Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
upofadown
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
31.
▲
by
upofadown
3mo ago
But claiming that your system is end to end encrypted means that you are claiming protection from you and your system. This is mainly a truth in advertising issue.
32.
▲
by
upofadown
3mo ago
>...pretty much any E2E system is falling under this definition. The definition is quite clear. It does not apply when the implementation is not distributed by the same entity that creates it for example. There are other related issues b
33.
▲
by
upofadown
3mo ago
If, say, Signal was completely controlled by the CIA[1] and was thus evil, then having incoherent cryptography as described in the article would be a feature, not a bug. Being able to reject law enforcement requests would produce a false
34.
▲
by
upofadown
3mo ago
How about GPG distributed with a Linux distribution like Debian as a counterexample? It would be fairly difficult to backdoor GPG in that case without getting caught. Everything happens in the open both at the GPG level and the Linux distri
35.
▲
by
upofadown
3mo ago
>SpaceX plans to send one million more satellites into orbit, for space-based data centres, ... I think we should wait to see how the first satellite data centre works out. It seems fairly unlikely that it could be practical. It seems ki
36.
▲
by
upofadown
3mo ago
The linked article makes the argument that looking at the BSD licensed example code in the RFC that defines Opus would mean that code written based on that understanding would be a derivative work and would have to be BSD licensed. This see
37.
▲
by
upofadown
4mo ago
A signature is not authentication in itself. It is only such if the signing entity is in some way restricting what it is willing to sign. The domain part of the email address in the "From" field is so restricted. The signing MTA w
38.
▲
by
upofadown
4mo ago
The article makes a reference to the failed ARC (Authenticated Received Chain) proposal which was intended to help DKIM not break email forwarding: https://www.ietf.org/archive/id/draft-adams-arc-experiment-c... I
39.
▲
by
upofadown
4mo ago
>Anyone can put anything in the “From” field of an email. ... and then the article goes on to talk about SPF, DKIM and DMARC which authenticates only the domain part of the "From" field. So just the reputation of the email serv
40.
▲
by
upofadown
4mo ago
If you specifically mean something that can embody Shor's algorithm, it is fairly clear these days that a fundamental breakthrough is required. So the timeline extends from tomorrow to never.
41.
▲
by
upofadown
4mo ago
Deliverability issues with which email provider(s)? Often times it turns out the problem is just with Gmail.
42.
▲
by
upofadown
4mo ago
Gmail is one of the shoddiest of the ultra-cheap email providers. If you use Gmail, a significant number of messages will disappear. They don't go to junk, they just disappear. Gmail will reject messages for obscure technical reasons.
43.
▲
by
upofadown
4mo ago
I guess there is an interesting possibility here. Perhaps the targets were encrypting end to end (that is more or less the default now with XMPP clients). With the TLS over top of everything the attackers would not know that. Perhaps they
44.
▲
by
upofadown
4mo ago
>That technology overlaps only partially, at best, with what’s used in quantum processors. Dunno, how can you say that for sure when we don't actually know how to make a practical quantum processor? The bigger issue is that we are s
45.
▲
by
upofadown
4mo ago
6x10 here. Even more text. Only readable because each pixel is completely distinct.
46.
▲
by
upofadown
4mo ago
A cryptographic identity is a public key as used in a public key signature scheme. So a particular person is represented by a ridiculously long number. That number can be shortened with some sort of hash to a shorter value to make a key fin
47.
▲
by
upofadown
4mo ago
From the article: >IBM is developing four custom ASICs — a decoder, a two-qubit gate controller, a single-qubit controller, and an amplifier — designed to handle quantum control at scale, with these circuits expected to converge around 2
48.
▲
Concluding the Arc Experiment
(ietf.org)
1 points
by
upofadown
4mo ago
|
0 comments
49.
▲
by
upofadown
4mo ago
The big news for some of us is that Exim has been dropped from ports. Here is a good article about transitioning from Exim to OpenSMTPD: https://nxdomain.no/~peter/time_for_opensmtpd.html I tried using OpenSMTPD a long
50.
▲
by
upofadown
4mo ago
The Steel Pulse idea actually sounds sort of possible...
51.
▲
by
upofadown
5mo ago
Checking the required hardware noise performance: >On superconducting architectures with 10−3 physical error rates... So still 1-2 orders of magnitude better than what we can achieve. This is against a 256 bit elliptic curve. For some re
52.
▲
by
upofadown
5mo ago
There are no preferences available for symmetrical encryption. GnuPG for example does AES for symmetrical encryption by default. Is it violating RFC-4880? I think things get philosophical here. I doubt that there is an implementation left t
53.
▲
by
upofadown
5mo ago
I stated that it was possible to use RFC-4880 in a way that is completely secure, not that every possible use is completely secure. Your example mentions 3DES. 3DES is secure. The reason it is not recommended is because 128 bit block length
54.
▲
by
upofadown
5mo ago
PGP covers the case where data is encrypted and might stick around in that state for a long time. Decades. So backwards compatibility is essential. Fortunately we can use the existing standard (RFC-4880) in a way that is completely secure.
55.
▲
by
upofadown
5mo ago
Yes. Both standards proposals have SHA256 fingerprints. Not that there is anything wrong with SHA1 fingerprints in practice. The sort of collisions that SHA1 is susceptible to are not an issue in this particular application. With SHA256 fin
56.
▲
by
upofadown
5mo ago
For something like PGP, any performance difference wouldn't matter. There is one message and the key agreement is done once. As long as things are fast enough to be imperceptible to the user we are fine.
57.
▲
by
upofadown
5mo ago
It is very hard to prevent a proposal from becoming a RFC. You have to generate ongoing opposition for longer than the supporters. FWIW, here is the LibrePGP proposal: * https://datatracker.ietf.org/doc/draft-koch-libre
58.
▲
by
upofadown
5mo ago
From the GnuPG prospective RFC-9580 is a deliberate fork away from what agreement could be achieved. Basically the faction that is now called RFC-9580 (mostly Sequoia and Proton) wanted to make a lot of changes to the existing standard but
59.
▲
by
upofadown
5mo ago
>Encryption would have been baked in from the start, rather than waiting for PGP, S/MIME, and TLS to add them later. This comment intrigued me so I did a tiny bit of research. It appears that X.400 uses S/MIME for encryption (s
60.
▲
by
upofadown
5mo ago
Yeah, you only get out something like 30% more energy than you put in[1]. So this isn't so much about how great solar is but is more about how bad corn ethanol is... [1] https://en.wikipedia.org/wiki/Ethanol_fuel_e
More ›