Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
noerps
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
noerps
13y ago
To explain a potential adversary, how crypto works or how he becomes a valueable asset for any given intelligence service without any given payment may not even attract people like me.
2.
▲
by
noerps
13y ago
Key infrastructure doesn't even emit security anymore. The P in PKI is for painful, and I really doubt that some CA, owned by big corporate entity (microsoft, oracle, ca) wouldn't manipulate the eternal append-only log-file for an
3.
▲
by
noerps
13y ago
Stackexchange is using the same approach to get rid of trolls.
4.
▲
by
noerps
13y ago
Even if we are hyping or sensationalizing this topic, current behavior is a very good indicator for future behavior.
5.
▲
by
noerps
13y ago
Since RSA patents expired, it's available, easier to comprehend and good enough until 2020 when the ECC patents expire.
6.
▲
by
noerps
13y ago
No, but people may be.
7.
▲
by
noerps
13y ago
See http://fail0verflow.com/blog/2013/megafail.html there are still security concerns.
8.
▲
by
noerps
13y ago
Same with c3 in berlin.
9.
▲
by
noerps
13y ago
"Once Panic Mode is on all requests issued by your browser will be forced over SSL" have an E for Effort Google Chrome.
10.
▲
by
noerps
13y ago
It's a hidden argument, but ymmv.
11.
▲
by
noerps
13y ago
A picture says more than 1024 words, and its funny, thanks a lot.
12.
▲
by
noerps
13y ago
Putting a better UX or UI has been considered for PGP/GPG a very long time, and if you really reflect on that topic, you'll learn that a fancy interface or UX won't solve anything. Foolproof software is operated by fools. Fac
13.
▲
by
noerps
13y ago
Another way to accomplish anonymity is to not use the so called internets, but I guess that is either very comfy or intresting.
14.
▲
by
noerps
13y ago
Welcome to counterintelligence, have a nice day. Sorry I forgot to point out https://en.wikipedia.org/wiki/Perfect_forward_secrecy
15.
▲
by
noerps
13y ago
The video and the links at < http://ec.europa.eu/justice/newsroom/data-protection/news/12... contradict at least the point of free personal data flow, european data seems to go only in some directions:
16.
▲
by
noerps
13y ago
That would nullify the only acceptable reason to use it in the first place, I think I'll stay with vi ~/TODO :)
17.
▲
by
noerps
13y ago
I really concur and like to add there are now one or two generations of young adults and their kids out there, who have never even considered privacy (as in non-exhibitionism).
18.
▲
by
noerps
13y ago
Last time I checked Chrome it wasn't possible to remove certificates from the store, has this changed yet?
19.
▲
by
noerps
13y ago
On consumers I would not expect much change to any other non-us service that keeps you invested and locked-in. There simply are no alternatives, some european services are currently shutting down. Even Schneier is stating that if you aren&#
20.
▲
by
noerps
13y ago
The option that somebody already is self hosting and using secure end to end crypto, it may be wise to add that option; it is not really breaking news to the people with the tin-foil-hat.
21.
▲
by
noerps
13y ago
I will never, ever, understand why I would like to delegate something so trivial and marginal to a distant server, for example: Todo: change password from XXX to ZZZ. I can imagine only procrastination as a valid reason to do so, because yo
22.
▲
by
noerps
13y ago
There may be information leaking (as in fingerprinting) from your device (that you are not aware of) that would allow very easy correlation, like in a mac address or existing session cookie, similar address in a public open network or whate
23.
▲
by
noerps
13y ago
It depends on distribution and packetmanager, I quit using debian based approaches a long time ago for that and some other reasons.
24.
▲
by
noerps
13y ago
The tradeoff is the same as keysize in crypto. It is time. If you choose to communicate a second time from the same endpoint with the same equipment you may achieve only pseudonymity. Since Tor doesn't limit the encapsulated protocols,
25.
▲
by
noerps
13y ago
With SSL, both parties negotiate synchronous encryption (like in AES) and key exchange (like in RSA) for that, the trust is established with signed certificates obtained from a 3rd party. Which is/was fine on paper and concept, the imp
26.
▲
by
noerps
13y ago
All Convergence does is delegate to another 3rd party, which may lead to the conclusion there may be an attack in progress, that you may not have noticed before. You still have to trust another stranger that may offer you some perspective o
27.
▲
by
noerps
13y ago
Learn and understand crypto, develop and follow procedure to embrace secure end-to-end communications with your peers.
28.
▲
by
noerps
13y ago
It simply does not need to scale very well to scare the few people which understand crypto and plausible deniability.
29.
▲
by
noerps
13y ago
Since you are doing crypto, chances are high you are doing it wrong the first approaches. Considering this, my choice would be to start with a believable pseudonym and generate a gpg- and/or rsa-key to sign stuff and tie it to that psu
30.
▲
by
noerps
13y ago
There are no implications for an average netizen, since an average netizen doesn't use strong end-to-end crypto nor does he/she avoid cloud-like-storage/services (it doesn't matter which). Average individuals aren't
More ›