Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zmanian
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
zmanian
10y ago
Virgil seems to be willfully ignorant. Tor needs greater political support in the West because of second crypto wars. Tor also needs more funding that is available for work on privacy and anonymity to support use cases like Securedrop. Too
62.
▲
by
zmanian
10y ago
The CMU attack required setting up a very large number of malicious relays on the Tor network. It was bad that Tor didn't notice the large number of new relays joining the network but greater vigilance is being shown. Tor is effective
63.
▲
by
zmanian
10y ago
I remember Ed Kemmet saying that NUMA optimizations are patent encumbered and presumably licensed. Probably part of the reason this is closed source.
64.
▲
by
zmanian
10y ago
I fully admit this line of thinking hasn't completely solidified for me. But empirically the iOS ecosystem is demonstrating that there is a close source ecosystem with better security properties than the open source one. Security advan
65.
▲
by
zmanian
10y ago
As consumers we don't face very good choices right now. When you buy an iPhone, you don't own it. You are a sharecropper on Apple's OS license. If you buy an Android with an unlockable bootloader, you own it. But if attacked,
66.
▲
by
zmanian
10y ago
Bamford's expertise in espionage is pretty similar. There seem to be two plausible explanations for the Shadow Brokers release. 1. The doctrine of the US govt in cyberwar is proportionate response. This is either preemption or escalati
67.
▲
by
zmanian
10y ago
I suspect many people will migrate to electron instead of web apps. APIs for USB and Bluetooth and the isolation offered by Chrome apps have no equivalent in extensions / web apps
68.
▲
by
zmanian
10y ago
This attack started with a well known pattern where protocols where you can freely mutate cyphertext in transit usually end of building a decryption oracle into them that an attacker can exploit. Then they found a novel oracle in the image
69.
▲
by
zmanian
10y ago
You'll get an exit with DDOS attack against it. Not an exit controlled by the attacker. The attacker will see the same fraction of Tor traffic with or without the attack. The Tor user base will notice a massively degraded experience. Y
70.
▲
by
zmanian
10y ago
This attack is a general amplifier on denial of service attacks on Linux server. If this attack was deployed against Tor, this would appear as a general DDOS attack against Tor and degrade most users experience. It would not help an attacke
71.
▲
by
zmanian
10y ago
I meant the former...
72.
▲
by
zmanian
10y ago
I think you are right. The same techniques could be applied in ethereum to reward ddos attackers. It's beautiful and terrible at the same time. <3 We may have found a deeper horror than assignation markets.
73.
▲
The Tor Project Social Contract
(blog.torproject.org)
18 points
by
zmanian
10y ago
|
0 comments
74.
▲
by
zmanian
10y ago
TouchId coming to the MacbookPro will bring the secure element from the Iphone with it. I'm hoping they also use the secure element to implement SecureBoot of only signed software. Ideally this could be disabled like in a Chromebook
75.
▲
by
zmanian
10y ago
I've been wanting something like this to sandbox build systems like npm, cargo etc so you can be sure your dependency resolution can't exfiltrate your keys.
76.
▲
Secure Memory in a Haskell Cryptographic Library
(cse.iitk.ac.in)
1 points
by
zmanian
10y ago
|
0 comments
77.
▲
by
zmanian
10y ago
I don't see anything in their site about end to encryption?
78.
▲
Privacy Enhanced Payment Channels for ZCash
(z.cash)
3 points
by
zmanian
10y ago
|
0 comments
79.
▲
by
zmanian
10y ago
IBM is pushing hyperledger / blockchain on Power8 pretty hard. Given how much memory bandwidth is a bottleneck on updating the internal Merkle trees, Power8 might be good for tx throughput
80.
▲
by
zmanian
10y ago
I can see this being immensely beneficial to environments that rely heavily of calling out openssl for TLS like node and python.
81.
▲
by
zmanian
10y ago
Rust is not a good language for low level crypto implementation because it offers no facilities for side channel resistant algorithims. Ring uses the extensively reviewed implementation from BoringSSL and considerable expertise from the aut
82.
▲
by
zmanian
10y ago
We do not currently have good options for small Post Quantum signatures. Hash Based signatures in a web of trust would result in enormous amounts of signature data for each public key. A stateful hash based signing protocol like XMSS might
83.
▲
by
zmanian
10y ago
I'm really impressed by how easy it is to get NISTP256 key from the enclave. I think Intel got a lot of things right and then completely failed on the signing and attestation process. Hopefully we can see a future iteration of SGX that
84.
▲
by
zmanian
10y ago
Bitcoin script provides a no elegant way to invalidate old states. There are various solutions to this in lightning network tx but they end up requiring actively watching the network in case an old state is broadcast. If you have a better m
85.
▲
by
zmanian
10y ago
You see a common pattern in crypto projects. The core of the project is passionate autodidacts and the experts are in periphery. Tor and Ethereum have ample access to experts via academic research, security auditors and academic consultants
86.
▲
Checked C
(research.microsoft.com)
336 points
by
zmanian
10y ago
|
156 comments
87.
▲
by
zmanian
10y ago
I'm entirely convinced that Intel would undermine the entire trusted computer over some relatively hairbrained ideas about new revenue sources. Intel needs to give us an alternative.
88.
▲
by
zmanian
10y ago
We need operating system vendors to give us a mechanism for easily creating and managed sandboxed dev environments. Ones dev environment should be a place where remote code execution is a high probablity and we need better tools to partitio
89.
▲
Interviewing Phineas Fisher about Hacking and Anarchism
(medium.com)
3 points
by
zmanian
10y ago
|
0 comments
90.
▲
by
zmanian
10y ago
Basically the jurisdiction is limited to equipment used by the county sheriff. To cover the police departments within the county, we need to pass a similar ordinance in each city. We are working on it
More ›