HNHacker News
TopNewBestAskShowJobs

hnolable

247 karma · joined August 16, 2012

submissionscomments
hnolable··on Ask HN: What do you want to see in Ubuntu 17.10?
MORE RUST PLEASE! :D
hnolable··on The True Cost of Bitcoin Transactions
The part you're missing is that Bitcoin is totally fine if it never changed from how it is today. Anonymity will come via Tumblebit. Lightning network can already work even without segwit.

Segwit never getting activated may even be a good thing. It will show everyone that Bitcoin has crystalized and can never be changed via petty human emotion. This was always Bitcoin's true selling point and we may be about to demonstrate it.

So yes, politics can and will be ignored.

hnolable··on The True Cost of Bitcoin Transactions
https://bitcoincore.org/en/2016/01/26/segwit-benefits/#block...
hnolable··on The True Cost of Bitcoin Transactions
Yes that's the issue here, the miners are playing politics by trying to flex their power. But no one is willing to play petty games. There's an obvious win for everyone sitting on the table ready to go. Political games will be ignored.
hnolable··on The True Cost of Bitcoin Transactions
You admitted that "The whole reason people want bigger blocks is for higher transaction throughput on-chain."

And said that "Segwit doesn't deliver that".

Segwit delivers that.

hnolable··on The True Cost of Bitcoin Transactions
You can play semantical games but segwit gives about 2x onchain capacity. And the only thing holding it up is a group of chinese miners/pools. Anyone truly wanting more onchain capacity should be engaging those miners/pools.

Of course that's not really what people bitching about tx fees want.

hnolable··on The True Cost of Bitcoin Transactions
Segwit requires 95% of miners to activate. Currently about 75% of hash power is controlled by a group of chinese miners/pools. This is about the % of hashing power that is missing for Segwit to activate.
hnolable··on The True Cost of Bitcoin Transactions
If Eric was serious about this he would have targeted this post at chinese miners who are stalling on activating segwit (which is a 2x blocksize increase and the foundation for instant & nearly free txs via the Lightning Network).
hnolable··on Tesla Announces $500M Common Stock Offering
Shares are valued by people based on three things. Future direct cash you receive from the company based on the shares you hold (e.g. dividends/distributions and share buybacks). Voting power (i.e. control) in the company based on the shares you hold. And finally the ability to sell the shares you hold on the open market in the future (i.e. price speculation). Issuing more shares (usually) directly affects (i.e. dilutes) #1 and #2. But #3 is not directly affected in any way.
hnolable··on NSA in P/poly: The Power of Precomputation
OTR anyone?

https://news.ycombinator.com/item?id=7252159

hnolable··on Harvard supercomputing cluster hijacked to mine Dogecoin
Ripple's consensus algorithm pretty much has this licked.

https://ripple.com/wiki/Consensus - http://bitcoin.stackexchange.com/questions/10180/what-are-th... - http://bitcoin.stackexchange.com/questions/13330/what-is-the...

hnolable··on Off-the-Record Messaging Protocol v3
Yes I get that, I think there is a new DH for almost every message, much better than TLS. The problem is we have no idea what the NSAs abilities are in terms of actual cryptanalysis/cracking, but we do know that they have an immense desire for it.

RFC 3526 puts the low end of the 1536 bit group's strength at 90 bits. If some unknown weakness was found that lowers that significantly that doesn't leave things very safe.

Agreed that curves would be ideal.

hnolable··on Off-the-Record Messaging Protocol v3
I believe the weakest link in OTR is its Diffie-Helman key exchange. If you break that you get the symmetric key and can decrypt everything passively. OTR has been using a 1536 bit modulus for its Diffie-Helman exchange since 2004 [1] (The weakest one from RFC 3526 [2]). Seems they are still using the same one today.

In 2004 this was probably a fine choice, especially considering the tradeoff between CPU processing (usability) and security. But considering the NSA scandal, specifically them recording all encrypted communications forever, and Bruce Schneier increasing his key lengths [3], and the ability for CPUs to process higher keylengths without any noticeable slowdown, I don't feel confident it is strong enough today.

Other than this gripe OTR is amazing and everyone should be using it.

Edit: xnyhps's post [4] concludes that only a single "cracking" of the 1536 bit group would need to occur to then decrypt any past or future OTR conversation "instantly".

