Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
xnull
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
Testing Theories of American Politics: Elites Interest Groups and Average Citizens
(journals.cambridge.org)
1 points
by
xnull
12y ago
|
0 comments
2.
▲
by
xnull
12y ago
The overall question is whether bindings or language features that expose direct control of the underlying architecture (such as D) can still be used to implement crypto. The answer is likely yes, though it is uncharted territory that only
3.
▲
by
xnull
12y ago
STARTTLS was never intended to thwart MITM however. We need to keep that in mind. It allows a way to start a secure channel that is backwards compatible under the assumption that an attacker can eavesdrop but not manipulate the contents of
4.
▲
by
xnull
12y ago
It has its own ("Network Security Services" or NSS). But that's not a reason to use Firefox on XP. ;)
5.
▲
by
xnull
12y ago
> whole explanation boils down to "managed languages are more complex, therefore worse." I hope that's not what I said... > Please point me to the specific native features which mitigate timing attacks. How am I suppose
6.
▲
by
xnull
12y ago
The window from disclosure of patches to duplication is narrowing and it appears from the bulletin that client connections are affected as well. Furthermore any computer you take anywhere outside your home router (and can you really trust y
7.
▲
by
xnull
12y ago
> Timing attacks are often the result of optimisations within the crypto library which inadvertently give away information, for example a loop which breaks on X != Y, instead of setting a failed = false bool and continuing to iterate thr
8.
▲
by
xnull
12y ago
> Net neutrality isn't a blanket term for "anything the government does relating to the Internet", it's focused on a specific issue. Of course. > I guess you could argue that net neutrality would make it easier to
9.
▲
by
xnull
12y ago
Some here may know me as a critic of overreaching and aggressive cyber enforcement (and related surveillance). First, I'm quite happy that this activity does not appear to be the result of wide scale infrastructure sabotage. And I am q
10.
▲
by
xnull
12y ago
I think implementation bugs are within the spirit of OP, especially provided the NSA claims to have provided an implementation fix for Heartbleed. The sorts of bugs I'm talking about exist in client and popular software. As far as temp
11.
▲
by
xnull
12y ago
Bug volume in crypto is extremely high. How many developers reuse IVs in stream ciphers? How many blindly use AES or somesuch other symmetric library and then build in no authentication whatsoever? How many antequated implementations of RSA
12.
▲
by
xnull
12y ago
Right, NEC3's 'solution' to obscure zones by signing hashes effectively just renames zones that probably come from some small collection ('www', 'ftp', 'ns', 'smtp', 'ilo') an
13.
▲
by
xnull
12y ago
Six digits sounds about right for a Tor bug for one target depending on the specifics. The RCE bug used by the FBI recently against the Tor Firefox Bundle would have cost something similar, though the payload suspended the process where it
14.
▲
by
xnull
12y ago
Oh we're not talking trivial bugs or single-site XSS. Disappointed that 'mediocre' vulns got interpreted in this thread as 'trivial'. Mediocre doesn't mean trivial, extremely scoped or useless. Mediocre means t
15.
▲
by
xnull
12y ago
> to fight terrorism Most of what the NSA does is geopolitical in nature. They are barely involved in CT activity (they do only minor amounts of CT). https://news.ycombinator.com/item?id=8370973 https://news.y
16.
▲
by
xnull
12y ago
> But I honestly can't help but feel we've reached pretty close to the bottom of that slope. In the sense that I feel like our government just kind of makes stuff up as it goes along and only occasionally responds well to the s
17.
▲
by
xnull
12y ago
My digest agrees. B9D1F5290EBE56780AF692E2B12037D6B7E085EF1F6050C1E27EA8426F94BFCC I found the quote you've posted in my copy as well. The definition I selected was from the glossary at the bottom. > "Tangled" Seems to me
18.
▲
by
xnull
12y ago
Actually, it does not look like the UID is a PUF - although it's a very interesting idea! "Unique ID (UID) - A 256-bit AES key that’s burned into each processor at manufacture. It cannot be read by firmware or software, and is use
19.
▲
by
xnull
12y ago
> Since PUFs typically get their values from random process variation How sure are we that this is the case, and how can we verify it? You can burn in whatever bits you want to the PUF. If there is a list, a product to UID mapping, a det
20.
▲
by
xnull
12y ago
From Tor: "So I'm totally anonymous if I use Tor? No. First, Tor protects the network communications. It separates where you are from where you are going on the Internet. What content and data you transmit over Tor is controlled b
21.
▲
by
xnull
12y ago
> Apple ... can't decrypt data encrypted with the passcode ... today or ever before. The passcode of 12 bits... Apple can and will provide ciphertexts, will hand over copies of the large amounts of data customers are encouraged and
22.
▲
by
xnull
12y ago
Prior to the "Secure Enclave", only a very small amount of certain data was encrypted on the device (past the alive-time of the device and where data _could have been encrypted_), the encryption keys were based on information abou
23.
▲
by
xnull
12y ago
The examples though _do_ have physical manifestations - everything that exists in the universe has a physical manifestation (by tautology). How is a feed forward circuit carrying information (to be integated) not a physical realization? It&
24.
▲
by
xnull
12y ago
Integrated Information Theory I think is a fad, and a bad one at that. One could think of integration of information as a necessary but not sufficient condition for consciousness a la Scott Aaronson [1] who applies more rigorous mathematica
25.
▲
by
xnull
12y ago
I understand how you feel about NSAKEY. Maybe you could reply to the others.
26.
▲
by
xnull
12y ago
The crypto bit is perfectly reasonable in this context as Elephant meets the standards for crypto publication in this regard. You excuse leaks water. Where you can no longer reasonably hold your position is where you got off the train.
27.
▲
by
xnull
12y ago
Maybe you could reply to the others. Agreed NSAKEY is old news.
28.
▲
by
xnull
12y ago
You've downvoted the content rather than replying to it. I'll repeat it again, for the benefit of the larger HN community (and you can get you jollies downvoting again). "MS, working with the FBI, developed a surveillance cap
29.
▲
by
xnull
12y ago
And the others? Do I get an ORCHESTRA?
30.
▲
A 61M-person experiment in social influence and political mobilization (2012) [pdf]
(jhfowler.ucsd.edu)
4 points
by
xnull
12y ago
|
0 comments
More ›