Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mahemm
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
mahemm
22d ago
I'm not sure this really hits E2EE. E2EE is a claim about who cannot read your mail, so the test is whether confidentiality survives a hostile operator. This model fails that test twice, and the choice of PGP decides how bad the second
2.
▲
by
mahemm
1mo ago
I found this to be a really informative piece about how people at the forefront of their field (in this case, AppSec) can move themselves farther with LLMs, as well as the limits to be dealt with and handled in that process.
3.
▲
Can AI do novel security research? Meet the HTTP Terminator
(portswigger.net)
1 points
by
mahemm
1mo ago
|
1 comments
4.
▲
by
mahemm
2mo ago
How does this differ from e.g. S3 pre-signed URLs?
5.
▲
by
mahemm
3mo ago
The tl;dr on why IO is important is you can just use (effectively) one program, but stuff different secrets inside them with a guarantee that no one can pull those secrets back out. Cryptographers have proven that it's possible to us
6.
▲
by
mahemm
3mo ago
It's interesting to see such ongoing strong jobs data in the face of unprecedentedly negative sentiment[1]. Not only do the numbers fail to look as bad as the sentiment, the numbers are actually fantastic and (AFAICT) fully uncorrelate
7.
▲
by
mahemm
5mo ago
I'm surprised y'all stopped at the personal finance layer. I've been thinking for awhile that LLMs would be really effective as personal financial advisers, and this kind of hookup (plus I guess another one for investment acc
8.
▲
by
mahemm
6mo ago
Would you be comfortable using this same logic to invest most of your net worth in lottery tickets/betting on black in a casino? If not, I'd be curious to hear what is different in that for you.
9.
▲
by
mahemm
6mo ago
My FAANG employer launched a service ~6 months ago that today seems millions of DAUs. This service was 100% vibe coded. This service was created 20x faster than the median launch, and had notably fewer issues than the median launch. If AI s
10.
▲
by
mahemm
11mo ago
The property you're talking about (next bit unpredictability) is important for a CSPRNG, but it doesn't matter at all for a PRNG. A PRNG just needs to be fast and have a uniform output. LCGs, for instance, do not have next bit unp
11.
▲
by
mahemm
11mo ago
What game is played? To me it seems pretty straightforward that for both the actual caloric content is ~0.
12.
▲
by
mahemm
11mo ago
To me this is completely unrelated to the quality of the PRNG, because security is explicitly a non-goal of the design. A general-purpose non-cryptographically secure PRNG is evaluated primarily on speed and uniformity of output. Any other
13.
▲
by
mahemm
11mo ago
You replied to a claim that Telegram doesn't do E2EE for groups saying 'Neither does Whatsapp/Signal'. That's wrong as `tptacek noted. If you meant something else, that wasn't clear.
14.
▲
by
mahemm
1y ago
Why not just read 64 bits off /dev/urandom and be done with it? All this additional complexity doesn't actually buy any "extra" randomness over this approach, and I'm skeptical that it improves speed either.
15.
▲
by
mahemm
2y ago
Yep! We're lucky to be part of an org that's growing across a few teams, so there's several jobs up for the wider Stores AppSec umbrella
16.
▲
by
mahemm
2y ago
Amazon | Full-time | Security Engineering/Management | Austin, TX | On-Site I am hiring a new Application Security team in Austin to focus on making the highest-privilege applications in the non-AWS side of the company the planet'
17.
▲
by
mahemm
5y ago
Who do you think declassifies and releases information? Who do you think passed and enforces the Freedom of Information Act?
18.
▲
by
mahemm
6y ago
>Money breeding laziness ... killed ICOs ICOs were killed by Solidity and the Ethereum ecosystem more generally being insufficiently expressive to create anything of value other than pyramid schemes (insofar as those have value).
19.
▲
by
mahemm
6y ago
This is the exact sort of thing that allows people to think that things like Telegram are acceptable equivalents to Signal instead of disastrously poor imitators. It's a shame the discourse around secure messengers has become so pollut
20.
▲
by
mahemm
6y ago
Can't do crypto without visualizations; I can't say how many times I've wanted someone to draw stuff out! Great article
21.
▲
by
mahemm
6y ago
The ideas that "culture is a matter of individual experience" and that "there was no dichotomy to begin with and nothing to deny" seem to affirm the postmodern idea from my POV. That's basically what they argue. By
22.
▲
by
mahemm
6y ago
Ironically, Nietzsche is considered (by some) to be one of the fathers of postmodern thought. His criticism of the objectivity of science in "On Truth and Lies in a Nonmoral Sense", his deconstruction of the Western concept of sel
23.
▲
by
mahemm
6y ago
A postmodern critique of this argument might start with your identification of a single "culture" that has a pattern. Who decides what this culture is and who its adherents are? What if there are exemplars of the culture that do
24.
▲
by
mahemm
6y ago
Lots of people ITT seem to have an incorrect understanding of the term postmodernism. It basically boils down to the observation that history and human experience don't really move towards a single goal, but instead consists of lots of
25.
▲
by
mahemm
7y ago
While this article does do a good job of illuminating the potential challenges, it's a bit frustrating that there's such scant discussion of solutions. IMO, this problem has been solved pretty comprehensively by the TUF framework[
26.
▲
by
mahemm
7y ago
I use the high level concept pretty regularly in my day-to-day as a security consultant specializing in cryptography, and this project is a fantastic way to democratize the use of differential fuzzing. The only negative thought I have about
27.
▲
by
mahemm
7y ago
The widespread usage of Telegram in a situation as sensitive as the Hong Kong protests is a failure on behalf of the security industry in educating the public. Even WhatsApp is miles better, but in reality it should be a no-brainer for the
28.
▲
by
mahemm
7y ago
I think it will be interesting to see the details of this project. Most of the current offerings do not have anywhere near the technical sophistication that FB can bring, and especially as they iterate I think they will leave every other cr
29.
▲
Facebook to Launch “GlobalCoin” Cryptocurrency in 2020
(bbc.com)
2 points
by
mahemm
7y ago
|
2 comments
30.
▲
by
mahemm
7y ago
The attack can only happen in an unusual setting (nodes using external PSKs that can act as both client and server simultaneously), meaning that this vulnerability will not have too much impact on the open internet. The more interesting iss
More ›