Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bracewel
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
bracewel
1y ago
This is mainly actually for testing constant-time code, rather than doing proper memory tracking (see https://www.imperialviolet.org/2010/04/01/ctgrind.html for a slightly out-of-date description of this tech
2.
▲
by
bracewel
1y ago
Author of the linked CL here: we added this mostly so that we could abuse the memory initialization tracking to test the constant-time-ness of crypto code (similar to what BoringSSL does, proposed by agl around fifteen years ago: https:&#x
3.
▲
Go Cryptography Security Audit
(go.dev)
58 points
by
bracewel
1y ago
|
1 comments
4.
▲
by
bracewel
4y ago
There is a fifth, incredibly common, (arguably) non-malicious possibility. You don't control the entirety of your web stack, and your hosting provider, or DNS provider, or someone else, has decided to be 'helpful' (either bli
5.
▲
by
bracewel
7y ago
ah yes, I remember personally lying to congress and pushing false narratives in the media. oh wait, no, that wasn't me was it...
6.
▲
Googlers Against Transphobia and Hate
(medium.com)
1 points
by
bracewel
7y ago
|
0 comments
7.
▲
by
bracewel
8y ago
Note that CABF bylaws require a simple majority of browsers to vote positively for a ballot for it to pass, regardless of how CAs vote.
8.
▲
Tg registrar was compromised for at least 9 days
(bugzilla.mozilla.org)
2 points
by
bracewel
9y ago
|
0 comments
9.
▲
Using BGP to Acquire Bogus TLS Certificates [pdf]
(petsymposium.org)
3 points
by
bracewel
9y ago
|
0 comments
10.
▲
Final Removal of Trust in WoSign and StartCom Certificates
(security.googleblog.com)
9 points
by
bracewel
9y ago
|
1 comments
11.
▲
Symantec explores selling web certificates business
(reuters.com)
52 points
by
bracewel
9y ago
|
20 comments
12.
▲
Apple's annual profits fall for first time in 15 years as iPhone sales decline
(theguardian.com)
15 points
by
bracewel
10y ago
|
2 comments
13.
▲
The RFC 5114 saga
(blog.intothesymmetry.com)
9 points
by
bracewel
10y ago
|
1 comments
14.
▲
Russia claims it can collect encryption keys
(engadget.com)
2 points
by
bracewel
10y ago
|
0 comments
15.
▲
by
bracewel
10y ago
> CA/SSL specification does not change weekly... The draft ACME specification does though.
16.
▲
Incidents involving the CA WoSign
(mail-archive.com)
2 points
by
bracewel
10y ago
|
0 comments
17.
▲
by
bracewel
10y ago
DNSSEC is enforced at the resolvers.
18.
▲
by
bracewel
10y ago
Yup.
19.
▲
by
bracewel
10y ago
Google did not write the HTTP/2 spec. While Roberto Peon is one of the authors (and a core developer of the preceding SPDY protocol) saying that HTTP/2 is some Google invention is a bit of a punch in the face to the IETF and the t
20.
▲
Early Impacts of Certificate Transparency
(facebook.com)
44 points
by
bracewel
10y ago
|
9 comments
21.
▲
by
bracewel
10y ago
It allowed users to bypass Twitter blocks by tweeting at the bot while tagging users that block them, which seems pretty bad and was abused very quickly. Also it's a violation of the Twitter TOS.
22.
▲
by
bracewel
10y ago
> paltry $15k The tech/security community is crazy.
23.
▲
StartSSL domain validation vulnerability
(oalmanna.blogspot.com)
154 points
by
bracewel
10y ago
|
73 comments
24.
▲
by
bracewel
11y ago
> The two CVEs against Varnish were both utterly bogus "trophy-hunter" CVEs in my opinion. (But don't take my word for it, judge for yourself.) ok > CVE-2013-4484: Varnish before 3.0.5 allows remote attackers to cause
25.
▲
Distributed Security Alerting
(slack.engineering)
2 points
by
bracewel
11y ago
|
0 comments
26.
▲
by
bracewel
11y ago
Dope watermarks.
27.
▲
by
bracewel
11y ago
Guh, until CF/FB can provide some data that shows users with no upgrade path are genuinely going to be effected by this, and not connections MITM'd by some crappy AV or other random middlebox the LV proposal seems like a pretty si
28.
▲
by
bracewel
11y ago
waits for RMS to get mad https://gcc.gnu.org/ml/gcc/2014-01/msg00247.html
29.
▲
Microsoft Updates Trusted Root Certificate Program to Reinforce Trust
(blogs.technet.microsoft.com)
2 points
by
bracewel
11y ago
|
0 comments
30.
▲
Why you should always use HTTPS
(developers.google.com)
2 points
by
bracewel
11y ago
|
0 comments
More ›