Live data from Hacker News

Viewing profile — midas007

midas007

HN member
Joined
Wed, Dec 04, 2013, 10:00 AM UTC
HN karma
618
Public activity
688 items

About midas007

I wanted to see what HN was like starting fresh with no karma in 2013.

Recent public activity

  1. comment
    Comment #7677093

    That's the whole point of OTP as an imaginary construction! It's a way to take any block cipher and turn it into a stream cipher with the power of XOR. (I'm only going to ask this …

  2. comment
    Comment #7677049

    What a flippant, uncivilized, unconstructive comment. Defense in-depth, every little bit helps.

  3. comment
    Comment #7677033

    Don't need your "help," don't care. "It's unreasonable to debate with an unreasonable person." Bye.

  4. comment
    Comment #7676991

    Absolutely not, that would NOT SCALE. Again, you're making accusations, shifting the conversation without providing evidence. Talking with you is pointless.

  5. comment
    Comment #7676960

    Unsafe for what, how? You're making all sorts of claims and now an accusation without backing them up with a shred of evidence. XTS is only useful for FDE, everything else should l…

  6. comment
    Comment #7676929

    Yes it does, and it's still CTR. Further, every solution is going to have other machinery solving specific concerns. You don't call XTS something else because you've used scrypt or…

  7. comment
    Comment #7676885

    That's trivial to add on, outside of CTR. You have a system of keys derived from a master key. Too many bytes encrypted with one key? Use a new key for subsequent writes. (And for …

  8. comment
    Comment #7676831

    Indistinguishable from a PRF A good block cipher satisfied this property, otherwise it's not a PRF and insecure. Hair-splitting, really. Actual OTP is an imaginary construction tha…

  9. comment
    Comment #7676819

    Outbound leads (investment, jobs, customers) are way, way harder than inbound. Even for YC alums, inbound is your friend. [0] http://techcrunch.com/2014/02/15/was-y-combinator-wort…

  10. comment
    Comment #7676719

    Fixed. That's beyond the scope of which mode, but it's important. However the less code one has, the fewer places there are for things to hide.

  11. comment
    Comment #7676717

    Yes, it's a known weakness. You have to rekey every X blocks.

  12. comment
    Comment #7676709

    Pretty hilariously wrong, and you know it. Supposed OTP constructions are defined as e(i) == E(...) ^ m(i) m(i) == D(...) ^ e(i) where E(...) = D(...) and where ... doesnt contain …

  13. comment
    Comment #7676571

    ? What's wrong with CTR? CTR is basically an OTP. Being OTP, encryption and decryption are basically the same construction (thank you XOR). cipherblockdata = blockcipher(key, nonce…

  14. comment
    Comment #7676503

    TL;DR For random-seek block encryption, don't use XTS, use CTR. It's simple. I like simple maths and code, it's less to screw up and less for implementations to screw up . For exam…

  15. comment
    Comment #7676456

    "and the 'sploit can be mitigated before bringing it online to the outside world" You should read more carefully. Also, keeping people waiting without an ETA for a down service bec…

  16. comment
    Comment #7676397

    Edge cases. The big picture is that it's not happening fast enough, which is why the government will need to step in and will need to assume a leadership role to push hard on this.…

  17. comment
    Comment #7675531

    Yes. \o/ Anything less is control-freak, incumbent cronyism with a mafia protection fee.

  18. comment
    Comment #7675515

    No problem, I wrote a script to fetch it for those uncomfortable with CVS. https://github.com/LibreSSL-Portable/libressl-portable/blob/...

  19. comment
  20. comment
    Comment #7675499

    Mountain View (for obvious reasons I guess): Google Express. But really, what difference is there over just extracting the functionality of local courier into a stand-alone global …

  21. comment
    Comment #7675439

    Nope. It is what it is: capital-intensive research that is hard and it takes a long time to come up with a molecule that will stop an infection without killing or disabling the pat…

  22. comment
    Comment #7675338

    That's part of it, but this is something governments have to take leadership on right now. That will only happen with direct pressure. Waiting until it's the leading cause of death…

  23. comment
    Comment #7675267

    It doesn't have to be that way, and waiting around for "someone else to handle it" will likely lead to a Tragedy of the Commons. Call your representatives [US: 0,1] or regional gov…

  24. comment
    Comment #7675178

    Exactly. But because of the difficulty, time and capital requirements, this is something that can't be left to the market economics. It will be too late by the time we need them be…

  25. comment
    Comment #7675128

    That's one side, the other side would be a crash program to develop a spectrum of closely-guarded, last-resort antibiotics.