HNHacker News
TopNewBestAskShowJobs

cendyne

333 karma · joined June 13, 2021

I sometimes write about cryptography cendyne.dev
submissionscomments
cendyne··on Ask HN: (How much) do you get paid for being on call?
I get half a day of vacation per week of oncall. It is awarded months after the fact due to manual spreadsheet tracking and HR processes.

That vacation is not eligible for pay out if I resigned.

cendyne··on Ask HN: Could you share your personal blog here?
https://cendyne.dev/posts/

Usually one article a month. The content is driven for what I feel strongly about in the moment, be it cryptography or managing teams to tech-social issues.

cendyne··on Chrome still hasn't changed its opinion about dropping JPEG XL support
Looking forward to when edge services like Cloudflare, Cloudimage, imgix, etc. support JXL too. AVIF has such a harsh encoding time. It is also a bit too bulky in wasm on the edge to encode yourself too.
cendyne··on Encrypting Data in the Browser Using WebAuthn
For those wondering: the local threat here is a malicious extension can modify the function of navigator.credentials.

While not malicious, this has been shown to be possible by 1Password. See https://www.future.1password.com/passkeys/ and I have confirmed it is possible to modify this function.

JavaScript can be monkey patched, in some ways this is great for polyfills. For other cases this can be a threat.

If browsers had an explicit mechanism to register extension provided Authenticators and locked down a way to modify the original navigator credentials interface, then we may be able to protect the "first" bytes that come back from the authenticator to the application.

cendyne··on What We Do in the /etc/shadow – Cryptography with Passwords
Thank you for these resources!
cendyne··on What We Do in the /etc/shadow – Cryptography with Passwords
The "augmented" label confused me a lot too. I saw Steve Thomas's presentation in person at DEF CON and could not find material online using that phrase outside of his materials.
cendyne··on Israel deploys remote-controlled robotic guns
An anime called Psycho-Pass comments on this. A system existed to replace the remote view with a cartoonish environment with chicken characters so the operators would not receive psychological harm from operating a violet instrument.
cendyne··on Microsoft Office 365 Message Encryption Insecure Mode of Operation
I love the adaptation for the season. ECB in halloween candy! The horror!

https://twitter.com/FiloSottile/status/1578783337442938882

cendyne··on Ask HN: Have you experienced “hiring fraud?”
I have been personally emailed to participate in an interview under another candidates name. It set off so many alarms for me. I did not respond.

Here’s what I was sent.

> Hope you're doing well.

> We're a tightly-knit team of full-stack developers and we need someone who can help us with client communications. Most of our developers are not native English speakers and we often face communication issues. That's why we need someone who's based in the U.S and has technical background.

> The main responsibility will be taking job interviews on our behalf. You should be able to join the meetings under someone else's name.

> This is an hourly engagement and the rate is $40 ~ $80 / hr depending on your experience.

> Please kindly reply to this email if you're interested.

cendyne··on MIT Engineers Create New Material Stronger Than Steel and Light as Plastic
I wonder what kind of efficiencies can be gained by swapping out metal for this in EV vehicles
cendyne··on A Base64 Surprise
Your example [1] on twitter for PHP is actually quite telling.

I do not think it is well known among application developers, which is why I wrote this post. In fact, my base64 implementation elsewhere is vulnerable to this and it never occurred to me.

Thank you for the rust library recommendation, I was using base64ct.

[1]: https://archive.is/RZwlH

cendyne··on A Base64 Surprise
Hey thanks!
cendyne··on Tell HN: Google returning 'Untitled' results that redirect to malware/spam
This happens to me when I research some RFC concepts surrounding oauth, saml, and the like. It’s incredibly frustrating.
← PreviousPage 2 of 2