Live data from Hacker News

Viewing profile — zahllos

zahllos

HN member
Joined
Sun, Jun 05, 2016, 1:27 PM UTC
HN karma
1,136
Public activity
338 items

About zahllos

No profile information was provided.

Recent public activity

  1. comment
    Comment #48872598

    I implemented something similar for my bot defences. If headless chrome is detected you still get the same anubis-style PoW but even if you submit the right answer you get rejected…

  2. comment
    Comment #48870552

    I've never done anything "serious" with haskell, just small personal projects. Mostly this is because I've found the ecosystem to be a pain - when I was trying stack stack was the …

  3. comment
    Comment #48382327

    Also true. The BOMs though are annoying.

  4. comment
    Comment #48374095

    Additional Detail: it is specifically utf-16 little endian when a byte order mark is not used, which is the opposite of the recommended choice of big endian in the RFC. Worse are t…

  5. comment
    Comment #48368472

    There is ARM SystemReady in a couple of flavours, one of which is UEFI: https://documentation-service.arm.com/static/68512137d12d1a1... While I'm not exactly enthused about UEFI I …

  6. comment
    Comment #47711200

    Not the OP, but: -march says the compiler can assume that the features of that particular CPU architecture family, which is broken out by generation, can be relied upon. In the wor…

  7. comment
    Comment #47495606

    No unfortunately it is not correct. You can supply a different CA to verify client certs against to what is given in server hello. There's no need for them to be related at all. Cr…

  8. comment
    Comment #47387356

    I agree. I wanted a particular tool to support my development. The libraries are well known and understood by people who work in text editors, but this is not my area and I have a …

  9. comment
    Comment #46800030

    The windows assessment and deployment kit is what you need, with the windows pe add-on: https://learn.microsoft.com/en-us/windows-hardware/manufactu... You should be aware there's …

  10. comment
    Comment #46043512

    I understand his concern perfectly. What I am saying is that his concern is not mitigated at all by the presence or absence of an IETF standard. This is going to happen anyway (non…

  11. comment
    Comment #46041146

    I guess that would have been Silverman etc? That's true there was NTRU before reductions were shown. Good call.

  12. comment
    Comment #46038370

    Source for this loss of security? I'm aware of the MATZOV work but you make it sound like there's a continuous and steady improvement in attacks and that is not my impression. Lots…

  13. comment
    Comment #46037082

    Sure. I'm not American either. I agree, maximum scrutiny is warranted. The thing is these algorithms have been under discussion for quite some time. If you're not deeply into crypt…

  14. comment
    Comment #46036613

    Indeed. Dual_EC was a NOBUS backdoor relying on the ECDLP. That's fair. My point was more that it looked suspicious at the time (why use a trapdoor in a CSPRNG) and at least the po…

  15. comment
    Comment #46035797

    SHA-2 was designed by the NSA. Nobody is saying there is a backdoor.

  16. comment
    Comment #46035679

    I will reply directly r.e. the analogy itself here. It is a poor one at best, because it assumes ML-KEM is akin to "internetting without cryptography". It isn't. If you want a bett…

  17. comment
    Comment #46035531

    The commentor means Dual_EC, a random number generator. The backdoor was patented under the form of "escrow" here: https://patents.google.com/patent/US8396213B2/en?oq=USOO83.9... -…

  18. comment
    Comment #46035417

    ML-KEM and ML-DSA are not "known weak". The justification for hybrid crypto is that they might have classical cryptanalytical results we aren't aware of, although there's a hardnes…

  19. comment
    Comment #46034678

    "The government" already have. That's what CNSA 2.0 means - this is the commercial crypto NSA recommend for the US Government and what will be in FIPS/CAVP/CMVP. ML-KEM-only for mo…

  20. comment
    Comment #46034478

    In context, this particular issue is that DJB disagrees with the IETF publishing an ML-KEM only standard for key exchange. Here's the thing. The existence of a standard does not me…

  21. comment
    Comment #45914429

    Ah no I was just being snarky and not at you. We're all missing (hyper)text markup language as the UI markup layer, plus js. We previously had some kind of alternative "load app fr…

  22. comment
    Comment #45912497

    We could call it Flash. Or Java Applets.

  23. comment
    Comment #45838453

    Yeah. No revenue. Nobody wants to hear about revenue! It's not about how much you make, it is about how much you're worth and who is worth the most? Companies that lose money.

  24. comment
    Comment #45537315

    End to end could still be default for 1-1 chats. Multi device support turns this into a small group chat but it is doable (Wire did it this way afaik; I think Signal does too). Sma…

  25. comment
    Comment #45391000

    You can sort of look up a birth certificate but the service isn't designed for that. It is here: https://www.gro.gov.uk/gro/content/ This is where you get certified copies should y…