Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
less_less
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
less_less
2y ago
To expand on this a little bit: TLS and other cryptosystems usually work by using an asymmetric algorithm (X25519, Kyber etc) to create a shared key, and then using an appropriate symmetric cipher mode (AES-GCM, ChaCha20/Poly1305 etc)
62.
▲
by
less_less
2y ago
Yeah, and they're pretty performant too. I also didn't notice when originally replying, but maybe it's worth tacking on: > ... even if the NIST curves are not backdoored mathematically, they're designed in a way to
63.
▲
by
less_less
2y ago
Really? My experience is that RSA in general is harder because it has so many knobs, but if you just lock it to the easiest-to-implement-securely choices then it's not so bad. However, for DJB's point there is a major advantage f
64.
▲
by
less_less
2y ago
Bernstein has multiple arguments. Section 7 is about ways that the NIST curves could hypothetically be backdoored, and about designing curves in a "rigid" way such that they are less likely to be backdoored ... at least assuming
65.
▲
by
less_less
2y ago
I mostly agree with this, but you could still have advice of like "use only xxx flavor of RSA-KEM for key establishment and yyy flavor of RSA-FDH-SHAKE for sigs" and things would be fine. Those still aren't exactly easy to
66.
▲
by
less_less
2y ago
There's a bunch of validation software at https://safecurves.cr.yp.to/verify.html
67.
▲
by
less_less
2y ago
I'm not sure this is true anymore. There are recent improvements in quantum factoring algorithms, which significantly reduce the number of qubits required. See eg https://eprint.iacr.org/2024/222
68.
▲
by
less_less
2y ago
> Dual EC DRBG is a bad design and so you shouldn't use it. It is reasonable to believe it's backdoored, but only the same way it would be reasonable to believe David Cameron stuck his dick in a dead pig. Some people say he did
69.
▲
by
less_less
2y ago
Unsurprisingly, Microsoft Dynamics 365 is an absolutely shit app from the user side too. It's horribly slow, has a nearly unusable UI, uninformative errors, that kind of thing. The expense reporting side of D365 is especially bad, or
70.
▲
by
less_less
2y ago
Depends how embedded and how many servers it's talking to. I'm also not sure you can really tolerate false positives, since the main domain you talk to might get revoked, but there are alternatives to Bloom filters that eliminate
71.
▲
by
less_less
2y ago
As a side project I also developed something like CRLite, but approximately 40% smaller: https://docs.rs/compressed_map/latest/compressed_map/ It's probably not state-of-the-art anymore, but it gets fair
72.
▲
by
less_less
2y ago
Perhaps it's a bit more than tangentially relevant? Yes, SW[U] predates it for hashing, and Brier et al builds indifferentiability on that. But Elligator2 is simpler and faster, and also works with Brier et al, though it only support
73.
▲
by
less_less
2y ago
Elligator is appropriate for use as a component in a steganography system, but in most cases the problem it solves isn't the hardest part of the system. It's also useful in cases where you need to hash to a curve in a way that pro
74.
▲
by
less_less
2y ago
""" uint32_t a = ..., b = ...; uint32_t res = a + b; uint32_t carry = res < a; """ But note well: this trick doesn't work when there is also a carry-in. That is, uint32_
75.
▲
by
less_less
2y ago
There's a Dutch card game called Rikken that intentionally incorporates bad shuffling. It's a trick-taking game, so the cards get clumped by suit during the hand, and you shuffle very lightly between hands. After shuffling, the
76.
▲
by
less_less
2y ago
I think you'd want the reverse, which is indeed elementary: if f halts then you get a circle-free TM, but if f does not halt then you get a non-circle-free TM. This can be done by f(); while(1) output_digit(0); or any number of
77.
▲
by
less_less
2y ago
Not even "Jesus is the reason I'm right". The point of the article is that life is like (the authors' conception of) an unsanitized Grimms' fairy tale: it's full of horrors, but has a happy ending, namely an a
78.
▲
by
less_less
2y ago
They wouldn't be immediately hacked, especially as this is a quantum algorithm anyway. But if it turns out that the current PQC schemes are not quantum-resistant, then that work will need to be redone (unless the progress in quantum c
79.
▲
by
less_less
2y ago
I'm not a huge fan of QKD, but there is a potential use case for it. Basically, for digital signatures we have schemes like SPHINCS+, and perhaps also PICNIC and FAEST, which don't require "mathematically structured" as
80.
▲
by
less_less
2y ago
It's NSA who wants only PQC and not hybrid. NIST is fine with hybrid. They don't plan to standardize hybrids as entire units, but they said they plan to standardize the KDF modes you'd need to build them.
81.
▲
by
less_less
3y ago
This isn't a particularly good way to learn RSA, and Javascript isn't a good environment to teach it. It's better to use Python, which at least has bignums. And obviously, seeing a wrong implementation of RSA isn't at
82.
▲
by
less_less
3y ago
I also disagree with the paper, but not for the same reason. > With this definition, you can trivially prove the titular sentence - "hallucination is inevitable" - is untrue. Unsurprisingly, that one sentence fragment doesn
83.
▲
by
less_less
3y ago
It's also rate-limited because patents cost money, go into a queue for years, and are reviewed by humans.
84.
▲
by
less_less
3y ago
The 90 degree turn 4x4 balancer is even better if your inputs and/or outputs are on opposite sides, making a T-shape. This is pretty common depending on the position of the balancer. In that case it fits into a 4x6 rectangle.
85.
▲
by
less_less
3y ago
I'm sure he's alleged something about the other variants. Like a few years ago he had this theory about "S-Unit attacks" on Kyber and NewHope, but it hasn't gone anywhere. IMHO the lattice finalists -- Kyber, Sab
86.
▲
by
less_less
3y ago
Yeah, sorry, "hasn't convinced very many other cryptographers" was probably too much of an understatement.
87.
▲
by
less_less
3y ago
To expand on this: Daniel J Bernstein (of Curve25519 etc fame) has alleged that NIST and/or NSA knows a secret weakness in Kyber and therefore pushed it instead of NTRU. While the allegations are vaguely plausible -- NSA employs some
88.
▲
by
less_less
3y ago
There is also the problem of embedded devices. Some of these will still be operational in 20 years, at which point a "cryptographically relevant quantum computer" might exist. So we want to ensure today that these devices can su
89.
▲
by
less_less
3y ago
> An OTP must have particular properties that words in a book don’t have to be provably secure. However, common materials that the communicators have access to without specific distribution can be useful for OTPs in their own way (thoug
90.
▲
by
less_less
3y ago
One interesting thing that's not in the video: there is a real application beyond the astronomy one, a scenario where you would want to roll one object around another object, and care about how many rotations it makes. https:/&#x
More ›