Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
NTroy
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
NTroy
5y ago
I believe the math you outline above refers to this step, located on page 7 of the Technical Summary: > Next, the client creates a cryptographic safety voucher that has the following properties: If the user image hash matches the entry i
2.
▲
by
NTroy
5y ago
It is my understanding that the vouchers are only encrypted with a key derived from the NeuralHash of the photo. Therefore an attacker would only need to find a matching NeuralHash, to decrypt the voucher. Apple needs the blinding key, beca
3.
▲
by
NTroy
5y ago
If Apple is to keep their word about guaranteeing the privacy of non-CSAM photos (which this whole discussion is about them not doing a very good job of), then they would only be able to do that with photos stored in iCloud because of this
4.
▲
by
NTroy
5y ago
Yes, this ^^^^^^ > The proposed attack on Apple's protocol doesn't work. With all due respect, I think you may have misunderstood the proposed attack @jonathanmayer, as what @jobigoud said is correct.
5.
▲
by
NTroy
5y ago
> For CSAM matches, the cryptographic header in the voucher combines with the server-side blinding secret (that was used to blind the known CSAM database at setup time) to successfully decrypt the outer layer of encryption. In the text y
6.
▲
by
NTroy
5y ago
The question doesn't presume that, as the the secret for blinding the CSAM database would only be helpful if a third party were also looking to see which accounts contained CSAM. In this case, the question assumes that an attacker woul
7.
▲
Apple's New CSAM Protections May Make iCloud Photos Bruteforceable
(crypto.stackexchange.com)
233 points
by
NTroy
5y ago
|
81 comments
8.
▲
Show HN: Open Source Police Accountability
(badapple.tools)
6 points
by
NTroy
5y ago
|
0 comments
9.
▲
by
NTroy
6y ago
Sure! - Both - Both - Yes. I wish that weren't the case, but considering that I can't find a single provider so far who respects end user privacy, I would expect for one who does so to charge more. - No. Ideally, the provider woul
10.
▲
by
NTroy
6y ago
Yeah, that's what I currently do. However as traffic grows in both volume and origin, and can be hard (and expensive) to keep up. That's why a privacy-respecting provider who already has the infrastructure would be ideal.
11.
▲
by
NTroy
6y ago
That's a good point. It wouldn't be the first time that providers (most notably VPN providers) have lied about their logging policies with devastating consequences for the end user while they get off scott free. Getting something
12.
▲
by
NTroy
6y ago
Yeah, currently I run my own DNS server. However, as traffic grows and so does your customer base and server locations, it would be nice to use a dedicated DNS provider, as they'll already have the infrastructure set up to handle a sig
13.
▲
by
NTroy
6y ago
A pricing scheme that isn't too far off of what you'd find from most other managed DNS providers. Obviously I wouldn't mind paying more for the "privacy" aspect, as long as the price isn't ridiculous. I don
14.
▲
Ask HN: Does truly private DNS hosting exist?
12 points
by
NTroy
6y ago
|
13 comments
15.
▲
by
NTroy
6y ago
https://GitHub.com/P5vc
16.
▲
Shown HN: Open Source Privacy
(priveasy.org)
1 points
by
NTroy
6y ago
|
1 comments
17.
▲
by
NTroy
6y ago
Their code: https://GitHub.com/P5vc
18.
▲
Show HN: Open Source, Community-Run Privacy Services
(priveasy.org)
2 points
by
NTroy
6y ago
|
1 comments
19.
▲
by
NTroy
6y ago
You are absolutely right. I work in the field of information security, where this seemingly backwards approach of thinking can quickly crumble optimistic projects! If you're not implementing security through the mindset of someone look
20.
▲
by
NTroy
6y ago
Recovered for/from what? I've had my account disabled in the past (I created it while I was underage, with an adult representing me. Once they changed their terms to no longer allow this, they temporarily banned my account). But,
21.
▲
by
NTroy
6y ago
Yes, I completely agree with you! I think being able to read through the actual code of the software you use, in order to fully understand it, what it does, and how it works is a priceless tool. On top of that, most open source tools also p
22.
▲
Ask HN: Is open source security effective?
5 points
by
NTroy
6y ago
|
2 comments
23.
▲
Show HN: Fetch Apply (Ansible/Puppet/Aviary.sh Alternative)
2 points
by
NTroy
6y ago
|
0 comments
24.
▲
by
NTroy
6y ago
You're absolutely right! But hey, I appreciate that at least they cite their sources!
25.
▲
by
NTroy
6y ago
I'm not sure exactly what you mean. If you're looking for a production example, then here's one: Priveasy.org is an open source group that uses P5.vc (the shorter domain's letters sounded-out sound kind of like "Pri
26.
▲
by
NTroy
6y ago
Yup, I do own a few! :) That's very true that they're mostly obscure domains, but that doesn't make them any harder to buy. Most domain registrars will show you all or most possible TLDs that are available for your domain. Yo
27.
▲
Ask HN: Why are there still so many 2-letter domain names available?
6 points
by
NTroy
6y ago
|
4 comments
28.
▲
Priveasy: A VPN that's community-run, transparent, and open source
(github.com)
2 points
by
NTroy
6y ago
|
0 comments
29.
▲
by
NTroy
6y ago
That would be amazing and terrible all at once: the pandemic could be over sooner, but more people will unnecessarily die before that happens. Although I’m curious as to how permanent the antibodies would be, as I’ve seen that they don’t la
30.
▲
by
NTroy
6y ago
Looks like a great article... however I have to be honest: the unnoticed, broken HTML on the main page of that link does not inspire too much confidence.
More ›