Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pbsd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
23 ms
·
181.
▲
by
pbsd
10y ago
0F 1A and 0F 1B have recently become memory bound verification instructions, as part of MPX. So really, only 0F 1F is likely to be long-term safe to use as a multibyte NOP. Likewise, after Pentium 4 REP NOP (F3 90) became PAUSE, the spinloc
182.
▲
by
pbsd
10y ago
Well, I suppose you could cite Miller and Koblitz on that (mostly Miller). This was the mid-80s, when progress in index-calculus algorithms was in full force. So they introduce elliptic curves, and basically say 'look, this problem see
183.
▲
by
pbsd
10y ago
I think progress against RSA is more likely, unless Shor happens first and kills everyone. I also hope to see a O(n^2) matrix multiplication algorithm within my lifetime. My point was not to defend RSA, but to point out that Cohn's arg
184.
▲
by
pbsd
10y ago
The argument laid out by Cohn also works against elliptic curves: the discrete log is not NP-hard either, and if anything even less people have tried to attack it than factorization (according to Cohn, subexponential factorization only happ
185.
▲
by
pbsd
10y ago
Some extra context: here's Maurer [1, §4], in 1991, describing the same property exploited here, on a generic class of CBC-like functions. Also, Knudsen [2, §4.4] on his 1994 PhD thesis. I believe Schneier et al.'s 'Practica
186.
▲
by
pbsd
10y ago
I don't think it's an oversight; the implementation calls `checked_add` and `checked_mul` explicitly -- https://github.com/rust-lang/rust/blob/1744c46e47434d8c0b63a...
187.
▲
by
pbsd
10y ago
GNU confirmed as Equation Group: https://godbolt.org/g/EDvrn2 . Wait, MSVC does this too---they're all in cahoots! $LL8@f: ; Line 4 mov ecx, DWORD PTR [edx+eax*4-4] sub ecx, 1640531527
188.
▲
by
pbsd
10y ago
https://www.tau.ac.il/~tromer/acoustic/
189.
▲
by
pbsd
10y ago
AES-NI uses the XMM register bank, but not necessarily any vector execution unit. Furthermore, it only uses the lower 128 bits of vector registers, whereas the linked document is referring to instructions that use the upper lanes as well,
190.
▲
by
pbsd
10y ago
We can demonstrate more forcibly that any such statement would be unjustified. For suppose we could be sure of finding such laws if they existed. Then given a discrete-state machine it should certainly be possible to discover by
191.
▲
by
pbsd
10y ago
For the sake of pedantry, SHA-512 eats 1024 bits, resp. 512 bits for SHA-256, at a time. It's the chaining variables that are of those lengths.
192.
▲
by
pbsd
10y ago
I think even Intel is confused about their own extensions at this point. The E7 and E5 Xeons are Haswell systems that slightly speed up SHA-256 and 512 with the introduced BMI2 RORX instruction. As far as I know there are no SHA extensions
193.
▲
by
pbsd
10y ago
SHA-512 should be much faster than SHA-256 on AVX2-capable processors. Go's implementation is subpar; try OpenSSL instead. On Skylake, SHA-512 is about as fast as MD5 now -- https://bench.cr.yp.to/results-hash.html#amd6
194.
▲
by
pbsd
10y ago
https://godbolt.org/g/gimahO
195.
▲
by
pbsd
10y ago
You can still freely access global variables inside lambdas, with or without captures.
196.
▲
by
pbsd
10y ago
That may be the case, but whatever the Clang frontend sends to C2 does produce better code than the Microsoft frontend. It probably already folds the stores at the frontend level, instead of leaving it to the backend to figure out.
197.
▲
by
pbsd
10y ago
Well, the Go implementation of P-256 is meant to be constant-time, even if we don't get a hard guarantee that the compiler won't screw that up somewhere somehow. On the other hand, the generic implementation of the other curves is
198.
▲
by
pbsd
10y ago
The hybrid ciphersuite idea comes from [1, Section 5.2], though you could also chalk it up to common sense. I don't think the blog spells out how it's done. [1] https://eprint.iacr.org/2014/599
199.
▲
by
pbsd
10y ago
Along these lines, it has been argued that the ancient Greeks could have discovered Lucas-Lehmer with their contemporary technology: https://infoscience.epfl.ch/record/215073/files/MGFinal.pdf
200.
▲
by
pbsd
10y ago
https://github.com/openssl/openssl/commit/ffaef3f1526ed87a46...
201.
▲
by
pbsd
10y ago
Your survey refers twice, in page 8, to Mike Hamburg as Hamburger. Got a chuckle out of me, but you should probably fix that.
202.
▲
by
pbsd
10y ago
You can think of it as a magic trick. The magician is convincing you the he's computing a totally legit action X, all the while abusing your trust (or your cognitive biases) to perform action Y instead right under your nose. In this ca
203.
▲
by
pbsd
10y ago
I'm pretty sure a simple while loop is better than either: size_t strlen(const char * s) { size_t index = 0; while(s[index] != 0) { index += 1; } return index; }
204.
▲
by
pbsd
10y ago
There's this well-known identity [1] a + b = (a ^ b) + ((a & b) << 1). This is essentially how a parallel ripple carry adder works. So (a + b) / 2 = (a + b) >> 1 = ((a ^ b) >> 1) + (a & b). [1] http:
205.
▲
by
pbsd
10y ago
There's a recent family of AES-based designs, explicitly exploiting AES-NI, that would make a good starting point for fast secure PRNGs: https://eprint.iacr.org/2016/299 .
206.
▲
by
pbsd
10y ago
While some of NaCl's kernels are written using qhasm, qhasm itself is not part of the build process of NaCl. This means that those functions cannot be ran on, say, Windows, because the calling convention (and the assembly syntax) is di
207.
▲
by
pbsd
10y ago
The most notable thing is the lack of assumptions. You don't have to assume anything other than the min-entropy of the sources. With a hash function, you generally need to assume that the hash function is a good extractor, instead of s
208.
▲
by
pbsd
10y ago
Something like for(size_t i = 0; i <= n; i += k) { work_with(n - i); }? This sort of loop always comes up in these discussions, and I was never convinced that signed integers were worth it for that alone.
209.
▲
by
pbsd
10y ago
Considering how tiny the bias is along with the added complexity of the solution (in a chaotic language like Javascript, no less), I'd say the SpiderOak people are not crazy for not having accepted it. There would be somewhat of an arg
210.
▲
by
pbsd
10y ago
`ReplaceFile` is supposed to be atomic, at least according to the documentation: https://msdn.microsoft.com/en-us/library/windows/desktop/hh8...
More ›