Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lambdafu
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
lambdafu
10mo ago
I have the Widex SmartRIC 220, and would buy them again. They are comfortable, have musical audio quality (Widex works with musicians), very low latency (reducing comb filter effect), and in general look and feel very professional. As for t
2.
▲
by
lambdafu
2y ago
Actually, with currently common key sizes, ECC up to 384 bits will fall to QC before RSA with 1024 bits, because fewer bits means fewer qubits needed. The main disadvantage of RSA is the structure of finite fields, which allows specialized
3.
▲
by
lambdafu
2y ago
For the attack all 60 signatures need a nonce that is special in this way. If for example only one out of the 60 is short, the attack fails in the lattice reduction step. The reason is that in the attack, all 60 short nonces "collude&q
4.
▲
by
lambdafu
2y ago
Caution here. If your modulus is too close to the maximum truncated value, there can be a bias in the upper bits, too. For example, if you reduce a number between 0 and 15 by the modulus 13, the values 0, 1 and 2 will be twice as likely as
5.
▲
by
lambdafu
2y ago
If the hosts are under your control, and never connect to untrusted hosts, then you are ok. The user authentication is encrypted, so the signatures are not visible to a man in the middle.
6.
▲
by
lambdafu
2y ago
We found it by investigating the security of SSH as part of a larger research program focussing on SSH, which also resulted in our publication of the Terrapin vulnerability. This particular bug basically fell into our hands while staring at
7.
▲
by
lambdafu
3y ago
No, because there may be other messages that are ignored, i.e. don't trigger a response message. Any such message can be used for injection. The details are implementation specific, though. The new strict-kex disallows all unexpected m
8.
▲
by
lambdafu
3y ago
Depends a bit on the MAC. CTR-EtM is technically vulnerable (i.e. cryptographically broken), but due to key stream desynchronization the attack will quickly lead to application errors, defeating the attacker. See Sect. 4.3.3.
9.
▲
by
lambdafu
3y ago
ChaPoly was added in 2013, but the weird KEX is even older, dating back all the way to 1998 in SSHv2. And surprisingly, the attack only works with the "better" symmetric ciphers that do INT-CTXT instead of INT-PTXT.
10.
▲
by
lambdafu
3y ago
Thanks! <3 Also for the kind words.
11.
▲
by
lambdafu
3y ago
It's prefix truncation, though.
12.
▲
by
lambdafu
9y ago
NeoPG uses Botan, which is a crypto library written in C++. I recommend reading its source code and comparing it with, for example, libgcrypt.
13.
▲
by
lambdafu
9y ago
Yes, I should document that. GPGME only exposes a high-level API, and application developers often want more control. For example, you can't inspect key material before importing it, but importing a key is not a reversible operation
14.
▲
by
lambdafu
9y ago
Hi, I'm "this guy". Thanks for pointing out -fpermissive, which was needed during the conversion for the legacy code. Since then I fixed all the warnings, so I can remove the flag ( https://github.com/das-lab