Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kkl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
Duplicate Signature Key Selection Attack in Let's Encrypt
(agwa.name)
71 points
by
kkl
11y ago
|
4 comments
62.
▲
Duplicate Signature Key Selection Attack in Let's Encrypt
(agwa.name)
5 points
by
kkl
11y ago
|
0 comments
63.
▲
Secure Password Hash Algorithm Migrations
(kel.bz)
3 points
by
kkl
11y ago
|
0 comments
64.
▲
by
kkl
11y ago
Thanks for clarifying. That is a really concise explanation.
65.
▲
by
kkl
11y ago
To make sure I understand correctly: Suppose I had the magical ability to find a special value that would equal the IV listed in the link (i.e. 506b0178ff6d1890....) when that special value was applied to SHA-1. I could then use the results
66.
▲
by
kkl
11y ago
Neat. I have also seen one of the authors do videos called "Watching YouTube The Hard Way" (unsure of exact title) which is a similar concept.
67.
▲
by
kkl
11y ago
A somewhat-related honeypot that I have seen: Include a directory "visiting-this-will-ban-you" in your robots.txt that IP bans whomever visits it.
68.
▲
by
kkl
11y ago
What great timing. I _just_ finished a Minimax algorithm to programmatically play the game of Rota. I did this as fun project to teach myself Golang. If this article seems interesting to you, I would suggest doing something similar.
69.
▲
by
kkl
11y ago
Awesome. Thanks for the correction.
70.
▲
by
kkl
11y ago
The CCC is an fascinating organization that hosts really interesting talks (among other things). Where else can you see talks titled "Mexican Botnet Dirty Wars", "Encrypted Email for Planet Earth", and "Basics of hy
71.
▲
by
kkl
11y ago
It is likely in response to this: https://community.rapid7.com/community/metasploit/blog/2015/...
72.
▲
by
kkl
11y ago
Why would you prefer CTR over CBC (assuming properly authenticated)? The only benefit I could think of is performance.
73.
▲
by
kkl
11y ago
Company: Praetorian Location: Austin, Texas Tags: REMOTE Positions: Security Engineer (Penetration Tester). More details at our careers page ( http://www.praetorian.com/company/careers ). Hello from Praetorian! We are
74.
▲
by
kkl
11y ago
This! I do not use Facebook but would love if this leads to increased interest in using asymmetric crypto to encrypt automated notification emails.
75.
▲
Where the Science Is Taking Us in Cybersecurity
(geer.tinho.net)
1 points
by
kkl
11y ago
|
0 comments
76.
▲
by
kkl
11y ago
I wonder if this was inspired by the recent #talkpay trend on Twitter. Announcing your salary on Twitter is not the best idea. It will likely to be found by a recruiter and then (possibly) used against you in negotiations. I support the tra
77.
▲
by
kkl
11y ago
What a nifty blog. I find visualizations incredibly useful when developing a deeper understanding of some mathematical concept so I am certainly bookmarking this. Another blog I find useful in this regard is Better Explained[1]. [1] http:&
78.
▲
by
kkl
11y ago
I am under the impression that attribution is a very difficult and often impossible process. If that is true, what is the point of including "Russian" in this headline? I would guess the most probable response would be something i
79.
▲
by
kkl
11y ago
Beautiful. This article made me smile. I also like that the author gave a simple "how-to" at the end in case I wanted to try it myself (i do!).
80.
▲
by
kkl
11y ago
This is a poisonous attitude to have with regards to the security of applications that you built. I hope that you take these claims seriously. Otherwise, I have no desire to use anything that you have built.
81.
▲
by
kkl
11y ago
This is a fantastic book. I recommend both the section on Google Chrome [1] and GHC [2]. Regardless of your level of interest in web browsers or compilers, they are both really educational and interesting reads. [1] http://aosabo
82.
▲
by
kkl
11y ago
I had the opposite experience. My speakers were all the way up and I scared myself.
83.
▲
by
kkl
11y ago
I'm sure you have checked out the official documentation ( http://lcamtuf.coredump.cx/afl/README.txt )? Fuzzing Python programs with AFL will be hard. AFL leverages a version of the GCC compiler to instrument (add a
84.
▲
by
kkl
11y ago
Afl-fuzz is really amazing. The only thing that bums me out about it is that it is not as open as it could be. From AFL's documentation: "PS. If you wish to submit raw code to be incorporated into the project, please be aware that
85.
▲
by
kkl
11y ago
Interesting. The D-Link security advisory ( http://securityadvisories.dlink.com/security/publication.asp... ) states that the issue was only partially resolved. What was changed (aside from adding an additional buffer ov
86.
▲
by
kkl
11y ago
I do not have concerns with the mantra itself just it's usage and the entitlement that often comes along with using it. The top answer on this Stack Exchange question is a good example of what I believe to be proper usage of the mantra
87.
▲
by
kkl
11y ago
I agree but you are the first person I've seen frame it in that way. I see people spew "don't roll your own crypto" often. Hopefully some variation of your "modern argument" becomes more prevalent in the near f
88.
▲
by
kkl
11y ago
I certainly agree with you. I just think the "don't roll your own crypto" advice is overly ambiguous. Ironically, I think my original comment was ambiguous as well. Let me clarify. I'm not endorsing rolling your own cryp
89.
▲
by
kkl
11y ago
The "Don't roll your own crypto" mantra is overly ambiguous and enforces the culture of elitism in information security. I hope that something displaces this regurgitated "advice" with something more helpful. I know
90.
▲
by
kkl
12y ago
It seems that changing your local DNS settings seems like a rather trivial barrier to get around but this technique is pretty useful. For me, procrastination is a subconscious habit and routing your time-sinks to "purple.com" is r
More ›