Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nextgens
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
nextgens
4mo ago
The original freenet design was replicating content as it was requested. You had no way of locating "all" the copies as they would get cached "along the way" elsewhere on the keyspace when you request them. That property
2.
▲
by
nextgens
4mo ago
Thank you for the downvotes. You're moving the debate here. The question was "How are the goals different?" from the project leader (who ought to know better), not whether moving them makes sense.
3.
▲
by
nextgens
4mo ago
You're getting this wrong. He has forked the project (to something that does not share the same goals so "fork" is arguable here), took the name, the cash and the goodwill. We went from "we have enough donations/don
4.
▲
by
nextgens
4mo ago
I've abstained form interfering until now... but have you honestly forgotten? Please explain how "the new freenet" tackles censorship resistance. https://web.archive.org/web/20001017133926/http:/
5.
▲
by
nextgens
8mo ago
Meshcore's crypto is interesting. ECB, issues with key generation, key negotiation, seldom authenticated data, ... It definitely works better than MT but please stop lauding it for its cryptographic properties ;) It's at the botto
6.
▲
by
nextgens
1y ago
TLS1.0 introduced modularity via the concept of "extensions". It's everything but a minor evolution of the protocol. One of the many things it brought is session tickets, enabling server-side session resumption without requir
7.
▲
by
nextgens
1y ago
TLS1.0 introduced modularity via the concept of "extensions". It's everything but a minor evolution of the protocol.
8.
▲
OpenBSD RCE to be released at t2.fi
(signedness.org)
5 points
by
nextgens
2y ago
|
0 comments
9.
▲
by
nextgens
3y ago
It would be great if Google supported rfc8414 and rfc7591. Right now most MUAs hardcode credentials instead of auto-discovering/registering/configuring them and decline to implement those standards "because the big boys don&#
10.
▲
by
nextgens
3y ago
As one of the maintainers of Mailu, I'd say use Mailu! Why? three main reasons: (a) security (as you have identified isolation matters, but that is not the only thing), (b) get the benefits of "battle-tested" setups and (c) f
11.
▲
Mailu 2.0 is out If you self-host your emails, check it out
(mailu.io)
7 points
by
nextgens
3y ago
|
1 comments
12.
▲
by
nextgens
3y ago
Mailu is a simple yet full-featured mail server as a set of Docker images. It is free software (both as in free beer and as in free speech), open to suggestions and external contributions. The project aims at providing people with an easily
13.
▲
by
nextgens
4y ago
No, and it doesn't protect the privacy of the viewer either!
14.
▲
by
nextgens
4y ago
Mailu - a mail server as a set of Docker images.
15.
▲
by
nextgens
5y ago
Sure you can defeat it using specialized tools... but at that point, you are far from "all I need is a pen" and opportunistic attacks. The tool will have to match the width of the zipper: you'll need a collection or to have d
16.
▲
by
nextgens
5y ago
Yes, we're talking about an attack against the zipper (and not the zip tie nor the bag) The goal here is tamper evidence... sure you can open the bag through the zipper but you won't be able to close the zipper back if you can
17.
▲
by
nextgens
5y ago
Use the zip-tie to "anchor" the slider too... that will defeat the pen trick.
18.
▲
Show HN: Mailu 1.9, now with MTA-STS and DANE support
(mailu.io)
2 points
by
nextgens
5y ago
|
0 comments
19.
▲
Freenet build 1492 released: video, diagnostics, pitch black, plugins
(freenetproject.org)
10 points
by
nextgens
5y ago
|
0 comments
20.
▲
by
nextgens
5y ago
What's the shortest chain-size that those free CAs can offer (assuming android>=5.0 devices)? It would be great to have a tool somewhere that matches client handshakes & supported CAs vs server config & choice of CA chains
21.
▲
by
nextgens
6y ago
The answer is complicated. IMHO It's clearly better than no TPM... as for whether it's better or worse than a physical chip, it's a different trade-off. One one side you have: - higher speed - higher protection against physic
22.
▲
by
nextgens
6y ago
https://en.wikipedia.org/wiki/FIPS_140-2#Level_2 It definitely does when there is no attempt made at protecting against it. L2 means "tamper evidence", you need L3 for things to start to be designed to preven
23.
▲
by
nextgens
6y ago
What I'm argueing in my talk is that it shouldn't be. Odds are your phone does it better :) Decaping a chip from a lost laptop is far from science fiction and can be performed at a fixed cost. Mitigation is super-cheap... There&#x
24.
▲
by
nextgens
6y ago
The PIN isn't required if you decap the TPM.
25.
▲
by
nextgens
6y ago
It's amazing that you disregard the most basic attack in your threat model ( https://safeboot.dev/threats/ ): going after the TPM itself. TPMs are usually FIPS 140-2 L2: not something that's meant to be hardene
26.
▲
by
nextgens
7y ago
That's basically what we've done with https://safepass.me/ and https://pwncheck.me/ ... and HIBP is the dataset we ship to our customers by default. If you are still looking to validate passwords
27.
▲
by
nextgens
7y ago
Let me know how it goes; if our sales droids don't come up with something acceptable on their own, I am keen to understand why and will work something out for you.
28.
▲
by
nextgens
7y ago
I am affiliated and no, you don't need to sign-up to get a preview: We have a video that shows how to set it up and basic operation: https://safepass.me/demo-video We have a free "home-use" license: if your P
29.
▲
by
nextgens
7y ago
Check https://safepass.me out (an active directory password filter)
30.
▲
by
nextgens
8y ago
Sure, but you can't "consolidate" them without re-transferring everything (typically differential snapshots)... whereas with native encryption, you just delete the snapshot.
More ›