Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
libroot
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
libroot
2mo ago
Again you responded to a position I havent taken. My argument was about who holds procedural power in standards bodies, given that some of the significant participants (NSA & GCHQ) have funded programs with hundreds of millions of $ per
2.
▲
by
libroot
2mo ago
What a weird comment. > where you think NSA "proposed" MLKEM or had some hand in its design Never said this and don't think it. Kyber came from an academic team through an open NIST competition, no one is disputing that. T
3.
▲
by
libroot
2mo ago
Imo "the optimal choice" is to be extremely skeptical to what comes to NSA proposing anything related to encryption/cryptography. From the first part of this blog series by DJB[1]: > Try to put yourself in the mindset of N
4.
▲
NSA and IETF, Part 9
(blog.cr.yp.to)
51 points
by
libroot
2mo ago
|
75 comments
5.
▲
by
libroot
2mo ago
This is also relevant if you get the phone back. There could be some nasty hw modifications that could leak data out of the phone in AFU state. Hopefully people in these kinds of situations take this into account. IMO all phones and compute
6.
▲
Exploiting ML-DSA bugs [pdf]
(cr.yp.to)
3 points
by
libroot
4mo ago
|
1 comments
7.
▲
by
libroot
4mo ago
> Posted new paper "Exploiting ML-DSA bugs" and demo scripts: https://cr.yp.to/papers.html#mldsa The current panic to roll out new ML-DSA code in place of ECC signatures will give away tons of keys to attackers
8.
▲
ExitFlare
(exitflare.com)
5 points
by
libroot
5mo ago
|
0 comments
9.
▲
Ears and Eyes – Searchable database of cases of physical surveillance devices
(notrace.how)
2 points
by
libroot
5mo ago
|
0 comments
10.
▲
by
libroot
9mo ago
Yes, the journalists did the redactions. The metadata timestamps in one of the documents show that the versions were created three weeks before the publication. And to be honest, the journalists generally have done a great work on pretty mu
11.
▲
by
libroot
9mo ago
Thank you. The most recent completely new information from the Snowden files is found in Jacob Appelbaum's 2022 thesis[1], in which he revealed information that had not been previously public (not found on any previously published docu
12.
▲
New information extracted from Snowden PDFs through metadata version analysis
(libroot.org)
324 points
by
libroot
9mo ago
|
123 comments
13.
▲
Going Through Snowden Documents, Part 3
(libroot.org)
3 points
by
libroot
9mo ago
|
0 comments
14.
▲
by
libroot
10mo ago
Weird, the certificate should be fine. Here's a link for Web Archive: https://web.archive.org/web/20251211220119/https://libroot.o... We also have Tor onion site: http://librootfuuucybrkp
15.
▲
Going Through Snowden Documents, Part 1
(libroot.org)
246 points
by
libroot
10mo ago
|
211 comments
16.
▲
by
libroot
1y ago
No, these encrypted VMs are not protected from buggy or malicious on-die components. SEV assumes that the SoC hardware is trusted.[1] And we don't even have to go that deep: both AMD SEV and Intel's equivalent, Intel SGX, have his
17.
▲
by
libroot
1y ago
It's hard to take corporate denials at face value. History shows that when it comes to surveillance and government cooperation, big tech companies often say one thing in public while doing another behind closed doors. Before the Snowde
18.
▲
Cloudflare: The Irresistible Hub for Mass-Surveillance
(libroot.org)
9 points
by
libroot
1y ago
|
2 comments
19.
▲
by
libroot
1y ago
Sure, threat models matter, but that's exactly the point. TEEs are marketed as if they solve the "malicious infrastructure" problem. Cloud providers tell you they can't see your data, and vendors pitch TEEs as some kind
20.
▲
Trusted Execution Environments? More Like "Trust Us, Bro" Environments
(libroot.org)
6 points
by
libroot
1y ago
|
3 comments