Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
soatok
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
soatok
9mo ago
(This is some_furry, I'm currently rate-limited. I thought this warranted a reply, so I switched to this account to break past the limit for a single comment.) > This statement is generic and misleading. It may be generic, but it&#x
2.
▲
by
soatok
1y ago
I strongly agree with you, but I have no confidence in my country's current elected representatives to ever do anything good, so our hands are tied until we vote them out.
3.
▲
by
soatok
1y ago
If they won't pay for it, they can also kindly fuck off and not crawl my blog. Both are fine outcomes for me.
4.
▲
by
soatok
2y ago
> Will the verification be automatic? Yes, and furthermore, there's already built-in support for ledger monitors to ensure the honest and integrity of their log. The whole point of Key Transparency is to keep the server honest. Publ
5.
▲
by
soatok
2y ago
> Signal's way to validate that a session isn't man-in-the-middle'd is the same as XMPP: You have to validate the session's fingerprint in real life, or over another secure channel, by scanning each other's QR co
6.
▲
by
soatok
2y ago
The whole point of end-to-end encryption is that you shouldn't have to. The entire point of Sealed Sender and their use of zero-knowledge proofs for group membership is so the server doesn't know who's talking to who, so they
7.
▲
by
soatok
2y ago
I wasn't present for the NIST crypto reading group, but I documented a lot of these in 2022, if you'd like a deeper dive into that problem space: https://soatok.blog/2022/12/29/what-we-do-in-the-etc-
8.
▲
by
soatok
2y ago
> The issue with security researchers, as much as I admire them, is that their main focus is on breaking things and then berating people for having done it wrong. This is plain incorrect in my experience. Recommended reading (addresses t
9.
▲
by
soatok
2y ago
> I don't see many "cryptography experts" putting effort into improving developer documentation resources for libraries. This isn't a "documentation resources for libraries" problem. It's a what librar
10.
▲
by
soatok
2y ago
Thanks, happy to help! > You seem to be posting from 2 different accounts: soatok and some_furry. Dunno if that’s on purpose, but in the off chance that it is not: Now you know. When folks have interesting comments that warrant a respons
11.
▲
by
soatok
2y ago
> If a user has to call into your keyserver to get a key before they can start a conversation with a new friend, as you're the sole authority who can decrypt the Merkle tree entries - does that introduce any problems? It would, but
12.
▲
by
soatok
2y ago
Thanks for the kind words. I wrote a previous deep dive into database cryptography, which talks about things like searchable encryption (which may offset some of the relevant inefficiencies): https://soatok.blog/2023/03
13.
▲
by
soatok
2y ago
> Is the intention that E2EE have a separate, parallel account recovery mechanism with more difficult requirements? I'm not sure the wording here is helpful. Let's start with a simple diagram: https://github.com/
14.
▲
by
soatok
2y ago
> For sure more than a single-digit percentage of people have tried a Q&A bot by now. Tried is doing a lot of heavy lifting. https://meow.social/@crumbcake/113156927685392932 > Shoot, Windows just updated to
15.
▲
by
soatok
2y ago
> The hype is around like content creation and AGI, which is a nothingburger. Right, which is why TFA specifically talks about "Generative AI".
16.
▲
by
soatok
3y ago
> Yes, that is absolutely what I meant. > That doesn't mean that it operates at the specific level of bosons or the force of gravity, which is what I read your comment as suggesting. This is a contradiction. If something is as fu
17.
▲
by
soatok
3y ago
> I didn't say that it belongs at the same level of abstraction, and no that isn't necessarily implied. The definition of fundamental is, in this context, best compared with this one from Merriam Webster: "of or relating t
18.
▲
by
soatok
3y ago
> Nobody said consciousness is best described at the subatomic level next to bosons. Above: > Conscious awareness appears to be a fundamental aspect of the universe -- as fundamental as the four known fundamental forces If it's a
19.
▲
by
soatok
3y ago
> And you haven't mentioned the moderation costs to Meta. What about my comment obligates me, in any way, to mention that? It seems like an odd thing to demand. What's going to happen is: the far-right pockets are ad-unfriendly
20.
▲
by
soatok
3y ago
> I always laugh when I see that "furry" is a category too choose server from on the official page. > Too bad there is no "hentai" that would be the cherry on the cake. It sounds like you think "furry" an
21.
▲
An Introduction to Database Cryptography
(soatok.blog)
1 points
by
soatok
3y ago
|
0 comments
22.
▲
by
soatok
3y ago
It does exactly what I've been describing! They provide AE, not AEAD. They feed an IV and ciphertext into HMAC. They don't feed additional authenticated data. If someone followed Signal's example, they either wouldn't ha
23.
▲
by
soatok
6y ago
I don't care about his opinions or takes, I care about the harm he inflicts by reinforcing the beliefs that undermine junior developers' confidence.
24.
▲
by
soatok
6y ago
> His comment was a response to your post. Your post discouraged people from writing crypto, because they aren't qualified. This is where you were gatekeeping. Re-read the post carefully . I included examples of people unwittingly
25.
▲
by
soatok
6y ago
I don't have a personal political agenda here. I'd love for GNU cryptography to be better, but the first step in fixing problems is to acknowledge they exist in the first place. GNUnet, GnuPG, etc. need to actually learn from mode
26.
▲
by
soatok
6y ago
It's so good. I've been meaning to write a GUI frontend (probably in Electron, but still) so that desktop users can experience its magic, but I keep putting it off. Maybe this weekend? :)
27.
▲
by
soatok
6y ago
> It's all best practices and hygine stuff. Which is fine, but hardly justfication for "Bad Cryptography". Cryptographers have spent years trying to clean up the GNU cryptography ecosystem [1] [2]. [1] https://t