Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tob_scott_a
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
tob_scott_a
12d ago
When people question the efficacy of using AI for security work, they're often asking the wrong questions. (I blame the initial marketing hype around Claude Mythos for much of the unhelpful discourse.) And I don't just mean they&#
2.
▲
by
tob_scott_a
5mo ago
If you can't write it down, why would you expect it to be universal and enforceable? Different cultures exist and have different opinions on what "decency' means, after all. A security researcher's ethical obligations ar
3.
▲
by
tob_scott_a
8mo ago
To test a Claude Skill for analyzing cryptographic implementations of cryptographic side-channels ([1] see constant-time-analysis), I had Claude vibe-code an Ed448 implementation. This includes: 1. The Ed448 signature algorithm 2. The Edwar
4.
▲
How we avoided side-channels in our new post-quantum Go cryptography libraries
(blog.trailofbits.com)
2 points
by
tob_scott_a
10mo ago
|
0 comments
5.
▲
Cloud cryptography demystified: Google Cloud Platform
(blog.trailofbits.com)
4 points
by
tob_scott_a
2y ago
|
0 comments
6.
▲
Disarming Fiat-Shamir Footguns
(blog.trailofbits.com)
2 points
by
tob_scott_a
2y ago
|
0 comments
7.
▲
by
tob_scott_a
2y ago
Recommended for this list: 1. https://archiv.infsec.ethz.ch/education/fs08/secsem/bleichen... - This is necessary to scare newbies away from implementing textbook RSA 2. https://www.iacr.org/a
8.
▲
Cryptographic design review of Ockam
(blog.trailofbits.com)
25 points
by
tob_scott_a
3y ago
|
3 comments
9.
▲
Cloud cryptography demystified: Amazon Web Services
(blog.trailofbits.com)
4 points
by
tob_scott_a
3y ago
|
0 comments
10.
▲
by
tob_scott_a
3y ago
> I think that attitude vastly underestimates the complexity of a typical TLS implementation If you ever get the impression that I'm underestimating the complexity of a typical TLS implementation, I promise you that I'm not. I
11.
▲
by
tob_scott_a
3y ago
woodruffw already wrote an excellent comment for this question: https://news.ycombinator.com/item?id=39131723 Rust isn't just memory-safety. The type system also coaxes developers towards eliminating some types of lo
12.
▲
by
tob_scott_a
3y ago
By itself? No. The other details covered in the blog post, however, would absolutely do something to fix denial of service attacks. To wit: x509-limbo
13.
▲
by
tob_scott_a
3y ago
I think getting it into cURL would be more impactful, since that's already tapped into by many OSS projects.
14.
▲
by
tob_scott_a
3y ago
> Carcinize existing C and C++ X.509 users. This could be game-changing for a lot of open source software. I spent years avoiding X.509 (and ASN.1, for that matter) in my designs because every time someone I trust poked it, a remotely ex
15.
▲
by
tob_scott_a
3y ago
Yeah, it's also deeper than that. Aptitude with a technology certainly correlates with intelligence, but it doesn't necessarily imply above-average intelligence. Some people attain their skills through Herculean levels of hard wor