627 karma · joined April 6, 2021
https://www.historyofinformation.com/detail.php?id=3439
"For this invention will produce forgetfulness in the minds of those who learn to use it, because they will not practice their memory. Their trust in writing, produced by external characters which are no part of themselves, will discourage the use of their own memory within them. You have invented an elixir not of memory, but of reminding; and you offer your pupils the appearance of wisdom, not true wisdom, for they will read many things without instruction and will therefore seem [275b] to know many things, when they are for the most part ignorant and hard to get along with, since they are not wise, but only appear wise."
Seems insane to me to think kids should be at burns.
A good number of the proposals (in particular, the proposals that actually got close to being chosen), are based on lattice constructions.
NTRU's underlying construction has been available to scrutinize for 30 years, whereas the Module-LWE proposals (Kyber being one) has had 11 years. Keep in mind, the largest employer (and under very tight classified controls) of number theorists _is_ the NSA. In terms of overall intellectual power, if there _is_ a problem in the MLWE constructions, they'd very likely be the first to find it, all while not saying a single word. Then, despite clear objections laid out by people with explicit expertise on the distinctions between RLWE and MLWE, especially w/r/t parameter choice, Kyber, under weaker parameters, was chosen anyway.
We can't rely on the obvious tells anymore – they've already played that hand (EC-DRBG) and were caught. If a bad standard is being pushed, it has to be done in a way that is so subtle, that it literally comes up to, "yeah, maybe this is weaker, but we haven't found a way to prove that". DJB already lost the selection process, so now the goal is to at the very least, avoid recommendations that push an unshielded, far less historically tested option, with no helpful antidote if it were to be broken.
I get that generally assuming conspiracies is a bad starting place for debate (after all, how do you disprove a hypothesis that is expected to be so surreptitiously constructed that it evades all ability to be scrutinized?), and I'd similarly think this is an unreasonable assumption, except for the fact _it has already happened and been exposed, multiple times_.
I am. I literally hold six patents around secure key generation and management. I stand by DJB's points.
/s
Tough to do when those who write the laws are a part of the problem. What do you suggest to make this so?
UHC requires the removal of politicians from qualified input, and this country's politicians love nothing more than to get overly involved in things they know nothing about.
Why do you feel differently?
and when played out of order, it's guaranteed to resolve to foobaz eventually or immediately, depending on when messages are received
when you encounter the scenario of a fork, there's usually a fork resolution rule, e.g. D: { "prev_hash": "<hash of B>", "content": "foobazbar" }
to resolve C vs D, sort lexicographically, choose direction of sort order and pick first
When you have non-continuous data due to messages dropping, e.g. you have B and perhaps an E that builds on C, you can either use the same lexicographic rule, or make the hash basis a combination of timestamp and hash, so you get temporality and lineage.
As for deletes, you have either the single set approach of simply making the message content empty and that _is_ the delete, or you have the 2-phase sets, where there exists an add set and a delete set.
Quite a few ways to approach it, but commutativity can be readily preserved.
That is insanely irresponsible and genuinely concerning. I don't care if they have a magical ring that defies all laws of physics and assuredly prevents any adversary stealing the backdoor. If an organization is implementing _ANY_ backdoor, they are an adversary from a security perspective and their guidance should be treated as such.
PFS in an open, freely-associable environment is far more complicated when you move beyond even the smallest of group sizes. Realistically, once the group size is beyond Dunbar's number you can reasonably assume that PFS is moot, because you no longer can depend on maybe four or five people's personal security, but 150+. Statistically, someone's opsec failure will be guaranteed.