Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
maxtaco
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
maxtaco
13y ago
No, there are no proofs based on e-mail addresses, because such proofs are not publicly-auditable. We could ask that maria prove to the server that she controls a given gmail account, but there's no way for the server to prove that to
92.
▲
by
maxtaco
13y ago
I'm not an authority on hushmail, but it seems like they do crypto on the server, and the server is just trusted to throw away the keys and plaintext? In the keybase Web client, all crypto happens on the browser. The server knows no k
93.
▲
by
maxtaco
13y ago
Yes to DNS, though we have to be careful here since DNS can be spoofed more easily than github or twitter proofs over https. I was thinking a slightly better way to prove ownership of foo.com would be to post a proof at https://
94.
▲
by
maxtaco
13y ago
Sorry, that was a little joke. I don't think anyone should hold more than a small portion of their total assets in cryptocurrencies.
95.
▲
by
maxtaco
13y ago
Seriously, the centrifuges connected to your 2008-era Lenovo netbook might be totally rooted after this transfer.
96.
▲
by
maxtaco
13y ago
It's likely the password you come up with will be better than the the unbroken 10 BTC WarpWallet challenge, so you have that assurance. Also, we implemented the protocol twice, using two different software stacks, and checked we came u
97.
▲
by
maxtaco
13y ago
You still need to remember a good password, but now you have to worry about keeping track of the file. If you lose either, you lose your coin. Plus 7Zip uses a PBKDF2-like key stretcher, but you're probably better off with scrypt, and
98.
▲
by
maxtaco
13y ago
That's not a totally fair analogy. The adversary in this case shouldn't even know you have bitcoin or a WarpWallet; so why would they bother to torture it out of you in the first place? Edit: but I guess I agree, it would be a nic
99.
▲
by
maxtaco
13y ago
I wrote a little blog article on how to store the majority of your bitcoin using a security-enhanced brainwallet. Part of the argument is that exchanges and online wallets are and will continue to be magnets for good XSS/CSRF attacks.
100.
▲
by
maxtaco
13y ago
MSR attracts some of the best researchers and makes it easy to get research done. No teaching requirements, grant applications or scrambling for funding. Just research. I sincerely hope tomorrow's Microsoft keeps MSR well-funded, it&
101.
▲
by
maxtaco
13y ago
This is a great analysis, but I'd hesitate to call anything the "root cause" of WWI. Of course the Ottoman Empire's decay was a factor, but hard to say that it was more important than the many others listed here and els
102.
▲
by
maxtaco
13y ago
I think Jakub P. was implying that the CSRF-token defense could also guard against this attack.
103.
▲
by
maxtaco
13y ago
I recently read a fabulous history of WWI (G.J. Meyer's _The World Undone_). What struck me is that if you modeled Europe in 1914 as a distributed system, you'd see incredible latencies between decisions being made and decisions b
104.
▲
U.S. Continues to Threaten Affordable Drug Lifeline for Millions
(doctorswithoutborders.org)
1 points
by
maxtaco
13y ago
|
0 comments
105.
▲
by
maxtaco
13y ago
Thank you for your construction. Cleaner than the one I dreamed up.
106.
▲
by
maxtaco
13y ago
Another alternative is https://OneShallPass.com . Free, auditable and open-source.
107.
▲
by
maxtaco
13y ago
How does SRP help? With SRP, you still have a server-side brute-forceable table of password hashes. The server stores v = g^x, x = H(s, p), for each user, where s is the salt and p is the password. g is known to the server (and hence the
108.
▲
by
maxtaco
13y ago
Thanks for pointing that out, it's bug in the pseudocode, but it's right here in the params file ( https://github.com/keybase/warpwallet/blob/master/src/json/p... ). I'll fix it no
109.
▲
by
maxtaco
13y ago
Congrats!
110.
▲
by
maxtaco
13y ago
Sorry, it's been fixed on the posted URL too.
111.
▲
by
maxtaco
13y ago
Was out to dinner. Fixed it, sorry for the 403.
112.
▲
by
maxtaco
13y ago
With a bounty -- the first to guess a 2-character password gets $50.
113.
▲
by
maxtaco
13y ago
Agwa, thanks for coming to DJB's and my defense. Unfortunately, anyone who disagrees with tptacek gets an automatic downvote.
114.
▲
by
maxtaco
13y ago
Well, I am done here. I imagine if we ever met each other in person we'd find each other reasonable people, but over these channels it's not coming across. Until then, good luck. And I can't resist: you'd be hard press
115.
▲
by
maxtaco
13y ago
Thank you for your reply and expanded comments. The adversary we are most worried about is a government agency in 2023 demanding a large Website turnover of all live data, backup data, and backup tapes. If a weakness in AES is found sometim
116.
▲
by
maxtaco
13y ago
Agreed. I am open to valid criticisms on the crypto and/or implementation shortfalls, but unjustified comments don't help.
117.
▲
by
maxtaco
13y ago
Is there any justification to your comments? Your criticisms on the crypto have all been debunked by those who know the crypto. See here for an example: http://d3j5vwomefv46c.cloudfront.net/photos/large/810438785.
118.
▲
by
maxtaco
13y ago
Passwords are bound to be weak, you are right. Running PBKDF2 only gives some protection against password-cracking, but a well-funded adversary can overcome that protection if the original password doesn't have enough entropy. For pas
119.
▲
by
maxtaco
13y ago
That's a good point. You can feel free to strip them off. After byte 8, the rest of the outputs will appear almost entirely random. It depends on your usage. I'm imagining a database table on a server with a column of TripleSec
120.
▲
by
maxtaco
13y ago
It wasn't trivial to write TripleSec, which I why we did it and open-sourced it. Any encrypted data you put onto a remote-server will live there forever, so your encryption has to be future-proof. I think it pays to hedge your bets he
More ›