Viewing profile — xnull
xnull
HN member- Joined
- Tue, Aug 19, 2014, 6:31 PM UTC
- HN karma
- 534
- Public activity
- 104 items
- HN profile
- View on Hacker News ↗
About xnull
No profile information was provided.
Recent public activity
- story
-
comment
Comment #8597148
The overall question is whether bindings or language features that expose direct control of the underlying architecture (such as D) can still be used to implement crypto. The answe…
-
comment
Comment #8593170
STARTTLS was never intended to thwart MITM however. We need to keep that in mind. It allows a way to start a secure channel that is backwards compatible under the assumption that a…
-
comment
Comment #8592989
It has its own ("Network Security Services" or NSS). But that's not a reason to use Firefox on XP. ;)
- comment
-
comment
Comment #8592895
> whole explanation boils down to "managed languages are more complex, therefore worse." I hope that's not what I said... > Please point me to the specific native features which mi…
-
comment
Comment #8592467
The window from disclosure of patches to duplication is narrowing and it appears from the bulletin that client connections are affected as well. Furthermore any computer you take a…
-
comment
Comment #8592430
> Timing attacks are often the result of optimisations within the crypto library which inadvertently give away information, for example a loop which breaks on X != Y, instead of se…
-
comment
Comment #8585051
> Net neutrality isn't a blanket term for "anything the government does relating to the Internet", it's focused on a specific issue. Of course. > I guess you could argue that net n…
-
comment
Comment #8575454
Some here may know me as a critic of overreaching and aggressive cyber enforcement (and related surveillance). First, I'm quite happy that this activity does not appear to be the r…
-
comment
Comment #8565442
I think implementation bugs are within the spirit of OP, especially provided the NSA claims to have provided an implementation fix for Heartbleed. The sorts of bugs I'm talking abo…
-
comment
Comment #8565170
Bug volume in crypto is extremely high. How many developers reuse IVs in stream ciphers? How many blindly use AES or somesuch other symmetric library and then build in no authentic…
-
comment
Comment #8565082
Right, NEC3's 'solution' to obscure zones by signing hashes effectively just renames zones that probably come from some small collection ('www', 'ftp', 'ns', 'smtp', 'ilo') and not…
- comment
-
comment
Comment #8564616
Six digits sounds about right for a Tor bug for one target depending on the specifics. The RCE bug used by the FBI recently against the Tor Firefox Bundle would have cost something…
-
comment
Comment #8564574
Oh we're not talking trivial bugs or single-site XSS. Disappointed that 'mediocre' vulns got interpreted in this thread as 'trivial'. Mediocre doesn't mean trivial, extremely scope…
-
comment
Comment #8559020
> to fight terrorism Most of what the NSA does is geopolitical in nature. They are barely involved in CT activity (they do only minor amounts of CT). https://news.ycombinator.com/i…
-
comment
Comment #8558990
> But I honestly can't help but feel we've reached pretty close to the bottom of that slope. In the sense that I feel like our government just kind of makes stuff up as it goes alo…
-
comment
Comment #8554092
My digest agrees. B9D1F5290EBE56780AF692E2B12037D6B7E085EF1F6050C1E27EA8426F94BFCC I found the quote you've posted in my copy as well. The definition I selected was from the glossa…
-
comment
Comment #8553942
Actually, it does not look like the UID is a PUF - although it's a very interesting idea! "Unique ID (UID) - A 256-bit AES key that’s burned into each processor at manufacture. It …
-
comment
Comment #8552920
> Since PUFs typically get their values from random process variation How sure are we that this is the case, and how can we verify it? You can burn in whatever bits you want to the…
-
comment
Comment #8539916
From Tor: "So I'm totally anonymous if I use Tor? No. First, Tor protects the network communications. It separates where you are from where you are going on the Internet. What cont…
-
comment
Comment #8535606
> Apple ... can't decrypt data encrypted with the passcode ... today or ever before. The passcode of 12 bits... Apple can and will provide ciphertexts, will hand over copies of the…
-
comment
Comment #8535543
Prior to the "Secure Enclave", only a very small amount of certain data was encrypted on the device (past the alive-time of the device and where data _could have been encrypted_), …
-
comment
Comment #8534936
The examples though _do_ have physical manifestations - everything that exists in the universe has a physical manifestation (by tautology). How is a feed forward circuit carrying i…