Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mstef
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
mstef
8y ago
the main dev of tox is kinda toxic to it's own project with kneejerk responses like these: https://github.com/TokTok/c-toxcore/issues/426 and https://github.com/irungentoo/toxcore&#x
62.
▲
by
mstef
8y ago
it has been done ages ago, is called the maidenhead locator system, it is better in many ways, for example you can choose the granularity of the grid providing some privacy: https://en.wikipedia.org/wiki/Maidenhead_Loca
63.
▲
by
mstef
9y ago
that would be less funny and lack the educational aspect.
64.
▲
Warning.js – show respect towards your visitors with this widget
(asciimoo.github.io)
9 points
by
mstef
9y ago
|
4 comments
65.
▲
by
mstef
9y ago
searx protects your privacy much better.
66.
▲
by
mstef
9y ago
you should have a look at searx instead, is also from the eu, and is completely free software, so free, that you as a user can demand the source code of the instance running due to the agpl license.
67.
▲
What the CIA hack&leak teaches us about the failure of current Cyber doctrines
(conspicuouschatter.wordpress.com)
1 points
by
mstef
10y ago
|
0 comments
68.
▲
by
mstef
10y ago
according to http://keys.mayfirst.org/pks/lookup?op=stats there's currently 4594571 keys on the bulk of public keyservers. considering the rumors that facebook and others also do signal and their user base is arou
69.
▲
by
mstef
10y ago
some of these tools actually fully replace pgp (see opmsg for example) however that is actually a very low bar to master. it seems pgp is seen as a silver bullet handling all use-cases like a charm, this is far from reality, actually it fai
70.
▲
by
mstef
10y ago
if you knew the story you'd know that Phil did actually an abysmal implementation which had to fixed by others.
71.
▲
by
mstef
10y ago
pgp does not provide anonymity at least not in the widely accepted form. every message has the recipient keyid in plaintext, unless you --throw-keyids but then you run into incompatibilities and inconveniences that make the whole exercise u
72.
▲
by
mstef
10y ago
the protocol is very generic and does not require anything related to phones. it is actually 3 parts, a key exchange, a signature mode and a ratchet. how you combine these is up to you. the app is one way to combine them with phones. there&
73.
▲
by
mstef
10y ago
count the keys on the keyservers, apply some multiplier, chances are that it's still less than signal users today.
74.
▲
by
mstef
10y ago
check out opmsg how it achieves compatibility with gnupg and imagine a tool that actually looks like gpg but figures out which crypto backend to call.
75.
▲
by
mstef
10y ago
signal the app exists and is much more used than already than pgp ever was. it's a different story that i don't recommend it myself, only the protocol.
76.
▲
by
mstef
10y ago
the listed examples all exist. signal is already more widely used than pgp ever was in the last 25 years.
77.
▲
by
mstef
10y ago
opmsg does masquerade as gnupg on the cli, if you take this further you could create a gnupg chameleon which detects what keys are available or what the input is based on auxillary info and then invoke the appropriate tool (which might be g
78.
▲
PGP needs to be retired in honor
(ctrlc.hu)
133 points
by
mstef
10y ago
|
92 comments
79.
▲
by
mstef
10y ago
strange, my mistake i guess. sorry for the noise
80.
▲
by
mstef
10y ago
deleted, mistake
81.
▲
by
mstef
10y ago
not the curve25519 based ones, the symmetric salsa based ones should be.
82.
▲
by
mstef
10y ago
the problem with "transparent to the end user" is a variation of Geers Law: "Any security technology whose effectiveness can't be empirically determined is indistinguishable from blind luck." if you do not control y
83.
▲
by
mstef
10y ago
the problem is not that "pgp doesn't use 25519" the problem is the openpgp format as per rfc4880 and the whole thing being from the naive nineties, not suited for advanced adversaries we have since then.
84.
▲
by
mstef
10y ago
i also gave a talk on pbp: https://www.youtube.com/watch?v=Kl_gLMef1mI
85.
▲
by
mstef
10y ago
also there will be soon (in 1-2 months) a hardware token available based on this. look for project: PITCHFORK
86.
▲
by
mstef
10y ago
back in the days i consulted with tom on pcp a bit. Why, because i took it a bit further with: https://github.com/stef/pbp - there's even an axolotl implementation available - but not integrated yet: https:/
87.
▲
by
mstef
10y ago
nice! this could also rate the hosts regarding their tracking/adserving history perhaps.
88.
▲
by
mstef
11y ago
utterson is in fact an established 7 year old static blog engine: https://github.com/stef/utterson/ for avoiding confusion please change your projects name. thx,s
89.
▲
Memspector: Inspect memory usage of Python functions
(github.com)
27 points
by
mstef
11y ago
|
1 comments
90.
▲
by
mstef
12y ago
a privacy respecting and much more polished search engine you might like is searx: https://github.com/asciimoo/searx
More ›