Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tabletopneedle
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
tabletopneedle
11mo ago
>It is questionable whether it solves its primary use case particularly well. It solves the problem of "how do I flaunt the fact I carry an iPhone to everyone around me" It's a conversation piece and way to flaunt your wea
2.
▲
by
tabletopneedle
3y ago
Five years ago, today, the infosec community found itself wondering about Robert Edward Grant's Quasi-primes, and an ever expanding portfolio of grifts by his company, Crown Sterling. These included * TIME AI, a completely bonkers, fiv
3.
▲
Crown Sterling: Five years since TIME AI, five years of grifts and lie
(rationalwiki.org)
2 points
by
tabletopneedle
3y ago
|
1 comments
4.
▲
by
tabletopneedle
7y ago
Even if you were using a perfect implementation of RSA-OAEP, it would still be less secure than Diffie-Hellman over Curve25519 (called X25519) or Curve448 (called X448). This is because RSA lacks forward secrecy: If the private RSA key is s
5.
▲
by
tabletopneedle
7y ago
If you're on Python and you for some weird reason absolutely have to use RSA, make sure to use RSA-OAEP and the pyca/cryptography library: https://cryptography.io/en/latest/hazmat/primitives/asy
6.
▲
by
tabletopneedle
7y ago
Hey, just wanted to chime in Crypto101 was the ~first book I read on crypto and it was really well written. Kudos for your work.
7.
▲
by
tabletopneedle
7y ago
There is no place to use RSA instead of Diffie-Hellman. DH provides forward secrecy, and the ECC variants are much faster and use shorter keys for equivalent security. They are harder to implement in a wrong way.
8.
▲
by
tabletopneedle
7y ago
Tl;dr Curve25519 for 128-bit security, to use with 128/256-bit symmetric cipher. X448 for 224-bit security to use with 256-bit symmetric cipher. - For symmetric ciphers choose any of the three below: -ChaCha20-Poly1305 -Salsa20-Poly130
9.
▲
by
tabletopneedle
7y ago
Yes. However, it never hurts to test your code. Assuming you're a C-programmer, read the libsodium docs first. https://download.libsodium.org/doc/public-key_cryptography/s... If you're using higher level
10.
▲
by
tabletopneedle
7y ago
Every time there's debate over Telegram's encryption the shill argument "it hasn't been broken in the wild now has it" pops up. This is fundamentally flawed thinking. The end-to-end-encryption is most likely reasona
11.
▲
by
tabletopneedle
7y ago
This reminds me of the Niemöller's poem. IIRC it went something like First they came for the A2017U1s, or they would have, except he never opposed the wrongdoing.
12.
▲
by
tabletopneedle
7y ago
It's much safer to just send the public key over whatever medium and then use an authenticated channel to verify the authenticity of said public key.
13.
▲
by
tabletopneedle
7y ago
With DH both public keys have effect on the randomness of the shared secret. If the app on the client generates a random DH key-pair for every session, and it uses a public DH value of the server pinned to it, the encryption is authenticate
14.
▲
by
tabletopneedle
8y ago
Thank you! So to help everyone (read whole post first), you should probably have the line KexAlgorithms sntrup4591761x25519-sha512@tinyssh.org,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256 in /etc/ssh/sshd
15.
▲
by
tabletopneedle
8y ago
I was able to install the software, but there is no documentation about how to create NTRU+X25519 keys and enable it. I checked manpages, mailing list and tried google. How is this done?
16.
▲
by
tabletopneedle
8y ago
For example, cleanroom has classification that implies some amount of dust particles/impurities in the air. The technicians don't talk about the number of dust particles allowed, they just consider class 5 suitable for some applic
17.
▲
by
tabletopneedle
8y ago
Until Tox defaults it's communication through Tor, it doesn't offer any notable differences. Sure, there is no central server, but intelligence agencies can see who you talk to without compromising server just by looking at the de
18.
▲
by
tabletopneedle
8y ago
People still need to communicate with their peers in insecure networks. Now you need to compare the nitty gritty details and choose the most secure one for your needs. If you need content protection to keep dick picks out of NSA office circ
19.
▲
by
tabletopneedle
8y ago
Remember that OTR, Cryptocat and PGP were secure enough when Snowden was agreeing about handing data to Greenwald and Poitras. So while Signal isn't secure if you're NSA's target, it might be secure enough to protect you from
20.
▲
by
tabletopneedle
8y ago
It's also the case you can't use Telegram's end-to-end encryption on desktop clients at all.
21.
▲
by
tabletopneedle
8y ago
"Google Play Services lets Google do silent background updates on apps on your phone and give them any permission they want. Having Google Play Services on your phone means your phone is not secure." Yes, Google can install a back