Live data from Hacker News

Viewing profile — doomrobo

doomrobo

HN member
Joined
Wed, Oct 17, 2012, 2:20 AM UTC
HN karma
2,239
Public activity
539 items

About doomrobo

Recent PhD in cryptography from the University of Maryland

Website: https://mrosenberg.pub Github: https://github.com/rozbb Keybase: https://keybase.io/mrosenberg Email: michael (@) mrosenberg (.) pub

[ my public key: https://keybase.io/mrosenberg; my proof: https://keybase.io/mrosenberg/sigs/dR6U3ijr9MYZyBe0ueW6L90pU8Adb817jaeWietnOH4 ]

Recent public activity

  1. comment
    Comment #49059352

    Recording of a talk with the same title. I’m not certain it’s the same content as the linked PDF though https://youtu.be/mS9Lr43cIB4

  2. story
  3. comment
    Comment #47478441

    I’ll ask the dual question: how many of the mobile safari checkmarks are fully fleshed out? Media Session has a check, but I have absolutely fought obvious Media Session implementa…

  4. comment
    Comment #47052828

    >Small block ciphers are thus generally a bad idea against active adversaries. >However, they can be very useful against passive adversaries whose capability is limited to observin…

  5. comment
    Comment #45618126

    Yes, if every single URL in your web application has a hash in it (including hrefs) then you don’t have to worry about anyone maliciously serving a webpage anymore. But how do you …

  6. comment
    Comment #45613724

    Emailed :)

  7. comment
    Comment #45611372

    1. I didn't know about this [1] actually! It looks like it's been unsupported for a few years now. The format looks pretty barebones, and we'd still need hashes like you said, as w…

  8. comment
    Comment #45611031

    Gotcha, yeah I agree. Fwiw, with the imagined code signing setup, the pubkey will be committed to in the transparency log, without any extra work. The purpose of the plugin is to g…

  9. comment
    Comment #45610566

    I'll actually argue the opposite. Transparency is _the_ pivotal thing, and code signing needs to be built on top of it (it definitely should be built into the browser, but I'm just…

  10. comment
    Comment #45608121

    You're right that, when your own server is trustworthy, fully self-hosting removes the need for SRI and integrity manifests. But in the case that your server is compromised, you lo…

  11. story
  12. story
  13. comment
    Comment #44173242

    Ah ok. How is the encryption key, if there is one, established then?

  14. comment
    Comment #44171967

    There are middle boxes between the two peers, yes? Routers and such. They observe the encrypted messages. They can brute force the password, even after the session is over. Even if…

  15. comment
    Comment #44171737

    If the server stores the transcript of a session, can it brute force the PIN later on? Magic Wormhole ( https://github.com/magic-wormhole/magic-wormhole ) avoids this by using a pa…

  16. story
  17. comment
    Comment #41641271

    In Europe, this is not uncommon for online purchases. You put in your IBAN number and authorize the transaction

  18. comment
    Comment #41434492

    Link should be https://status.gitlab.com/

  19. comment
    Comment #41213946

    It’s not actually much different. The main reason to use this is because it’s the standardized version of that concept and has been analyzed by people. All the smaller cryptographi…

  20. comment
    Comment #40988396

    What’s grim? 9.4 billion chickens are killed every year in the US. That’s 25.7 million a day https://www.nationalchickencouncil.org/statistic/broiler-ind...

  21. comment
    Comment #40389750

    IBE allows two users to communicate without the trusted party being online

  22. comment
    Comment #40005735

    The idea of "appear to be resistant to attack" is an empirical one. When someone says that, they are saying that we simply have not found a good attack against this problem. That c…

  23. comment
    Comment #39555537

    https://www.youtube.com/watch?v=uwJQQux0TF0

  24. comment
    Comment #39364229

    There was a great interview with the authors of this game and accompanying book https://srslywrong.com/podcast/290-half-earth-socialism-w-tr...

  25. comment
    Comment #39340180

    Also grad student. I use Voice Dream reader on my devices and it's helped a lot with reading dense texts https://www.voicedream.com/