Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kpdemetriou
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
kpdemetriou
1y ago
Unlike Dual_EC_DRBG, Bitcoin doesn't use suspicious unexplained constants - all major constants have clear justifications as far as I'm aware.
2.
▲
Cord: Canonical serialization in Rust for security-sensitive applications
(github.com)
3 points
by
kpdemetriou
2y ago
|
1 comments
3.
▲
by
kpdemetriou
2y ago
Cord is a deterministic serialization format built in Rust, designed for security-sensitive applications where consistent and unambiguous binary representations are essential. Many serialization formats allow multiple binary representations
4.
▲
by
kpdemetriou
2y ago
I'm not sure what you mean - Minibone's entire purpose is to allow you to not trust the server with users' plaintext data. Naturally, you DO need to run Minibone in an environment that's not compromised, but even if you&
5.
▲
by
kpdemetriou
2y ago
I'm curious, how do you imagine using it in Python?
6.
▲
by
kpdemetriou
2y ago
Think of it this way: if your database gets breached, your app won't leak user data if your users aren't all targeted by active attackers. It's not a substitute for transport security. If active attackers are an important par
7.
▲
by
kpdemetriou
2y ago
I'm one of the authors. We built Minibone as a community contribution because we realized how unnecessarily vulnerability-prone E2EE app development is today - after seeing app after app repeatedly making the same mistakes. Minibone is
8.
▲
by
kpdemetriou
2y ago
The team behind this project (read: we) developed an expansive SDK for multi-user collaborative apps, including realtime docs. We use it to power many of the features of https://backbone.dev/ The multi-user scenario is sign
9.
▲
by
kpdemetriou
2y ago
In principle, yes. In practise it's not widely supported (yet). Here's a relevant blog post: https://levischuck.com/blog/2023-02-prf-webauthn
10.
▲
by
kpdemetriou
2y ago
One of the authors here. Streaming is actually in the works.
11.
▲
by
kpdemetriou
2y ago
It's much more bare-bones. Minibone exposes a more approachable and misuse-resistant higher-level API including support for things like opportunistic key rotations and groundwork for forward evolution!
12.
▲
Minibone: practical end-to-end encryption for web apps
(github.com)
88 points
by
kpdemetriou
2y ago
|
67 comments
13.
▲
by
kpdemetriou
3y ago
Re: BLAKE2, I'm not sure it's fair to say that BLAKE2 is more widely used overall. But I do agree BLAKE2 is a bit of an outlier in terms of adoption. I think part of the reason is that SHA2 remains the go-to option, else I'd
14.
▲
by
kpdemetriou
3y ago
Implemented correctly, I agree the difference in security margin may not be too important. Otherwise, Serpent is more resistant to timing attacks. Weaknesses in implementation are as important as weaknesses in design. Regardless, the compar
15.
▲
by
kpdemetriou
3y ago
Absolutely, but NIST ultimately choose the winners, giving them the option to pick (non-obviously) weak/weaker algorithms. Historically only the winners are adopted. Look at the AES competition - how often do you see Serpent being ment
16.
▲
by
kpdemetriou
3y ago
Bernstein is often right, despite the controversy around the Gimli permutation. In this particular case it's worth noting that neither BSI (Germany) nor NLNCSA (The Netherlands) recommend Kyber. Unfortunately, alternative algorithms ar
17.
▲
by
kpdemetriou
3y ago
Assuming the cryptography is solid (big if), you primarily have to worry about end-device compromise or a supply chain attack. Is it the latter you're worried about?
18.
▲
by
kpdemetriou
3y ago
The typical trajectory of VC-backed companies is one of the things that led us to develop Backbone[1]. We've opted to forego VC funding and the short-term benefits in entails to build the long-term foundational infrastructure for end-t
19.
▲
by
kpdemetriou
3y ago
The impact of E2EE in the event of database compromises is a little under-rated because the conversation often centers around the maximalist targeted survaillenace threat model. Yet, many more individuals will be affected as a result of pla
20.
▲
by
kpdemetriou
3y ago
The web app case is unfortunately more hazardous: - You're also trusting a large population of Certificate Authorities (CAs), subject to the post-compromise implications of Certificate Transparency. Only one needs to be compromised. -
21.
▲
by
kpdemetriou
3y ago
Regarding #3, you'll need to load the immutable URL, perhaps indirectly, from someplace that ultimately has a user-facing URL. If an attacker can modify content in transit, then they can modify the content under the user-facing URL to
22.
▲
by
kpdemetriou
4y ago
> Zero knowledge cloud > Data in our cloud is end to end encrypted so your credentials are never exposed to anyone but you. A few comments: 1. You might want to avoid calling this zero-knowledge. While your docs suggest som
23.
▲
by
kpdemetriou
5y ago
Hi everyone, OP here. Let me offer some background. fuuids are designed to be sortable and collision-free (for most practical purposes, details below) IDs within a 16-byte footprint making them interpretable as UUIDs. Lazare very helpfully
24.
▲
Sortable Collision-Free UUIDs
(github.com)
94 points
by
kpdemetriou
5y ago
|
62 comments
25.
▲
Post-Quantum Cryptography for Python
(github.com)
1 points
by
kpdemetriou
6y ago
|
0 comments