[1] https://web.archive.org/web/20041215062523/http://www.cypher... [2] http://www.ietf.org/rfc/rfc3526.txt [3] https://news.ycombinator.com/item?id=6376954 [4] https://blog.thijsalkema.de/blog/2014/01/17/misconceptions-a...

hnolable··on Ethereum: A Turing-Complete Cryptocurrency
Fair enough, although their technology can be appreciated separately from the pre-mine. Anyone can fork it and do a purely mined version.
hnolable··on Ethereum: A Turing-Complete Cryptocurrency
Ripple is also working on the same thing and is supposedly releasing them "soon": https://ripple.com/wiki/Contracts
hnolable··on Bitcoin Network Speed Breaks 1 Petahash per Second
If you're interested in a Bitcoin like currency without mining check out Ripple.
hnolable··on Proposal to Change the Default TLS Ciphersuites Offered by Browsers
All the supported curves in TLS are most likely influenced by the US government (NIST, ANSI, and SECG). So we don't really have an option to use curves with a non-US provenance.

http://tools.ietf.org/html/rfc4492#appendix-A or list all openssl curves: $ openssl ecparam -list_curves

hnolable··on Proposal to Change the Default TLS Ciphersuites Offered by Browsers
No, the DHE/ECDHE (ephemeral key exchanges) don't protect against MITM, it protects against passive dragnet decryption. But the RSA/ECDSA/DSS part (certificate signing) does. All TLS ciphersuites include certificate signing to protect against MITM, but not all include ephemeral key exchange.
hnolable··on Proposal to Change the Default TLS Ciphersuites Offered by Browsers
TLS_RSA_WITH_AES_256_CBC_SHA256 is not forward secret (if you have the certificate private key you can passively decrypt all past/future sessions) so removing it is a great idea. I'm only responding to what you said and not making a judgement about the rest of the guy's suggestions.
hnolable··on Critical Vulnerability in Cryptocat
Does anyone know if there are any issues with the javascript OTR library they use (https://github.com/arlolra/otr)? Or are all the issues only with their custom multi party chat encryption system?
hnolable··on DecryptoCat
Does anyone know if there are any issues with the javascript OTR library they use (https://github.com/arlolra/otr)? Or are all the issues only with their custom multi party chat encryption system?
hnolable··on LinkedIn suffers DNS hijack
My understanding is app.net is trying to be a paid version of twitter. There was/is much debate whether it could ever take off. This is the first time I've ever seen someone link to it. Although now I realize that the link is to the app.net cofounder so that doesn't really say much.
hnolable··on LinkedIn suffers DNS hijack
I guess they didn't mark their cookies as 'Secure'. Oh well, the real story here is an app.net link at #1 on HN.
hnolable··on Make DuckDuckGo your Chrome default search engine
Just use Google through a VPN you trust. Same threat model, better results.
hnolable··on Someday, you may use bitcoin without knowing it
Here's something to ponder... Sure once in a while your bank/CC payment system protects you from a shady merchant... saving you what... 100$ (max?). Personally in my entire life I can't remember charging back once due to a shady merchant but let's assume you've saved 1000$ because of chargebacks.

Here's one of the risks you have to bear to enable your chargebacks: http://mashable.com/2011/01/28/identity-theft-infographic/ ... worth it? Think how many insecure databases your name and address and credit card # (and sometimes phone number) are stored in across the net...

hnolable··on Someday, you may use bitcoin without knowing it
Totally agree with you on that. But let's compare your trust of your bank vs your trust of your mattress or your safe or your brain password that no one but you can produce.
hnolable··on Google Checkout will be retired, transition to Google Wallet
Wow, so it _is_ true, that's the confirmation I was looking for. Really hard to believe. I knew if they did shut them off they would point to the fact it's still "beta". The subscription feature has been labeled beta since it was released in March 2009. This is sick.
hnolable··on Google Checkout will be retired, transition to Google Wallet
That sentence is confusing at best. "If you don't have your own payment processing" What does that mean? I thought Google Checkout was my payment processor? Do they mean if you already have a payment processor other than Google?

And if I _do_ have my own payment processing then I won't need to "transition to a different solution within six months". What does that mean, are they going to give me all the subscribers credit card info so I can start charging their cards myself? I don't think so.

As far as I know Braintree only does direct credit card processing, similar to Stripe. If they are planning on migrating all the Google Checkout subscriptions to Braintree credit card subscriptions that would be great but it doesn't sound like that to me. And how would that work for the Google Checkout users who were able to manage their subscriptions through the Google Checkout interface? Does Braintree have an interface for all Google Checkout users or do they lose their interface and need to go through the merchant now?

hnolable··on Google Checkout will be retired, transition to Google Wallet
Anyone have any idea if this effectively terminates any existing recurring Google Checkout subscription payments (on November 20)? If so, that's kind of a big deal. Cutting off merchants from their revenue stream is a great way to get people really angry and could easily destroy a business.
hnolable··on Are Bitcoins The Future?
NSA, China, Russia, most governments really, and possibly a lot of banks, could do a 51% attack and shut down transaction processing... or do double spends, but shutting down all transaction processing seems more damaging. This won't ever change, unless Bitcoin really causes governments to lose most of their power and money.

Edit: gavin has a plan (http://gavintech.blogspot.com/2012/05/neutralizing-51-attack...) but my guess is if they did the work to start an attack in the first place they'd have planned for gavin's plan and acquired enough older coins to foil it. It'd be nice if more thought went into other ways to thwart a possible attack but I'm not sure there really are any. Most people seem to discount and completely avoid the issue.

Page 1 of 3Next →