Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lotharrr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
lotharrr
5y ago
Yep, if both parties are behind NAT, or some sort of firewall that prevents inbound connections from the other, they'll fall back to using the pre-configured public relay server (or any other server you tell them to use). I need to bui
32.
▲
by
lotharrr
5y ago
Edit: no worries, I just added it there a minute ago, didn't realize I'd left that box blank. I'm Brian Warner.
33.
▲
by
lotharrr
5y ago
For (my) magic-wormhole, yep, entirely, source is on the github link above. It uses a pair of helper servers (that I run), for which the source is also on github. But the protocol (implemented in the client, not the server) is carefully des
34.
▲
by
lotharrr
5y ago
(author of magic-wormhole here) aww, thanks :) BTW for anyone reading, https://wormhole.app/ is awesome and serves a very similar purpose, but uses entirely different technology (no PAKE) and has a different security model.
35.
▲
by
lotharrr
6y ago
Hey.. neat project! From the docs at https://docs.doppler.com/docs/share-security : > 2. Client-side JavaScript generates a cryptographically random 64 character passphrase > 3. Client-side JavaScript generates a
36.
▲
by
lotharrr
6y ago
(I'm the author of magic-wormhole) Nice! I'm glad to see libp2p getting more use. I would love to have it as a connection protocol in magic-wormhole someday. Your implementation looks really slick. I'll echo mintplant's
37.
▲
by
lotharrr
6y ago
I've seen pretty good video from the NDI Tools ( https://www.ndi.tv/tools/ ), which includes a pair of smartphone apps (one to transmit the camera, a second to transmit a screen capture), and a receiver program on t
38.
▲
Securing JavaScript Modules
(medium.com)
4 points
by
lotharrr
6y ago
|
0 comments
39.
▲
by
lotharrr
7y ago
It might make more intuitive sense if you reverse the question. Suppose you've uploaded a file to AWS, let's say 1MB, but you don't entirely trust that they won't change the data on you. You're about to sell all you
40.
▲
by
lotharrr
7y ago
Incidentally, the real goal of magic-wormhole is to provide the initial secure introduction between two people's communication tools. Get your public key into my address book safely, and then all those other modes have something to wor
41.
▲
by
lotharrr
7y ago
(magic-wormhole author here) It's probably worth pointing out that the 2^-16 chance is per invocation of the protocol.. it's not an offline attack. So you'd have to be reeeealy patient to run it enough times to give the attac
42.
▲
by
lotharrr
8y ago
The data is encrypted on your client before it leaves your computer. You're relying upon the servers to hold onto your ciphertext (i.e. availability), but not to keep it secret (confidentiality). And the client can detect changes to th
43.
▲
by
lotharrr
8y ago
(author of Tahoe here, although I'm not much involved these days) > Tahoe-LAFS makes some impressive claims like maintaining confidentiality while running on untrusted machines. I think a lot of folks now would assert that really an
44.
▲
by
lotharrr
8y ago
Least Authority is actually a German company now (although it was started in the US): https://leastauthority.com/about-us/
45.
▲
by
lotharrr
8y ago
(author of magic-wormhole here) To transfer a file, both parties do need to be online at the same time. The server (which I run) does not store the file's data: it stores tiny key-exchange messages until both sides manage to make a dir
46.
▲
by
lotharrr
8y ago
magic-wormhole uses a 256-word list, so the two-word default provides 16 bits of entropy. But the code goes into PAKE, not a symmetric encryption key, so an attacker only gets one shot to guess it (it's an interactive protocol, so they
47.
▲
by
lotharrr
8y ago
(author of magic-wormhole here) Nope, the server gets no more power than a random network attacker. The codes are single-use, enforced by PAKE, so an attacker (or the server) gets at most one chance to guess the code for any single executio
48.
▲
by
lotharrr
8y ago
BTW it's been in debian+ubuntu for a couple of years, so `apt install magic-wormhole` works too.
49.
▲
by
lotharrr
8y ago
The short answer is that PAKE is single-use, so the attacker only gets one guess (and their attempt prevents the legitimate peer from trying either). Each time they consume someone else's transfer attempt, they get a 1-in-65k chance of
50.
▲
by
lotharrr
8y ago
(author of magic-wormhole here) I do. You can use your own, but then both sides have to type in the same --relay-url=URL value (instead of using the one that's baked into the app). magic-wormhole is both a file-transfer tool and a libr
51.
▲
by
lotharrr
9y ago
There's an ebook version floating around, which will give you at least the story (if not the somewhat-interactive way of discovering it). Search for "Portal: A Dataspace Retrieval, by Rob Swigart". The author approved of it b
52.
▲
by
lotharrr
9y ago
It'll probably just break for the remainder of that month. I'm hosting that transit server on Linode, and I think (does anyone know for sure?) that their policy is to just turn off the interface if you go over your monthly allow
53.
▲
by
lotharrr
9y ago
You also need to read the full AES key to your recipient. If you've already got a secure channel to your recipient, great: you can just paste them the key. But if you're sitting next to a new friend at a conference and want to thr
54.
▲
by
lotharrr
9y ago
I love Keybase.. they're doing great things to bind public keys to names at large identity providers (twitter, github, etc). And in many cases, the github username of your intended recipient is the only thing you know about them anyway
55.
▲
by
lotharrr
9y ago
I'm not gonna argue against that. Using pip-install certainly limits our current audience to people who are comfortable with python packaging tools, which basically means python developers. I'm hoping to get beyond that, once I ge
56.
▲
by
lotharrr
9y ago
Signal and Syncthing are great. magic-wormhole is more about setting up that initial connection: when two humans know each other, but their computers haven't met yet (i.e. know each others pubkeys). In Signal, the security of the initi
57.
▲
by
lotharrr
9y ago
yup, except with netcat: * the network-side attacker gets to see and modify all your data * the receiver must have a public IP address * the receiver must tell something to the sender, which is the opposite of the direction the data will fl
58.
▲
by
lotharrr
9y ago
Yeah, if you've already gotten a public key set up (and an account on the target machine), then scp is much easier and completely secure. magic-wormhole is more aimed at situations where you don't yet have that pubkey copied over.
59.
▲
by
lotharrr
9y ago
AirDrop: waaaay better UI, awesome animated drag-and-drop, dead-simple to use, works offline. Not so strong at clearly identifying who the file came from or is going to. Not clear what sort of integrity/confidentiality properties you g
60.
▲
by
lotharrr
9y ago
Yup, it still does. In the face of a lucky-guessing attacker, PAKE basically degenerates down into plain unauthenticated Diffie-Hellman, which means Alice-Mallory has one key, and Mallory-Bob has a different key. Mallory could decrypt the m
More ›