Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
qrmn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
31.
▲
by
qrmn
11y ago
And that's no coincidence: the prospect of Scottish independence was seen as a grave threat to the United Kingdom by HMG; so, yes, they conducted information operations against it. I am quite sure that seeing the results that the SNP g
32.
▲
by
qrmn
11y ago
Indeed. Taiyo-Yuden were (still are, until December) one of the very best of the actual manufacturers of optical media: and they explicitly cite that optical media is losing its relevance as why they're ceasing operations in that marke
33.
▲
by
qrmn
11y ago
Unfortunately, nobody (especially in the intelligence community echo-chamber) wants to entertain the idea that some of what they have been doing endangers thousands of people directly, and all the Five Eyes and beyond indirectly, by delib
34.
▲
by
qrmn
11y ago
The mismanagement of security at OPM predates Snowden's disclosures. However, it's pretty much target #1 for any foreign intelligence agency. The OPM data contains enough details that would allow a good intelligence agency to trac
35.
▲
by
qrmn
11y ago
Richard Karsmakers used "virii" to describe a plural of computer virus in the 16-bit era, largely on the basis that it was shorter. It isn't correct Latin, but it is a VX scene thing, so is absolutely correct in this contex
36.
▲
by
qrmn
11y ago
IMSI catchers are transceivers . They are not hard to find, they are easily triangulated: they literally broadcast their location. Honestly, denying their usage is remarkably pointless. If you want a location, then I suggest: grab a spectr
37.
▲
by
qrmn
11y ago
I don't think CRLs usually are, under current infrastructure anyway. How can you verify the certificate of the server when it's signed by the certificate you want to fetch; or check that it hasn't been revoked when what you&#
38.
▲
by
qrmn
11y ago
The best option would be to add a MAC or authentication tag correctly, for example with an AE mode like CHACHA20_POLY1305, AES_256_GCM, AES_256_OCB, or one of the new CAESAR candidates, etc. But then you'd need extra space for the MAC&
39.
▲
by
qrmn
11y ago
100% scummy. Question is, what do we do about it? I wonder... Is bundling adware installers with GPL software a violation of the GPL? (If not, should it be? v2?/v3?) Where's the installer's source? It wraps it in one linked
40.
▲
by
qrmn
11y ago
A fair point. btrfs would have a much easier time of it. We then have the interesting consequence that we can observe times and sizes of COW updates, but in truth SSDs have that anyway.
41.
▲
by
qrmn
11y ago
Not many years ago - just 3! The Tories have a slimmer majority now than they had in the coalition, and a Lords which isn't all roses and flowers about this. And the Lib Dems (in one of the few promises they actually kept) sent the Dra
42.
▲
by
qrmn
11y ago
But this isn't disk encryption! Filesystems have metadata: which is where a MAC can go, next to the filename. There's just no way this should be unauthenticated XTS, this is simply the wrong mode to use, you should use an AEAD.
43.
▲
by
qrmn
11y ago
I can't think of many scenarios in which this would be a win which aren't usually compressed archive downloads of some sort anyway, or might be better presented as a torrent with a tree hash and some multisourcing. LZ4 might be a
44.
▲
by
qrmn
11y ago
Just to be clear, the SID's noise generator is NOT a TRNG - it's a XOR shift register, basically an LFSR with no 1-tap. It's predictable.
45.
▲
by
qrmn
11y ago
It may surprise you that the order matters - in the hands of a potential attacker, combining random sources is not commutative! If your last random source comes from an attacker who can read your state, then they can manipulate your state
46.
▲
by
qrmn
11y ago
Two parts to your question: 1. Yes, the NSA can likely break 1024-bit DHE at scale - as well as 1024-bit RSA or anything smaller. (Probably also the RC4 stream cipher, if you didn't listen and are still using that.) 2. ECDHE is totally
47.
▲
by
qrmn
11y ago
Neither. ECDHE on P-256 doesn't have this problem, is available almost everywhere and is faster and safer: use that, or better still, Curve25519 and friends (in OpenSSH already, coming up in TLS later this year hopefully?). There'
48.
▲
by
qrmn
11y ago
Did happen with the Silk Road bitcoins, 30K BTC of which were auctioned off before the trial.
49.
▲
by
qrmn
11y ago
They're not even the most arcane. Consider reading up on rapid tornado (Raptor) codes, other fountain codes, Goppa codes… there are whole families of error-correcting codes with different sets of tradeoffs. And the decoding can be enli
50.
▲
by
qrmn
11y ago
Isn't this basically another take on HAVEGE[1]? I'm not sure I'd call that a true random source. [1] https://www.irisa.fr/caps/projects/hipsor/; see http://www.issihosts.com/hav
51.
▲
by
qrmn
11y ago
I'm also struggling to see any advantages to still using Sourceforge in 2015. Firstly, they're well-known by now to be complicit in sponsored 'wrapper' installers bundling some pretty awful stuff - check out what they di
52.
▲
by
qrmn
11y ago
Microsoft could push a security update enabling TLS 1.1 and 1.2 by default? (I'm not saying they will, but they could.)
53.
▲
by
qrmn
11y ago
Mobile operators directly encouraging cleartext so they can fuck with traffic? That's the exact case made for encryption. (You can see how that went down at IETF 92.) Interesting note about the Google data compression proxy. Can we
54.
▲
by
qrmn
11y ago
A good, open, microcontroller design with no caches, USB (or something), a TRNG, an onboard voltage/clock regulator, registers/RAM which zeroises on faults/parity/intrusion sensors, a fresh approach to avoiding SPA/
55.
▲
by
qrmn
11y ago
It won't just include it, at this stage it seems set to become mandatory-to-implement (not necessarily mandatory to deploy). We'll see.
56.
▲
by
qrmn
11y ago
"The final archive format" is a very big promise that 4q doesn't keep right now. It falls short of 7z, RAR and tar.xz, and certainly isn't ready to replace them at the moment. I'm not too familiar with Coffeescript,
57.
▲
by
qrmn
12y ago
Because directory hierarchies go from top to bottom - /dir/subdir/file.ext - or, globally, //hostname/dir/subdir/file.ext, or protocol://hostname/dir/subdir/file.ext etc. That
58.
▲
by
qrmn
12y ago
You can find a list of nginx's versions simply from the download directory: http://nginx.org/download/ - I know that much. By the way... DSS? Is anyone anywhere using DSS certificates on the internet anymore? (And
59.
▲
by
qrmn
12y ago
MediaTek have not been historically known for engaging with the open-source community, documenting their chipsets, and complying with the GPL, to put it mildly. Unless anyone knows that's changed in recent years?
60.
▲
by
qrmn
12y ago
That it's compatible is nice, but Telegram cannot be recommended as a secure messenger. Knowledgeable people have reviewed its cryptography and found it wanting, even "bizarre and nonsensical". You may want to look into other
More ›