Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pbsd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
21 ms
·
151.
▲
by
pbsd
9y ago
One thing that tends to get overlooked in these discussions is what being 'a decade ahead' really means. Suppose you go back to 2007. What ciphers are you able to break now that you couldn't then? In the past decade, I can th
152.
▲
by
pbsd
9y ago
This curl function actually came up in conversation with someone about a month ago. We figured that there was no way the core transformation was secure, and that was about the extent of our interest in it.
153.
▲
by
pbsd
9y ago
(Generalized) Feistel networks have to be neither balanced nor over bits (see, e.g., [1]), so you could conceivably devise a 'perfect' permutation for any particular resolution. For example, with 320x200, you'd do something l
154.
▲
by
pbsd
9y ago
I don't think it was the NSA either, but do note that Juniper itself had originally Q set to a different value than the recommended one, and then _that_ value was modified.
155.
▲
by
pbsd
9y ago
We can agree on that. But now I am completely lost as to what your original point was...
156.
▲
by
pbsd
9y ago
u8 gets promoted to signed int before the shift. That he only used unsigned types is irrelevant.
157.
▲
by
pbsd
9y ago
There's no sign-extension involved. Let's say the input is (uint8_t)128. This gets promoted to (int)128, which is then shifted 24 bits to the left. If the input was (int8_t)128, it would get sign-extended into (int)-128, but tha
158.
▲
by
pbsd
9y ago
For what it's worth, the size-prefixed jcc/call binutils bug had already been fixed a couple of years ago: https://sourceware.org/bugzilla/show_bug.cgi?id=18386
159.
▲
by
pbsd
9y ago
For what it's worth, I just went back to an earlier version (10240) of win32kbase.sys, and the search is indeed a lot simpler...it's essentially a flat linear table search (to be clear, it's still iterating through every GDI
160.
▲
by
pbsd
9y ago
Yeah, it's proportional to the total number of GDI objects. Approximately: DWORD HmgNextOwned(DWORD index, DWORD pid, HANDLE * handle) { GDI_TABLE_ENTRY entry; GreAcquireHmgrSemaphore(); // GetNextEntryIndex i
161.
▲
by
pbsd
9y ago
HmgNextOwned doesn't do, by itself, all that much. There is some mild pointer-chasing, but not too horrible. All it does is to go through the global GDI handle table and look for handles owned by the terminating process. It is used loo
162.
▲
by
pbsd
9y ago
The typical way you'd solve that would be to take [K * pi 1 0 0] [K * e 0 1 0] [K * sqrt(2) 0 0 1] [K * 194.927424491 0 0 0] for some large-ish K, say 2^20, and look for a short(est) vector of this latti
163.
▲
by
pbsd
9y ago
According to the Logjam paper, the 1024-bit individual logarithm would cost around 30 (parallelizable) core-days once the group precomputation is over with. Unless they're being exceedingly stingy with their hardware, 30 core-days (les
164.
▲
by
pbsd
9y ago
I didn't realize that was in there, but yes.
165.
▲
by
pbsd
9y ago
The more important point to take away from this paper is not that 1024-bit is already considered broken, so this doesn't matter. It's that the cost of 2048-bit DH---which is used and recommended today, and will stick around foreve
166.
▲
by
pbsd
9y ago
sage: p=2^255-19 sage: sqrt(GF(p)(-486664)) 6853475219497561581579357271197624642482790079785650197046958215289687604742 The formula in Wikipedia is not wrong, but note that it maps E_{a,d} to M_{A, B} with B = 4/(a -
167.
▲
by
pbsd
9y ago
Your conversion between Edwards and Montgomery is not quite correct. I suspect that is why you're getting different results (though I didn't really go over the whole thing). RFC 7748 does include the correct conversion routines in
168.
▲
by
pbsd
9y ago
What exactly is the problem? Converting between Montgomery and twisted Edwards is well documented by now, for example in [3, Theorem 3.2] or RFC 7748. The descriptions in, e.g., [1, §3.2] or [2, §4.3] for the Montgomery y-recovery trick are
169.
▲
by
pbsd
9y ago
I haven't seen a description of it anywhere that I can think of. The driver lives in C:\Windows\system32\mcupdate_{genuineintel,authenticamd}.dll. All it does is detect which CPU it's running on, and load the appropriate microcode
170.
▲
by
pbsd
9y ago
The loop needs to be short because the loopback buffer is only active in loops of 64 or fewer entries (usually fewer real instructions, something like 40 or so). Moreover, Skylake introduced one loopback buffer per thread, instead of the pr
171.
▲
by
pbsd
9y ago
Windows does have a microcode update driver, as you would expect, so it can fix this. However, looking at the microcode update driver on an updated Windows 10 as of right now, I don't see a recent enough microcode version to fix it. Th
172.
▲
by
pbsd
9y ago
Almost certainly not the former, no. At best the code would be "supplementary material", which reviewers are not required to go over.
173.
▲
by
pbsd
9y ago
For what it's worth, BLAKE2 has the original number of rounds of BLAKE: 12 and 10. It was increased to 16 and 14 before the 3rd round of the competition, because BLAKE was fast enough that increasing the round numbers like this would s
174.
▲
by
pbsd
10y ago
That's a criticism I'm entirely on board with, and is not limited to linear algebra libraries. HTTP client libraries are worse, there's not a single good one.
175.
▲
by
pbsd
10y ago
std::valarray does not have multidimensional support at all. In fact, std::valarray is a relatively abandoned part of the standard library. You'll have to go with one of the 3rd party libraries for better support. My point was not so m
176.
▲
by
pbsd
10y ago
Not to mention all of that array behavior is available on the standard C++ library with std::valarray<T>, e.g., https://godbolt.org/g/JBSvuH . There was talk of a more thorough standard multi-dimensional array typ
177.
▲
by
pbsd
10y ago
That won't help much; you can zero the entire final state easily, e.g., with the message IV0 IV1 IV2 IV3 (or by xoring the latest diffuse() output back into the state), in which case you get diffuse(0) = 0 and with your finalization fu
178.
▲
by
pbsd
10y ago
The 2^64 attack there is for 128-bit ECC, which is not hypothesis---it's a standard Pollard rho attack. That is, the entire purpose of rho is to find a "key collision" aP + bQ = cP + dQ, from which we can immediately derive t
179.
▲
by
pbsd
10y ago
> but everyone was happy with it. For what it's worth, that worst-of-all-worlds solution was what made me give up on Rust back on 0.9, and I haven't really missed it since.
180.
▲
by
pbsd
10y ago
Grover's algorithm does not help much against collisions; Brassard-Hoyer-Tapp (which does use Grover internally) does (at ~2^85 time), but requires a large (also ~2^85) amount of quantum storage. Basically: generate ~2^85 random string
More ›