HNHacker News
TopNewBestAskShowJobs

CiPHPerCoder

6,663 karma · joined February 25, 2016

My name is Scott. I do a lot of open source security research, and cryptography.

Previously AWS Cryptography (2019 - 2023).

Unless otherwise stated, my opinions are my own and do not reflect my employer.

https://scottarc.blog/about/

submissionscomments
CiPHPerCoder··on Solving Open Source Supply Chain Security for the PHP Ecosystem
> I don't get it, who is going to pay for the time and energy required to audit everything?

Not everything has to be audited. That's why there's different levels of attestations.

In terms of economic incentives: If you're a company bit by one of the recent supply chain issues (colors.js, etc.), you might be able to justify hiring a security vendor to audit the code that your company depends on. This would provide a net-positive benefit to the entire ecosystem, even if it's only a small set of audited code.

Maybe one day, we can even make this an expectation of large players. But that's a discussion for down the road.

On the opposite end of things, you have independent security consultants that want to establish their reputation so they can get paid engagements with software companies.

One avenue available to everyone is review open source software, report vulnerabilities to their maintainers. This can be thankless or even traumatic; i.e. https://github.com/opencart/opencart/pull/1594

Gossamer would open an alternative approach: Hang your shingle out by publishing negative (vote-against) attestations of vulnerable versions of open source software and positive attestations (e.g. code-review) of the versions that mitigated the issues they disclosed. Anti-malware vendors (e.g. WordFence) could even issue weaker positive assertions (spot-check) for WordPress plugin/theme updates after vetting the known-good releases. Security companies depend heavily on their ability to earn trust to thrive, and that's a hard market to break into; this offers another way in.

In short, the economic challenges you're imagining aren't the ones that this project will face. (Although, there will assuredly be challenges.)

Companies acting in their own self-interest can be leveraged to cover the hot paths of the universal dependency graph, and security up-starts can be leveraged to cover their blind spots. Given enough time, the ecosystem will eventually reach some sort of equilibrium, and many new opportunities will be made in the process.

> I presume the big package maintainers already have eyes on their stuff - symfony etc.

Read the discussion on the Symfony Encryption component: https://github.com/symfony/symfony/pull/39344

Just because they have eyes on their stuff doesn't mean that those eyes have the necessary domain-specific expertise to identify problems. If it weren't for Paragon (paragonie-security on Github) and their associates in the security industry, the issues identified in the earlier versions of the module would likely have persisted and been shipped.

CiPHPerCoder··on Google hired union-busting consultants to convince employees “unions suck”
> Then Google should just hire 100,000 devs this year, why not?

Hold up that's actually a good idea. It would help a lot of entry level devs bulk up their resume and learn hands on skills. This would lead to an influx of sorely needed new talent to the entire tech industry and enable a lot more innovation than was possible before, if only due to HR red tape.

CiPHPerCoder··on Random number generator updates for Linux 5.17
I am stoked for updating all my systems to use Linux 5.17 now.
CiPHPerCoder··on My Many Girlfriends
Well, I'm not so sure that insincere has negative connotations in English anymore, given how ubiquitous this behavior is. But point taken.
CiPHPerCoder··on My Many Girlfriends
> I am sorry, I don't know how to phrase it in English without ruining the nuance. It's a mix of calculating, cunning, and a bit flirtatious?

The closest word I can think for what you describe is insincere. See also: almost every influencer on TikTok.

CiPHPerCoder··on Why Web3?
Their MVP is a slide deck, or a sales website.
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
Enjoy your vulnerabilities
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
This is a good thing. Separate tool for separate use cases.

Bug jedisct1 if you want YubiKey support for minisign.

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
What is your bar for "audited"?

I've reviewed both the design and implementation for age in the past and only found nitpicky things to improve (mostly related to HKDF).

I can take a fresh look and make a pretty PDF on paragonie.com if you care so much.

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
> So, it's brand new. Got it.

No. Brand new means completely new. Something that's going on 3 years old isn't brand new anymore.

A more appropriately term is relatively new. Civilization is relatively new compared to the age of the universe. Age is relatively new compared to modern computers.

But neither civilization nor age are brand new.

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
No, Thomas was talking about rage. https://github.com/str4d/rage
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
Confusing the two is perilous.

https://blog.cryptographyengineering.com/2016/03/21/attack-o...

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
> But what I believe someguydave was referring to was stuff like smartcard/Yubikey support, not different uses of encryption and signing.

https://twitter.com/FiloSottile/status/1474941666545086465 ¯\_(ツ)_/¯

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
> GnuPG has stood up pretty well for three decades

Make sure you also look for libgcrypt, which had a lot of cryptographic weaknesses in the 2010s.

https://www.cvedetails.com/vulnerability-list/vendor_id-4711...

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
I don't read your wiki, so no, you were not the cause of it.

This list item was prompted by a private discussion with friends.

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
It still uses better encryption than Telegram, Threema, and several other products that market themselves as "private messaging" apps.
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
More specifically, Trillian is analogous to Chronicle, which is what Gossamer uses as its underlying ledger. But yeah, there's a lot of similarities. You're on the right track. :)
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
Gossamer is a 2017 design of an idea that was first published in 2015. However, it was exclusively focused on the PHP community from its inception, so it's unsurprising that nobody's heard of it.
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
Solving the problem you care about requires doing what I just said. :)

And, yes, there is a lot of work necessary to get WordPress to use Gossamer. I can't guarantee a deadline right now, but 2022 looks hopeful.

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
It isn't brand new, no.
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
Yes: https://github.com/paragonie/libgossamer/blob/master/docs/tu...

The intention was to allow security vendors to offer code reviews of open source dependencies, and you can choose which you trust. This mechanizes Linus's Law and ensures there's an audit trail with "many eyeballs".

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
It's been around since 2019, and has been discussed heavily on Hacker News.
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
A "complete replacement" for GPG would be a dumb idea to begin with.

You want a specific tool for each of these use-cases. Choose one from the list for each use case.

1. Private messaging: Signal, WhatsApp, Cwtch

2. File encryption: age

3. Encrypted backups: age + a Reed-Solomon encoder for catching flipped bits

4. Digital signatures: minisign, signify, OpenSSH signatures

The problem with GPG (and with PGP in general) is it tried to do too many things. Complexity is the enemy of security.

CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
Consider, for the age and minisign/signify use-case: https://gossamer.tools
CiPHPerCoder··on GnuPG used to ask for your support to help protect online privacy
Calling age an unknown upstart is a weird take.
CiPHPerCoder··on Intuitive Advanced Cryptography [pdf]
This is one of the most fun papers I've read in a while. I won't spoil anything; sit down with it when you have time and be prepared to laugh a bit.
CiPHPerCoder··on Why I Have Settled on XChaCha20+Blake3 for AEAD
OCB isn't committing, so it doesn't solve the stated problem.
CiPHPerCoder··on Why I Have Settled on XChaCha20+Blake3 for AEAD
Worth noting that the 10 and 7 are double ChaCha rounds, which means that the strength of BLAKE3's bit diffusion is closer to ChaCha14 than ChaCha7.

Given that the best attack against ChaCha fails to break ChaCha8, it's reasonable to conclude that BLAKE3 is secure.

CiPHPerCoder··on Facebook has exempted high-profile users from some or all of its rules
I maintain an account only so nobody can impersonate me to others.
CiPHPerCoder··on Facebook has exempted high-profile users from some or all of its rules
This tracks with their other choices and behaviors, unfortunately.
← PreviousPage 4 of 34Next →