Viewing profile — myrion
myrion
HN member- Joined
- Sat, Nov 14, 2015, 2:17 PM UTC
- HN karma
- 325
- Public activity
- 88 items
- HN profile
- View on Hacker News ↗
About myrion
No profile information was provided.
Recent public activity
-
comment
Comment #47762502
I don't use old Reddit, and haven't noticed this behaviour either.
-
comment
Comment #47135105
Well, yes, if they use something completely different to what's published and designed. But no, we're not talking about the case where there's no trust at all in the government, be…
-
comment
Comment #47135096
That's not how that works - they can prove they check by showing logs, rather than VPs. There's even legal limits on what identifiers they can store and for how long. But even igno…
-
comment
Comment #47128279
In the Swiss system, it depends on what they verified. If they required your full ID, that has a document number like a passport and they could track that. If they did the right th…
-
comment
Comment #47128214
There's no dynamic analysis done, necessarily. In the Swiss design, fex, SD-JWTs are used for selective disclosure. For those, any information that you can disclose is pre-hashed a…
-
comment
Comment #47128118
The revocation checking is implemented in a way where the government doesn't know who you checked and you can even cache the information (if that's good enough for you) so they won…
-
comment
Comment #47128101
That assumes the companies store the individual tokens, as does the government. Neither of which are part of the design, but could be done if both sides desired it. The Swiss desig…
-
comment
Comment #46762375
Schweissen und löten. Has nothing to do with Switzerland (Schweiz) ;)
-
comment
Comment #45984374
Because politicians make laws, and those affect the "legal hurdles" that companies need to deal with.
-
comment
Comment #45488983
Considering that companies will do everything to avoid doing sensible things that cost money - yes, of course the government has to step in and mandate things like this. It's no di…
-
comment
Comment #44181257
There's no much difference between the two positions, and the former is very much a lead-in to the latter.
-
comment
Comment #43471859
FIDO authenticators. If the "autofill" doesn't work, you can't be tricked into overriding it.
-
comment
Comment #43025055
Great and simple UI, synced across all your devices (which is what ended up killing RSS in f.ex. Thunderbird for me).
-
comment
Comment #42631345
Unfortunately the self-host documentation isn't great and the deployment options are quite limited. Sure, it's at least dockerised, but it requires root privileges (so no running i…
-
comment
Comment #39987457
Show me that law, because as far as I can tell, that's complete nonsense. I know of a bunch of people who legally purchased and installed aircon in their homes.
-
comment
Comment #39987414
No, Switzerland is at most a semi-direct democracy. We don't vote on every last decision the government takes, after all - we have a bicameral parliament and an executive branch fo…
-
comment
Comment #37879320
It does for me, because his criticism (since shown to be wrong) never included the claim that KYBER was broken, just that it wasn't perfect and that he was unfairly treated. Cranks…
-
comment
Comment #37879298
First off, thanks for the reply. It has since been pointed out to me elsewhere that there are now responses showing his central claim of a maths error to be false, which means all …
-
comment
Comment #37869130
Hm. Yeah, I really need to adjust my view on this - I found NIST's responses dodgy precisely because they seemed so unwilling to engage, and I still thought of him as respected eno…
-
comment
Comment #37868810
The last part I agree with - clearly KYBER isn't trivially broken if this is the best he can come up with. What doesn't seem clear to me, and I'd appreciate if you could tell me wh…
-
comment
Comment #37868511
At least for myself, I disagree that NIST could only win by not running the competition. The impression I have right now is that they made some mistakes and in response to having t…
-
comment
Comment #37868393
Here's my honest shot at it: In between a bunch of conspiratorial hinting, djb argues that KYBER-512 is weaker than NIST claims. To make that argument, he points out a fairly egreg…
- story
-
comment
Comment #35776896
That's if hashed by md5, which really shouldn't be the case anymore. SHA-1 isn't much better, aiui, but would still be a more reasonable reference today - at least as far as I can …
-
comment
Comment #35551981
Incidentally, Lego and Duplo are compatible! So eventually you can use the Duplo blocks as large building blocks under more intricate Lego designs.