Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sweis
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
First flight of Facebook's Aquila solar-powered plane
(facebook.com)
2 points
by
sweis
10y ago
|
0 comments
62.
▲
by
sweis
10y ago
Facebook supports PGP too, by the way: https://www.facebook.com/notes/protect-the-graph/securing-em... And runs as a Tor hidden service at https://facebookcorewwwi.onion/ : https://www.f
63.
▲
by
sweis
10y ago
And we had some smart outside people review it: https://twitter.com/matthew_d_green/status/75140316340882636...
64.
▲
by
sweis
10y ago
Here's a whitepaper to start: https://fbnewsroomus.files.wordpress.com/2016/07/secret_conv...
65.
▲
by
sweis
10y ago
Hi. To move all messages to be E2E encrypted, we need credible solution for web clients and every other platform, including old feature phones. This is easier said than done, but is something we are thinking about. Secret Conversations is a
66.
▲
by
sweis
10y ago
I am confident Facebook will meet your high standards when it comes to E2E encryption for Messenger.
67.
▲
“Analysis and Design of Blockchains” presentation by Rafael Pass
(docs.google.com)
1 points
by
sweis
10y ago
|
0 comments
68.
▲
Facebook open sources CTF platform
(m.facebook.com)
5 points
by
sweis
10y ago
|
0 comments
69.
▲
by
sweis
10y ago
Got it. Here's the code: https://github.com/passbolt/passbolt/blob/master/app/Control... I didn't know gpgauth existed, but this is what they appear to be using (the site has a broken cert
70.
▲
by
sweis
10y ago
I haven't found it in the code yet, but the landing page's protocol diagram with optional "/auth/verify" might have potential to be abused as a decryption oracle. It depends how they check the nonce.
71.
▲
How to Build Your Own Rogue GSM BTS for Fun and Profit
(evilsocket.net)
262 points
by
sweis
11y ago
|
61 comments
72.
▲
by
sweis
11y ago
I have seen strong interest in SGX among some large Intel customers.
73.
▲
by
sweis
11y ago
The headline misses the most interesting part: This is released by the NSA.
74.
▲
by
sweis
11y ago
This map has much better pew pew sounds: http://threatbutt.com/map/
75.
▲
by
sweis
11y ago
Nate Lawson has a good explanation of timing attacks (against my own code): http://rdist.root.org/2009/05/28/timing-attack-in-google-key...
76.
▲
by
sweis
11y ago
I briefly looked at Telegram's crypto code a couple months ago. Here's a few funny things I spotted: Telegram's message format uses ambiguous padding, so they have to try all padding lengths when validating a message: https:
77.
▲
by
sweis
11y ago
This Yagisawa paper is of poor quality and lacks adequate proofs. It unfortunately uses the exact title as a 2011 paper by Brakerski, Gentry, and Vaikuntanathan: https://eprint.iacr.org/2011/277.pdf The BGV paper is th
78.
▲
by
sweis
11y ago
This team is hiring, by the way: https://www.facebook.com/careers/department?req=a0I1200000G4...
79.
▲
Facebook on “Embracing Open Source Security” and Osquery
(code.facebook.com)
2 points
by
sweis
11y ago
|
1 comments
80.
▲
by
sweis
11y ago
Hi. Someone else commented, but you should have received an encrypted verification email with a link. We don't want to start sending you encrypted notifications until we confirm you're actually able to read them. If you click that
81.
▲
by
sweis
11y ago
Hi Scott. We're not using PEAR. If you are interested in looking at the implementation and other interesting security stuff, we have a lot of security openings: Security Software Engineer - https://www.facebook.com/care
82.
▲
by
sweis
11y ago
Hi. We use a generic subject line "Encrypted Notification from Facebook" and tried to remove fields that leak metadata. The From: field should just say "Facebook". Please contact me if you do see anything leaking metadat
83.
▲
by
sweis
11y ago
Thanks, I noticed the square brackets as well. We'll look into it.
84.
▲
by
sweis
11y ago
Hi Chris. I worked on this and want to diagnose your server error. When you decrypted from the command line, did you notice the plaintext blob preceding the HTML message content? Look for "Content-Type: text/plain;" and see i
85.
▲
by
sweis
11y ago
Looks like they have some code on Github: https://github.com/ProjectVault/orp/tree/master/software/os/...
86.
▲
Cryptographic Right Answers
(gist.github.com)
187 points
by
sweis
11y ago
|
130 comments
87.
▲
by
sweis
11y ago
Strange that this let me resubmit the same link. Usually HN will detect duplicates.
88.
▲
by
sweis
11y ago
An LWN article about clear containers is here: http://lwn.net/SubscriberLink/644675/54520a696ff9cddc/
89.
▲
Intel Clear Linux Project
(clearlinux.org)
12 points
by
sweis
11y ago
|
3 comments
90.
▲
by
sweis
11y ago
"When you sign up for a passcard, your registrar will give you a secret key" How is this decentralized if the registrar issues your secret keys for you? Couldn't they hijack your identity at any time? It sounds more like a fe
More ›