HNHacker News
TopNewBestAskShowJobs

h0cked

43 karma · joined December 1, 2013

submissionscomments
h0cked··on Goodbye Academia
If your goal is just to producing quality papers, this is perfectly great. If your research involves systems and implementations, it sucks to have to write every bits of code yourself. I don't think CS research is just about theory, at least not the line of research I am doing, I am all about making it readily available to others to use.
h0cked··on How to write a great research paper [pdf]
I think he literally meant the CVS given the age of Simon... lol
h0cked··on How I published a fake paper, and why it is the fault of our education system
I don't, but I do review papers for people that I don't know if they have a good reputation.
h0cked··on How I published a fake paper, and why it is the fault of our education system
Well, I do agree that students can have different quality, and we shouldn't discriminate Indian students. But the problem is that enough Indian students have made bad reputation for all Indian students here (U.S), and to avoid future loss (time and effort of the faculties), we just start to reject any Indian students (at least in my own circle).
h0cked··on How I published a fake paper, and why it is the fault of our education system
I used to think if it's IEEE or ACM, they are ok (not good) to publish. Nowadays, I am not so sure after seeing a bunch of low quality "international" conferences in Asian especially in India. ACM seems a little better than IEEE...

Now my rule is to only publish in conferences that I know or are well known in the field....

Aslo reject any requests to serve as a TPC or reviewer for conferences from this region..The papers are normally low quality and waste of my time to read...

h0cked··on Don't Support Information Architects
That's what I am doing for sure now.
h0cked··on Telegram protocol defeated. Authors are going to modify crypto-algorithm
well, if someone causes you significant lose, will you turn down a norch? That's why we are bashing on them as they are making BS claims about how secure their protocol is.
h0cked··on Crowdsourcing a More Secure Future
I actually have a theory that this is all a scam... the person who found the bug is actually the authors (or a friend) of the Telegram protocol. They published the security issue and reward themselves so that 1) they don't have to pay anyone else; 2) they get good publicity by doing this; 3) shut others up up front as this is really a very easy bug to figure out (a few others hinted the possibility as the key exchange is unautenticated DH, which is bound to flaws like this)
h0cked··on Crowdsourcing a More Secure Future
The same reason as why Google provide Gmail for free, 1) to get a huge user base (fame = money, in today's internet world; 2) get a hold of user data
h0cked··on Crowdsourcing a More Secure Future
Are you trolling or for real? 1) Telegram is NOT open soure. 2) OTR has been around for years.
h0cked··on Telegram protocol defeated. Authors are going to modify crypto-algorithm
Telegram's contest itself is meaningless regarding the security of its protocol (as others explained in details). Finding bugs such as this deserves 200k more than anything else
h0cked··on $200,000 to the first person to break Telegram
It's simple unauthenticated Diffie-Hellman key agreement, which is known for MITM attack. Yes, you ask A to accept B's identity upon key exchange, but to what extend A would know B is really B not the server playing along? A plausible method would have A and B exchange certificates separate from the Diffie-Hellman key exchange process, and use those as the identity verification mechanism.
h0cked··on $200,000 to the first person to break Telegram
unauthenticated Diffie-Hellman key agreement is known for MITM attack.
h0cked··on $200,000 to the first person to break Telegram
This is like putting messages encrypted with ANY encryption algorithm, and ask people to guess the key. This has nothing to do with whether the communication protocol is secure or not.
h0cked··on Telegram, a.k.a. “Stand back, we have Math PhDs”
The Math PhD who designed the should write the protocol up as a paper, submit to top conferences like CCS and S&P. And he will see how badly the reviewers will dump on his protocol.
h0cked··on Telegram, a.k.a. “Stand back, we have Math PhDs”
The comments from TFA doesn't say a shit but full of "you are wrong, because you don't understand it" without debating the technical details.
h0cked··on Telegram, a.k.a. “Stand back, we have Math PhDs”
I am with you. ACM Champions mean a shit to me, and I have enough publications in crypto and secure communication to claim that I am a ACM Champion, and BTW I have a PHD actually related to security and crypto. But, NONE of my credentials is a valid argument about how secure my protocols are.

This kind of attitude (trust us, we have enough credentials to show) seems to be a universal problem with people in academics. Come on, don't do this. We all get the sense that you have to bluff to get your paper published, but this is not going to work for a product to be accepted.

h0cked··on Stop Saying Bitcoin Transactions Aren’t Reversible
i am with you, i actually think the author coming from economics background who knows nothing about cryptography systems should just shut up before saying anything stupid in public...