Live data from Hacker News

Viewing profile — myrion

myrion

HN member
Joined
Sat, Nov 14, 2015, 2:17 PM UTC
HN karma
325
Public activity
88 items

About myrion

No profile information was provided.

Recent public activity

  1. comment
    Comment #47762502

    I don't use old Reddit, and haven't noticed this behaviour either.

  2. comment
    Comment #47135105

    Well, yes, if they use something completely different to what's published and designed. But no, we're not talking about the case where there's no trust at all in the government, be…

  3. comment
    Comment #47135096

    That's not how that works - they can prove they check by showing logs, rather than VPs. There's even legal limits on what identifiers they can store and for how long. But even igno…

  4. comment
    Comment #47128279

    In the Swiss system, it depends on what they verified. If they required your full ID, that has a document number like a passport and they could track that. If they did the right th…

  5. comment
    Comment #47128214

    There's no dynamic analysis done, necessarily. In the Swiss design, fex, SD-JWTs are used for selective disclosure. For those, any information that you can disclose is pre-hashed a…

  6. comment
    Comment #47128118

    The revocation checking is implemented in a way where the government doesn't know who you checked and you can even cache the information (if that's good enough for you) so they won…

  7. comment
    Comment #47128101

    That assumes the companies store the individual tokens, as does the government. Neither of which are part of the design, but could be done if both sides desired it. The Swiss desig…

  8. comment
    Comment #46762375

    Schweissen und löten. Has nothing to do with Switzerland (Schweiz) ;)

  9. comment
    Comment #45984374

    Because politicians make laws, and those affect the "legal hurdles" that companies need to deal with.

  10. comment
    Comment #45488983

    Considering that companies will do everything to avoid doing sensible things that cost money - yes, of course the government has to step in and mandate things like this. It's no di…

  11. comment
    Comment #44181257

    There's no much difference between the two positions, and the former is very much a lead-in to the latter.

  12. comment
    Comment #43471859

    FIDO authenticators. If the "autofill" doesn't work, you can't be tricked into overriding it.

  13. comment
    Comment #43025055

    Great and simple UI, synced across all your devices (which is what ended up killing RSS in f.ex. Thunderbird for me).

  14. comment
    Comment #42631345

    Unfortunately the self-host documentation isn't great and the deployment options are quite limited. Sure, it's at least dockerised, but it requires root privileges (so no running i…

  15. comment
    Comment #39987457

    Show me that law, because as far as I can tell, that's complete nonsense. I know of a bunch of people who legally purchased and installed aircon in their homes.

  16. comment
    Comment #39987414

    No, Switzerland is at most a semi-direct democracy. We don't vote on every last decision the government takes, after all - we have a bicameral parliament and an executive branch fo…

  17. comment
    Comment #37879320

    It does for me, because his criticism (since shown to be wrong) never included the claim that KYBER was broken, just that it wasn't perfect and that he was unfairly treated. Cranks…

  18. comment
    Comment #37879298

    First off, thanks for the reply. It has since been pointed out to me elsewhere that there are now responses showing his central claim of a maths error to be false, which means all …

  19. comment
    Comment #37869130

    Hm. Yeah, I really need to adjust my view on this - I found NIST's responses dodgy precisely because they seemed so unwilling to engage, and I still thought of him as respected eno…

  20. comment
    Comment #37868810

    The last part I agree with - clearly KYBER isn't trivially broken if this is the best he can come up with. What doesn't seem clear to me, and I'd appreciate if you could tell me wh…

  21. comment
    Comment #37868511

    At least for myself, I disagree that NIST could only win by not running the competition. The impression I have right now is that they made some mistakes and in response to having t…

  22. comment
    Comment #37868393

    Here's my honest shot at it: In between a bunch of conspiratorial hinting, djb argues that KYBER-512 is weaker than NIST claims. To make that argument, he points out a fairly egreg…

  23. story
  24. comment
    Comment #35776896

    That's if hashed by md5, which really shouldn't be the case anymore. SHA-1 isn't much better, aiui, but would still be a more reasonable reference today - at least as far as I can …

  25. comment
    Comment #35551981

    Incidentally, Lego and Duplo are compatible! So eventually you can use the Duplo blocks as large building blocks under more intricate Lego designs.