HNHacker News
TopNewBestAskShowJobs

doomrobo

2,242 karma · joined October 17, 2012

Recent PhD in cryptography from the University of Maryland

Website: https://mrosenberg.pub Github: https://github.com/rozbb Keybase: https://keybase.io/mrosenberg Email: michael (@) mrosenberg (.) pub

[ my public key: https://keybase.io/mrosenberg; my proof: https://keybase.io/mrosenberg/sigs/dR6U3ijr9MYZyBe0ueW6L90pU8Adb817jaeWietnOH4 ]

submissionscomments
doomrobo··on Show HN: Super fast/cheap text-to-speech API
How is this cheaper than Google TTS? Google's standard voices are $4 per million characters. And the deep learning ones are $16 per million characters, same as this offering. Plus Google gives you the first 1M free every month.

https://cloud.google.com/text-to-speech/pricing

doomrobo··on Le Sphinx – Pocket cipher device (1930)
A more secure, more discreet, and also much slower pocket encryption device is a deck of cards

https://en.wikipedia.org/wiki/Solitaire_(cipher)

doomrobo··on Proofs based on diagonalization help reveal the limits of algorithms
It turns out that these are all kind of the same, the Liar's Paradox, Russell's Paradox, the Halting Problem, etc. And indeed the they rely on a "diagonal map" i.e., a map x -> (x, x) in the construction.

This was a great read, if you want a mathematical take on it, and some generalization too. https://arxiv.org/abs/math/0305282v1

doomrobo··on Prepare for the Textpocalypse
https://archive.is/7APty
doomrobo··on A chiral aperiodic monotile
Out of curiosity, could you share the exciting unproven theorems in topology you referred to?
doomrobo··on Tell HN: Suspicious pricing for text-to-speech on AWS/Google Cloud
> Costs have decreased for 2018 tech, but not for 2023 tech

WaveNet is 2018 tech though. I'm curious why that hasn't gotten cheaper.

doomrobo··on Why woodpeckers can hammer without getting headaches (2022)
This explanation is apparently controversial

https://www.science.org/content/article/contrary-popular-bel...

doomrobo··on Massive geothermal apartment complex is going up in Brooklyn, first of its kind
I've only heard of ground loops being used for when heat pumps have to operate in absolutely frigid temps (like < -20F). What's the efficiency improvement over using ambient air? NYC doesn't get too far below freezing, even in the dead of winter, and I hear modern refrigerants are pretty dang good.
doomrobo··on Show HN: TxtNet Browser – Browse the Web over SMS, No Wi-Fi/Mobile Data Needed
Nice! One small thing I noticed: it looks like you don't have compression turned up all the way. You might be able to save a lot of bandwidth if you use the most aggressive brotli settings for everything that's sent over SMS
doomrobo··on On Eliezer Yudkowsky's Time op-ed
> If you don't want an AI system copying its weights all over the place hash the weights out of band, compute a hash on any outbound network traffic, and then shut it off if any of those hashes show up

> Afaik nobody is doing this right now, easy win, no Predator drones required

What? This doesn't work for like 3 reasons. I'm not standing up for Yudkowsky here, but this response isn't very good.

doomrobo··on Data Brokers Are a Threat to Democracy
I'm relying on this (admittedly pithy) explanation https://www.youtube.com/watch?v=d-7o9xYp7eE
doomrobo··on Data Brokers Are a Threat to Democracy
I don’t see this as contradictory. It’s the same reasons it’s a bad idea to talk to cops: it can’t help you, it can hurt you, you might say something false, they might mishear you
doomrobo··on Medieval Arabic surgeon Ibn al Quff's account on surgical pain relief
Entirely off-topic, but I immediately noticed that the website uses Fira Sans for all the text. I appreciate open-access journals using open-source fonts.
doomrobo··on Why does the all 0 public key have a known private key in SR25519 and ED25519?
This is a great question. To rephrase: is it possible to come up with an RSA modulus that even you don't know the factorization of?

The answer, I believe, is we have no way of doing that so far. The closest thing that exists is "multiparty" or "distributed" generation of an RSA modulus. Roughly, in the two party case of Alice and Bob, this means Alice picks some pair of numbers (P1, Q1) and Bob similarly picks some (P2, Q2). Then, Alice and Bob engage in some secure multiparty computation protocol whereby they obliviously a) check P1+P2 and Q1+Q2 are prime, and b) if so, output N=(P1+P2)(Q1+Q2) to both Alice and Bob.

