Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mstef
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
mstef
3y ago
yes, back in the days CEO (Corporate Europe Observeratory https://corporateeurope.org/ ) alter-eu ( https://www.alter-eu.org/ ), and a bunch of other NGOs where using (and also sponsoring it). But it is also w
32.
▲
by
mstef
3y ago
a few years ago i was maintaining lobbyfacts. ama
33.
▲
by
mstef
4y ago
what a coincidence this article was just 4h ago linked here: https://news.ycombinator.com/item?id=34308734 and is similar policymaker influencing pseudo science conflating correlation and causation...
34.
▲
by
mstef
4y ago
yes, and that is more of a lobbyist paper aimed at policymakers, it refers to some TNO studies as the "scientific" basis for the claims, but those studies are not publicly available, at least they're not linked directly in th
35.
▲
by
mstef
4y ago
you should try omnom, v1 has been created when del.icio.us was sold. it has been revamped into a v2 earlier this year: https://github.com/asciimoo/omnom distinguishing features: selfhosted, in-browser-snapshots-as-curr
36.
▲
by
mstef
4y ago
let me quote NIST Special Publication 800-63B: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecret > Verifiers SHALL require subscriber-chosen memorized secrets to be at least 8 characters in length. Verifiers
37.
▲
by
mstef
4y ago
do you guys have a whitepaper about how you do crypto?
38.
▲
by
mstef
4y ago
searx is doing exactly this, has opensearch support so can be added to your browser search bar.
39.
▲
by
mstef
5y ago
some time ago i made a comparison between different jailing tools: https://ctrlc.hu/~stef/jails.txt
40.
▲
by
mstef
5y ago
you might want to read the whitepaper regarding bruteforce attacks: https://github.com/stef/pwdsphinx/blob/master/whitepaper.org...
41.
▲
by
mstef
5y ago
what does rotation mean? you can change your passwords, both the "master" which i rather call input, and the output password as well. i mean you can have a new output password without changing your input password. and no although
42.
▲
by
mstef
5y ago
the thing is. sphinx is designed by people with outstanding crypto protocol design credentials, the guys who came up with hmac and hkdf cryptographic primitives. the nice thing about sphinx is that it comes with "information theoretic
43.
▲
by
mstef
5y ago
not sure, by looking at the sqrl wikipedia page it's not immediately obvious how this works. but yeah, "derived password generator" sounds correct, with one important detail. the there is (almost) no state at the client, and
44.
▲
by
mstef
5y ago
There's a new kid in town: https://www.ctrlc.hu/~stef/blog/posts/sphinx.html pro: it has much stronger security guarantees than the rest, it's self-hosted, but you can use other peoples servers! con
45.
▲
by
mstef
5y ago
my .vimrc is originally from him, it still says: > " Last update: Thu Dec 10 02:02:02 CET 1998 thank you so much sven! r.i.p.
46.
▲
by
mstef
5y ago
if you read the linked page, you will see the story and how the nsa replaced the DES algorithm with a completely new algorithm.
47.
▲
by
mstef
5y ago
i am the author of a password manager which you don't have to trust: https://www.ctrlc.hu/~stef/blog/posts/sphinx.html
48.
▲
by
mstef
5y ago
see the section "Different Versions" on this page: https://cryptomuseum.com/crypto/philips/px1000/
49.
▲
by
mstef
5y ago
thank you! may i return the compliments? i love playing on cryptohack.org so many fun and educational challenges! kudos!
50.
▲
by
mstef
5y ago
sorry, no. but there is an emulator[1], so you can test the roms, or you can write your own code and test it without having the hw. [1] https://github.com/iddq/sim68xx/tree/px1000
51.
▲
by
mstef
5y ago
it's a pocket telex from the early 80ies, you can read more about the device here: https://www.cryptomuseum.com/crypto/philips/px1000/index.htm
52.
▲
by
mstef
5y ago
fascinating details, happy to have stirred up these memories!
53.
▲
by
mstef
5y ago
also interesting might be this generic link unrelated to the NSA backdoor: https://cryptomuseum.com/crypto/philips/px1000/
54.
▲
by
mstef
5y ago
afaik the firmware was developed by philips ufsa[1] based on directions (test vectors?) by the NSA, lots of effort was put into making the algo run efficiently on the CPU in the px1000. [1] https://www.cryptomuseum.com/crypt
55.
▲
by
mstef
5y ago
nice summary of my post! thank you very much
56.
▲
by
mstef
5y ago
author of the break here, ama.
57.
▲
by
mstef
5y ago
i mean an algebraic full key recovery out of 17 ciphertext chars is nothing else but catastrophic. and i'm sure this can be done much more efficiently.
58.
▲
by
mstef
5y ago
actually since large parts of my addendum blog post were quoted here, here is another quote: > lets me conclude that the PX1000cr algorithm is indeed a confirmed backdoor. I guess, me and the cryptomuseum people had a misunderstanding ab
59.
▲
by
mstef
6y ago
Crypto AG. https://archive.is/d6z6l
60.
▲
by
mstef
7y ago
no, it is not. you are mixing up the two cases, one were there was no condom indeed with S.W., and the other case with the other woman A.A. where the condom was allegedly damaged.
More ›