Viewing profile — zahllos
zahllos
HN member- Joined
- Sun, Jun 05, 2016, 1:27 PM UTC
- HN karma
- 1,136
- Public activity
- 338 items
- HN profile
- View on Hacker News ↗
About zahllos
No profile information was provided.
Recent public activity
-
comment
Comment #48872598
I implemented something similar for my bot defences. If headless chrome is detected you still get the same anubis-style PoW but even if you submit the right answer you get rejected…
-
comment
Comment #48870552
I've never done anything "serious" with haskell, just small personal projects. Mostly this is because I've found the ecosystem to be a pain - when I was trying stack stack was the …
-
comment
Comment #48382327
Also true. The BOMs though are annoying.
-
comment
Comment #48374095
Additional Detail: it is specifically utf-16 little endian when a byte order mark is not used, which is the opposite of the recommended choice of big endian in the RFC. Worse are t…
-
comment
Comment #48368472
There is ARM SystemReady in a couple of flavours, one of which is UEFI: https://documentation-service.arm.com/static/68512137d12d1a1... While I'm not exactly enthused about UEFI I …
-
comment
Comment #47711200
Not the OP, but: -march says the compiler can assume that the features of that particular CPU architecture family, which is broken out by generation, can be relied upon. In the wor…
-
comment
Comment #47495606
No unfortunately it is not correct. You can supply a different CA to verify client certs against to what is given in server hello. There's no need for them to be related at all. Cr…
-
comment
Comment #47387356
I agree. I wanted a particular tool to support my development. The libraries are well known and understood by people who work in text editors, but this is not my area and I have a …
-
comment
Comment #46800030
The windows assessment and deployment kit is what you need, with the windows pe add-on: https://learn.microsoft.com/en-us/windows-hardware/manufactu... You should be aware there's …
-
comment
Comment #46043512
I understand his concern perfectly. What I am saying is that his concern is not mitigated at all by the presence or absence of an IETF standard. This is going to happen anyway (non…
-
comment
Comment #46041146
I guess that would have been Silverman etc? That's true there was NTRU before reductions were shown. Good call.
-
comment
Comment #46038370
Source for this loss of security? I'm aware of the MATZOV work but you make it sound like there's a continuous and steady improvement in attacks and that is not my impression. Lots…
-
comment
Comment #46037082
Sure. I'm not American either. I agree, maximum scrutiny is warranted. The thing is these algorithms have been under discussion for quite some time. If you're not deeply into crypt…
-
comment
Comment #46036613
Indeed. Dual_EC was a NOBUS backdoor relying on the ECDLP. That's fair. My point was more that it looked suspicious at the time (why use a trapdoor in a CSPRNG) and at least the po…
-
comment
Comment #46035797
SHA-2 was designed by the NSA. Nobody is saying there is a backdoor.
-
comment
Comment #46035679
I will reply directly r.e. the analogy itself here. It is a poor one at best, because it assumes ML-KEM is akin to "internetting without cryptography". It isn't. If you want a bett…
-
comment
Comment #46035531
The commentor means Dual_EC, a random number generator. The backdoor was patented under the form of "escrow" here: https://patents.google.com/patent/US8396213B2/en?oq=USOO83.9... -…
-
comment
Comment #46035417
ML-KEM and ML-DSA are not "known weak". The justification for hybrid crypto is that they might have classical cryptanalytical results we aren't aware of, although there's a hardnes…
-
comment
Comment #46034678
"The government" already have. That's what CNSA 2.0 means - this is the commercial crypto NSA recommend for the US Government and what will be in FIPS/CAVP/CMVP. ML-KEM-only for mo…
-
comment
Comment #46034478
In context, this particular issue is that DJB disagrees with the IETF publishing an ML-KEM only standard for key exchange. Here's the thing. The existence of a standard does not me…
-
comment
Comment #45914429
Ah no I was just being snarky and not at you. We're all missing (hyper)text markup language as the UI markup layer, plus js. We previously had some kind of alternative "load app fr…
-
comment
Comment #45912497
We could call it Flash. Or Java Applets.
-
comment
Comment #45838453
Yeah. No revenue. Nobody wants to hear about revenue! It's not about how much you make, it is about how much you're worth and who is worth the most? Companies that lose money.
-
comment
Comment #45537315
End to end could still be default for 1-1 chats. Multi device support turns this into a small group chat but it is doable (Wire did it this way afaik; I think Signal does too). Sma…
-
comment
Comment #45391000
You can sort of look up a birth certificate but the service isn't designed for that. It is here: https://www.gro.gov.uk/gro/content/ This is where you get certified copies should y…