HNHacker News
TopNewBestAskShowJobs

cassonmars

627 karma · joined April 6, 2021

Just an engineer that doesn’t believe in “impossible”.
submissionscomments
cassonmars··on Snap Wants to be a State Actor??–Kansas v. Snap
Probably not, the current (and hopefully not continuing) state admin (outside of the governor who has been a nice check against the legislature and judicial insanity here) is very ideologically aligned to the point of trying to find ways to imprison trans people.
cassonmars··on Resident Evil 4 (GameCube) – complete byte-identical decompilation to C/C++
They really did. And through great irony, such objections are preserved.

https://www.historyofinformation.com/detail.php?id=3439

"For this invention will produce forgetfulness in the minds of those who learn to use it, because they will not practice their memory. Their trust in writing, produced by external characters which are no part of themselves, will discourage the use of their own memory within them. You have invented an elixir not of memory, but of reminding; and you offer your pupils the appearance of wisdom, not true wisdom, for they will read many things without instruction and will therefore seem [275b] to know many things, when they are for the most part ignorant and hard to get along with, since they are not wise, but only appear wise."

cassonmars··on I co-founded Burning Man. The festival has lost its soul
They can be, but unfortunately the org has threatened to revoke official regional burn status unless they followed all the same rules, in particular, that children be allowed. There used to be some leeway on that, and there were really wonderful regional burns that did not permit kids. They were forced to, which resulted in the "real" burn being in a small taped off area.

Seems insane to me to think kids should be at burns.

cassonmars··on NSA and IETF, Part 9
Let's opt for the simplest possible way to describe this.

A good number of the proposals (in particular, the proposals that actually got close to being chosen), are based on lattice constructions.

NTRU's underlying construction has been available to scrutinize for 30 years, whereas the Module-LWE proposals (Kyber being one) has had 11 years. Keep in mind, the largest employer (and under very tight classified controls) of number theorists _is_ the NSA. In terms of overall intellectual power, if there _is_ a problem in the MLWE constructions, they'd very likely be the first to find it, all while not saying a single word. Then, despite clear objections laid out by people with explicit expertise on the distinctions between RLWE and MLWE, especially w/r/t parameter choice, Kyber, under weaker parameters, was chosen anyway.

We can't rely on the obvious tells anymore – they've already played that hand (EC-DRBG) and were caught. If a bad standard is being pushed, it has to be done in a way that is so subtle, that it literally comes up to, "yeah, maybe this is weaker, but we haven't found a way to prove that". DJB already lost the selection process, so now the goal is to at the very least, avoid recommendations that push an unshielded, far less historically tested option, with no helpful antidote if it were to be broken.

I get that generally assuming conspiracies is a bad starting place for debate (after all, how do you disprove a hypothesis that is expected to be so surreptitiously constructed that it evades all ability to be scrutinized?), and I'd similarly think this is an unreasonable assumption, except for the fact _it has already happened and been exposed, multiple times_.

cassonmars··on NSA and IETF, Part 9
Are you a cryptographer?

I am. I literally hold six patents around secure key generation and management. I stand by DJB's points.

cassonmars··on NSA and IETF, Part 9
because the NSA has never surreptitiously pushed bad standards they used to exploit before

/s

cassonmars··on If You Build It, They Will Come
> IMO the penalties for corruption in public service jobs (all the way to the top!) should also be outsized to match the damage it does to society.

Tough to do when those who write the laws are a part of the problem. What do you suggest to make this so?

cassonmars··on Web-based cryptography is always snake oil
Your argument would be far more charitable if NIST had not already been caught pushing a broken standard at the behest of the NSA before. DJB might be combative and somewhat caustic, but the one thing he's never been, given enough time in the retrospect to show it, is wrong.
cassonmars··on An American Privacy Emergency
The problem with attempting to provide universal healthcare in the united states is that, despite health professionals attesting to the necessity and validity of certain health related topics, the current administration in particular is very keen about stripping away access to these forms of care, as far as they legally can (medicare/medicaid, VA, federal funding).

UHC requires the removal of politicians from qualified input, and this country's politicians love nothing more than to get overly involved in things they know nothing about.

cassonmars··on Amazon drops Sam Altman movie after announcing OpenAI partnership
This feels like a strange take to me. With the internet, it has never been easier for people anywhere in the (connected) world to find an audience, which we've seen to great and detrimental effects. Prior to this, reaching widespread audiences _required_ powerful entities (publishers, marketers, broadcasters).

Why do you feel differently?

cassonmars··on What Caused That Loud Boom in South Carolina?
Save a click: no public information exists yet.
cassonmars··on Show HN: Freenet, a peer-to-peer platform for decentralized apps
For a basic CRDT set, merge rules have to have some kind of temporality basis in the messages such that commutativity is preserved. usually it's a timestamp, sometimes it's an unforgeable value like a hash, e.g. A: { "prev_hash": null, "content": "foobar" } B: { "prev_hash": "<hash of A>", "content": "foobarbaz" } C: { "prev_hash": "<hash of B>", "content": "foobaz" }

and when played out of order, it's guaranteed to resolve to foobaz eventually or immediately, depending on when messages are received

when you encounter the scenario of a fork, there's usually a fork resolution rule, e.g. D: { "prev_hash": "<hash of B>", "content": "foobazbar" }

to resolve C vs D, sort lexicographically, choose direction of sort order and pick first

When you have non-continuous data due to messages dropping, e.g. you have B and perhaps an E that builds on C, you can either use the same lexicographic rule, or make the hash basis a combination of timestamp and hash, so you get temporality and lineage.

