Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nmadden
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
nmadden
2y ago
> The real thing exists largely because it makes proofs easier. I would not say that. It exists because practical padding oracle attacks (which are adaptive CCA) have been known for decades. CCA2 very much captures real-world attacks. Is
62.
▲
by
nmadden
2y ago
Right, but IND-CCA1 is kind of a toy security goal though. A sort theoretical consolation prize if you can’t achieve the real thing. And AFAICT, no actually implemented schemes do obtain even CCA1?
63.
▲
by
nmadden
2y ago
I don’t know how Swift and Koka handle things, but I’ve written a lot of Tcl that uses the same CoW reference-counting trick. (Tcl is an under-appreciated FP language: everything is a string, and strings are immutable, so it has had efficie
64.
▲
by
nmadden
2y ago
The thing that I always want to know with FHE: the gold standard of modern encryption is IND-CCA security. FHE by definition cannot meet that standard (being able to change a ciphertext to have predictable effects on the plaintext is the de
65.
▲
by
nmadden
2y ago
There’s a lot to say about the problems of JWTs, but they absolutely are extremely widely used for access tokens, and by many big players (Microsoft, Okta, etc). The JWT RFC is a product of the OAuth working group.
66.
▲
by
nmadden
2y ago
So just X25519 then?
67.
▲
by
nmadden
2y ago
If a single point matches the curve equation of a well-known curve then that’s pretty compelling evidence.
68.
▲
by
nmadden
2y ago
The About page doesn’t say anything about whether it was peer-reviewed or not (nor supplies any evidence that the author is “distinguished”). Maybe it was peer-reviewed and rejected, hence why a “distinguished” researcher would resort to se
69.
▲
by
nmadden
2y ago
What is this? Is it a preprint or a peer-reviewed article? A blog?
70.
▲
by
nmadden
2y ago
> NIST has finally understood that complex password requirements decrease security, because nobody is attacking the entrophy space - they are attacking the post-it note/notepad text file instead. Actually NIST provide a detailed rat
71.
▲
by
nmadden
2y ago
The article links to this study, and the diagrams seem to be adaptations of figure 4. https://www.dropbox.com/scl/fi/4tyqsnuof548f1wio7dgf/Factors... Edit: I don’t think cotton is the best replacement. I’m no
72.
▲
by
nmadden
2y ago
Well, wool is particularly bad, emitting way more greenhouse gases than most other textiles for equivalent fabric output. And sheep farming has quite a shocking impact on biodiversity. https://www.vox.com/future-perfect/
73.
▲
by
nmadden
2y ago
I agree with the thrust of your argument, but I just want to point out that wool is not environmentally neutral. Sheep are incredibly destructive and have historical caused a lot of degradation of habitats. https://www.monbiot.co
74.
▲
Machine Learning and the Triumph of Gofai
(neilmadden.blog)
1 points
by
nmadden
2y ago
|
0 comments
75.
▲
by
nmadden
2y ago
Elliptic curve crypto is not post-quantum. (Indeed it’s likely to be broken before RSA if cryptographically relevant quantum computers occur).
76.
▲
by
nmadden
2y ago
One of the nice things about Tufte-Latex is that refs get put into margin notes right at the point of reference. Edit: example https://mirror.apps.cam.ac.uk/pub/tex-archive/macros/latex/c...
77.
▲
by
nmadden
2y ago
I don’t remember much about the specifics of OCB. But the xchacha/xsalsa20 approach is completely generic, so can be applied to any cipher: effectively just run a large nonce through a PRF to derive a fresh key for each message.
78.
▲
by
nmadden
2y ago
(Article author here). Being able to see if two messages are equal means that it doesn’t even achieve IND-CPA security (when nonces repeat). Although this may seem like a small loss of security, it can have significant consequences. For exa
79.
▲
by
nmadden
2y ago
I did some work with Rete for my undergraduate dissertation. One thing I remember about the original paper is that it defines the algorithm in terms of a kind of virtual machine, where specific instructions implement the matching process. I
80.
▲
by
nmadden
2y ago
And then you find out about special soundness and that this is not only expected behaviour, but crucial to the security definitions and you realise that signatures are absolutely cursed.
81.
▲
by
nmadden
3y ago
Do they do attestation by default? I thought for Apple at least that was only a feature for enterprise managed devices (MDM). Attestation is also a registration-time check, so doesn’t necessarily constrain where the passkey is synced to lat
82.
▲
by
nmadden
3y ago
Well, SQIsign signatures are about the same size (204 bytes) than RSA-2048 (256 bytes). So ok, but most people who care about size on the wire have moved to EC sigs, which are much smaller (64 bytes). And “fast to verify” is not really true
83.
▲
by
nmadden
3y ago
Well, there are PQC (public key) signature schemes based on hash functions, but they all have large signatures (in the multi-kB range) and other drawbacks (eg being stateful). Moving to a MAC is also not a crazy idea in a lot of deployments
84.
▲
by
nmadden
3y ago
Oops, that’s a typo.
85.
▲
by
nmadden
3y ago
I wrote about putting secrets in URLs a few years ago: https://neilmadden.blog/2019/01/16/can-you-ever-safely-inclu...
86.
▲
by
nmadden
3y ago
Surprised not to see Little Bobby Tables make the list. I used to see that everywhere. https://xkcd.com/327/
87.
▲
by
nmadden
3y ago
> Many algorithms have been studied, but they are significantly less efficient than those used today. Actually, several post-quantum algorithms are considerably faster than current algorithms. But they have much larger ciphertexts, sig
88.
▲
by
nmadden
3y ago
Personally, I feel that HAC has aged surprisingly well compared to other books of that era. It’s focus on theory and fundamentals helps there. I still think it has some of the best introductions to cryptography topics. But, yes, read it in
89.
▲
by
nmadden
3y ago
Just to be clear, you are asking how all this evidence refutes your totally unsupported assertion that 3DES is “perfectly secure” against the NSA? When even the NSA, who co-designed DES in the first place, forbid its continued use?
90.
▲
by
nmadden
3y ago
You can of course use Macaroons with OAuth, which was something that I tried to get the OAuth WG interested in, with little success. But I did get it added to my then employer’s AS product: https://neilmadden.blog/2020
More ›