Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
myrion
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
26 ms
·
1.
▲
by
myrion
5mo ago
I don't use old Reddit, and haven't noticed this behaviour either.
2.
▲
by
myrion
7mo ago
Well, yes, if they use something completely different to what's published and designed. But no, we're not talking about the case where there's no trust at all in the government, because then you don't get verifiable cred
3.
▲
by
myrion
7mo ago
That's not how that works - they can prove they check by showing logs, rather than VPs. There's even legal limits on what identifiers they can store and for how long. But even ignoring that, they'd be storing only very limite
4.
▲
by
myrion
7mo ago
In the Swiss system, it depends on what they verified. If they required your full ID, that has a document number like a passport and they could track that. If they did the right thing and only asked for the over 18 bit, then they wouldn
5.
▲
by
myrion
7mo ago
There's no dynamic analysis done, necessarily. In the Swiss design, fex, SD-JWTs are used for selective disclosure. For those, any information that you can disclose is pre-hashed and included in the signed credential. So `over_18: true
6.
▲
by
myrion
7mo ago
The revocation checking is implemented in a way where the government doesn't know who you checked and you can even cache the information (if that's good enough for you) so they won't notice at all.
7.
▲
by
myrion
7mo ago
That assumes the companies store the individual tokens, as does the government. Neither of which are part of the design, but could be done if both sides desired it. The Swiss design actually doesn't store the issued tokens centrally. I
8.
▲
by
myrion
8mo ago
Schweissen und löten. Has nothing to do with Switzerland (Schweiz) ;)
9.
▲
by
myrion
10mo ago
Because politicians make laws, and those affect the "legal hurdles" that companies need to deal with.
10.
▲
by
myrion
1y ago
Considering that companies will do everything to avoid doing sensible things that cost money - yes, of course the government has to step in and mandate things like this. It's no different from safety standards for car manufacturers. Do
11.
▲
by
myrion
1y ago
There's no much difference between the two positions, and the former is very much a lead-in to the latter.
12.
▲
by
myrion
1y ago
FIDO authenticators. If the "autofill" doesn't work, you can't be tricked into overriding it.
13.
▲
by
myrion
2y ago
Great and simple UI, synced across all your devices (which is what ended up killing RSS in f.ex. Thunderbird for me).
14.
▲
by
myrion
2y ago
Unfortunately the self-host documentation isn't great and the deployment options are quite limited. Sure, it's at least dockerised, but it requires root privileges (so no running it in a secured kubernetes env) and forces you to u
15.
▲
by
myrion
2y ago
Show me that law, because as far as I can tell, that's complete nonsense. I know of a bunch of people who legally purchased and installed aircon in their homes.
16.
▲
by
myrion
2y ago
No, Switzerland is at most a semi-direct democracy. We don't vote on every last decision the government takes, after all - we have a bicameral parliament and an executive branch for those! We just also have votations on a lot of things
17.
▲
by
myrion
3y ago
It does for me, because his criticism (since shown to be wrong) never included the claim that KYBER was broken, just that it wasn't perfect and that he was unfairly treated. Cranks and assholes occasionally are unfairly treated, but ge
18.
▲
by
myrion
3y ago
First off, thanks for the reply. It has since been pointed out to me elsewhere that there are now responses showing his central claim of a maths error to be false, which means all of this is now moot - KYBER is as secure as claimed. It has
19.
▲
by
myrion
3y ago
Hm. Yeah, I really need to adjust my view on this - I found NIST's responses dodgy precisely because they seemed so unwilling to engage, and I still thought of him as respected enough to warrant better responses. If he's turned so
20.
▲
by
myrion
3y ago
The last part I agree with - clearly KYBER isn't trivially broken if this is the best he can come up with. What doesn't seem clear to me, and I'd appreciate if you could tell me why you think differently, is that KYBER-512 is
21.
▲
by
myrion
3y ago
At least for myself, I disagree that NIST could only win by not running the competition. The impression I have right now is that they made some mistakes and in response to having those pointed out went "well, that's just like, you
22.
▲
by
myrion
3y ago
Here's my honest shot at it: In between a bunch of conspiratorial hinting, djb argues that KYBER-512 is weaker than NIST claims. To make that argument, he points out a fairly egregious math mistake (the whole "2^40+2^40" bit)
23.
▲
Bug in ansible.posix collection opened firewalls
(puzzle.ch)
4 points
by
myrion
3y ago
|
0 comments
24.
▲
by
myrion
3y ago
That's if hashed by md5, which really shouldn't be the case anymore. SHA-1 isn't much better, aiui, but would still be a more reasonable reference today - at least as far as I can see. I wish it were scrypt, PBKDF2 or argon2i
25.
▲
by
myrion
3y ago
Incidentally, Lego and Duplo are compatible! So eventually you can use the Duplo blocks as large building blocks under more intricate Lego designs.
26.
▲
by
myrion
4y ago
The NYT is in no way far left. It's a fairly centrist, vaguely middle-right publication. They have the occasional leftist essay, but far more often their op-eds are very strangely right-wing. I say strangely, because it's not very
27.
▲
by
myrion
4y ago
It might make tradeoffs that make it unacceptable in other situations, particularly ones that are focused on being resource constrained in some way. For example it could have low RAM usage, but become exponentially slower with message size,
28.
▲
by
myrion
4y ago
Indeed.
29.
▲
by
myrion
4y ago
I enjoyed it a lot too. It was a different take, but I thought that apart from the very first episode, it was very good and really wanted more.
30.
▲
by
myrion
4y ago
I wish Pinterest were less effective at making google image search useless, not more efficient...
More ›