Live data from Hacker News

Viewing profile — AnaniasAnanas

AnaniasAnanas

HN member
Joined
Mon, May 14, 2018, 10:46 AM UTC
HN karma
224
Public activity
385 items

About AnaniasAnanas

No profile information was provided.

Recent public activity

  1. comment
    Comment #20506192

    Banks are not known for using the best/safest solutions. Just take 4 digit pins and 3DES into account for example. > who only offer certs of RSA and P-{256,384}? I am pretty sure t…

  2. comment
    Comment #20481417

    Nobody was ever fired for using DJB. Meanwhile I would gladly fire someone for using AES128 or the NSA-sponsored curves, despite being in Suite B.

  3. comment
    Comment #20481376

    > some of them do involve using RSA with absurd key sizes and they'll likely fail the competition. Only one (specifically DJBs joke Post-QC algorithm), and it did not pass to the s…

  4. comment
    Comment #20481276

    > WhatsApp, Telegram and Signal use mobile phone numbers as identifiers One notable exception (which as I understand is tptacek-approved) is Wire, which only needs an email.

  5. comment
    Comment #20481251

    > Nobody actually wants to rely on a single entity (for or non-profit) for their communication You don't have to do that. Protocols like tox for example are distributed and use DHT…

  6. comment
    Comment #20318629

    It's even worse than it seems. The certificates are only a few megabytes long. https://twitter.com/FiloSottile/status/1145091106138394625

  7. comment
    Comment #20315619

    Both Signal and Wire are FOSS though.

  8. comment
    Comment #20314100

    As much as I believe that Efail was the result of badly implemented email clients it's not like the OpenPGP standard hadn't any involvement with it whatsoever. DJB for example sugg…

  9. comment
    Comment #20313823

    I tried exporting org-mode to latex in the past and found it extremely buggy. I don't really see a reason not to just directly use LaTeX instead.

  10. comment
    Comment #20313727

    *Everywhere. My own school experience in Europe was pretty much the same as he described. And it is not only my school experience either, there were many cases of unpunished power …

  11. comment
    Comment #20313711

    The schools that I went to had around 300 students. It did not stop the abuse by teachers nor did it stop the bullying that the teachers ignored.

  12. comment
    Comment #20313633

    OCaml is very popular in academia though, especially in the field of theoretical computer science and formal verification. Coq, Frama-C, Flow, CompCert, etc are all written in OCam…

  13. comment
    Comment #20249401

    No offense, I am genuinely curious, why would anyone use any closed source software for anything related to security after the Snowden revelations?

  14. comment
    Comment #20235857

    Why does everyone seem to hate delay slots? I understand that it makes writing assembly more annoying but most people use a compiler anyway.

  15. comment
    Comment #20235694

    A better question would be: why were Coinbase employees allowed to use any browser with javascript enabled and outside of a VM? Qubes OS has been a thing for quite a while.

  16. comment
    Comment #20235672

    I mentioned the possibility of an untrustworthy person gaining access to bugzilla yesterday but it seems that most people disagreed with it: https://news.ycombinator.com/item?id=20…

  17. comment
    Comment #20235632

    The voters are not one person. Sadly democracy ends up being the fascism of the many.

  18. comment
    Comment #20233160

    Whoever made the decision not to take backups for example. The ones who will have to pay for their mistakes will be the taxpayers otherwise.

  19. comment
    Comment #20231145

    Shouldn't the one responsible personally have to pay for it rather than the city and its taxpayers?

  20. comment
    Comment #20222991

    > It needs to be possible to hire people that you trust not to disclose all your secrets, and your customer's secrets I disagree, it needs to be possible for whistle-blowers to ope…

  21. comment
    Comment #20222950

    Companies seem to try to abuse patent, trademarks, and copyrights as much as they can anyway. The best of-course would be if NDAs, patents, and copyrights all disappeared overnight…

  22. comment
    Comment #20222834

    > NDAs and non-competes have their uses I have yet to see a valid use that does not hinder whistle-blowing, the advancement of technology, or does not abuse the employees. I am sur…

  23. comment
    Comment #20222792

    NDAs and non-compete agreements should not ever be considered as valid contracts by the government.

  24. comment
    Comment #20222738

    It will be seen by a malicious actor anyway after the fix is released. The difference is that there will be more time for a malicious actor to act against a fork if an embargo is a…

  25. comment
    Comment #20221432

    Consider trying the debian package until it is updated in your system.