Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
richm44
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
richm44
12y ago
I'm saying they're unfixable because there's no way to tell the JIT to create constant-time code. Certainly Christopher Meyer has said that he's reported some that remain private since they've not been fixed. Heartb
62.
▲
by
richm44
12y ago
You do realise that JSSE has lots of timing attacks etc. and that's pretty much unfixable in managed code? It's also had numerous bugs in it's SSL/TLS implementation (mainly because no one uses it) such as mishandling ze
63.
▲
by
richm44
12y ago
You get OCSP checking for non-EV certificates too in many browsers. However, you can remove any additional delay by using OCSP stapling.
64.
▲
by
richm44
12y ago
Don't fork a new process for each image, write something that uses the imagemagick library directly (or another library if you prefer). Don't do them serially, use threads so you can make use of all your cores. That said, even ser
65.
▲
by
richm44
12y ago
Given that those instructions if used as-is would render all unencrypted content inaccessible for around 2 years, I'd strongly suggest moving the warning section to the top.
66.
▲
Using Frankencerts to Find Flaws in SSL Certificate Verification
(cs.utexas.edu)
2 points
by
richm44
12y ago
|
0 comments
67.
▲
by
richm44
12y ago
Not really, he talks about HTTP which wasn't really designed for that purpose. There are plenty of protocols that were. Does this actually have anything to add that isn't covered in http://en.wikipedia.org/wiki&#x
68.
▲
by
richm44
12y ago
I stopped at the point where he claimed that APIs were always synchronous, this wasn't even true in the 80s. For example XLib is a rather well used API and is asynchronous (there are many others).
69.
▲
by
richm44
12y ago
And we can trust that you're not one of their competitors who's simply trying to get people embarrass them why? Simply saying "please try to break this 3rd party site" is rather questionable.
70.
▲
by
richm44
12y ago
I once had to fix a system that was dual boot NT and Solaris x86 after Solaris wrapped around and put log messages into the boot sector. I fixed it by typing in the boot code for NT from a screenshot of a hexdump in the NT resource kit usin
71.
▲
by
richm44
13y ago
That's a very good point (and easy to change in the code). When I was thinking about what to write I considered making a modified version of the PoC that was a bit more readable and adding a few tweaks like handling different TLS versi
72.
▲
by
richm44
13y ago
Sure, I simplified things a little bit for clarity. The aim was really to get away from people just looking at the block of hex and seeing 'magic'. :-)
73.
▲
Understanding the Heartbleed Proof of Concept
(westpoint.ltd.uk)
26 points
by
richm44
13y ago
|
6 comments
74.
▲
by
richm44
13y ago
The last time I looked at it the go stack was very weak compared to any of the mature C SSL stacks. IIRC it only took me a few minutes to find a security bug (which I reported and is now fixed) that I'd reported against various browser
75.
▲
by
richm44
13y ago
That's actually something openssl does okay. See http://www.openssl.org/docs/crypto/threads.html it's actually one of the few things that are properly documented.
76.
▲
by
richm44
13y ago
About an inch if you're face down in it.
77.
▲
by
richm44
13y ago
Fair enough. I'll read it properly and then comment. :-)
78.
▲
Talking to Chromecast with Qt
(plus.google.com)
52 points
by
richm44
13y ago
|
1 comments
79.
▲
by
richm44
13y ago
Just looking at the table of contents is a bit worrying. :-( Why are block cipher modes like CBC and CTR, and issues like padding listed in the stream cipher section? Those aren't relevant to stream ciphers (though you can regard count
80.
▲
by
richm44
13y ago
Adam Langley has written up the details of the issue here: https://www.imperialviolet.org/2014/02/22/applebug.html