Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nmadden
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
181.
▲
by
nmadden
6y ago
I’m not sure what the state of the art is, but certainly Prolog has been used for these kinds of things. Specialised dialects like ECLiPSe [1] have lots of options for solving constraint optimisation problems. [1]: http://eclipse
182.
▲
by
nmadden
6y ago
It’s only 3rd-party cookies, right?
183.
▲
by
nmadden
6y ago
Well like any large codebase there will be things that need improving. The handful of places where we have similar issues are relatively unlikely to cause a real problem in the near future.
184.
▲
by
nmadden
6y ago
Funnily enough, I actually suggested we adopt something like GREASE for OAuth parameters: https://mailarchive.ietf.org/arch/msg/oauth/Rqxs-QDqqdQkt36S... There wasn’t a lot of support.
185.
▲
by
nmadden
6y ago
As an example, rejecting unrecognised query parameters can cause ossification of web protocols. For example, I do a lot of work with OAuth and it is accepted security best practice now to use PKCE [1] on all authorisation requests [2]. Howe
186.
▲
by
nmadden
6y ago
That’s an ok(ish) definition of indistinguishability for a block cipher, but not for a mode of operation like ECB.
187.
▲
by
nmadden
6y ago
These kinds of patterns are present in input data quite often - eg fixed headers, markup etc. As usual, there’s even an xkcd on it: https://xkcd.com/1286/
188.
▲
by
nmadden
6y ago
Which is the classic illustration that ECB is _not_ indistinguishable from random, even to a casual observer.
189.
▲
by
nmadden
6y ago
The Tower Number Field Sieve is only applicable to pairing-based ECC though, right? It doesn't impact the security of the curves used in most mainstream crypto (Curve25519, NIST P-256 etc).
190.
▲
by
nmadden
6y ago
Tcl has had sandboxed interpreters with resource limits for a long time [1]. You can even remove built-in commands (for/while etc) if you want to. You can limit the language to a purely declarative subset and selectively expose command
191.
▲
by
nmadden
6y ago
https://www.logicmatters.net/tyl/
192.
▲
by
nmadden
6y ago
Firstly, setting the domain attribute on a cookie explicitly allows sub-domains. You want to leave that off to enable host-only cookies. But secondly, as I just said the host/domain on the cookie does nothing at all to prevent cross-or
193.
▲
by
nmadden
6y ago
That doesn't impact CSRF at all. If I send a request from a page on foo.example.com to api.example.com your browser will send those cookies no matter how tightly scoped they are because the destination of the request matches the cook
194.
▲
by
nmadden
6y ago
Subdomain hijacking is not rare for the simple reason that websites are built by marketing departments. E.g., here’s Hanno Böck tweeting about a subdomain takeover he found at Kaspersky just recently: https://twitter.com/h
195.
▲
by
nmadden
6y ago
This isn't true. Although SameSite is a good defence in depth, it provides no protection against CSRF from sub-domains (subdomain hijacking is fairly common), or in older browsers. It also is incompatible with some site features - e.g.
196.
▲
by
nmadden
7y ago
Well this is trivially true: here's my domain specific language "main". It has a single keyword "main" that when executed runs the main method of the 100 million line codebase (which is the language runtime).
197.
▲
by
nmadden
7y ago
Right, and it’s not just Safari. This is the current complexity of User-Agent sniffing that the SameSite change requires if you need to disable it: https://www.chromium.org/updates/same-site/incompatible-clie...
198.
▲
by
nmadden
7y ago
I updated the blog post, I had misunderstood that part of the age spec.
199.
▲
by
nmadden
7y ago
Yes, but no such tool exists (yet) as far as I’m aware. You also need to tie the chunks together so that they cannot be rearranged, duplicated, or deleted. You also need to be careful about what you think this tells you. For example, suppos
200.
▲
by
nmadden
7y ago
If this is all you need use age with a password/passphrase (scrypt). It does exactly what you want.
201.
▲
by
nmadden
7y ago
Yes, I raised an issue on github. But I think there are general points raised that are more widely applicable than just to age.
202.
▲
by
nmadden
7y ago
I wrote up some more detailed notes here: https://neilmadden.blog/2019/12/30/a-few-comments-on-age/
203.
▲
by
nmadden
7y ago
An example of why I think this is important. Adam Langley’s post that is linked from the spec [1] talks about cases where people want to do things like: decrypt file | tar xz Elsewhere in these comments somebody also mentioned the
204.
▲
by
nmadden
7y ago
Is there a detailed description of the security goals and crypto rationale anywhere? For example, it seems that if you use scrypt then you get fully authenticated encryption: the message must have come from somebody who knows the password (
205.
▲
by
nmadden
7y ago
It’s also worth pointing out that non-repudiation requires stronger properties than cryptography alone can guarantee. If I surreptitiously leak my private key onto the internet I can later plausible deny that I signed messages. (The Signal
206.
▲
by
nmadden
7y ago
It is, although COSE is significantly different to JOSE in many ways.
207.
▲
by
nmadden
7y ago
That’s not correct. Latin-1 and UTF-8 are both compatible with 7-bit ASCII but they are not the same encoding. For instance é (e acute) is a single byte in latin-1 (0xe9) but is two bytes in UTF-8 (0xc3 0xa9)
208.
▲
by
nmadden
7y ago
No, I'm not defending PGP. Even without the automation, every PGP-encrypted email almost certainly results in a bunch of internal plaintext emails between employees that could easily accidentally cc the wrong person, etc. I'm just
209.
▲
by
nmadden
7y ago
I used to get about 1 or 2 PGP-encrypted emails with security bug reports per year when I managed this for my employer. There's a dedicated team that receives security reports now, with email feeding into an automated ticketing system
210.
▲
by
nmadden
7y ago
With any algorithm complexity analysis you have to define what the inputs are considered to be. For cryptography, algorithms are designed to be constant-time with respect to the non-secret inputs. The secret inputs (which you are trying to
More ›