Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
AnaniasAnanas
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
AnaniasAnanas
7y ago
Banks are not known for using the best/safest solutions. Just take 4 digit pins and 3DES into account for example. > who only offer certs of RSA and P-{256,384}? I am pretty sure that nginx and openssl only recently added support fo
2.
▲
by
AnaniasAnanas
7y ago
Nobody was ever fired for using DJB. Meanwhile I would gladly fire someone for using AES128 or the NSA-sponsored curves, despite being in Suite B.
3.
▲
by
AnaniasAnanas
7y ago
> some of them do involve using RSA with absurd key sizes and they'll likely fail the competition. Only one (specifically DJBs joke Post-QC algorithm), and it did not pass to the second round.
4.
▲
by
AnaniasAnanas
7y ago
> WhatsApp, Telegram and Signal use mobile phone numbers as identifiers One notable exception (which as I understand is tptacek-approved) is Wire, which only needs an email.
5.
▲
by
AnaniasAnanas
7y ago
> Nobody actually wants to rely on a single entity (for or non-profit) for their communication You don't have to do that. Protocols like tox for example are distributed and use DHT in order to find peers.
6.
▲
by
AnaniasAnanas
7y ago
It's even worse than it seems. The certificates are only a few megabytes long. https://twitter.com/FiloSottile/status/1145091106138394625
7.
▲
by
AnaniasAnanas
7y ago
Both Signal and Wire are FOSS though.
8.
▲
by
AnaniasAnanas
7y ago
As much as I believe that Efail was the result of badly implemented email clients it's not like the OpenPGP standard hadn't any involvement with it whatsoever. DJB for example suggests small authenticated and encrypted packets, so
9.
▲
by
AnaniasAnanas
7y ago
I tried exporting org-mode to latex in the past and found it extremely buggy. I don't really see a reason not to just directly use LaTeX instead.
10.
▲
by
AnaniasAnanas
7y ago
*Everywhere. My own school experience in Europe was pretty much the same as he described. And it is not only my school experience either, there were many cases of unpunished power abuse that the teachers engaged in in nearby schools.
11.
▲
by
AnaniasAnanas
7y ago
The schools that I went to had around 300 students. It did not stop the abuse by teachers nor did it stop the bullying that the teachers ignored.
12.
▲
by
AnaniasAnanas
7y ago
OCaml is very popular in academia though, especially in the field of theoretical computer science and formal verification. Coq, Frama-C, Flow, CompCert, etc are all written in OCaml. Heck, if you are running a graphical GNU distribution cha
13.
▲
by
AnaniasAnanas
7y ago
No offense, I am genuinely curious, why would anyone use any closed source software for anything related to security after the Snowden revelations?
14.
▲
by
AnaniasAnanas
7y ago
Why does everyone seem to hate delay slots? I understand that it makes writing assembly more annoying but most people use a compiler anyway.
15.
▲
by
AnaniasAnanas
7y ago
A better question would be: why were Coinbase employees allowed to use any browser with javascript enabled and outside of a VM? Qubes OS has been a thing for quite a while.
16.
▲
by
AnaniasAnanas
7y ago
I mentioned the possibility of an untrustworthy person gaining access to bugzilla yesterday but it seems that most people disagreed with it: https://news.ycombinator.com/item?id=20221397
17.
▲
by
AnaniasAnanas
7y ago
The voters are not one person. Sadly democracy ends up being the fascism of the many.
18.
▲
by
AnaniasAnanas
7y ago
Whoever made the decision not to take backups for example. The ones who will have to pay for their mistakes will be the taxpayers otherwise.
19.
▲
by
AnaniasAnanas
7y ago
Shouldn't the one responsible personally have to pay for it rather than the city and its taxpayers?
20.
▲
by
AnaniasAnanas
7y ago
> It needs to be possible to hire people that you trust not to disclose all your secrets, and your customer's secrets I disagree, it needs to be possible for whistle-blowers to operate freely. It should also be possible to disclose
21.
▲
by
AnaniasAnanas
7y ago
Companies seem to try to abuse patent, trademarks, and copyrights as much as they can anyway. The best of-course would be if NDAs, patents, and copyrights all disappeared overnight. Trademarks are generally fine but they can be abused.
22.
▲
by
AnaniasAnanas
7y ago
> NDAs and non-competes have their uses I have yet to see a valid use that does not hinder whistle-blowing, the advancement of technology, or does not abuse the employees. I am sure that you will find a few valid use-cases if you try har
23.
▲
by
AnaniasAnanas
7y ago
NDAs and non-compete agreements should not ever be considered as valid contracts by the government.
24.
▲
by
AnaniasAnanas
7y ago
It will be seen by a malicious actor anyway after the fix is released. The difference is that there will be more time for a malicious actor to act against a fork if an embargo is applied.
25.
▲
by
AnaniasAnanas
7y ago
Consider trying the debian package until it is updated in your system.
26.
▲
by
AnaniasAnanas
7y ago
It is important to also understand what causes the issue, how it was exploited, etc. Plus I am pretty sure that they had the bug report before the fix was released.
27.
▲
by
AnaniasAnanas
7y ago
Anyone can run a fork though, I right now might be running my personal fork. This is part of the point of free software. Plus, you assume that the select few developers that are given the exploit information are trustworthy. The exploit bei
28.
▲
by
AnaniasAnanas
7y ago
https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 I find it really gross that they do not allow others to access it. This behavior damages the forks.
29.
▲
by
AnaniasAnanas
7y ago
Would you mind elaborating? What does it have that uBlock Origin doesn't?
30.
▲
by
AnaniasAnanas
7y ago
Non-mobile link: https://en.wikipedia.org/wiki/Submarine_Command_System#SMCS-...
More ›