Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
swordswinger12
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
swordswinger12
10y ago
Yeah, it's a model of computation used in this line of research. See the original Goldreich/Ostrovsky paper for more info: http://dl.acm.org/citation.cfm?id=233553
62.
▲
by
swordswinger12
10y ago
If you're interested in the basic tools used in this system, this is another paper that uses some similar ones: http://arxiv.org/abs/1503.06115 Phil Rogaway called it 'elegant', fwiw.
63.
▲
by
swordswinger12
10y ago
I have an honest, and probably dumb, question: how do warrant canaries actually avoid the prohibition against disclosing the receipt of a national security letter? Like, how is taking down a warrant canary legally dissimilar from just tweet
64.
▲
by
swordswinger12
10y ago
No, I'm sorry, that's not how cryptography works. A 'skim' clarifies nothing - you need precise proofs to understand security. And yes, I'm aware they provide proofs in the extended report, but the adversarial model
65.
▲
by
swordswinger12
10y ago
I'm not sure you're right about that. There are legitimate reasons to criticize this paper (its unclear, confusing security claims, for one) but the basic functionality they build can be used for an IDS, which seems beneficial to
66.
▲
by
swordswinger12
10y ago
My god, you're so right - any criticism of capitalism is indeed preposterous! You should write a strongly-worded letter to the author of the article to set her straight.
67.
▲
by
swordswinger12
10y ago
Only the BCLO scheme ( http://www.cc.gatech.edu/~aboldyre/papers/bclo.pdf ) has that particular leakage, which is (roughly speaking) the first half of the plaintext bits, not sqrt(n) bits.
68.
▲
by
swordswinger12
10y ago
Nice charts, this is really cool. One thing, though - it's weird to have "researchers" not compared against engineers, since at lots of places they're functionally just two different titles for the same job. Is there a r
69.
▲
by
swordswinger12
10y ago
Dave Zuckerman has been doing theoretical CS research for about twenty-five years. Are you saying you think it's likely that either (a) he was an NSA double agent this whole time, or (b) he recently started doing clandestine work for t
70.
▲
by
swordswinger12
10y ago
The IC3 research group at Cornell, and especially Elaine Shi's group, has been thinking about this recently. They are (I think) working on some kind of program analysis framework using deep PL techniques to formally verify smart contra
71.
▲
by
swordswinger12
10y ago
Exactly zero. The authors are well-known theory researchers at a major university, not NSA double-agents. Also, this paper was peer-reviewed and published at one of the top theory conferences in the field. This doesn't guarantee the pr
72.
▲
by
swordswinger12
11y ago
Ehhhh.... well, it's complicated. For most cryptosystems, the answer is no, because if you can solve the underlying problem efficiently you can break the security of the scheme as defined . It turns out that this isn't always a &
73.
▲
by
swordswinger12
11y ago
No, I mean your original comment is inaccurate. The paper presents a time-space lower bound for parity learning, but the encryption scheme based on this result is only 'unconditionally secure' in a model where the adversary is res
74.
▲
by
swordswinger12
11y ago
That is the conventional meaning of 'provably secure' in every text and research paper on modern cryptography.
75.
▲
by
swordswinger12
11y ago
You're falling victim to the same misconception. It is not a contradiction to say both that a cryptographic scheme is provably secure and that its security relies on a conjecture about the hardness of a computational problem.
76.
▲
by
swordswinger12
11y ago
The scheme in this paper is in the bounded-storage model...
77.
▲
by
swordswinger12
11y ago
This is a common misconception. The algorithm itself is provably secure, in the sense that violating the stated security guarantees of the algorithm is equivalent to solving a problem that's considered to be computationally intractab
78.
▲
by
swordswinger12
11y ago
It's clear that they're different constructions. The two papers don't even share an author. Why do you need hardware support for GCM-SIV?
79.
▲
by
swordswinger12
11y ago
All of his problems with GCM are fixed in the recent modification, GCM-SIV. Can't standards bodies just add that?
80.
▲
by
swordswinger12
11y ago
Can you search your emails? If so, how is the search index stored? Is it local or stored at ProtonMail?
81.
▲
by
swordswinger12
11y ago
You're not understanding my problem. You modeled security against a certain attack by picking one particular distribution of queries and saying "we resist this attack this much with this query distribution". An attacker doesn
82.
▲
by
swordswinger12
11y ago
Yeah, this approach has been tested and has failed miserably: http://eprint.iacr.org/2016/103.pdf
83.
▲
by
swordswinger12
11y ago
Another thing from that same section that worried me was their discussion of inference attacks on first and last names. Their results assume names will be queried based on a particular distribution instead of an arbitrary (maybe even advers
84.
▲
by
swordswinger12
11y ago
I read the whitepaper, and while I have many questions one detail in particular jumped out at me: "The client authenticates with an X.509 certificate or a self-signed certificate where the private key is derived from a passphrase. When
85.
▲
by
swordswinger12
11y ago
So here's an analogy that might help: Today, most RSA keys are 2048 bits. You can go up to 4096, but things start to get a little bit too slow for comfort. Double again and they get much slower. Now imagine doing RSA with a 100k-200k b
86.
▲
by
swordswinger12
11y ago
Nice to see a fellow Hoosier on HN - I went to school at IU and lived in Monroe County for several years. Anyway, the plane could have been involved with the Crane naval research center: http://www.navsea.navy.mil/Home/
87.
▲
by
swordswinger12
11y ago
Most zk-SNARK constructions are in the "common reference string" model, which requires a one-time trusted setup of a random string accessible to all parties: https://en.wikipedia.org/wiki/Common_reference_stri
88.
▲
by
swordswinger12
11y ago
Anybody who (as I do) finds this kind of thing fascinating should go back and read Young and Yung's work on kleptography from the late 90's: http://www.cryptovirology.com/cryptovfiles/research.html They were
89.
▲
by
swordswinger12
11y ago
Interesting article, but the history of public-key crypto in the article is a little iffy. EDIT: Here's a cool article about the birth of public-key crypto written recently by a friend of mine: https://medium.com/stanfo
90.
▲
by
swordswinger12
11y ago
Graph theory is a good example of this - the asymptotically fastest minimum spanning tree algorithm was made possible by Hopcroft and Karp just drawing weird data structures on a chalkboard until union-find popped out, which gives you near-
More ›