Breaking homegrown crypto
kivikakk.ee
kivikakk.ee
In case anyone is concerned, this bears repeating: This attack broke CodeIgniter 2's poorly designed Encrypt class, but CodeIgniter 3's Encryption class offers authenticated encryption.
If you're still using CodeIgniter 2, upgrade.
If you're using CodeIgniter 3, make sure you're not using Encrypt.
Exception: Don't use mcrypt. It's abandonware.
Reads almost like a walk through.
Side note: Why is a .ee (Estonia) domain site hosted in Japan (Tokyo)?
Similar to many start-ups and tech projects being hosted <everywhere> on .io (Indian Ocean) domains.
Regarding the geographic location, it's probably a Choopa/vultr machine.
Seems like a digitalocean clone though with more geographical locations and they support arbitrary OS images.
This is because we want good stories to have multiple chances at making the front page. The current story is a great example. In fact, we invited tdurden to repost it, as we sometimes do when we notice an article that we think the community might find interesting, but which fell through the cracks.
We're working on a better duplicate handling system that will reduce the number of reposts in the story stream, but getting it right is surprisingly subtle, and we'd rather take longer than get it wrong.
If it's longer than a tweet, don't read it on your phone.