Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mspecter
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
31.
▲
by
mspecter
8y ago
What's the plan for pairing based curves now that the Extended Tower Number Field Sieve has made BN256 unusable for many applications[1]? Do you plan on integrating BLS curves any time soon? [1] see https://godoc.org/go
32.
▲
Facebook/Cambridge Analytica: Privacy lessons and a way forward
(internetpolicy.mit.edu)
3 points
by
mspecter
9y ago
|
0 comments
33.
▲
by
mspecter
9y ago
And an update from (mostly) the same authors for 2017: https://dspace.mit.edu/handle/1721.1/97690
34.
▲
by
mspecter
10y ago
The theory is that the cops would be the ones selecting the finger. This would be no different from LE trying to crack a password, and the system permanently locking them out. However, I am also Not A Lawyer.
35.
▲
by
mspecter
10y ago
Hi, author here. Really happy (but somewhat surprised) to see this up on HN, and am generally interested in pursing this as a PhD thesis topic. If anyone has ideas or thoughts on novel systems in this arena I’d be very interested to hear ab
36.
▲
by
mspecter
10y ago
Hey Matt, just wanted to voice some support for what you're doing. The US gov't needs all the help it can get.
37.
▲
by
mspecter
11y ago
This looks interesting, I've been following the development of Radare for a while, excited for it to get production-ready. Also for those looking for an alternative to IDA Pro, Binary Ninja isn't bad, and is an order of magnitude
38.
▲
by
mspecter
11y ago
Hi, I'm a co-author on this paper, awesome to see it up on Hacker News.
39.
▲
by
mspecter
11y ago
Yeah, stuxnet used a stolen signing cert from Realtek.
40.
▲
by
mspecter
11y ago
No MIT?
41.
▲
by
mspecter
11y ago
Also check out the HackRF One! You can look at a much wider spectrum, as well as broadcast. The thing itself is 300$, and completely open. ( https://www.sparkfun.com/products/13001 )
42.
▲
by
mspecter
11y ago
Not looking for a job, but I just wanted to say that I use your product and it's probably the only reason I'm going to finish my thesis. Thank you.
43.
▲
by
mspecter
11y ago
Full Disclosure, I'm a co-author on the MIT paper that this article cites. The posted article is talking about the following two op-eds by WaPo[1,2]. What's interesting here is that in [2] they call for a national academies study
44.
▲
Congressional letters to major browsers – can you restrict government CA's?
(energycommerce.house.gov)
2 points
by
mspecter
11y ago
|
0 comments
45.
▲
by
mspecter
11y ago
I'm a grad student in the department this is replacing, but will be continuing on to the PhD program in EECS. I'm really excited to see this happening, the department it was replacing needed a bit of help and it's good to see
46.
▲
by
mspecter
12y ago
>"...meanwhile CNNIC sincerely urge that Google would take users’ rights and interests into full consideration" And that, ladies and gentlemen, is exactly what they're doing.
47.
▲
by
mspecter
12y ago
SYSTEM is roughly equivalent to root on linux. My interpretation of the article is that he managed to escalate far enough to get into the kernel, allowing him to to modify some data structure to give a user land process higher privileges. S
48.
▲
by
mspecter
12y ago
I was lucky enough to take 6.828 a few years ago, it was quite a bit of fun! Oddly, we tended to use xv6 just as a reference rather than anything else, as we built a custom version of JoS[1], which turned out to actually be an exokernel[2].
49.
▲
by
mspecter
12y ago
Shouldn't the certs related to OS / app updates be self-signed (the root of trust being Microsoft/Apple/pkgmanager*), rather than anyone in your CA? Like, a new Java update should be signed by Oracle, not signed by Joe S
50.
▲
by
mspecter
13y ago
I was lucky enough to take a short-course version of 6.001 taught by some MIT 6.001 alums over MIT's Independent Activities Period (IAP). Materials are available here: http://web.mit.edu/alexmv/6.S184/ I real
51.
▲
by
mspecter
13y ago
So, this might be naive, but for static information like the shared libs it's using, you might want to check out otool, and then pick up a good disassembler (I'm a fan of hopper, which is relatively cheap). For dynamic analysis you might wa
52.
▲
by
mspecter
13y ago
An interesting application of Pin for malware analysis / visualization is Danny Quist's Vera[1] and de-obfuscation framework[2]. It's also used in MIT's Architecture course to benchmark different architecture designs. [1] http://www.offens
53.
▲
by
mspecter
14y ago
I wonder if he'd be willing to move the entire thing to an MIT auditorium. I'm sure there's a larger audience that would like to see this speech live, and the ability to ask questions about the situation could be invaluable.
54.
▲
by
mspecter
14y ago
As someone in a long distance relationship, it would be awesome to be able to visit my SO over a weekend spontaneously if the flight price were below a certain threshold. I currently have to manually search Kayak which is a bit suboptimal.