HNHacker News
TopNewBestAskShowJobs

AnaniasAnanas

224 karma · joined May 14, 2018

submissionscomments
AnaniasAnanas··on Opmsg – A GPG Alternative
Banks are not known for using the best/safest solutions. Just take 4 digit pins and 3DES into account for example.

> who only offer certs of RSA and P-{256,384}?

I am pretty sure that nginx and openssl only recently added support for ed25519 certificates. Although to be honest I don't really like the idea of let's encrypt. The addressing system that tor uses has solved that issue already.

> but where most browsers use secp256r1?

This is an issue. Browser vendors should prioritize the djb algorithms.

AnaniasAnanas··on Opmsg – A GPG Alternative
Nobody was ever fired for using DJB. Meanwhile I would gladly fire someone for using AES128 or the NSA-sponsored curves, despite being in Suite B.
AnaniasAnanas··on Opmsg – A GPG Alternative
> some of them do involve using RSA with absurd key sizes and they'll likely fail the competition.

Only one (specifically DJBs joke Post-QC algorithm), and it did not pass to the second round.

AnaniasAnanas··on Opmsg – A GPG Alternative
> WhatsApp, Telegram and Signal use mobile phone numbers as identifiers

One notable exception (which as I understand is tptacek-approved) is Wire, which only needs an email.

AnaniasAnanas··on Opmsg – A GPG Alternative
> Nobody actually wants to rely on a single entity (for or non-profit) for their communication

You don't have to do that. Protocols like tox for example are distributed and use DHT in order to find peers.

AnaniasAnanas··on SKS Keyserver Network Under Attack
It's even worse than it seems. The certificates are only a few megabytes long. https://twitter.com/FiloSottile/status/1145091106138394625
AnaniasAnanas··on SKS Keyserver Network Under Attack
Both Signal and Wire are FOSS though.
AnaniasAnanas··on SKS Keyserver Network Under Attack
As much as I believe that Efail was the result of badly implemented email clients it's not like the OpenPGP standard hadn't any involvement with it whatsoever. DJB for example suggests small authenticated and encrypted packets, something that OpenPGP does not have. See https://groups.google.com/forum/#!original/boring-crypto/BpU...

Since I am apparently replying too fast and I need to slow down, here is my reply to the child post by Sir_Cmpwn:

> I don't really see the link between the email you posted and efail

GPG decrypts the whole message which might be gigaoctets long and throws it to the output. After it has been decrypted it checks the MDC (if it exists) and throws an error if the MDC does not match or if it is missing. Meanwhile if a OpenPGP message was composed of small authenticated packets GPG would be able to first authenticate if the MAC of the packet is correct and then return an error right away if it does not match. If it did match it would return plaintext and move on to the next packet. You can see now how efail would be prevented, right?

> PGP

Do people use PGP nowadays? I was under the impression that pretty much everyone used GPG ever since it was released.

