HNHacker News
TopNewBestAskShowJobs

epimenov

88 karma · joined July 12, 2011

submissionscomments
epimenov··on Official Mastodon server of the Dutch government
It makes sense really. About a week ago there was “code red” storm in the Netherlands, and first phone alarm contained something along the lines of “for more details see this Twitter account”.

Then they removed any mention of twitter from from the second message.

epimenov··on App-Only Banks Rise in Europe and Aim at Traditional Lenders
All business bank accounts in the NL include those transaction fees. Consumer ones (as in Premium in bunq) do not.
epimenov··on Anger Over Tourists Swarming Vacation Hot Spots Sparks Global Backlash
They do allow "stopovers". Where you can stay in Iceland for few days between the flights. Those are heavily marketed during the flight too.
epimenov··on Uber’s Self-Driving Cars Were Struggling Before Arizona Crash
Funnily enough Romania is on top of the pedestrian fatalities statistics within the EU: http://ec.europa.eu/eurostat/statistics-explained/index.php/...

Maybe you should reconsider the law.

epimenov··on Show HN: Moocha.io – A search engine for MOOCs
or https://www.moocha.io/search?query=basket+weaving
epimenov··on NeverSSL
I think OS X opens captive.apple.com
epimenov··on The Dropbox hack is real
They're actually talking about 2FA for 1password itself. Not supporting TOTP via 1password for other services.
epimenov··on The Dropbox hack is real
1Password can do 2FA, also syncs between all your devices. And no trusted 3rd party cloud service.
epimenov··on WhatsApp's Signal Protocol integration is now complete
The whitepaper (https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...) claims that the attachments of any type are encrypted
epimenov··on SSH tunnelling for fun and profit: AutoSSH
Same here actually, the user has /bin/false as shell.
epimenov··on SSH tunnelling for fun and profit: AutoSSH
I have a key generated for AutoSSH only.

Also you can limit to which hosts/ports it can connect with:

     no-agent-forwarding,no-X11-forwarding,command="read a; exit",permitopen="host:port" ssh-ed25519 AAAA
Pretty nifty.
epimenov··on Alan Rickman, Harry Potter and Die Hard Actor, Dies Aged 69
http://www.tylervigen.com/spurious-correlations
epimenov··on YouTube change served lower-quality video to Firefox 43 for 2 weeks
They said in the ticket that the issue does NOT affect the majority of Firefox users. It was just a calculation of the impact, and they decided not to release a hotfix. I'm pretty sure if it was affecting all firefox users it would be fixed in a matter of hours too.
epimenov··on Data Privacy Protection: Why Tutanota Is in Germany
I guess this is relevant: https://twitter.com/evacide/status/679117565411610625
epimenov··on Entering Public Beta
People are working on bringing ChaCha20-Poly1305 to TLS for this.

https://datatracker.ietf.org/doc/draft-ietf-tls-chacha20-pol...

https://blog.cloudflare.com/do-the-chacha-better-mobile-perf...

epimenov··on Please Stop Writing Secure Messaging Tools
There was a TOR talk where a person from China told that he recommended two systems to different people: TOR and some other one. The people he recommended the other one ended up in prison.

This kind of consequences you get when you falsely claim security. This is the main reason I want people stop saying that Telegram is somehow secure. It's just another messenger, people who need security should use something else. There must be no confusion about it.

epimenov··on Please Stop Writing Secure Messaging Tools
OTR is.

As far as I know there's been one whitepaper on TextSecure itself (https://eprint.iacr.org/2014/904.pdf).

epimenov··on Please Stop Writing Secure Messaging Tools
>Absolutely dangerous thinking is to declare cryptography off limits. With that in mind eventually you just scare more people to participate in this process and eventually be left with a tiny core community.

Anybody can participate, just don't claim it's secure.

> Sure, that's exactly how SSL works. We invented crypto systems and we are using them until they are broken, then we phase them out for something else.

