Viewing profile — midas007
midas007
HN member- Joined
- Wed, Dec 04, 2013, 10:00 AM UTC
- HN karma
- 618
- Public activity
- 688 items
- HN profile
- View on Hacker News ↗
About midas007
Recent public activity
-
comment
Comment #7677093
That's the whole point of OTP as an imaginary construction! It's a way to take any block cipher and turn it into a stream cipher with the power of XOR. (I'm only going to ask this …
-
comment
Comment #7677049
What a flippant, uncivilized, unconstructive comment. Defense in-depth, every little bit helps.
-
comment
Comment #7677033
Don't need your "help," don't care. "It's unreasonable to debate with an unreasonable person." Bye.
-
comment
Comment #7676991
Absolutely not, that would NOT SCALE. Again, you're making accusations, shifting the conversation without providing evidence. Talking with you is pointless.
-
comment
Comment #7676960
Unsafe for what, how? You're making all sorts of claims and now an accusation without backing them up with a shred of evidence. XTS is only useful for FDE, everything else should l…
-
comment
Comment #7676929
Yes it does, and it's still CTR. Further, every solution is going to have other machinery solving specific concerns. You don't call XTS something else because you've used scrypt or…
-
comment
Comment #7676885
That's trivial to add on, outside of CTR. You have a system of keys derived from a master key. Too many bytes encrypted with one key? Use a new key for subsequent writes. (And for …
-
comment
Comment #7676831
Indistinguishable from a PRF A good block cipher satisfied this property, otherwise it's not a PRF and insecure. Hair-splitting, really. Actual OTP is an imaginary construction tha…
-
comment
Comment #7676819
Outbound leads (investment, jobs, customers) are way, way harder than inbound. Even for YC alums, inbound is your friend. [0] http://techcrunch.com/2014/02/15/was-y-combinator-wort…
-
comment
Comment #7676719
Fixed. That's beyond the scope of which mode, but it's important. However the less code one has, the fewer places there are for things to hide.
-
comment
Comment #7676717
Yes, it's a known weakness. You have to rekey every X blocks.
-
comment
Comment #7676709
Pretty hilariously wrong, and you know it. Supposed OTP constructions are defined as e(i) == E(...) ^ m(i) m(i) == D(...) ^ e(i) where E(...) = D(...) and where ... doesnt contain …
-
comment
Comment #7676571
? What's wrong with CTR? CTR is basically an OTP. Being OTP, encryption and decryption are basically the same construction (thank you XOR). cipherblockdata = blockcipher(key, nonce…
-
comment
Comment #7676503
TL;DR For random-seek block encryption, don't use XTS, use CTR. It's simple. I like simple maths and code, it's less to screw up and less for implementations to screw up . For exam…
-
comment
Comment #7676456
"and the 'sploit can be mitigated before bringing it online to the outside world" You should read more carefully. Also, keeping people waiting without an ETA for a down service bec…
-
comment
Comment #7676397
Edge cases. The big picture is that it's not happening fast enough, which is why the government will need to step in and will need to assume a leadership role to push hard on this.…
-
comment
Comment #7675531
Yes. \o/ Anything less is control-freak, incumbent cronyism with a mafia protection fee.
-
comment
Comment #7675515
No problem, I wrote a script to fetch it for those uncomfortable with CVS. https://github.com/LibreSSL-Portable/libressl-portable/blob/...
- comment
-
comment
Comment #7675499
Mountain View (for obvious reasons I guess): Google Express. But really, what difference is there over just extracting the functionality of local courier into a stand-alone global …
-
comment
Comment #7675439
Nope. It is what it is: capital-intensive research that is hard and it takes a long time to come up with a molecule that will stop an infection without killing or disabling the pat…
-
comment
Comment #7675338
That's part of it, but this is something governments have to take leadership on right now. That will only happen with direct pressure. Waiting until it's the leading cause of death…
-
comment
Comment #7675267
It doesn't have to be that way, and waiting around for "someone else to handle it" will likely lead to a Tragedy of the Commons. Call your representatives [US: 0,1] or regional gov…
-
comment
Comment #7675178
Exactly. But because of the difficulty, time and capital requirements, this is something that can't be left to the market economics. It will be too late by the time we need them be…
-
comment
Comment #7675128
That's one side, the other side would be a crash program to develop a spectrum of closely-guarded, last-resort antibiotics.