Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
paragon_init
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
You Wouldn't Base64 a Password! (Cryptography Concepts for Developers)
(paragonie.com)
1 points
by
paragon_init
11y ago
|
0 comments
62.
▲
You Wouldn't Base64 a Password (Cryptography Concepts for the Average Developer)
(paragonie.com)
2 points
by
paragon_init
11y ago
|
0 comments
63.
▲
by
paragon_init
11y ago
When PHP 7 is released later this year, PHP users will finally be able to quickly and easily leverage a CSPRNG in their projects. random_bytes(int) - Generate a string of random bytes from the OS (e.g.. /dev/urandom)
64.
▲
Show HN: Polyfill for random_bytes() and random_int() in PHP 5 projects
(github.com)
7 points
by
paragon_init
11y ago
|
1 comments
65.
▲
Actually Secure “Remember Me” Checkbox – Yes, They Are Possible [PHP]
(paragonie.com)
1 points
by
paragon_init
11y ago
|
0 comments
66.
▲
Why and How to Encrypt Sensitive Data in Web-Based Applications [PHP]
(paragon.enterprises)
8 points
by
paragon_init
11y ago
|
0 comments
67.
▲
A Guide to Secure Data Encryption in PHP
(paragonie.com)
1 points
by
paragon_init
11y ago
|
0 comments
68.
▲
Guide to Secure Data Encryption in Web Applications with PHP
(paragonie.com)
3 points
by
paragon_init
11y ago
|
0 comments
69.
▲
by
paragon_init
11y ago
It might be worth noting that 'sarciszewski was the author of that remark.
70.
▲
by
paragon_init
11y ago
Agreed. It's a red flag for "expect more exploitable issues to be found around the corner" and can result in biased distributions, but it by itself does not break a RNG.
71.
▲
[PHP] Secure User Authentication with "Remember Me" Checkboxes
(paragonie.com)
1 points
by
paragon_init
11y ago
|
0 comments
72.
▲
[PHP] Secure User Authentication with “Remember Me” Checkboxes
(paragonie.com)
1 points
by
paragon_init
11y ago
|
0 comments
73.
▲
Generate Secure Random Strings and Integers in PHP
(paragonie.com)
1 points
by
paragon_init
11y ago
|
1 comments
74.
▲
Quick Answers to Development and Application Security Questions
(paragonie.com)
2 points
by
paragon_init
11y ago
|
0 comments
75.
▲
How to Safely Generate Random Strings and Integers in PHP
(paragonie.com)
1 points
by
paragon_init
11y ago
|
0 comments
76.
▲
by
paragon_init
11y ago
Encrypt-Then-MAC just makes sense. If the first thing you do when you receive a blob of encrypted data is check that it's authentic (in constant-time!), the attack surface is greatly reduced.
77.
▲
by
paragon_init
11y ago
I think that's why the statement was "be careful with" rather than "don't"
78.
▲
by
paragon_init
11y ago
If you build something open source and it gets incredibly popular, security researchers will also probably come to you. This creates its own problems, of course. (Can't have problems without PR.)
79.
▲
by
paragon_init
11y ago
Awesome. We're looking forward to developing with PHP 7. :)
80.
▲
by
paragon_init
11y ago
https://www.imperialviolet.org/2014/06/27/streamingencryptio... Thomas's answer probably has to do with the risks of decrypting a stream and being unable to authenticate it first. (See also: the Cryptogr
81.
▲
by
paragon_init
11y ago
If you are a business, then definitely yes. But the average self-taught developer will not have the resources available to hire a security consultant. Instead of throwing money at the problem, you can instead choose to teach yourself more a
82.
▲
by
paragon_init
11y ago
CTR saves you the trouble of padding your plaintext before encrypting, thus eliminating an entire class of cryptography attacks (i.e. padding oracles). The security margins of CBC and CTR are otherwise similar. GCM is far more preferred to
83.
▲
by
paragon_init
11y ago
We've implemented your recommendations. Glad to hear you liked our post even without the suggested improvements.
84.
▲
Using Encryption and Authentication Correctly
(paragonie.com)
49 points
by
paragon_init
11y ago
|
18 comments
85.
▲
by
paragon_init
11y ago
Happy to see that it's open source, too. https://github.com/nehbit/aether-public
86.
▲
How to Prevent XSS Vulnerabilities in PHP Projects
(paragonie.com)
2 points
by
paragon_init
11y ago
|
0 comments
87.
▲
Reasoning by Lego: A wrong way to think about cryptography
(cryptofails.com)
42 points
by
paragon_init
11y ago
|
13 comments
88.
▲
by
paragon_init
11y ago
Yep, and it probably deserves its own Show HN entry from the author. I bet it would get a lot of positive attention.
89.
▲
by
paragon_init
11y ago
Yes, curated lists can become burdensome. We try to stay on top of change requests and are always looking for more material to add.
90.
▲
by
paragon_init
11y ago
Thanks for the removal recommendation. Would you prefer that we remove the statements crediting your Amazon reading list as well?
More ›