AnaniasAnanas··on TeXmacs 1.99.1
I tried exporting org-mode to latex in the past and found it extremely buggy. I don't really see a reason not to just directly use LaTeX instead.
AnaniasAnanas··on Schools are using unproven surveillance technology to monitor students
*Everywhere. My own school experience in Europe was pretty much the same as he described. And it is not only my school experience either, there were many cases of unpunished power abuse that the teachers engaged in in nearby schools.
AnaniasAnanas··on Schools are using unproven surveillance technology to monitor students
The schools that I went to had around 300 students. It did not stop the abuse by teachers nor did it stop the bullying that the teachers ignored.
AnaniasAnanas··on SKS Keyserver Network Under Attack
OCaml is very popular in academia though, especially in the field of theoretical computer science and formal verification. Coq, Frama-C, Flow, CompCert, etc are all written in OCaml. Heck, if you are running a graphical GNU distribution chances are that you have installed FFTW, which is written in OCaml. The "industry" is not the only thing that matters when considering the adoption of a language.
AnaniasAnanas··on SSH gets protection against side-channel attacks
No offense, I am genuinely curious, why would anyone use any closed source software for anything related to security after the Snowden revelations?
AnaniasAnanas··on MIPS R3000
Why does everyone seem to hate delay slots? I understand that it makes writing assembly more annoying but most people use a compiler anyway.
AnaniasAnanas··on Firefox zero-day was used in attack against Coinbase employees, not its users
A better question would be: why were Coinbase employees allowed to use any browser with javascript enabled and outside of a VM? Qubes OS has been a thing for quite a while.
AnaniasAnanas··on Firefox zero-day was used in attack against Coinbase employees, not its users
I mentioned the possibility of an untrustworthy person gaining access to bugzilla yesterday but it seems that most people disagreed with it: https://news.ycombinator.com/item?id=20221397
AnaniasAnanas··on Hit by Ransomware Attack, Florida City Agrees to Pay Hackers $600k
The voters are not one person. Sadly democracy ends up being the fascism of the many.
AnaniasAnanas··on Hit by Ransomware Attack, Florida City Agrees to Pay Hackers $600k
Whoever made the decision not to take backups for example. The ones who will have to pay for their mistakes will be the taxpayers otherwise.
AnaniasAnanas··on Hit by Ransomware Attack, Florida City Agrees to Pay Hackers $600k
Shouldn't the one responsible personally have to pay for it rather than the city and its taxpayers?
AnaniasAnanas··on Facebook moderators break NDAs to expose working conditions
> It needs to be possible to hire people that you trust not to disclose all your secrets, and your customer's secrets

I disagree, it needs to be possible for whistle-blowers to operate freely. It should also be possible to disclose to the whole world new and superior techniques and technologies that a company tries to hide.

> This is what privacy regulations are all about

I am pretty sure that this is a separate thing to NDAs. Nevertheless I believe that the solution should be technical rather than legal, with things like end to end encryption and public key cryptography.

AnaniasAnanas··on Facebook moderators break NDAs to expose working conditions
Companies seem to try to abuse patent, trademarks, and copyrights as much as they can anyway. The best of-course would be if NDAs, patents, and copyrights all disappeared overnight. Trademarks are generally fine but they can be abused.
AnaniasAnanas··on Facebook moderators break NDAs to expose working conditions
> NDAs and non-competes have their uses

I have yet to see a valid use that does not hinder whistle-blowing, the advancement of technology, or does not abuse the employees. I am sure that you will find a few valid use-cases if you try hard enough, however in the vast majority of cases they are used in order to repress the rights of others.

AnaniasAnanas··on Facebook moderators break NDAs to expose working conditions
NDAs and non-compete agreements should not ever be considered as valid contracts by the government.
AnaniasAnanas··on Mozilla patches Firefox zero-day abused in the wild
It will be seen by a malicious actor anyway after the fix is released. The difference is that there will be more time for a malicious actor to act against a fork if an embargo is applied.
AnaniasAnanas··on Mozilla patches Firefox zero-day abused in the wild
Consider trying the debian package until it is updated in your system.
AnaniasAnanas··on Mozilla patches Firefox zero-day abused in the wild
It is important to also understand what causes the issue, how it was exploited, etc. Plus I am pretty sure that they had the bug report before the fix was released.
AnaniasAnanas··on Mozilla patches Firefox zero-day abused in the wild
Anyone can run a fork though, I right now might be running my personal fork. This is part of the point of free software.

Plus, you assume that the select few developers that are given the exploit information are trustworthy. The exploit being public from the first day is better than if even a single developer is untrustworthy or compromised.

AnaniasAnanas··on Mozilla patches Firefox zero-day abused in the wild
https://bugzilla.mozilla.org/show_bug.cgi?id=1544386

I find it really gross that they do not allow others to access it. This behavior damages the forks.

AnaniasAnanas··on uBlock Origin 1.20
Would you mind elaborating? What does it have that uBlock Origin doesn't?
AnaniasAnanas··on The NYC subway system runs on OS/2
Non-mobile link: https://en.wikipedia.org/wiki/Submarine_Command_System#SMCS-...
Page 1 of 13Next →