At the end of the protocol (after repeating enough times that it succeeds), both parties have derived an N whose factorization they don't know.

I don't know much about this area of study, but searching multiparty RSA modulus generation should bring up relevant papers.

doomrobo··on Why does the all 0 public key have a known private key in SR25519 and ED25519?
Another use is for password authenticated key exchange. The CPace protocol picks its generator using a hash to group operation. See page 13 of https://eprint.iacr.org/2018/286
doomrobo··on Amazon is closing its cashierless stores in NYC, San Francisco and Seattle
Likely relevant, NYC passed a law 3 years ago requiring stores to accept cash

https://www.nytimes.com/2020/01/23/nyregion/nyc-cashless-ban...

doomrobo··on Encryption Lava Lamps (2017)
To answer the questions in this thread: having a preshared key (PSK) doesn't save you. The problem remains replay attacks: even if you have a PSK, if you don't have a fresh session, then an adversary can replay old messages back to you.

The only solution to the replay problem is to have the poor-entropy machine keep a strikelist of all the messages (or hashes thereof) it has ever received from the entropy service. Thus, when receiving a new message, it can make sure it's not a replay. Of course, this means that you've turned a stateless protocol into a stateful one, and require non-volatile storage on the device for a potentially long period of time.

As far as I know, nobody actually does this.

doomrobo··on Encryption Lava Lamps (2017)
(not an original though, but repeating here)

Thought experiment: Suppose you had a computer that didn't have a good entropy source. You need this computer to have good entropy because it needs to connect to some service, and the connection needs to be cryptographically secured and resilient to replay attacks (ie attacks where an adversary, not necessarily the service, sends an old message in response to a fresh request). Suppose further that you had a separate service that exposes a camera feed of some lava lamps—perfect for fixing your entropy problem. How do you suppose you will connect to that camera feed?

doomrobo··on Planting Undetectable Backdoors in Machine Learning Models
Preprint: https://arxiv.org/abs/2204.06974
doomrobo··on Wikipedia 'intentionally' distorts history of the Holocaust, study claims
The journal article referenced: https://www.tandfonline.com/doi/full/10.1080/25785648.2023.2...
doomrobo··on Reimplementing the Coreutils in a modern language (Rust)
Can confirm. My shred implementation is in there and I was very new to Rust at the time of writing
doomrobo··on The Rust Implementation of GNU Coreutils Is Becoming Remarkably Robust
It had some CVEs but not many [0]. I think the better argument is that some of the original code is just really hard to read. Click around the repo [1]

[0] https://www.cvedetails.com/vulnerability-list.php?vendor_id=...

[1] https://github.com/coreutils/coreutils/

doomrobo··on Skelet #34 Is Infinite
What is <C and <B?
doomrobo··on Setting the bozo bit on Apple
Yes, it's Apple's bug reporting system

https://openradar.appspot.com

doomrobo··on Why Google and Apple work to snuff out the mobile web
Personal experience as a web dev: the mobile Safari PWA experience (and even regular browser experience) is terrible. The browser is riddled with bugs and lacks support for features that have been around for a while. I apologzie for not having examples bc it was a few months ago that I was struggling with this, but hopefully someone else can fill some in. I honestly believe Apple's stranglehold on the mobile browsing experience has been one of the most disempowering things to mobile users in the last decade.
doomrobo··on GCC now includes Modula-2 and Rust. Do they work on OpenBSD?
My guess is println! wasn't defined because the std crate isn't supported for the OpenBSD target yet
doomrobo··on EABitTricks.h
Take a 64 bit number and treat it like a bit field where each bit represents inclusion/exclusion of an element in a set S of size 64. Thus every number with M 1s represents a (distinct) M-sized subset of S
doomrobo··on “Eeny, meeny, miny, mo” and the ambiguous history of counting-out rhymes (2015)
Yup! It's called ablaut. English has ablaut reduplication for children's words like kitty-cat or sing-song
doomrobo··on Alameda took 1B hit in mobileCoin trade to prop up FTX
Agreed. But I think you mean Lenny from Of Mice and Men
doomrobo··on Why We're Suing NSO Group
What? NSO dealt arms to the Saudi government and similarly authoritarian regimes.
← PreviousPage 2 of 16Next →