Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mahemm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
mahemm
8y ago
Moving past the silly headline, there is actually a pretty substantial achievement here. Using formal verification tools, the team proved the following properties for the library: * Memory safety (no buffer overruns etc) * Type safety (all
32.
▲
by
mahemm
8y ago
Sounds like insufficient testing to me. This kind of deep/far reaching issue should have been crashing tests written before others would have seen it. Assuming that there is some testing in their work (if not; there's the answer),
33.
▲
by
mahemm
8y ago
Not a legitimate complain at all--the jury is still out as to whether it will ever be possible to create a quantum computer capable of breaking current asymmetric primitives.
34.
▲
by
mahemm
8y ago
Why not use Signal? Better privacy guarantees and the same underlying protocol.
35.
▲
by
mahemm
8y ago
In case this dies: https://archive.fo/f4RHX
36.
▲
by
mahemm
8y ago
If that's the case then you haven't been working with good auditors. That said, the opportunity to do this (scrub reports) is a driving decision behind many companies' choice to work with more permissive firms. If you want a
37.
▲
by
mahemm
8y ago
I have personally been a part of security audits that have found critical vulnerabilities in some of the best-known tech companies on the globe. Just because there exists a world of auditors who function as rubber stamps does not mean we al
38.
▲
by
mahemm
8y ago
A counterpoint to this is the billion dollar success of cryptocurrencies such as IOTA and Verge that are fundamentally broken from a cryptographic point of view.
39.
▲
by
mahemm
8y ago
Something that scares me here--where is the awareness of emergent security errors arising from multi-threaded cryptography? As an example, consider a multithreaded streaming crypto API which consumes a symmetrically-encrypted data stream wi
40.
▲
by
mahemm
9y ago
It absolutely is! Which is why I felt like it was important to bring more attention to the much lesser security stance of others in the space.
41.
▲
by
mahemm
9y ago
What's your quip for plaintext group chat
42.
▲
by
mahemm
9y ago
I worded that poorly and have edited the OP to reflect that. I was referring to the recently re-discovered paper about group chats (e.g. https://www.helpnetsecurity.com/2018/01/11/whatsapp-signal-g... paper h
43.
▲
by
mahemm
9y ago
Following all of the negative press Signal has gotten recently, I feel it's unethical to let a Telegram post pass without a reminder that they don't even bother to encrypt group chats, and that there is still no proof whatsoever t
44.
▲
by
mahemm
9y ago
Not true. In order to make sure there isn't a run on their fake currency, they need to ensure that the balance tips towards buying bitcoin rather than cashing out holdings. If the price goes too low, people will start trying to convert
45.
▲
by
mahemm
9y ago
It's mind boggling to me that anyone takes IOTA seriously anymore. The fact that it's in ternary should be enough to convince the more risk-averse technical people of the folly of its design. More optimistic techies should have be