Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lotharrr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
61.
▲
by
lotharrr
9y ago
The two sides exchange IP addresses (inside the encrypted channel), and try to connect to all of them. If that fails to produce a successful handshake, they fall back to a "Transit Relay Server" that I run. So they'll manage
62.
▲
by
lotharrr
9y ago
If I did things right, the rendezvous server shouldn't get any advantage over a network attacker: one guess per invocation of the program, 1-out-of-65536 chance of getting it right, 65535-out-of-65536 chance of giving you a WrongPasswo
63.
▲
by
lotharrr
9y ago
Yeah, also the two sides can exchange (encrypted) notes about their apparent network environment (including their public IP address, as reported by the rendezvous server), which might give them a clue that they're on the same LAN. Also
64.
▲
by
lotharrr
9y ago
Interesting.. I'll take a look at it. My first thought is that magic-wormhole needs a canonical way to allocate "nameplates" (the numeric channel identifier at the start of the wormhole code), and that's tricky to do in
65.
▲
by
lotharrr
9y ago
Nifty.. I'll look at the network side of that, maybe we can steal some ideas. At the moment magic-wormhole depends upon one of: * at least one side has a public IP address * both sides are on the same (private) LAN * a TURN-like "
66.
▲
by
lotharrr
9y ago
Nice! It might be interesting to use the magic-wormhole API to set up the piknik keys. In the long term, I'm pushing magic-wormhole to serve as a provisioning tool for other (more persistent) connections.
67.
▲
by
lotharrr
10y ago
Hm, now I want my order email to include a (nonce) barcode that I print out and leave on my door, and the USPS worker has to scan that before they can claim anything was delivered.
68.
▲
by
lotharrr
10y ago
In particular, there's all sorts of mischief an attacker can do when serialized(A,B)==serialized(C,D) but A!=C and B!=D. I've seen OAuth implementations do this, allowing someone to submit the signature from a "good" mes
69.
▲
by
lotharrr
11y ago
webRTC is an awesome way for getting data from one web browser to another, but you must bootstrap it by copying a webRTC "offer" message in both directions first. Most of the webRTC-based videochat services (Firefox Hello, talky.i
70.
▲
by
lotharrr
11y ago
Yeah, the 16-bit "wormhole code" means that each active MitM attack has a 2^-16 chance of success, and a 1-(2^-16) chance of causing a broken connection. The error message you get (which also happens if someone simply mistypes the
71.
▲
by
lotharrr
11y ago
There are two useful things (IMHO) in magic-wormhole. The first is the PAKE-based security model, with the invitation codes. The second is the "try to find each other" STUN-fallback transit stuff. Transit is way less interesting t
72.
▲
by
lotharrr
11y ago
Author here.. didn't realize this made it to HN yet, I was wondering where the spike in traffic came from :). Sorry to miss the initial questions, but feel free to ask me more.
73.
▲
by
lotharrr
12y ago
I've been able to create URL-based "unlisted" hangouts with: http://plus.google.com/hangouts/_ That will redirect you to a new hangout URL, and (in my experience) you can just copy/paste the new URL
74.
▲
by
lotharrr
12y ago
In general I agree, but the problem with Glacier's retrieval pricing in particular is that it's quoted as dollars-per-byte (like all their other prices), but in fact it's really dollars-per-(peak-bytes-per-second). It's
75.
▲
by
lotharrr
13y ago
Might it be even safer to squash 'rc' down to a single pair of values (0 or 1), rather than leaving the caller with the responsibility of testing a byte for zeroness safely? By leaking the 255 possible values for "not equal&q
76.
▲
by
lotharrr
13y ago
I would hope the built-in software-upgrade process does exactly that (independent of transport-layer SSL), but I have no evidence either way. The manual-download pages on http://support.apple.com/downloads/ publish SHA
77.
▲
by
lotharrr
13y ago
Nope. Linux systems don't need EGD: the in-kernel gatherers do everything the user-space EGD daemon would, and better. The problem they're aiming to solve is that some things (like first-boot ssh key generation) are running so ear
78.
▲
by
lotharrr
13y ago
Thanks! Glad you liked it! I plan to do a proper brown-bag Air-Mozilla presentation of it soon, so we'll have a video recording available online (and not just the slides). FYI, I showed three different designs in that presentation, to