Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gtank
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
21 ms
·
1.
▲
by
gtank
6y ago
Gotcha. I was wondering about both - it seems possibly useful to be able to automate my authZ and groups in ShareWith, but mostly I would like to see what a Zanzibar-aaS can do. Guess I'll stay tuned :)
2.
▲
by
gtank
6y ago
Super cool. I've been waiting for someone to pick up Zanzibar since the paper came out! What are your plans for surfacing the policy relations to developers?
3.
▲
by
gtank
7y ago
This is a user-facing implementation of https://wiki.mozilla.org/Security/Binary_Transparency , built on top of Let's Encrypt ( https://letsencrypt.org/ ) and exisiting Certificate Transparency infra
4.
▲
by
gtank
8y ago
It’s enough because of the underlying PAKE technique. The passwords do not directly become the key, and an unsuccessful bruteforce attempt breaks the session. PAKE isn’t really new, but it’s certainly underused for how much it changes the p
5.
▲
TLS 1.2 Session Tickets
(blog.filippo.io)
183 points
by
gtank
9y ago
|
48 comments
6.
▲
by
gtank
10y ago
Author here, glad you enjoyed the talk! Looking into it more I noticed that there's a Go implementation[1] that is noted to be constant-time with a !amd64 build tag. So it isn't just the assembly one. [1] https://golang
7.
▲
by
gtank
10y ago
URL mistake. Direct link: https://www.nccgroup.trust/globalassets/our-research/us/whit...
8.
▲
Abusing Privileged and Unprivileged Linux Containers
(nccgroup.trust)
101 points
by
gtank
10y ago
|
50 comments
9.
▲
by
gtank
10y ago
You should see their (much faster!) subsequent paper. It develops an entirely new mapping to take advantage of Intel vector extensions, then invokes Valefor instead of Bael.
10.
▲
by
gtank
11y ago
There's a lot more to defeating traffic analysis than random padding: http://freehaven.net/anonbib/cache/oakland2012-peekaboo.pdf
11.
▲
by
gtank
11y ago
CoreOS has released one: https://github.com/coreos/go-oidc We're currently using it in our own OAuth/OIDC identity provider.
12.
▲
by
gtank
11y ago
I have a very similar set of good memories. I put more time into deobfuscation, updating, detection evasion, and (eventually) server emulation than bots per se. My contact info is in my profile, it would be cool to see if we ran into each o
13.
▲
by
gtank
11y ago
I highly endorse this sort of thing! Reverse engineering online games is how I really got started with computers. It's a great teaching tool because the reward loop is short and immediately relevant - you get superpowers, in the game y
14.
▲
by
gtank
11y ago
People who object to javascript crypto usually mean that in the context of "browser javascript", which is fraught with peril [1]. The javascript language itself isn't necessarily the problem (although parts of it are dodgy by
15.
▲
by
gtank
12y ago
I've been interested in formal treatments of ledgers for a while now. Does anyone know if other work has been done in this area?
16.
▲
by
gtank
12y ago
Development of mlpack has been going on for at least 7 years and my impression is that it's pretty mature. It was originally affiliated with a lab at Georgia Tech, where its current maintainer (a friend of mine) is a PhD student. The d
17.
▲
Least Authority's Security Audit of Cryptocat
(leastauthority.com)
2 points
by
gtank
12y ago
|
0 comments
18.
▲
by
gtank
13y ago
Speaking for northern NM: I was in Albuquerque recently and can't say enough of the hiking nearby. The city actually backs into the Sandia Mountains, which are full of good trails. If you're into the history, brief drives north or
19.
▲
by
gtank
13y ago
I've spent tons of time in Greenville. The wholly-walkable downtown hosts lots of restaurants (recommended: The Lazy Goat), coffee shops, the Greenville Symphony Orchestra, and an extensive park along the river. Local breweries, nearby
20.
▲
by
gtank
13y ago
As a former longtime resident of the south, including a few years in Tuscaloosa (we seem to have overlapped - 2008-2010), I'd advise against judging the region by the standard of Tuscaloosa. I know it's a huge college town and tha
21.
▲
by
gtank
13y ago
It's the default port for running a local rack app (sort of a ruby-web-stuff middleware). For specific values of "developer" :)
22.
▲
by
gtank
13y ago
This turned out to be an interesting little game. I bet you can always tell a developer. Here's mine: a: audobox.com b: buzzfeed.com/emofly/eggs-in-exciting-holes (bookmarked for ideas) c: calendar.google.com d: dashboard.her
23.
▲
by
gtank
13y ago
Good suggestion- that may be worth adding. Anecdotally, though, we've been using this ourselves for a while without seeing that. People seem to get that they should speak clearly.
24.
▲
by
gtank
13y ago
We have now fixed this and it should be available on tablets as soon as the Play store propagates the new version.
25.
▲
by
gtank
13y ago
That should not be the case, as we've allowed distribution to everywhere. It could be a device issue- are you on a tablet? We're working to fix that issue at the moment. If you are on a phone, what type is it and which Android ver
26.
▲
by
gtank
13y ago
That's a good suggestion! Our idea here is to add useful context to what would otherwise be an unnavigable pile of audio.
27.
▲
by
gtank
13y ago
Thanks! The app works for long-form recordings too. We upload in chunks throughout the session, and the battery usage from our all-day tests is currently about 30% on a Nexus 4.
28.
▲
by
gtank
13y ago
I don't have quite such a way with words, but Matasano is awesome. It's also worth noting that they take interns (full disclosure: me, twice) and yes- you will do those things, for real, immediately. Don't know how? Ask and prepare to learn
29.
▲
by
gtank
13y ago
They're on our machines, but under keys that we don't have. We're also considering a federated model that would give users control over their storage.
30.
▲
by
gtank
13y ago
We’re designing this thing so that even we can never access your recordings. Building it with actual security in mind poses some UX challenges (don’t lose all your credentials at the same time!) but we’d rather have that problem than any am
More ›