Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sdevlin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
121.
▲
by
sdevlin
12y ago
"Theory and practice" was a poor choice of words on my part. The point is simply that there are assumed-hard problems and cryptographic constructions based on them. If there is wiggle room between these things (as in RSA), it can
122.
▲
by
sdevlin
12y ago
This is a pretty neat survey on the gulf between theory and practice, which is basically where practical cryptographic attacks live. For example, RSA is based on the integer factoring problem, but they are not equivalent. Vanilla RSA does n
123.
▲
by
sdevlin
12y ago
I guess I'm still unclear how that would work in the context of AES. Or really any symmetric construction, come to think of it.
124.
▲
by
sdevlin
12y ago
I think he's talking about something like: c = encrypt(k, m) sleep(rand()) return c Which is not what blinding is. Blinding is not really about adding a random delay as much as it is about preventing an attacker from control
125.
▲
by
sdevlin
12y ago
A better strategy (and an area of research for Dan Bernstein, author of the referenced paper) is to design crypto that doesn't leak this kind of side-channel information. See, for example, his Salsa20 family of stream ciphers.
126.
▲
by
sdevlin
12y ago
I think it would be tough to attack TLS with this. A couple important stumbling blocks off the top of my head: We need to pull off the attack in the context of a single TLS session, because new AES keys are generated for each one. This mean
127.
▲
by
sdevlin
12y ago
This attack is conceptually simple, and the linked paper ( http://cr.yp.to/antiforgery/cachetiming-20050414.pdf ) is very approachable for the layman. I recommend giving it a read. Here's the basic idea: 1. The
128.
▲
by
sdevlin
12y ago
One of the requirements for the attack is partial plaintext control. This is feasible if you're running malicious JavaScript in the user's browser. So what you do is generate an HTTP request that, taken together with the SSL MAC,
129.
▲
by
sdevlin
12y ago
What are dynamic modules?
130.
▲
by
sdevlin
12y ago
In duckduckgo you can just do: [query] !pb
131.
▲
by
sdevlin
12y ago
Pinboard is an awesome service. If you don't have an account, you should. It's especially refreshing for those (like me) who despise the Internet of JavaScript Bullshit. Pinboard is fast as hell because it doesn't waste your
132.
▲
by
sdevlin
12y ago
> If you split into multiple parts, each part of the key is useful: it lets you reduce your search space by however many bits of the key you have. That doesn't have to be true. Rather than splitting an AES key K into substrings, a b
133.
▲
by
sdevlin
12y ago
Those connections needn't be concurrent.
134.
▲
by
sdevlin
12y ago
> You need 16 million connections with 1GB of data, _in_ _each_ _connection_ to practically attack RC4. This isn't accurate. There are two major attacks described in the recent literature on RC4. The first targets single-byte biases
135.
▲
by
sdevlin
12y ago
Advanced search often leads to SQL injection. This is because there are some parts of SQL queries that can't be parameterized. If you allow the user to dynamically select which table to query against, or which columns to fetch, or how
136.
▲
by
sdevlin
12y ago
None of that requires JavaScript. You basically just described the Lavabit model, where user passwords were used to derive key material that was never stored on the server. If you trust the server to give you good client-side code barring e
137.
▲
by
sdevlin
12y ago
Just to be clear, are you suggesting that there is an elite cadre of cryptobullies browbeating the general public into broadcasting compromising information all over the cleartext internet?
138.
▲
by
sdevlin
12y ago
Burp Suite has a pretty rich feature set. How does this compare? For example, is something scriptable like Burp Intruder included (or planned)?
139.
▲
by
sdevlin
12y ago
Conventions and usage vary by setting, but yes, it's to prevent nonce reuse. A typical scenario might use a single encryption key for many different messages. A simple strategy is to allocate 64 bits to a message counter and 64 bits to
140.
▲
by
sdevlin
12y ago
That would not solve the problem of active man-in-the-middle attacks.
141.
▲
by
sdevlin
12y ago
It seems pretty trivial to me. Can't you just send different messages to different people?
142.
▲
by
sdevlin
12y ago
> For example, Alice can tell Bob "The funds were transferred, thanks!" and tell Carol "Bob is stealing money." — and the protocol will ascribe integrity to the messages for both participants and label them as the sam
143.
▲
by
sdevlin
12y ago
Here's one possible approach. Assume the attacker can modify plaintext on disk indirectly. This might be viable if e.g. the user's browser cache lives in the TC volume. (Not sure what typical TC-in-Dropbox usage patterns are, so t
144.
▲
by
sdevlin
13y ago
Thanks for the great reply! I didn't realize the Chrome web store requires your private key. That's insane.
145.
▲
by
sdevlin
13y ago
> The best way is a browser extension, but even that has its pitfalls (firefox especially since there's no real sandboxing). I would be greatly interested if you could expand on some of the pitfalls of browser extensions and how the
146.
▲
by
sdevlin
13y ago
That is a pretty good list of recommendations, but I have a couple criticisms. The recommendations are mostly low-level. None of them are wrong, but they put undue burden on developers to get details right. For example, the AES-CTR recommen
147.
▲
by
sdevlin
13y ago
The web is not a secure medium for this kind of application.* This is because all the encryption features they tout depend implicitly on content (HTML and JavaScript) the server sends you every time you use the application. Because you rece
148.
▲
by
sdevlin
13y ago
Simply: performing a timing attack against a hash function implies performing a second-preimage attack against the hash function.
149.
▲
by
sdevlin
13y ago
That is a good way to think of it. Indeed, that is how cryptographic randomness is typically defined. Simply put: given the first k bits of a random stream, can you predict the k+1th bit (more than 50% of the time)? A generator that passes
150.
▲
Entropy Attacks
(blog.cr.yp.to)
16 points
by
sdevlin
13y ago
|
1 comments
More ›