.
▲
by
kkl
10y ago
I didn't understand the motivations of virtual ethernet right away but this presentation piqued my interest. If you are (like me) and not a low-level networking person, I found this write-up on switchd to be an good compliment to this
46.
▲
Web Storage: the lesser evil for session tokens
(blog.portswigger.net)
195 points
by
kkl
10y ago
|
69 comments
47.
▲
by
kkl
10y ago
Two job titles that come to mind: * Penetration Tester * Security Engineer Those should bring up quite a few results.
48.
▲
Security challenges for the Qubes build process
(blog.invisiblethings.org)
64 points
by
kkl
10y ago
|
17 comments
49.
▲
BLESS: SSH Certificate Authority for Ephemeral SSH Sessions
(github.com)
54 points
by
kkl
10y ago
|
18 comments
50.
▲
by
kkl
10y ago
This is a great paper. Basically, AES-GCM fails when nonces are repeated. If that sounds like a impossibility, it isn't. The authors found several TLS implementations that had faulty nonce generation algorithms. Notably, one device wou
51.
▲
Signal Protocol and Deniable Authentication
(praetorian.com)
3 points
by
kkl
10y ago
|
0 comments
52.
▲
by
kkl
10y ago
Signal does not require an Android device.
53.
▲
by
kkl
10y ago
Some relevant background information on this issue: https://github.com/LibreSignal/LibreSignal/issues/37
54.
▲
by
kkl
10y ago
You just sold me on a Pinboard account. That is great.
55.
▲
by
kkl
10y ago
A number of comments in this thread appear to suggest that Lavabit was end-to-end encrypted. It was not. https://moxie.org/blog/lavabit-critique/
56.
▲
by
kkl
10y ago
There are known biases throughout RC4 output. There are really bad biases towards the beginning. A small file would likely be XOR'd with certain bytes or patterns of bytes. If this is not exploitable in your hypothetical scenario, it
57.
▲
A Systematic Analysis of the Juniper Dual EC Incident
(eprint.iacr.org)
1 points
by
kkl
10y ago
|
0 comments
58.
▲
Scalable vendor security reviews
(googleonlinesecurity.blogspot.com)
1 points
by
kkl
11y ago
|
0 comments
59.
▲
by
kkl
11y ago
I do not know of any attacks against encrypt-then-MAC CBC-mode but I believe at least part of the rationale behind the migration away from CBC-mode is due to increased complexity of decryption. With CBC-mode decryption I have at least one e
60.
▲
Go Proverbs Illustrated
(gregosuri.com)
3 points
by
kkl
11y ago
|
0 comments
More ›