Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
shinigami
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
shinigami
5y ago
What monumental cowardice. The "high ideological rhetoric" is something not even mildly "ideological". And then it's their fault that the shitty dudebros of HN had a fit? Please ban me from the orange hellsite so th
2.
▲
by
shinigami
6y ago
> The layperson doesn't have to understand the intricacies of email protocols, it's enough that they consider email to be non-repudiable. They consider it non-repudiable not because of DKIM, it's just a common misconceptio
3.
▲
by
shinigami
6y ago
> The only reason why laypersons consider email to be non-repudiable is because of additional protocols like SPF and DKIM that were implemented after the original spec You really think that laypersons have any idea of what DKIM is? >
4.
▲
by
shinigami
6y ago
You do realize that email is older than DKIM? And that commerce existed before emails? You don't need DKIM to solve the issues you've pointed out. Again: How many disputes like that have been resolved with DKIM?
5.
▲
by
shinigami
6y ago
You can dispute that without DKIM. How many disputes like that have been resolved with DKIM?
6.
▲
by
shinigami
6y ago
You didn't answer it. In which scenario Amazon would deny sending an email and you would be protected by DKIM?
7.
▲
by
shinigami
6y ago
Then digitally sign it. Sign and scan it. Do not require signing every single email you send to protect 0,1% of them.
8.
▲
by
shinigami
6y ago
Why do you need Amazon to digitally sign a contract?
9.
▲
by
shinigami
6y ago
So maybe digitally sign the contracts instead of unwillingly sign every single email you send?
10.
▲
by
shinigami
6y ago
Sure. So why do we need DKIM to authenticate contracts?
11.
▲
by
shinigami
6y ago
I meant: authenticating a contract via email. I guess you sign and scan them?
12.
▲
by
shinigami
6y ago
Sure. But what authenticates the contract? Do you sign and scan them?
13.
▲
by
shinigami
6y ago
So... no need for DKIM
14.
▲
by
shinigami
6y ago
It's still a terrible idea...
15.
▲
by
shinigami
6y ago
We could catch a lot of criminals if we every OS had a backdoor that the police could access. So, are you in favor of that?
16.
▲
by
shinigami
6y ago
Good luck arguing that Gmail forged and signed an email from you.
17.
▲
by
shinigami
6y ago
Entering an contract via an email is a ridiculous idea from the start.
18.
▲
by
shinigami
6y ago
Exactly, downvotes hurt so much!
19.
▲
by
shinigami
6y ago
It's the opposite, really. It improved a lot after the heartbleed issue.
20.
▲
by
shinigami
6y ago
If one implements ECDSA, but does not follow SECG, one is also doing it wrong on multiple levels. Yet here we are.
21.
▲
by
shinigami
6y ago
That simply does not work in the real world. Also, why does this only applies to crypto? A RCE vuln can have a much larger impact than mishandling cofactors. Should we have canonical implementations of every piece of software imaginable?
22.
▲
by
shinigami
6y ago
It's difficult to assess one's "comfort" with the math. I've been working with crypto for more then 10 years and I wouldn't say that I'm perfectly "comfortable" (e.g. the Ristretto stuff). Should
23.
▲
by
shinigami
6y ago
> malleability is not one of them, if one is following RFC 8032 This is like claiming Weierstrass curves don't have any problems if you follow the NIST/SECG standards. The whole point of the "SafeCurves" it to be easi
24.
▲
by
shinigami
6y ago
That's a good example of how a "SafeCurve" caused a vulnerability that wouldn't exist in Weierstrass curve. But many smart people made many such mistakes in the past. If we gatekeep it to much then we won't have any
25.
▲
by
shinigami
6y ago
> Montgomery curves work well with the montgomery ladder, which is easy to use in constant time, and that any 32-byte string is a valid public key for ECDH. You can also have Montgomery ladder an a 32-byte encoding with Weierstrass curve
26.
▲
by
shinigami
6y ago
Exactly. Yes, it's still not as efficient... but it feels to me that if they were found before and were "marketed" as Curve25519 was, we would be using them instead. There were always more efficient formats (binary curves, ex
27.
▲
by
shinigami
6y ago
It's sad that efficient complete formulas for Weierstrass curves were found only after Curve25519 was well established. Now we are stuck with all these cofactor issues. Ristretto is nice but so terribly complex: https://rist
28.
▲
by
shinigami
7y ago
Subject Public Key Info is just an Algorithm Identifier and the public key. The Algorithm Identifier is an OID and the parameters (ECParameters when using EC keys). It's these parameters that can contain the custom EC domain parameters
29.
▲
by
shinigami
7y ago
Yes, and my point is that the "fear of becoming the next Venezuela" is purely paranoid and has no basis in reality. > t seems to me that mainstream media was constantly attacking Bolsonaro during the election, so may I ask what
30.
▲
by
shinigami
7y ago
In 13 years of PT government, Brazil became nowhere near "becoming the next Venezuela". Most of the anti-PT sentiment was fueled by the media, which wanted a right-wing government back. It spectacularly backfired since Bolsonaro i
More ›