Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mprime1
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
mprime1
4y ago
If architecture sounds appealing, try this History of Architecture course. It briefly touches on history of art and other interesting related subjects. After watching it, I ended up watching a lot of other art related educational content,
62.
▲
by
mprime1
4y ago
My hero! Thank you for your work. (Yes, not adding much insightful conversation. I don’t care if I get downvoted.)
63.
▲
by
mprime1
4y ago
Currently reading the Mongoliad book series (Neal Stephenson, Greg Bear and star cast of other contemporary sci-fi writers). Recommended if this kind of history is interesting to you.
64.
▲
by
mprime1
4y ago
> Alley Cat Thank you for bringing this back into my main memory. Spent so many hours playing this and completely forgot about it. Quick search turned up a couple of sites where you can play this emulated online!
65.
▲
by
mprime1
4y ago
I feel like you are talking about ‘MQ’ in general term, but you’re describing a pretty specific one. One that is not very flexible and requires you to bend your system around it to make it work. Not all MQs are the same. Some offer a pletho
66.
▲
by
mprime1
4y ago
Not GP but heres what I think they meant. In the old days you could look at at raw non-rendered HTML and it would be so simple that you can render it in your head. With the advent of more sophisticated web frameworks like the one mentioned,
67.
▲
by
mprime1
4y ago
This is also pure HTML+JS without dependencies.
68.
▲
by
mprime1
4y ago
Interesting! Never thought of adding important contact info to my emergency stash, but in retrospect it is a great idea. Linked your project.
69.
▲
by
mprime1
4y ago
> Problem: Send the decryption pasword I can choose a password such as 'The name of uncle Robert's favorite movie' (i.e. something that it's easy for her, but hard for everyone else). OR I can call her, and say: 
70.
▲
by
mprime1
4y ago
Thank you for saying so. I've been noodling with the idea of trying to submit a HOPE talk.
71.
▲
by
mprime1
4y ago
YES! Better privacy for daily life. This is exactly what I had in mind. Thank you for sharing!
72.
▲
by
mprime1
4y ago
I started with CBC (without MAC) and upgraded with GCM since it was a more convenient way to provide integrity without adding the MAC step manually. I should really make sure IV/Salt are regenerated automatically after use. (there is a
73.
▲
by
mprime1
4y ago
I asked myself in the past 'how secure are password-protected zip files?', and the answers I found online all seem to agree on 'not very secure'. Rather than trying to explain why, I provided a reasonably reputable sourc
74.
▲
by
mprime1
4y ago
Time is a finicky concept with computers. Could your time-based scheme be defeated by changing the system clock on the attacker computer?
75.
▲
by
mprime1
4y ago
I use multiple ones, they're kinda compartmentalized. One for web logins, one for critical operational secrets, one for 'cold storage'. Plus variants of PortableSecret for various other odds and end use cases like emergency r
76.
▲
by
mprime1
4y ago
In order to have 100'000 potential victims, you need to have an attacker that knows 100'000 users using this and details of how what they do with it in order to convincingly phish them. That would be a very sophisticated attacker.
77.
▲
by
mprime1
4y ago
FWIW, I (author) agree wholeheartedly with everything you say. I'm just sharing a little hack I came up with. I hope some people add it to their toolchain (not my specific implementation, the idea in general). And offering a bounty see
78.
▲
by
mprime1
4y ago
Algorithms are standards recommended by institutes like NIST, so probably not going to change anytime soon. To your point, the W3C Crypto library APIs might change, and break my secrets. Unlikely but possible. I don't know that bringin
79.
▲
by
mprime1
4y ago
Fair point, I'd switch to Argon2, but it is not part of the W3C Cryptography APIs so I'd need to bring in a library or hand-roll and implementation.
80.
▲
by
mprime1
4y ago
I use a password manager for online credentials I regularly need to login across devices. There's other secrets I'd rather never upload to the cloud, with all the risks that entails. I have various other methods to store and ba
81.
▲
by
mprime1
4y ago
I'm jealous of how in 5 minutes you made it look 10X better. X-)
82.
▲
by
mprime1
4y ago
Very cool, and better UX! Added you to the project README. (I got a bunch of compliments for this project today, I hope you are enjoying seeing them too given we had the same idea)
83.
▲
by
mprime1
4y ago
Multiple pictures is doable, but adds some complexity to the generated code so decided to do without. Also, there's a trivial workaround (zip file with multiple pictures).
84.
▲
by
mprime1
4y ago
Postmortem: - Bitcoin is hard - Wallets come with sophisticated anonymization built-in - Don't create the bounty wallet 20 minutes before posting on HN (if that snafu had happened today while this post was on the front page, I would ha
85.
▲
by
mprime1
4y ago
> "Why not a password-protected zip/rar/7zip/..." on your page Great suggestion! > not having to debate this myself eh eh.. good luck with that... I think the problem is that it can be used "good" a
86.
▲
by
mprime1
4y ago
Author here. Thank you for mentioning Argon2, I didn't know about it. https://en.wikipedia.org/wiki/Argon2 > There is no reason not to use Argon2 In this case, the reason for not using Argon2 is that it's
87.
▲
by
mprime1
4y ago
> This is an ingenious idea, one that becomes obvious only in retrospect. Thank you.
88.
▲
by
mprime1
4y ago
Except this is secure :-) https://security.stackexchange.com/questions/35818/are-passw...
89.
▲
by
mprime1
4y ago
Someone else commented the same, you are not crazy
90.
▲
by
mprime1
4y ago
To be clear: I use gpg too. But I can't expect my mom or girlfriend to learn how to use it. With PortableSecret I can communicate privately with them, without installing or learning anything new.
More ›