Viewing profile — AnaniasAnanas
AnaniasAnanas
HN member- Joined
- Mon, May 14, 2018, 10:46 AM UTC
- HN karma
- 224
- Public activity
- 385 items
- HN profile
- View on Hacker News ↗
About AnaniasAnanas
No profile information was provided.
Recent public activity
-
comment
Comment #20506192
Banks are not known for using the best/safest solutions. Just take 4 digit pins and 3DES into account for example. > who only offer certs of RSA and P-{256,384}? I am pretty sure t…
-
comment
Comment #20481417
Nobody was ever fired for using DJB. Meanwhile I would gladly fire someone for using AES128 or the NSA-sponsored curves, despite being in Suite B.
-
comment
Comment #20481376
> some of them do involve using RSA with absurd key sizes and they'll likely fail the competition. Only one (specifically DJBs joke Post-QC algorithm), and it did not pass to the s…
-
comment
Comment #20481276
> WhatsApp, Telegram and Signal use mobile phone numbers as identifiers One notable exception (which as I understand is tptacek-approved) is Wire, which only needs an email.
-
comment
Comment #20481251
> Nobody actually wants to rely on a single entity (for or non-profit) for their communication You don't have to do that. Protocols like tox for example are distributed and use DHT…
-
comment
Comment #20318629
It's even worse than it seems. The certificates are only a few megabytes long. https://twitter.com/FiloSottile/status/1145091106138394625
-
comment
Comment #20315619
Both Signal and Wire are FOSS though.
-
comment
Comment #20314100
As much as I believe that Efail was the result of badly implemented email clients it's not like the OpenPGP standard hadn't any involvement with it whatsoever. DJB for example sugg…
-
comment
Comment #20313823
I tried exporting org-mode to latex in the past and found it extremely buggy. I don't really see a reason not to just directly use LaTeX instead.
-
comment
Comment #20313727
*Everywhere. My own school experience in Europe was pretty much the same as he described. And it is not only my school experience either, there were many cases of unpunished power …
-
comment
Comment #20313711
The schools that I went to had around 300 students. It did not stop the abuse by teachers nor did it stop the bullying that the teachers ignored.
-
comment
Comment #20313633
OCaml is very popular in academia though, especially in the field of theoretical computer science and formal verification. Coq, Frama-C, Flow, CompCert, etc are all written in OCam…
-
comment
Comment #20249401
No offense, I am genuinely curious, why would anyone use any closed source software for anything related to security after the Snowden revelations?
-
comment
Comment #20235857
Why does everyone seem to hate delay slots? I understand that it makes writing assembly more annoying but most people use a compiler anyway.
-
comment
Comment #20235694
A better question would be: why were Coinbase employees allowed to use any browser with javascript enabled and outside of a VM? Qubes OS has been a thing for quite a while.
-
comment
Comment #20235672
I mentioned the possibility of an untrustworthy person gaining access to bugzilla yesterday but it seems that most people disagreed with it: https://news.ycombinator.com/item?id=20…
-
comment
Comment #20235632
The voters are not one person. Sadly democracy ends up being the fascism of the many.
-
comment
Comment #20233160
Whoever made the decision not to take backups for example. The ones who will have to pay for their mistakes will be the taxpayers otherwise.
-
comment
Comment #20231145
Shouldn't the one responsible personally have to pay for it rather than the city and its taxpayers?
-
comment
Comment #20222991
> It needs to be possible to hire people that you trust not to disclose all your secrets, and your customer's secrets I disagree, it needs to be possible for whistle-blowers to ope…
-
comment
Comment #20222950
Companies seem to try to abuse patent, trademarks, and copyrights as much as they can anyway. The best of-course would be if NDAs, patents, and copyrights all disappeared overnight…
-
comment
Comment #20222834
> NDAs and non-competes have their uses I have yet to see a valid use that does not hinder whistle-blowing, the advancement of technology, or does not abuse the employees. I am sur…
-
comment
Comment #20222792
NDAs and non-compete agreements should not ever be considered as valid contracts by the government.
-
comment
Comment #20222738
It will be seen by a malicious actor anyway after the fix is released. The difference is that there will be more time for a malicious actor to act against a fork if an embargo is a…
-
comment
Comment #20221432
Consider trying the debian package until it is updated in your system.