HNHacker News
TopNewBestAskShowJobs

andiw

19 karma · joined May 18, 2011

submissionscomments
andiw··on Cryptographic Best Practices
Can someone help me understand this recommendation:

Under symmetric encryption, the authors write:

> If you are in a position to use a key management system (KMS), then you should use KMS. If you are not in a position to use KMS, then you should use authenticated encryption with associated data (AEAD).

These seem orthogonal to me. KMS := how keys are generated and distributed to communication partners. AEAD := how data is encrypted between communication partners using those keys.

How can it be “use a KMS if you can _or else_ use AEAD”? Shouldn’t it be “and”? What am I missing?

andiw··on IAmA a malware coder and botnet operator, AMA
Yep, also he likes to use conditional tense (would) in 'if' clauses, which is a typical language trap for German native speakers.
andiw··on Google.pl's crazy doodle
Not for me (US), I see a thanksgiving turkey. Oh well...
andiw··on PSN has been hacked again
Note, according to the original article (http://sony.nyleveia.com/2011/05/17/warning-all-psn-users-yo...) as well as this forum discussion (http://www.neogaf.com/forum/showthread.php?t=430574), this is in fact a new vulnerability that is independent of the original PSN hack.

The problem seems to be that the email validation required for resetting the password could be circumvented. There is no detailed information in the posts how, but likely either the validation hash was generated in a insecure fashion, or the email address input was not properly sanitized and allowed piggybacking (CCing) a 2nd email address to receive the confirmation email.