As for deletes, you have either the single set approach of simply making the message content empty and that _is_ the delete, or you have the 2-phase sets, where there exists an add set and a delete set.

Quite a few ways to approach it, but commutativity can be readily preserved.

cassonmars··on I built my own hair electrolysis machine
based
cassonmars··on A cryptography engineer's perspective on quantum computing timelines
As you are someone building cryptographic libraries used by people all over the world, which includes those who might be seen as "enemies" by the organization in question, this is not a gradient — it's quite binary in nature.
cassonmars··on A cryptography engineer's perspective on quantum computing timelines
I genuinely do not understand how someone working in the capacity that you do, for things that matter universally for people, can contend that an organization who is intentionally engaging in NOBUS backdoors can be remotely trusted at all.

That is insanely irresponsible and genuinely concerning. I don't care if they have a magical ring that defies all laws of physics and assuredly prevents any adversary stealing the backdoor. If an organization is implementing _ANY_ backdoor, they are an adversary from a security perspective and their guidance should be treated as such.

cassonmars··on The Hackers Who Tracked My Sleep Cycle
It's insane to me that Stripe cancels accounts when they get used for card testing. I get that it's because the onus would be on them otherwise, but the problem is that the onus is on anyone but the card companies in the first place.
cassonmars··on Federal Right to Privacy Act – Draft legislation
How do you propose fixing the corruption?
cassonmars··on Show HN: s@: decentralized social networking over static sites
PFS is valuable largely in stable, small groups that rarely change shape or association.

PFS in an open, freely-associable environment is far more complicated when you move beyond even the smallest of group sizes. Realistically, once the group size is beyond Dunbar's number you can reasonably assume that PFS is moot, because you no longer can depend on maybe four or five people's personal security, but 150+. Statistically, someone's opsec failure will be guaranteed.

cassonmars··on Intel Demos Chip to Compute with Encrypted Data
You can if the manufacturer has a track record that refutes the notion, and especially if they have verifiable hardware matching publicly disclosed circuit designs. But this is Intel, with their track record, I wouldn't trust it even if the schematics were public. Intel ME not being disable-able by consumers, while being entirely omitted for certain classes of government buyers tells me everything I need to know.
cassonmars··on System76 on Age Verification Laws
Yes!
cassonmars··on System76 on Age Verification Laws
It's simple. Don't comply. Software engineers, despite not having the same requirement of mechanical engineers, should uphold the ethical obligations of their craft. This law is harmful. Given the requirement of compelled speech, given code has been _proven_ to be such, Do. Not. Comply.
cassonmars··on Excommunicated devs making games with AI
This is funny as most Michelin star chefs I've had the luxury of knowing love fast food
cassonmars··on Tell HN: YC companies scrape GitHub activity, send spam emails to users
And Cluely
cassonmars··on Finding and Fixing a 50k Goroutine Leak That Nearly Killed Production
I had the same confusion reading this – what kind of go-based webservice framework can you discretely deploy new handlers without restarts/redeploys? Would be a really awesome thing to have!
cassonmars··on Kernighan's Lever
or you're working in embedded systems, machine learning, cryptography, or any other specialized field where being clever is very important
cassonmars··on I'm just having fun
You would likely enjoy Isaac Asimov's "Profession": https://www.abelard.org/asimov.php
cassonmars··on Texas is suing all of the big TV makers for spying on what you watch
The hard part _includes_ the crypto and the sandboxing. Short of playing security theater games like "chuck it in a TEE", the moment your data needs any kind of processing, or possesses relationships with other users data (or their ability to view your data, like a social media feed), the complexity increases exponentially.
cassonmars··on Update and shut down no longer restarts PC, 25H2 patch addresses decades-old bug
With things like kpatch you can even update the kernel without a reboot
cassonmars··on Intent to Deprecate and Remove XSLT
XSLT is great, but its core problem is that the tooling is awful. And a lot of this has to do with the primary author of the XSLT specification, keeping a proprietary (and expensive) library as the main library that implements the ungodly terse spec. Simpler standards and open tooling won out, not just because it was simpler, but because there wasn't someone chiefly in charge of the spec essentially making the tooling an enterprise sales funnel. A shame.
cassonmars··on Road to ZK Implementation: Nethermind Client's Path to Proofs
There's different proof constructions, but many are depending on recursive SNARKs. You basically have an execution harness prover (proves that the block of VM instructions and inputs were correct in producing the output), and then a folding circuit prover (that proves the execution harness behaved correctly), recursively folding over the outer circuit to a smaller size. In Ethereum world, a lot of the SNARKs use a trusted setup — the assumption is that for as long as one contributor to the ceremony was honest (and that there wasn't a flaw in the ceremony itself), then the trusted setup can be trusted. The outsized benefit of the trusted setup approach is that it allows you to shift the computational hardness assumption over to the statistical improbability of being able to forge proof outputs for desired inputs. This of course, assumes that the trusted setup was safe, and that quantum computers aren't able to break dlog any time soon
Page 1 of 6Next →