Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nmadden
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
121.
▲
by
nmadden
4y ago
It’s still legal in England and Northern Ireland, but smacking children is banned in Scotland and Wales.
122.
▲
by
nmadden
4y ago
That's been my experience, and chimes with what the author writes at the end about performance. I remember trying to stream a few hundred MB of CSV data with Prolog a few years ago and giving up after not being able to either write or
123.
▲
by
nmadden
4y ago
If you’re not actually remembering these passwords and you want to increase security from 95 to 113 bits, then it is much more efficient to simply add a few more characters to the password. pwgen -s 19 provides the same extra protection as
124.
▲
by
nmadden
4y ago
If you’re the sort of person that already uses 72-bit passwords and you want to make sure something is secure over the long-term, then the best thing you can do is add more bits of entropy to that password. Adding extra characters increases
125.
▲
by
nmadden
4y ago
So, Argon2 is great and everything, and in an economic security model it certainly is more secure than PBKDF2, given what we currently know about costs of operations. However, it doesn't really fundamentally change the argument of the
126.
▲
by
nmadden
4y ago
Right. I believe Apple also do something similar with their built-in password manager: the password/PIN alone is not enough to decrypt, you also need access to a per-device secret key. FWIW, I am the article author and I use 1Password
127.
▲
by
nmadden
4y ago
Would you be happy if a service you used encrypted your private data with 56-bit DES encryption? Because that is basically what you are saying. If a password is estimated to have 40 bits of entropy on average (as per Wikipedia), then adding
128.
▲
by
nmadden
4y ago
This is sad news. My condolences. I enjoyed his blog very much. He will be missed.
129.
▲
by
nmadden
4y ago
You could just truncate SHA-256 to 20 bytes for that matter.
130.
▲
by
nmadden
4y ago
As I understand it, the MITM attack is relying on the lack of authentication rather than lack of confidentiality. The attacker can go to LE and get a challenge file (AIUI), which they host on a fake version of the website. They then use DNS
131.
▲
by
nmadden
4y ago
> For HTTP challenge, yes its true. I know very little about ACME, but surely this (not having a cert yet) is only true the very first time you get a cert, or if you let the existing cert expire?
132.
▲
by
nmadden
4y ago
An explosion of witches is usually down to too much eye of newt.
133.
▲
by
nmadden
4y ago
Ha! Wow, looks like there is a redirect when the referrer is HN…
134.
▲
by
nmadden
4y ago
Coda Hale’s old article on the topic is still good: https://codahale.com/a-lesson-in-timing-attacks/ (Note that Java’s MessageDigest.isEqual has been constant time since shortly after that article and you should use it
135.
▲
by
nmadden
4y ago
Tracking units of measurement is so important for security (bits vs bytes vs BN_ULONGs). There was a bug a few years ago with Bouncy Castle using 16 bit vs 16 byte keys, IIRC, due to a similar mixup. Ideally units are captured in the type s
136.
▲
by
nmadden
4y ago
BouncyCastle has its own implementation of ECDSA, and it’s not vulnerable to this bug.
137.
▲
by
nmadden
5y ago
I’m sure reproducible builds has some small part to play in supply chain security, but I think it is massively over-emphasised. My own view is that all of supply chain security is somewhat of a red herring anyway. I don’t want to have to tr
138.
▲
by
nmadden
5y ago
> As an example of where this central point of failure becomes problematic, attackers can modify a package to include malware in what is known as a digital supply chain attack. What we really want, and what no package manager can give us
139.
▲
by
nmadden
5y ago
This is a good article about the benefits of conditions and restarts, but I've always been a bit suspicious of adding special-purpose mechanisms for this. I think you can do something similar with normal functions (closures) and dataty
140.
▲
by
nmadden
5y ago
He said security-critical not safety-critical. Security-critical implies an adversarial setting.
141.
▲
by
nmadden
5y ago
Configuring your webserver/reverse proxy to talk HTTP/2 to backend appservers is a good improvement against request smuggling. (If they support it, sadly not guaranteed). The binary format is much less ambiguous. There is a talk b
142.
▲
by
nmadden
5y ago
Well indeed, but the hyperlinks here are just surfacing the coupling that already exists between those services. Making explicit an already implicit coupling. Two other points: - you can use HATEOAS to let one microservice discover the li
143.
▲
by
nmadden
5y ago
The format that Digest uses to transmit passwords is not a lot better than plaintext. It’s a simple salted hash, which is easily brute-forced offline unless the password is strong.
144.
▲
by
nmadden
5y ago
Why do you think it’s hard for one microservice to generate links to another microservice? The alternative is that all the clients are tightly coupled to both of them.
145.
▲
by
nmadden
5y ago
Don’t you just return links that refer to the other service? (ie absolute URLs). That is kind of the point of hyperlinks: the service hosting a resource can change, and you just change the links you serve rather than changing lots of hard-c
146.
▲
by
nmadden
5y ago
Right. SCRAM is only secure if you already have a secure channel - eg if you’ve already done a TLS handshake with certificate auth. A PAKE is secure on its own. However, IMO most people saying they need a PAKE could use SCRAM instead and ac
147.
▲
by
nmadden
5y ago
Digest should just die. It’s a terrible standard that makes it essential impossible to store passwords securely on the server.
148.
▲
by
nmadden
5y ago
Well SHA-3 is a hash function, and indeed somewhat slow in software. But the team have since enormously expanded the primitives based on the same core design, with much better performance: https://keccak.team/sw_performance.
149.
▲
by
nmadden
5y ago
Aside from the various technical reasons others have given, I would like to say please have a look at the underlying design of SHA-3 - it’s really elegant, with so many applications beyond just hash functions. Ironically, I feel like SHA-3
150.
▲
by
nmadden
5y ago
Yes - technically you don't need to escape : in most places, but many implementations will do so anyway as they use a single encoding method for all URI components. (And if you don't encode these things where they are not required
More ›