The only difference is there's a maillist with actual cryptographers (https://www.ietf.org/mail-archive/web/tls/current/threads.ht...), that iterate over design. If you look at the history of TLS, you'll see how tricky is to get crypto right. There has been lots of attacks on the protocol, that no one person could've think of. You don't have that if you roll your own and/or have "very good reasons" when people point your mistakes out.

epimenov··on Please Stop Writing Secure Messaging Tools
This is absolutely dangerous thinking. There are a lot of people researching crypto and making sure it's secure. If you're using non-standard crypto, you don't have that safety net.

They're using primitives that are proven to be insecure against certain types of attacks (non-checked DH, MAC-then-encrypt, etc). And their code seems to be not perfect (https://twitter.com/matthew_d_green/status/58291636575066931...).

Signal on the other hand uses a variant of OTR (https://whispersystems.org/blog/advanced-ratcheting/). Which was thoroughly reviewed, and mentioned in NSA documents as not-cracked.

You can't just invent something and claim "last time I checked it's not broken". It's not broken (yet) if enough competent eyes looked at it, and the more standard building blocks you use, the easier to make those claims. That is absolutely not what Telegram does. I really wish the myth that Telegram is secure would die.

epimenov··on Please Stop Writing Secure Messaging Tools
I think it means that push notifications are delivered via google cloud platform
epimenov··on Telegram bans public ISIS channels
Basically they're not following cryptographic best practices. And their defense of it is flimsy at best.

I you want easy-to-use secure messenger you should use Signal. (https://whispersystems.org/)

epimenov··on How is NSA breaking so much crypto?
Validating EC is even harder. Accepting arbitrary curves is a bad practice. The draft of TLS 1.3 uses named curves and named primes for both DH and ECDH. And it starts with 2048 bits, because the possibility of NSA cracking 1024 primes was mentioned in the logjam paper.

See https://tools.ietf.org/html/draft-ietf-tls-tls13-09#page-49

epimenov··on A tale of software maintenance: OpenSSL and EVP_CHECK_DES_KEY

  /  sw_vers 
  ProductName:	Mac OS X
  ProductVersion:	10.11
  BuildVersion:	15A282a
  /  /usr/bin/ssh -V
  OpenSSH_6.9p1, LibreSSL 2.1.7
I guess it is ready for production
epimenov··on Important Notice Regarding Public Availability of Stable Patches
Also https://twitter.com/grsecurity/status/450995354972864513
epimenov··on Three Tales of Second System Syndrome
MySQL also started version 6.0 and then stopped developing it. They also tried to fix the unicode support (utf8mb4 by default).
epimenov··on Show HN: A simple “stateless” password manager for Chrome
and the best part is you can't change your password in case some website becomes compromised and the hash is leaked. (without changing the secret key and as the result changing all passwords on all websites).
epimenov··on Topo – A library to create in-process topologies of goroutines
You're using one input source in the example. I think the main issue that it promotes bad usage pattern.
epimenov··on Topo – A library to create in-process topologies of goroutines
I think you misunderstood the blog post and go channels. Shuffle is absolutely not want you want to use (in the README example). Sending to a channel blocks until the message is accepted by the receiver (unless you're using buffered channel).

What you want to do instead, create 1 channel, and make multiple goroutines (Sinks) read from it, then whenever goroutine is finished with the task it would take a new message from that channel.

By picking a channel to dispatch yourself you don't take into account busy-ness of it, so you might wait on a channel even though there are others that are idling waiting for messages to be accepted.

epimenov··on Wikileaks releases copies of FinFisher surveillance software
That's not true. What people do is take a zip file and then append files to the end till you get desired md5. It would behave like a zip file.

See http://www.mscs.dal.ca/~selinger/md5collision/

epimenov··on Bloodhound – Elasticsearch client and DSL for Haskell
As far as I know bool filters are preferred over and/or filters (see http://www.elasticsearch.org/blog/all-about-elasticsearch-fi...)

Seminearring and Monoid Filter could encourage usage of the bool filters, instead of and/or.

Thank you otherwise, I was longing for something similar when I was editing JSON queries. Going to try that the next time I have to do some ES work.

Page 1 of 2Next →