Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ttybird
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
ttybird
5y ago
All of the chat protocols that I use are open actually, yet neither I nor you use a client that supports matrix, irc, xmpp, etc at the same time. Clients that supported multiple protocols died for a reason. These were "jack of all trad
32.
▲
by
ttybird
5y ago
Dunno about that. XMPP and Matrix seem to have solved this issue. Plus implementing TLS is much more difficult than implementing e2ee so I do not get the argument.
33.
▲
by
ttybird
5y ago
I was not planning to get a paid account there anyway. And regardless I prefer gitlab (due to the ICE stuff).
34.
▲
by
ttybird
5y ago
If that was the case then \query would not exist. There are (were) many smaller groups that use private channels. It is also how me and my first bf and some of my friends ended up talking.
35.
▲
by
ttybird
5y ago
The cost is that it is fragmenting the already fragmented scene of open protocols with an inferior solution. Now I will have to install a 5th chat client in order to talk with the few people that will move to it.
36.
▲
by
ttybird
5y ago
And yet almost nobody who uses irc uses it, unlike omemo (xmpp) and olm (matrix). Its encryption also predates matrix by a decade, its dh prime is only 1.5k bits big.
37.
▲
by
ttybird
5y ago
What does this solve that xmpp and matrix do not? And still no e2ee, after all these years.
38.
▲
by
ttybird
5y ago
Just had this happen to me with my Microsoft/Minecraft account. I had migrated my mojang account 2 days ago and today I was told that apparently they "detected some activity that violates our Microsoft Services Agreement" and
39.
▲
by
ttybird
5y ago
To be more specific, I personally estimate that it will take around 2^108 attempts on average to find one such key, which is much more difficult compared to an aes128 batch attack.
40.
▲
by
ttybird
5y ago
Kuhn's post seems to be based solely on ideological arguments and seems to be mostly critisizing the company's actions rather than the license. I will personally disagree regarding the unsatisfiable obligations part. As for res
41.
▲
by
ttybird
5y ago
Still though, in order for this to work you also need the specific key of one of their peers, so at the end of the day you still need a second preimage attack. And to be honest while I consider this as a silly decision on their part the f
42.
▲
by
ttybird
5y ago
Just to verify that we are on the same page. Are you claiming that given spacific x (and thus also h(x)) for a cryptographic hash function with output length n bits you can compute a y so that h(x) = h(y) in time 2^(n/2) with a reasona
43.
▲
by
ttybird
5y ago
instead of (3ma_id, pk) the compromised server sends Dave (3ma_id, pk') where (SHA256-128(pk) == SHA256-128(pk')) I can't see how the server can create pk' just with a collision attack in this case if pk is not control
44.
▲
by
ttybird
5y ago
Full disclosure is the only responsible disclosure method. I am glad that they decided to be public about it.
45.
▲
by
ttybird
5y ago
You are correct in a very technical sense. However this is only applicable if your friend is the one that is attacking... themselves. All that a collision attack can do in this case is to get you to think that the public key that your frien
46.
▲
by
ttybird
5y ago
https://www.gnu.org/licenses/gpl-faq.html#ModifyGPL It is allowed.
47.
▲
by
ttybird
5y ago
I believe that they do. This attack is unwaranted and without substance or explanation.
48.
▲
by
ttybird
5y ago
SSPL is a free software license, just like AGPL but slightly stricter.
49.
▲
by
ttybird
5y ago
AGPL is both capitalist and socialist at the same time, depending on the developer. "Oh, you want to use my software for a nonfree internet service? Sure! You just got to negotiate a license with me :)" I can't see anything a
50.
▲
by
ttybird
5y ago
There are many issues with this article. First of all the fact that the hashes are truncated does not matter, collision attacks are not an issue in this case, preimage attacks are. Secondly, in recent linux kernel versions /dev/ra
51.
▲
by
ttybird
5y ago
Sure you can, just like the AGPL versions of mongodb. You just need to follow the terms of the license.
52.
▲
by
ttybird
5y ago
I do not know about OSI but SSPL most certainly fits the FSF free software definition.