Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sweis
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
sweis
11y ago
Facebook is hiring for open source security engineers, by the way: https://www.facebook.com/careers/department?req=a0I1200000G4...
92.
▲
by
sweis
11y ago
Hi. You can easily find corroboration that I work at Facebook and my contact information. Please feel free to contact me with details of your issues. If you have specific security vulnerabilities to report, here's a link to our Whiteha
93.
▲
by
sweis
11y ago
That was the Facebook AV Marketplace, which to my knowledge does not exist anymore. Here's the old post about it from 2012: https://www.facebook.com/notes/facebook-security/the-faceboo...
94.
▲
by
sweis
11y ago
Hi everyone. I work on the security team at Facebook. While investigating the claims of this post, we've confirmed that Facebook doesn't use Recorded Future -- an open source aggregator of public data -- to scan any private conten
95.
▲
by
sweis
12y ago
Yep, we ran the entire Linux stack pinned in the L3 cache, so no data or code hit main memory which was not encrypted. Ironically, we could test this by disabling VT-d and using a DMA device to read encrypted main memory. Here's an old
96.
▲
by
sweis
12y ago
You modify the kernel. As for SMIs, you know where SMRAM is located in memory and the cache geometry, so can ensure that there are cache ways available which SMIs won't evict. Cache evictions can also be monitored by CPU performance co
97.
▲
by
sweis
12y ago
You don't need a "protected processor". At PrivateCore, we kept all key material pinned in the L3 cache and ensured it was never evicted to main memory. Frozen Cache did something similar with No-Fill Mode. Tresor used CPU de
98.
▲
Darpa “Brandeis” program granting $60M for privacy reseach
(fbo.gov)
3 points
by
sweis
12y ago
|
0 comments
99.
▲
by
sweis
12y ago
If you remotely attest your own software, how is that anti-freedom? I use remote attestation to verify that my firmware, kernel, initrd, and configuration were booted as expected. It's a tool you can use for your own benefit. What you
100.
▲
by
sweis
12y ago
They implemented end-to-end crypto in this web client as well. Since it's JS served on each request, it's vulnerable to compromise on the server side. I also don't know how key material is securely provisioned to your browser
101.
▲
by
sweis
12y ago
Big Boring System led me to reminisce and find an old school WWIV BBS and standalone Tradewars game accessible via telnet: telnet bbs.filenet.wwiv.net telnet twgs.exiled.org 2002
102.
▲
by
sweis
12y ago
How "modern" is modern? I understand there are some TPM implementations out there that are on-package, but there are still new servers being sold with TPM headers that I would expect to be easy to interpose. Regardless, this whole
103.
▲
by
sweis
12y ago
Why do you think those USB devices are "pretty likely"? In this case, I would bet on a firmware compromise, similar to DIETYBOUNCE: https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_..
104.
▲
by
sweis
12y ago
Not specific to PeerPub, but I helped work on a prototype of a federated login system based on OpenID that used blind signatures in a similar fashion: http://private-idp.appspot.com/ https://code.google.com/
105.
▲
by
sweis
12y ago
People can't trust that the site is actually serving the right JS crypto implementation. It can be broken at any time, which would allow the site to intercept communications. It needs client-side code to do it correctly, for example, s
106.
▲
by
sweis
12y ago
Long story short, memory bandwidth is much faster than the best x86 crypto implementations can handle. Encrypting disks or network is no problem today, but we'll need architectural changes to support full memory encryption without a pe
107.
▲
by
sweis
12y ago
I've heard predictions that a significant portion of new x86 servers will be using non-volatile memory within the new 5-7 years. Memory is becoming the new disk. This could have major security implications, as memory contents are unenc
108.
▲
by
sweis
12y ago
This is indeed a cool feature. I hadn't been aware of it until now. I see that Dirk Balfanz from Google published a IETF draft a couple years ago. I need to digest the security implications, but it seems like a nice mitigation to sessi
109.
▲
Craig Gentry named MacArthur Fellow for work on fully homomorphic encryption
(macfound.org)
152 points
by
sweis
12y ago
|
21 comments
110.
▲
by
sweis
12y ago
These are great challenges for learning crypto. They've provided solutions in 10 different languages.
111.
▲
The Matasano Crypto Challenges
(cryptopals.com)
404 points
by
sweis
12y ago
|
71 comments
112.
▲
by
sweis
12y ago
I think Joe Fitz is working on some malicious active memory prototypes as well. Could be very interesting and scary.
113.
▲
Facebook Buys Secure Server Technology Provider PrivateCore
(techcrunch.com)
41 points
by
sweis
12y ago
|
3 comments
114.
▲
Facebook acquires encryption startup PrivateCore to better protect its servers
(thenextweb.com)
3 points
by
sweis
12y ago
|
0 comments
115.
▲
PrivateCore is joining Facebook
(privatecore.com)
2 points
by
sweis
12y ago
|
0 comments
116.
▲
by
sweis
12y ago
Doubtful. Snapchat hired another ex-Googler, Jad Boutros, as director of information security: http://www.bloomberg.com/news/2014-05-01/snapchat-hires-goog... Jad is an excellent hire.
117.
▲
Crypto Projects that Might Not Suck [pdf]
(saweis.net)
2 points
by
sweis
12y ago
|
0 comments
118.
▲
by
sweis
12y ago
Like this TOTP debugger? https://google-authenticator.googlecode.com/git/libpam/totp.... It used to generate a QR code for you to scan, but that's apparently broken.
119.
▲
by
sweis
12y ago
I could not find any technical details from Gemalto besides this blurb, which doesn't inspire confidence: "We encrypt your CloudEntr password with a cryptographic hash function – and make sure you’re the only one with the key. We
120.
▲
by
sweis
12y ago
Are the unique secrets defined by the user or at manufacture time? If by the manufacturer, then it is potentially a security and privacy concern.
More ›