Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sweis
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
121.
▲
Cisco Open Sources Experimental "FNR" Block Cipher
(blogs.cisco.com)
7 points
by
sweis
12y ago
|
0 comments
122.
▲
In Defense of JavaScript Crypto
(rdist.root.org)
5 points
by
sweis
12y ago
|
0 comments
123.
▲
by
sweis
12y ago
This is great to see. I remember ToneLoc when it came out. Looking back, it was still the wild west. I remember finding dial-ins that had no logins at all and just dumped you to a shell.
124.
▲
Security of Symmetric Encryption against Mass Surveillance
(eprint.iacr.org)
2 points
by
sweis
12y ago
|
0 comments
125.
▲
by
sweis
12y ago
I use old-fashion serial cables for kernel development in 2014. It would be hard to debug without it. Sometimes you have bugs on physical systems that aren't reproducible in a VM and can only get any output via a physical serial cable.
126.
▲
Crypto source derived from Secret.ly Android app
(gist.github.com)
1 points
by
sweis
12y ago
|
0 comments
127.
▲
"Privacy versus government surveillance" by Ross Anderson
(weis2014.econinfosec.org)
1 points
by
sweis
12y ago
|
0 comments
128.
▲
Deanonymisation of clients in Bitcoin P2P network
(arxiv.org)
1 points
by
sweis
12y ago
|
0 comments
129.
▲
by
sweis
12y ago
Enabling IOMMU is one relatively easy software mitigation to DMA attacks. There are some gaps, but it stops the trivial cases where a device can access all of memory.
130.
▲
by
sweis
12y ago
I primarily like XTS because it's very fast and can be efficiently pipelined on x86 platforms with AESNI. I can get 215 Gbps throughput on 8 cores of a modern Intel CPU. Also, if XTS is used in a length-preserving fashion, it can encry
131.
▲
by
sweis
12y ago
TRESOR is only effective against passive forensics and only protects key material. It does not protect against an attacker able to manipulate memory contents through, say, DMA or other malicious devices.
132.
▲
by
sweis
12y ago
Why does Safe use the Botan crypto library? Botan has a single contributor who says "[Botan] has never undergone an impartial third-party security review, and thus it is entirely possible/probable that a number of exploitable flaw
133.
▲
ISEC Completes TrueCrypt Audit
(isecpartners.github.io)
34 points
by
sweis
12y ago
|
8 comments
134.
▲
by
sweis
13y ago
This has been confirmed: https://twitter.com/eastdakota/status/454778897079734273
135.
▲
EFF Crypto Usability Prize Workshop
(cups.cs.cmu.edu)
2 points
by
sweis
13y ago
|
0 comments
136.
▲
Encrypted Google BigQuery client supports search over encrypted data
(code.google.com)
2 points
by
sweis
13y ago
|
0 comments
137.
▲
by
sweis
13y ago
Is there any way to use the existing EB-5 Immigrant Investor visa? http://www.uscis.gov/working-united-states/permanent-workers... As far as I know, to qualify for an EB-5 you need to invest at least US$1M and create 1
138.
▲
by
sweis
13y ago
CBC is okay if it is used to encrypt before MACing. The issue is that TextShredder used CBC without any authentication, i.e. a MAC. That means someone can modify the ciphertext in transit and it won't be detected. This opens up several
139.
▲
by
sweis
13y ago
As far as I can tell, the AesCryptoServiceProvider they are using inherits the default CBC mode from here: http://msdn.microsoft.com/en-us/library/system.security.cryp... So, it appears to be using CBC. However, t
140.
▲
by
sweis
13y ago
This appears to be using AES-CBC without any authentication: https://textshredder.codeplex.com/SourceControl/latest (HN breaks the link directly to the code, but add this fragment to go straight to the AES.cs class: &q
141.
▲
Anonymouth: Document writing style anonymization tool
(github.com)
2 points
by
sweis
13y ago
|
0 comments
142.
▲
by
sweis
13y ago
As you just said, users must trust the JS coming from Keybase. It might be compromised at any time. Next, people usually mumble about auditing it, downloading a copy, signing it, etc. At the end of the day, you arrive to code installed on t
143.
▲
by
sweis
13y ago
Even though there is a disclaimer, I think the "encrypt in your browser" feature ( https://keybase.io/encrypt ) undermines Keybase's security credibility. This form has essentially the same level of security as
144.
▲
by
sweis
13y ago
Hey Adam. I didn't realize BBF delivered. Is there a minimum order size? I've been ordering from Costco, which is convenient but has a limited selection.
145.
▲
by
sweis
13y ago
So, users are locked into MePIN's proprietary app and depend on MePIN's website to log in, rather than using a open standard that can run offline. If you use HOTP/TOTP, you can use open source Google Authenticator, DuoSecurit
146.
▲
by
sweis
13y ago
Yes, TRESOR can help against cold boot attacks, which are passive and read-only. Several physical attack vectors can modify the contents of memory, thus compromise the software stack and divulge keys kept in registers or cache. Our approach
147.
▲
by
sweis
13y ago
TRESOR only helps against passive attacks since since the code is still exposed in memory. Active attacks that modify memory can easily circumvent it.
148.
▲
by
sweis
13y ago
Hi. L3 caches are indeed huge these days. For example, the latest Mac Pros are shipping with 30MB L3 caches. You can do a lot with that space. My company PrivateCore runs an entire Linux/KVM stack within the L3 cache, then fully encryp
149.
▲
by
sweis
13y ago
At PrivateCore, we keep key material (and the entire Linux stack) pinned in the CPU cache, then encrypt main memory. This would thwart physical memory extraction attacks, like cold booting, Fireware, Thunderbolt, NV-DIMMs, bus analyzers, ma
150.
▲
Turing Complete Return Oriented Programming (ROP) Compiler
(github.com)
2 points
by
sweis
13y ago
|
0 comments
More ›