Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
croikle
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
croikle
12y ago
I'm aware of simple brute-force attacks on short key IDs [0], which are just the last 32 bits of the fingerprint (e.g. 438CF0E2). With significant effort, one might be able to extend that to 64 bits. I'd be much more surprised by
2.
▲
by
croikle
12y ago
I believe it's Certificate Transparency, a Google project for globally monitoring SSL certificates. http://www.certificate-transparency.org/
3.
▲
by
croikle
12y ago
Is there any protection from trolls sending mail to this address? Yes, one can roll back the change, but an automated attack would win. Perhaps the address should be an unguessable <GUID>@ngrok.org instead? Or do you validate SPF and
4.
▲
by
croikle
12y ago
Yeah, the way the rules work magnesium is a dead-end. You have to double-oxygen to get to silicon, and then it's smooth sailing. (Note that all implemented reactions are listed if you scroll down)
5.
▲
by
croikle
13y ago
> For instance try finding out what stocks and weights make up the Russell 2000 index This actually sounds like a fun little linear algebra problem.
6.
▲
by
croikle
13y ago
Seems to work for me. I opened the Flash Player preference pane and discovered that it had already updated to 12.0.0.70.
7.
▲
by
croikle
13y ago
So, I'm not sure about that one. Apparently s_client ignores the error and completes the connection because it's intended to be used for debugging. > Currently the verify operation continues after errors so all the problems wi
8.
▲
by
croikle
13y ago
Yeah, I'm not sure. The linked diagram [1] shows them influencing routing, rather than some timing issue. [1] https://www.documentcloud.org/documents/785152-166819124-mit...
9.
▲
by
croikle
13y ago
Bufferbloat on the upstream pipe, if somebody is using your shared connection.
10.
▲
by
croikle
13y ago
AMA: http://www.reddit.com/r/MMA/comments/13govr/hi_rmma_im_one_o... You can find plenty of wikidrama at https://en.wikipedia.org/wiki/User_talk:Agent00f and https://en.w
11.
▲
by
croikle
13y ago
One license offered for Phil Rogaway's OCB block-cipher mode explicitly prohibits military use. (although, as I read it, the military could use still open source implementations under the other license) http://www.cs.ucdavis
12.
▲
by
croikle
13y ago
Even disregarding Apple's control over the software, the system depends on Apple as a trusted key distributor. This is the vulnerability which the article is concerned with, as far as I can tell.
13.
▲
by
croikle
13y ago
It's a cute idea, but you have 1/r^4 intensity scaling, which is prohibitive even at lunar distance. The lunar ranging experiments receive "one photon every few seconds" [1]. You could probably do better with bigger equi
14.
▲
by
croikle
13y ago
> Apple claims that even with access to the device, a nine digit passcode would take 2.5 years to brute force. That's 2.5 iPhone-years of computation, though. A speedy desktop could be 10 times as fast, and that's before we get
15.
▲
by
croikle
13y ago
Chrome's pinning is a definite upgrade, but it's more vulnerable than some people make it seem. In practice, a pin consists of a list of CA certificates which are allowed to sign for the given domain (the list is in [1]). This l
16.
▲
by
croikle
13y ago
No. You cannot outsource your random number generation unless you have an ultimately trusted third party. The important thing is that nobody knows your random numbers. After all, random.org could be malicious or compromised, too.
17.
▲
by
croikle
13y ago
In fact, even better: you can add forwarding to your existing connection. <newline>~C opens a command line, which accepts the following commands: ssh> help Commands: -L[bind_address:]port:host:hostport Request lo
18.
▲
by
croikle
13y ago
You can skip the master and spawn a fresh connection for your tunnel using `-o ControlPath=none`.
19.
▲
by
croikle
13y ago
Judging by [1], the latter. 1: http://identity.mozilla.com/post/56526022621/what-is-an-iden...
20.
▲
by
croikle
13y ago
s/prevent/mildly discourage
21.
▲
by
croikle
13y ago
To be fair, at 10 gigabits that buffer is only 12.5 ms, but given their dedication to latency I can see it being worth investigating.
22.
▲
by
croikle
13y ago
This flight was a month ago, and was briefly discussed here [0]. Video of the winning flight is available [1]. [0] https://news.ycombinator.com/item?id=5884266 [1] https://www.youtube.com/watch?v=syJq10EQko
23.
▲
AeroVelo human-powered helicopter officially wins Sikorsky Prize
(aerovelo.com)
3 points
by
croikle
13y ago
|
1 comments
24.
▲
US Emergency Alert System private SSH key mistakenly distributed
(arstechnica.com)
159 points
by
croikle
13y ago
|
39 comments
25.
▲
by
croikle
13y ago
This sort of thing is used, e.g. [0]. It collects entropy at a limited rate, though, so for demanding applications (SSL servers, say) you want dedicated hardware: [1], [2]. [0]: https://en.wikipedia.org/wiki/Hardware_ra
26.
▲
by
croikle
13y ago
Note that it's possible to convert your keys to use PBKDF2: http://martin.kleppmann.com/2013/05/24/improving-security-of...
27.
▲
by
croikle
13y ago
Or perhaps the best move is to hide. With such a large range of time, almost any species you encounter will be either incredibly primitive (thus not so interesting, and not receptive to your signals), or tremendously advanced, and a seriou
28.
▲
by
croikle
13y ago
I'm a fan of Diceware. Strong entropy guarantees and memorable passwords.
29.
▲
by
croikle
13y ago
Don't worry about it. Actually, you get meat & fur from that event, so it's not terrible.
30.
▲
by
croikle
13y ago
Warning: while the first part of the game works fine in a touch-based interface, a later section requires a keyboard. You'll be annoyingly unable to proceed on a touchscreen.
More ›