HNHacker News
TopNewBestAskShowJobs

CraftThatBlock

1,568 karma · joined April 23, 2014

https://github.com/Cretezy

https://cretezy.com

Work @ Lyft, all opinions my own

submissionscomments
CraftThatBlock··on Ask HN: Cryptography questions (key shortening and key verification)
1) Getting a shortened key

To start off, users enter a master password, which a key is then derived from (with a salt from a server) using scrypt, which a key length of 512 bits (the dkLen could be changed, although I would like to keep it to 512 bits/64 bytes for legacy reasons).

On the client-side, I would also like to use AES, which requires 256 bits (or 128/192) keys. My problem is getting a shorter key that is based on the original key.

My current proposal is using PBKDF2 (with HMAC-SHA-256) with a salt from the server (or use the same salt as the master key) to derive a secondary key, which will be recreated every time the user logs in. My problem with this solution is that there is no need for an intensive deriviation, since the original key will already be "secure", therefor having a low iteration count (or even just 1) would be an option. Which could also just be HMAC-SHA-256(master key, salt).

My second solution is simply calculating the SHA-256 of the master key, since using a salt seems overkill for digesting a 512 bits key already. This is simpler since there's no need to store a secondary salt (if not using the master salt). I would prefer this solution but I'm unsure if this is fit for this usage, since the generated hash would be used for AES purposes.

The third solution was to simply slice the master key and take the first half, which would be 256 bits. I was also unsure if this would be recommended.

CraftThatBlock··on Show HN: MasterPassX, deterministic stateless password generator
I'm going to be adding a better form input to highly recommended users to use good passwords.

Since it doesn't store the master password (just the key derived from it), that is the true "game over" but would require trying the whole 2^256 space with HMAC-SHA256 to brute force the key.

If they try to brute force the actual mastet password, it would be extremely slow since it uses scrypt with a high n, which runs at 2 hash/sec on a good desktop (probably could be a lot higher using dedicated hardware, but still very very low compared to SHA256 which stands at millions of hash/sec).

I don't understand your last point, can you rephrase it?

CraftThatBlock··on Is Facebook down?
https://www.messenger.com/login/password/ yields:

"Facebook Will Be Back Soon Facebook is down for required maintenance right now, but you should be able to get back on within a few minutes. In the meantime, read more about why you're seeing this message. Thanks for your patience as we improve the site."

CraftThatBlock··on Why did AirAsia fly a crippled jet away from a nearby airport yesterday?
Am from St-Hubert and there's not much training here. We have an airport, but it's main purpose isn't training. That crash was a single off accident, could've happened anywhere (I live about 10 minutes away from the crash site).
CraftThatBlock··on Ask HN: What are some good React resources?
https://github.com/enaqx/awesome-react is a great start.
CraftThatBlock··on Do not let your CDN betray you: use subresource integrity (2015)
And IIRC, it's built-in to creat-react-app.
CraftThatBlock··on ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network
Looks great on mobile however
CraftThatBlock··on Improving on Tor .onion Address Usability
This is a great step forward, however the nature of all "domains" is centralised. DNS is a great idea, that decouples the centralisation to many parties, but it is central at many points; registrars, ICANN, DNS servers (though can be local). Tor's unique .onion address are the perfect way to fix the centralisation and the security, but comes at the cost of human readability.
CraftThatBlock··on How to rickroll Spotify for Android
This raises the question of: why is Spotify on HTTP for the first seconds? Would it be to bypass the TLS handshake, hence a faster "start" time? Wouldn't a constant connection (à la WebSocket with TLS) fix this?
CraftThatBlock··on Ask HN: What's the state of current HN iOS clients?
When in iOS, I used https://app.hackerwebapp.com/. In Android I'm using Materialistic.
CraftThatBlock··on Ask HN: What is your experience switching away from QWERTY keyboard?
Is there any keyboard similar to the TypeMatrix (for ease of use and helping with RSIs) with mechanical switches?
CraftThatBlock··on Grand jury subpoena for Signal user data
Apps that claim "privacy" only actually protect the security, not anonymity of their users.
CraftThatBlock··on Grand jury subpoena for Signal user data
The "privacy" apps nowadays (Signal for instance) is morw about security than anonymity.
CraftThatBlock··on Project Shield
So... Tor?
CraftThatBlock··on Goodbye Mac OS Forge, hello GitHub
This is long overdue. Google slowly been doing the same with moving from Google Code (which was supposed to be dead? It is though?) to GitHub, but a little progression is better than no progression.
CraftThatBlock··on Ask HN: What is a good React stack?
To get started on all of this, is there any boiler plates with auth built-in to take a look instead of reimplementing everything from the base up?
CraftThatBlock··on Ask HN: Freelancer? Seeking freelancer? (April 2016)
SEEKING WORK - Remote/Montreal

General development, full stack developer jack of all trades, specialist in JavaScript (Node, front-end), and PHP. Many years of experience in web development and can do full web applications.

Mainly an experienced full stack Node.js, and PHP developer, front-end developer (mainly JavaScript). 1-2 years experience with Go for backend and web development. Many years of work with Java, some web development with it.

Contact me at cretezy@gmail.com, available immediately.

CraftThatBlock··on GitHub seems to be experiencing technical difficulties
That was quick, I was about to post it. Hopefully everything isn't on fire over at Github.
CraftThatBlock··on W^X enabled in OpenBSD Firefox port
Firefox on iOS https://appsto.re/ca/-LZ_6.i
CraftThatBlock··on Ten Dropbox Engineers Build Lossless 'Pied Piper' Compression Algorithm
Look at the Github.. I laughed. :)
CraftThatBlock··on G is for Google
That's .xxx
CraftThatBlock··on Αnonymous is dead
http://pastebin.com/wEkCAmYF
CraftThatBlock··on Αnonymous is dead
Will do.
← PreviousPage 10 of 10