Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kwantam
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
kwantam
5y ago
One incomplete answer: At the bottom, this lets you prove that you know a signature without revealing what that signature is. This idea has been used in anonymous credential systems---much like this one! In the cryptographic literature, the
32.
▲
by
kwantam
5y ago
This is very cool and really impressive! Nice work, both on a conceptual level and on getting everything to actually work :) If anyone is curious, here are a couple pointers to related work on problems similar to this. First, the ideas us
33.
▲
by
kwantam
5y ago
See my response to a sibling comment of yours. Your initial claim had absolutely nothing to do with "broad side effects." You claimed that prednisone is almost never the right treatment. That is false, and runs counter to evidence
34.
▲
by
kwantam
5y ago
OP said: "there is almost no condition for which the right treatment is prednisone." I said: "prednisone is on the WHO's list of essential medicines," which is very strong evidence that the claim is incorrect. Your
35.
▲
by
kwantam
5y ago
Are you a doctor? Are you a veterinarian? If no, how likely do you believe it is that you are better informed than a trained professional after a web search for side effects? Prednisone is on the WHO's list of essential medicines. It a
36.
▲
by
kwantam
5y ago
It's not wrong per se, but it is poorly written: "within-group variability" is preferred (by most style manuals) because the hyphen makes clear that "within" modifies "group".
37.
▲
by
kwantam
5y ago
I'm not defending the prior poster's statement, but the first part of their statement specifically mentions high-profile anti-vax deaths. There are interpretations of that argument that have nothing to do with de-humanizing, but
38.
▲
by
kwantam
5y ago
I was reading about this just yesterday, and was intrigued to learn that the backfire effect may not be real and/or may be very weak. Here's one meta-study: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC74
39.
▲
Activision Blizzard employees petition for CEO Bobby Kotick’s resignation
(washingtonpost.com)
2 points
by
kwantam
5y ago
|
0 comments
40.
▲
by
kwantam
5y ago
Possible solution: binary search to find the number of hops (buffering intermediate responses so that you don't have to re-send them), and send all missing TTLs in parallel once you've determined the number of hops to use. You cou
41.
▲
by
kwantam
6y ago
There may be some unstated assumptions here that I'm missing, but as presented this does not appear to be a useful idea. The meat of the idea, as I understand it, is: passports can be easily validated (because they contain a secret key
42.
▲
by
kwantam
7y ago
Ah, quick update to the above (can't edit anymore): the final construction I posted in the above message is not good for arbitrary messages, because if msg starts with an all-zeros block then the inner and outer hash invocations won&
43.
▲
by
kwantam
7y ago
D'oh. Of course. One thing we could do in this case is use NMAC rather than HMAC. First, let's more explicitly define a Merkle Damgaard function in terms of its compression function and initialization vector. For some compression
44.
▲
by
kwantam
7y ago
There are a lot of things that are much safer to do with SHA-3 (as in Libra) than with SHA-2. If H is in the SHA-2 family, you're much better off doing HMAC(info, msg) than H(H(info) || msg) In particular, HMAC has pr
45.
▲
by
kwantam
7y ago
SHA-512/256 is already quite misuse-resistant, so it's entirely plausible that there's nothing to worry about in this specific case. But if we limit ourselves to standard Merkle Damgaard hashes (i.e., not ChopMD), then the
46.
▲
by
kwantam
7y ago
You're absolutely right that H(public || private) may help against length extension (e.g., if we try to use H as a MAC), whereas H(private || public) certainly does not! As stated, though, this is only a heuristic: de
47.
▲
by
kwantam
7y ago
A slightly unfortunate trend in protocol design has been to prepend rather than append "info" fields to hash inputs. In other words, we tend to see H(info || msg) instead of H(msg || info) There are some good rea
48.
▲
by
kwantam
7y ago
Great question! The very short answer is "yes." In slightly more detail: We wanted to be able to test with a 4096-bit RSA modulus whose factorization was plausibly unknown, but this is a tough thing to find! (We certainly didn
49.
▲
by
kwantam
7y ago
Hi HN, I'm one of the authors of this paper. Very cool to see it being discussed here! I'm happy to answer questions about private airdrops, with two caveats: first, I'm not associated with Handshake, so I probably don't
50.
▲
by
kwantam
7y ago
A missed opportunity: the balls-and-bins discussion didn't go on to discuss the power of two choices. In short, if you're tossing N balls randomly into N bins, you should expect the most heavily loaded bin to get log N of the ball
51.
▲
by
kwantam
7y ago
Here's one intuitive way to think about what this means: Imagine that you stumble on two infinitely powerful computers that share a bunch of entangled quantum state. Further, let's say you know how to write software for them but y
52.
▲
by
kwantam
7y ago
Since there's little technical detail it's hard to be certain, but I doubt this is useful as a proof in the way one might wish (that is, proving that a web server delivered content X at date Y). The reason is, it does not appear t
53.
▲
by
kwantam
7y ago
Indeed! Another publication on this topic from that time: https://www.usenix.org/conference/usenixsecurity12/technical... and commentary on the paper from a few years later https://blog.acolyer.org/
54.
▲
by
kwantam
7y ago
Note that #7 is not actually true anymore, and actually hasn't been for quite a while. A paper from Mehdi Tibouchi [1] shows how to represent points on essentially any curve as uniform random bitstrings. Another paper by Aranha, Fouque
55.
▲
by
kwantam
7y ago
It's possible to rule out some (but not necessarily all) cross-protocol attacks with a simple and cheap tweak. I have not proved that this rules out everything, but it appears to be no weaker than the scheme sans tweak, and proofs shou
56.
▲
by
kwantam
8y ago
As a stopgap measure until the licensing issues are straightened out, you can build an updated version of the package yourself rather easily. What's below should more or less work to generate an updated intel-microcode package starting
57.
▲
by
kwantam
8y ago
I learned this in undergrad calc 1 as the Heaviside cover-up method [1], named after Oliver Heaviside. Heaviside was a remarkably productive scientist [2], contributing to a range of topics from vector calculus to electromagnetic theory. [1
58.
▲
by
kwantam
8y ago
Sounds like Becker, Regazzoni, Paar, Burleson. "Stealthy dopant-level hardware trojans." Proceedings of CHES, August 2013. https://sharps.org/wp-content/uploads/BECKER-CHES.pdf
59.
▲
by
kwantam
10y ago
There's a forthcoming paper at PLAS (co-located with ACM CCS, in late October) that applies formal reasoning to a Rust-like type system. The contribution here is a formalization of borrowing and ownership semantics very close to Rust&#
60.
▲
by
kwantam
10y ago
So, what do you think about BitBabbler's analysis and design while you're at it? The problem with BitBabbler is that they have a lot of text but, as far as I can tell, no circuit diagrams and no real discussion of what they&#x
More ›