Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
vabmit
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
vabmit
11y ago
But, where did you get that public key that you're using to verify the signatures? Personally, I got that public key because it was included in an ISO image that I downloaded over TLS from website. So, if that TLS session was compromis
62.
▲
by
vabmit
11y ago
https://github.com/ProtonMail
63.
▲
by
vabmit
11y ago
Disclosure Note: I'm with ProtonMail. Please note that I don't officially speak for the company. But, I'm a crypto guy and this is Hackernews so... 1. While historically advertising a hosting location was a bit of a red flag
64.
▲
by
vabmit
11y ago
Verified. ProtonMail received no additional requests for money. And, those are the attackers' words. The original attackers claim they stopped. They hit many other Swiss companies and stopped after they were paid, as well. They are scr
65.
▲
by
vabmit
11y ago
The problem with ProtonMail is that their business model and brand are based on being domiciled in Switzerland and operating under Swiss law. Their datacenter threatened them if they didn't pay the attackers and no other datacenter in
66.
▲
by
vabmit
11y ago
CloudFlare was the first company ProtonMail called (with in 5 minutes of the DDoS starting). Unfortunately, they couldn't help ProtonMail. But, thanks to @rdl for responding to a txt on his cell phone at an inopportune time and mobiliz
67.
▲
by
vabmit
11y ago
Because ProtonMail would have been required to give CloudFlare encryption keys that would have 1) allowed CloudFlare to inject JavaScript to steal decryption passwords and keys 2) Allowed CloudFlare to collect metadata on traffic for indiv
68.
▲
by
vabmit
11y ago
For a site the size of ProtonMail, $6K is the cost for protection for a single month. Most of the companies that offer this kind of protection require you to sign a one to three year contract. There are two kinds of protection, basic HTTP&#
69.
▲
by
vabmit
11y ago
Protonmail's e-mail servers were off line for multiple days. With an outage of that length mail will start to bounce. It depends on the local configuration. But, 3 days/72 hours is pretty standard.
70.
▲
by
vabmit
11y ago
No. They ran the coins through a Coin Mixer: https://coinmixer.net
71.
▲
by
vabmit
11y ago
Aside from risk mitigation there are a few other things that no one has mentioned. First, shorting. If you sell 3 month US Treasuries that you do not have because you think that you are going to be able to buy them later at a lower price, y
72.
▲
by
vabmit
13y ago
.onion crawling was a 20% time project in 2009/2010 (IIRC). I'm sure you could find the announcement if you searched for it. Google does crawl and index.
73.
▲
Indictment: 13 Anon Members for Op Payback
(scribd.com)
1 points
by
vabmit
13y ago
|
0 comments
74.
▲
by
vabmit
13y ago
> Isn't step one President Obama ordering these programs > to be stopped? It's hard to see how he's going to > prosecute anyone for carrying out programs his own > administration either started or allowed to cont
75.
▲
by
vabmit
13y ago
Didn't Assange say in a (secretly?) recorded video where he was talking with Schmidt and another person that while the Americans got trusted root keys from Diginotar, the Chinese hacked Verisign and grabbed their root keys? I'll
76.
▲
by
vabmit
13y ago
I think you're confusing complexity with difficulty. It may be 10^12 times more complex. But, if you're making your own FGPAs or chips and you can just use different word sizes or massively add more gates or processing cores. Or,
77.
▲
by
vabmit
13y ago
Lenstra et al performed the factorization you cite, again on CPUs. Lenstra said in 2007 that he expected with in 5 years to be able to do 1024bit number - again with CPUs. 2048bit is no where near 10^12 harder if you use GPUs with larger wo
78.
▲
by
vabmit
13y ago
There's no need for a quantum computer. Everyone should be using at least 4096bit RSA. 1024bit RSA keys can be factored with conventional non-specialized hardware (read: CPU's, not even GPU's) with GNFS. IMHO, 2048bit RSA key
79.
▲
by
vabmit
13y ago
An interesting thing to note about 4096bit RSA openPGP keys, that's what Snowden was using. His PGP Key was a 4096bit RSA signing key with a 4096bit RSA encryption subkey.
80.
▲
by
vabmit
13y ago
The spike to 10+ sounds like it might be io blocking rather than CPU (which would be stuff like queries). If you look at your time wait (%wa) in top, and the output of iostat, you should be able to get an idea. If you're on VPS systems
81.
▲
by
vabmit
13y ago
> 1) A test to see how the journalist will react and to > flush out more information. I.e. force him to disclose > more information so they know what he has. I think they already know through a post event review of MicroSoft's
82.
▲
by
vabmit
13y ago
A number of start-ups have either already failed with a very similar business model or failed to go exponential growth. There was a good "Lessons Learned" post by one of them recently here on hacker news that got comments by both
83.
▲
Snowden: UK GCHQ Paid $150MM by NSA
(rt.com)
1 points
by
vabmit
13y ago
|
0 comments
84.
▲
by
vabmit
13y ago
Interesting comment! Yes, I have been trying to avoid EC because some of the random walk stuff I read made me uncomfortable given standardized curves. I always thought that NSA vector register desire was strictly due to block size of cipher
85.
▲
by
vabmit
13y ago
Or, they have a better (probably non-Ring) factoring method. I can't conceptualize what that might be, though.
86.
▲
by
vabmit
13y ago
RNG/PRNG output quality and the internals of the algorithms.
87.
▲
by
vabmit
13y ago
As the size of a semiprime increases, the number of smooth numbers that can be discovered (the "yield") by the GNFS with polynomials selected with academically known optimal polynomial selection algorithms decreases. With a reduct
88.
▲
by
vabmit
13y ago
Navy Seal Leak: _No_Easy_Day_ available from Amazon: http://www.amazon.com/No-Easy-Day-Firsthand-ebook/dp/B008MG1... (Notice how he makes no mention of ISA even being there, or doing any SSE). I don't recall
89.
▲
by
vabmit
13y ago
I think so. Yes. IIRC, the first time I saw this leaked was a combo leak by a Navy Seal and a member of the Executive. The Seal leaked that they powered down Bin Laden's computers to take his hard drives after they shot him. The Exec
90.
▲
by
vabmit
13y ago
>Still, you call for a Cambridge detective, the Secret Service also shows up, and that doesn't cause major head scratching? No. If something similar happened in Boston and you called BPD, you'd probably get a BPD detective that
More ›