Live data from Hacker News

Viewing profile — kaeporan

kaeporan

HN member
Joined
Wed, Apr 02, 2014, 9:32 PM UTC
HN karma
31
Public activity
39 items

About kaeporan

Twitter: @kaepora Github: @kaepora

Recent public activity

  1. comment
    Comment #7702182

    > You should have just conceded the point (it turned out later in the thread that you were wrong to have brought it up). Instead, you relentlessly personalized it. Now you're unhap…

  2. comment
    Comment #7702083

    Since you've asked me not to share contents of private emails, I won't. But your insistence on assuming bad faith on my part and rudely rejecting any conflict resolution from my en…

  3. comment
    Comment #7702056

    I'll make sure to answer any other comments so long as I have something to contribute.

  4. comment
    Comment #7702030

    I need to investigate this properly before I offer you an educated answer with details.

  5. comment
    Comment #7701998

    I hope I'm not mistaken, but my understanding is that you can have the same message C that would decrypt with K1 to the plaintext "Hello world" but with K2 to another plaintext of …

  6. comment
  7. comment
    Comment #7701969

    Sorry, Thomas, but after you repeatedly replied to my private requests for conflict resolution with threats and abusive remarks, I refuse to interact with you entirely, publicly or…

  8. comment
    Comment #7701929

    The attacker could send different Ks to each user so that K decrypts C to a different plaintext.

  9. comment
    Comment #7701523

    I don't think it would be trivial (it's likely possible to some degree, but authentication and integrity checks might make it slightly more difficult), but the issue with this prot…

  10. comment
    Comment #7701499

    I endorse continuous transcript consistency, but believe that TextSecure currently does not allow its users to benefit from it and that this should be resolved. I think mpOTR is ir…

  11. comment
    Comment #7701424

    Thanks for laying out your thought process, it's very helpful. > I pointed out that the protocol Cryptocat builds that UI on is so bad that you conceded downthread that you're buil…

  12. comment
  13. comment
    Comment #7701343

    It really seems like you wrote this comment not to add anything to the conversation, but simply to discourage me from commenting. I really don't understand. I'm trying to be constr…

  14. comment
    Comment #7701285

    UI is absolutely a very difficult part of the problem, and here we see an example outlining this. Even a capable protocol still has problems if the UI fails to translate the capabi…

  15. comment
    Comment #7701189

    My original comment was simply to point out a current problem in this protocol design. There are some ways one can deploy to make it more difficult for Alice to send different mess…

  16. comment
    Comment #7701028

    Thanks for agreeing to turn the discussion in a more constructive direction, Thomas. I agree that mpOTR is a dead end. The initial paper by Goldberg et al describes a protocol that…

  17. comment
    Comment #7700920

    I'm sorry, but I don't think your approach to this discussion is constructive. I hope TextSecure developers address my initial concern, and that's all for me.

  18. comment
    Comment #7700882

    I think TextSecure is an excellent and inspiring project. All I'm trying to do is identify an area of concern for me. I'm not sure why you're attacking me personally here. I think …

  19. comment
    Comment #7700764

    I'm quite certain that the current TextSecure chat allows my proposed scenario with Alice, Bob and Carol to go through without issue. This is the main problem here. So while transc…

  20. comment
    Comment #7700224

    Yes, per your quote, transcript consistency is discussed. But the discussion simply outlines problems with implementing it in their mobile use case — to my understanding the curren…

  21. comment
    Comment #7700145

    The fact that transcript consistency is waved aside, despite being an essential property of a messaging protocol especially in a group context, is problematic, from my perspective.…

  22. comment
    Comment #7525818

    I disagree; I don't think your summary is accurate. This is an audit of a pre-release prototype. All the bugs were fixed before release, and our blog post at https://blog.crypto.ca…

  23. comment
    Comment #7524258

    To be clear, I'm not trying to cast aspersions. As I've already stated, TextSecure is a great project that I strongly recommend. I'm trying to have a serious discussion regarding t…

  24. comment
    Comment #7522592

    Why isn't Moxie replying? Publishing an audit, with or without vulnerabilities, surely is beneficial to TextSecure. I don't understand their reticence to publish audits. We know OT…

  25. comment
    Comment #7522587

    I was the person who wrote to OTF asking them to fund our audit. I have no idea if they require it — I'm always the one to initiate the process.