Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
some_furry
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
some_furry
4d ago
Requiring manual key verification is a bad design that doesn't scale or benefit most people.
2.
▲
by
some_furry
4d ago
If your concern is "muh phone number", then you can pay and not have to give the phone number to sign up. It's already the case today (and has been for years) that you don't need to give strangers your phone number to ch
3.
▲
by
some_furry
4d ago
> Together with how low a profile they keep, I'm not convinced they aren't a honeypot. You don't need to be convinced of such things. In fact, it's better if technical people remain skeptical and check . I did in 202
4.
▲
The V8 JavaScript Runtime Undermined My Constant-Time JavaScript Library
(soatok.blog)
6 points
by
some_furry
5d ago
|
0 comments
5.
▲
Megolm Key Confusion Vulnerability
(lotte.chir.rs)
3 points
by
some_furry
5d ago
|
0 comments
6.
▲
by
some_furry
6d ago
Trying to position the conversation as "we're on the same team, trying to figure the problem out together" also helps a lot of the intensity of these conversations melt away.
7.
▲
by
some_furry
20d ago
> Citizens United is a very sound ruling. Corporations only have the powers granted to them by the state. Contributing to politics need not be one of them.
8.
▲
by
some_furry
22d ago
> About the post you linked, see [1] and [2], which makes me question both whether that is an actual vulnerability (Signal, the messenger recommended by the author, also didn't have that check, and it's addition is absent from
9.
▲
by
some_furry
29d ago
Every time Meta does something, it makes me yearn for the day they lose that $1.4 Trillion lawsuit and declare bankruptcy.
10.
▲
by
some_furry
1mo ago
I had to create an inbox filter for oss-security to go into a different label/folder to make my email usable.
11.
▲
by
some_furry
2mo ago
I wouldn't worry about too many mathematicians adopting the "even AI couldn't solve it" attitude. Business folks riding the hype train? Maybe.
12.
▲
by
some_furry
2mo ago
> One attack weakens HAWK, a post-quantum cryptography cipher candidate. I don't trust these PQC things one bit. I'll use them in combination with a strong clasically-resistant cipher (in so-called hybrid encryption modes), but
13.
▲
by
some_furry
2mo ago
https://codeberg.org/awebo-chat/awebo
14.
▲
by
some_furry
2mo ago
To be clear: This isn't a technical discussion, it's a political one. While your point is valid on its own merits, it isn't relevant here.
15.
▲
by
some_furry
2mo ago
It's a mix of grifts, gaffes, and Project 2025 .
16.
▲
by
some_furry
2mo ago
I don't personally have a horse in this race, but if you want to accurately predict the next step: Start with the outcome you believe will be the most in line with the spirit and traditions of the open source community. This is precise
17.
▲
by
some_furry
2mo ago
It's not that silly of a blogpost. See: "permanent underclass", a term popular among people that believe that an Artificial General Intelligence (AGI) is imminent and desirable .
18.
▲
We cannot wait for better post-quantum signature algorithms
(blog.cloudflare.com)
9 points
by
some_furry
2mo ago
|
0 comments
19.
▲
by
some_furry
2mo ago
You're all over the place except where the discussion was actually taking place.
20.
▲
by
some_furry
2mo ago
What does a work of fiction have to do with whether two distinct government entities are the same thing or not? That's beyond moving goalposts. Just take the L, dude.
21.
▲
by
some_furry
2mo ago
NIST does a lot of things that have nothing to do with computer security! Would you indict NIST MEP https://www.nist.gov/mep/about-nist-mep as being an NSA project without evidence?
22.
▲
by
some_furry
2mo ago
Didn't the FDA used to recommend pasteurizing milk?
23.
▲
by
some_furry
2mo ago
> You're argument is that I shouldn't think of NIST as a patsy for the NSA, Incorrect. My argument is that they aren't the same entity. The thing you said is a whole different argument. "I like waffles" "So
24.
▲
by
some_furry
2mo ago
> In the past NSA has weakened encryption standards, for example NSA madified DES standard. They made DES more secure against differential cryptanalysis (a method that was classified at the time DES was being designed). Sure, the whole &
25.
▲
by
some_furry
2mo ago
> But if I am honest, NIST recommending it at all is enough to suspect it of being compromised. NIST isn't the NSA and doesn't have the NSA's goals in mind. They are briefed by NSA on some matters, sure, but they're n
26.
▲
by
some_furry
2mo ago
Telecoms. I wrote at length about this debate in my blog post about threat modeling: https://soatok.blog/2026/06/30/soatoks-informal-guide-to-thr...
27.
▲
by
some_furry
2mo ago
Let me distill this down to its most basic structure to make sure I'm understanding you. Supoose we're trying to decide between two services for a long term group chat. Service A, on the server-side, sees all messages, in plaintex
28.
▲
by
some_furry
2mo ago
You mostly got it, yeah. Point 1, ECC is only also broken after Q-Day. Hybrids obviously help if you believe Q-Day is far into the future, or never coming. But if you take Q-Day happening as possible in our lifetime , the HNDL threat means
29.
▲
by
some_furry
2mo ago
It depends what I'm doing. My dayjob involves a lot of code review and protocol cryptanalysis, so I agonize quite a bit there. My blog would be less fun if I maintained the same level of rigor. If that makes any sense. ^^;
30.
▲
by
some_furry
2mo ago
> Err, where did you wrote that? I can’t find it in your last two articles. Just now. In an HN comment. I write in conversational English. I'm not always going to meticulously write everything like a formal argument might. If you di
More ›