Live data from Hacker News

Viewing profile — xnull

xnull

HN member
Joined
Tue, Aug 19, 2014, 6:31 PM UTC
HN karma
534
Public activity
104 items

About xnull

No profile information was provided.

Recent public activity

  1. story
  2. comment
    Comment #8597148

    The overall question is whether bindings or language features that expose direct control of the underlying architecture (such as D) can still be used to implement crypto. The answe…

  3. comment
    Comment #8593170

    STARTTLS was never intended to thwart MITM however. We need to keep that in mind. It allows a way to start a secure channel that is backwards compatible under the assumption that a…

  4. comment
    Comment #8592989

    It has its own ("Network Security Services" or NSS). But that's not a reason to use Firefox on XP. ;)

  5. comment
  6. comment
    Comment #8592895

    > whole explanation boils down to "managed languages are more complex, therefore worse." I hope that's not what I said... > Please point me to the specific native features which mi…

  7. comment
    Comment #8592467

    The window from disclosure of patches to duplication is narrowing and it appears from the bulletin that client connections are affected as well. Furthermore any computer you take a…

  8. comment
    Comment #8592430

    > Timing attacks are often the result of optimisations within the crypto library which inadvertently give away information, for example a loop which breaks on X != Y, instead of se…

  9. comment
    Comment #8585051

    > Net neutrality isn't a blanket term for "anything the government does relating to the Internet", it's focused on a specific issue. Of course. > I guess you could argue that net n…

  10. comment
    Comment #8575454

    Some here may know me as a critic of overreaching and aggressive cyber enforcement (and related surveillance). First, I'm quite happy that this activity does not appear to be the r…

  11. comment
    Comment #8565442

    I think implementation bugs are within the spirit of OP, especially provided the NSA claims to have provided an implementation fix for Heartbleed. The sorts of bugs I'm talking abo…

  12. comment
    Comment #8565170

    Bug volume in crypto is extremely high. How many developers reuse IVs in stream ciphers? How many blindly use AES or somesuch other symmetric library and then build in no authentic…

  13. comment
    Comment #8565082

    Right, NEC3's 'solution' to obscure zones by signing hashes effectively just renames zones that probably come from some small collection ('www', 'ftp', 'ns', 'smtp', 'ilo') and not…

  14. comment
  15. comment
    Comment #8564616

    Six digits sounds about right for a Tor bug for one target depending on the specifics. The RCE bug used by the FBI recently against the Tor Firefox Bundle would have cost something…

  16. comment
    Comment #8564574

    Oh we're not talking trivial bugs or single-site XSS. Disappointed that 'mediocre' vulns got interpreted in this thread as 'trivial'. Mediocre doesn't mean trivial, extremely scope…

  17. comment
    Comment #8559020

    > to fight terrorism Most of what the NSA does is geopolitical in nature. They are barely involved in CT activity (they do only minor amounts of CT). https://news.ycombinator.com/i…

  18. comment
    Comment #8558990

    > But I honestly can't help but feel we've reached pretty close to the bottom of that slope. In the sense that I feel like our government just kind of makes stuff up as it goes alo…

  19. comment
    Comment #8554092

    My digest agrees. B9D1F5290EBE56780AF692E2B12037D6B7E085EF1F6050C1E27EA8426F94BFCC I found the quote you've posted in my copy as well. The definition I selected was from the glossa…

  20. comment
    Comment #8553942

    Actually, it does not look like the UID is a PUF - although it's a very interesting idea! "Unique ID (UID) - A 256-bit AES key that’s burned into each processor at manufacture. It …

  21. comment
    Comment #8552920

    > Since PUFs typically get their values from random process variation How sure are we that this is the case, and how can we verify it? You can burn in whatever bits you want to the…

  22. comment
    Comment #8539916

    From Tor: "So I'm totally anonymous if I use Tor? No. First, Tor protects the network communications. It separates where you are from where you are going on the Internet. What cont…

  23. comment
    Comment #8535606

    > Apple ... can't decrypt data encrypted with the passcode ... today or ever before. The passcode of 12 bits... Apple can and will provide ciphertexts, will hand over copies of the…

  24. comment
    Comment #8535543

    Prior to the "Secure Enclave", only a very small amount of certain data was encrypted on the device (past the alive-time of the device and where data _could have been encrypted_), …

  25. comment
    Comment #8534936

    The examples though _do_ have physical manifestations - everything that exists in the universe has a physical manifestation (by tautology). How is a feed forward circuit carrying i…