Viewing profile — NTroy
NTroy
HN member- Joined
- Tue, Aug 11, 2020, 5:52 PM UTC
- HN karma
- 160
- Public activity
- 33 items
- HN profile
- View on Hacker News ↗
About NTroy
Recent public activity
-
comment
Comment #28108792
I believe the math you outline above refers to this step, located on page 7 of the Technical Summary: > Next, the client creates a cryptographic safety voucher that has the followi…
-
comment
Comment #28107416
It is my understanding that the vouchers are only encrypted with a key derived from the NeuralHash of the photo. Therefore an attacker would only need to find a matching NeuralHash…
-
comment
Comment #28107386
If Apple is to keep their word about guaranteeing the privacy of non-CSAM photos (which this whole discussion is about them not doing a very good job of), then they would only be a…
-
comment
Comment #28107343
Yes, this ^^^^^^ > The proposed attack on Apple's protocol doesn't work. With all due respect, I think you may have misunderstood the proposed attack @jonathanmayer, as what @jobig…
-
comment
Comment #28104348
> For CSAM matches, the cryptographic header in the voucher combines with the server-side blinding secret (that was used to blind the known CSAM database at setup time) to successf…
-
comment
Comment #28104261
The question doesn't presume that, as the the secret for blinding the CSAM database would only be helpful if a third party were also looking to see which accounts contained CSAM. I…
- story
- story
-
comment
Comment #25421897
Sure! - Both - Both - Yes. I wish that weren't the case, but considering that I can't find a single provider so far who respects end user privacy, I would expect for one who does s…
-
comment
Comment #25421698
Yeah, that's what I currently do. However as traffic grows in both volume and origin, and can be hard (and expensive) to keep up. That's why a privacy-respecting provider who alrea…
-
comment
Comment #25421667
That's a good point. It wouldn't be the first time that providers (most notably VPN providers) have lied about their logging policies with devastating consequences for the end user…
-
comment
Comment #25421609
Yeah, currently I run my own DNS server. However, as traffic grows and so does your customer base and server locations, it would be nice to use a dedicated DNS provider, as they'll…
-
comment
Comment #25421567
A pricing scheme that isn't too far off of what you'd find from most other managed DNS providers. Obviously I wouldn't mind paying more for the "privacy" aspect, as long as the pri…
-
story
Ask HN: Does truly private DNS hosting exist?
I've spent a long time attempting to find any managed DNS/DNS hosting providers that also guarantee privacy. Does anyone on here know of any DNS hosting provider that can meet the …
-
comment
Comment #25192769
https://GitHub.com/P5vc
- story
-
comment
Comment #24417948
Their code: https://GitHub.com/P5vc
- story
-
comment
Comment #24313348
You are absolutely right. I work in the field of information security, where this seemingly backwards approach of thinking can quickly crumble optimistic projects! If you're not im…
-
comment
Comment #24313299
Recovered for/from what? I've had my account disabled in the past (I created it while I was underage, with an adult representing me. Once they changed their terms to no longer allo…
-
comment
Comment #24313281
Yes, I completely agree with you! I think being able to read through the actual code of the software you use, in order to fully understand it, what it does, and how it works is a p…
-
story
Ask HN: Is open source security effective?
As of late, I've found my self in the middle of quite a few debates on open source network/system security. Specifically, I've had to defend a number of projects who only use open …
-
story
Show HN: Fetch Apply (Ansible/Puppet/Aviary.sh Alternative)
Fetch Apply (https://github.com/P5vc/FetchApply) is a new system configuration and management tool, that follows the same principles as aviary.sh. Fetch Apply, however, has much be…
-
comment
Comment #24203424
You're absolutely right! But hey, I appreciate that at least they cite their sources!
-
comment
Comment #24203346
I'm not sure exactly what you mean. If you're looking for a production example, then here's one: Priveasy.org is an open source group that uses P5.vc (the shorter domain's letters …