Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
winterdeaf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Password managers less secure than promised
(ethz.ch)
8 points
by
winterdeaf
8mo ago
|
0 comments
2.
▲
by
winterdeaf
1y ago
So much vitriol. I understand it's cool to hate on EA after the SBF fiasco, but this is just smearing. The key to scientific thinking is empiricism and rationalism. Some people in EA and lesswrong extend this to moral reasoning, but ut
3.
▲
by
winterdeaf
2y ago
As far as I am aware, there is no way to stop malicious tags without modifying the protocol to authenticate the messages being broadcast as originating form a genuine tag. [1] Making a tag that is not trackable is currently as easy as flipp
4.
▲
by
winterdeaf
2y ago
This is such a charade. Making "invisible" airtags is trivial [1], and I wouldn't be surprised if such airtags are being manufactured en-masse. We allowed the creation of a global tracking network under the false pretense of
5.
▲
by
winterdeaf
4y ago
I would argue that it is not misleading -- the website domain is, after all, "breakingthe3ma.app". The title of the paper presents a more academic angle, and is intended to highlight what the "learned lessons" are, but l
6.
▲
Breaking the Threema Secure Messenger
(breakingthe3ma.app)
16 points
by
winterdeaf
4y ago
|
4 comments
7.
▲
by
winterdeaf
4y ago
> well-reviewed zero-footgun nacl.SecretBox()-style thing for this use case, but there simply isn't. You'd be surprised, but I've seen designers who managed to shoot themselves in the feet with SecretBox() calls alone. Any
8.
▲
by
winterdeaf
4y ago
To put it in Igor's words, it is like "somebody baked a cake following a recipe, but without ever having tasted or seen a real cake". The crypto design is brittle, but the practical attacks are somewhat limited. The reason wh
9.
▲
by
winterdeaf
4y ago
Tarsnap does not actually look bad. But any client-to-server protocol that is not TLS1.3 will make cryptographers twitch, and (as noted in the documentation pages) compression is bound to offer a side-channel attack (if only an impractical
10.
▲
by
winterdeaf
4y ago
The same research group working on the Telegram MTProto security analysis is behind these attacks on MEGA! (I should add: disclosure, I work there too.)
11.
▲
by
winterdeaf
4y ago
This speaks volumes about the need of standardized encrypted cloud storage protocols. It always surprises me how fragmented the entire space is: Syncthing "untrusted devices" support is still experimental, Nextcloud does support
12.
▲
Cryptographic Weaknesses in Telegram's MTProto
(mtpsym.github.io)
44 points
by
winterdeaf
5y ago
|
11 comments