Live data from Hacker News

Viewing profile — NTroy

NTroy

HN member
Joined
Tue, Aug 11, 2020, 5:52 PM UTC
HN karma
160
Public activity
33 items

About NTroy

An open source security and privacy enthusiast looking to make the world a better place every day

Recent public activity

  1. comment
    Comment #28108792

    I believe the math you outline above refers to this step, located on page 7 of the Technical Summary: > Next, the client creates a cryptographic safety voucher that has the followi…

  2. comment
    Comment #28107416

    It is my understanding that the vouchers are only encrypted with a key derived from the NeuralHash of the photo. Therefore an attacker would only need to find a matching NeuralHash…

  3. comment
    Comment #28107386

    If Apple is to keep their word about guaranteeing the privacy of non-CSAM photos (which this whole discussion is about them not doing a very good job of), then they would only be a…

  4. comment
    Comment #28107343

    Yes, this ^^^^^^ > The proposed attack on Apple's protocol doesn't work. With all due respect, I think you may have misunderstood the proposed attack @jonathanmayer, as what @jobig…

  5. comment
    Comment #28104348

    > For CSAM matches, the cryptographic header in the voucher combines with the server-side blinding secret (that was used to blind the known CSAM database at setup time) to successf…

  6. comment
    Comment #28104261

    The question doesn't presume that, as the the secret for blinding the CSAM database would only be helpful if a third party were also looking to see which accounts contained CSAM. I…

  7. story
  8. story
  9. comment
    Comment #25421897

    Sure! - Both - Both - Yes. I wish that weren't the case, but considering that I can't find a single provider so far who respects end user privacy, I would expect for one who does s…

  10. comment
    Comment #25421698

    Yeah, that's what I currently do. However as traffic grows in both volume and origin, and can be hard (and expensive) to keep up. That's why a privacy-respecting provider who alrea…

  11. comment
    Comment #25421667

    That's a good point. It wouldn't be the first time that providers (most notably VPN providers) have lied about their logging policies with devastating consequences for the end user…

  12. comment
    Comment #25421609

    Yeah, currently I run my own DNS server. However, as traffic grows and so does your customer base and server locations, it would be nice to use a dedicated DNS provider, as they'll…

  13. comment
    Comment #25421567

    A pricing scheme that isn't too far off of what you'd find from most other managed DNS providers. Obviously I wouldn't mind paying more for the "privacy" aspect, as long as the pri…

  14. story
    Ask HN: Does truly private DNS hosting exist?

    I've spent a long time attempting to find any managed DNS/DNS hosting providers that also guarantee privacy. Does anyone on here know of any DNS hosting provider that can meet the …

  15. comment
    Comment #25192769

    https://GitHub.com/P5vc

  16. story
  17. comment
    Comment #24417948

    Their code: https://GitHub.com/P5vc

  18. story
  19. comment
    Comment #24313348

    You are absolutely right. I work in the field of information security, where this seemingly backwards approach of thinking can quickly crumble optimistic projects! If you're not im…

  20. comment
    Comment #24313299

    Recovered for/from what? I've had my account disabled in the past (I created it while I was underage, with an adult representing me. Once they changed their terms to no longer allo…

  21. comment
    Comment #24313281

    Yes, I completely agree with you! I think being able to read through the actual code of the software you use, in order to fully understand it, what it does, and how it works is a p…

  22. story
    Ask HN: Is open source security effective?

    As of late, I've found my self in the middle of quite a few debates on open source network/system security. Specifically, I've had to defend a number of projects who only use open …

  23. story
    Show HN: Fetch Apply (Ansible/Puppet/Aviary.sh Alternative)

    Fetch Apply (https://github.com/P5vc/FetchApply) is a new system configuration and management tool, that follows the same principles as aviary.sh. Fetch Apply, however, has much be…

  24. comment
    Comment #24203424

    You're absolutely right! But hey, I appreciate that at least they cite their sources!

  25. comment
    Comment #24203346

    I'm not sure exactly what you mean. If you're looking for a production example, then here's one: Priveasy.org is an open source group that uses P5.vc (the shorter domain's letters …