HNHacker News
TopNewBestAskShowJobs

jameswryan

26 karma · joined May 6, 2022

submissionscomments
jameswryan··on A quick post on Chen's algorithm
Rainbow is not a KEM, but a signature scheme.
jameswryan··on Actual Uses for Near-Term Quantum Computers
> ... destroying Internet security seems like a dubious reason to build a new machine.

I can't agree with this; Destroying internet security is an excellent reason to build a new machine.

jameswryan··on Random Number Generator Recommendations for Applications
/dev/random does not block when 'out of entropy'. 'Running out of entropy' isn't something that can happen, and /dev/random will only block if the RNG hasn't been initialized (short enough after boot to not matter).

See Jason Donenfeld's authoritative talk on the Linux RNG for details: https://youtu.be/-_yzaSp2xtY

jameswryan··on Cryptographic Best Practices
The Discrete Log Problem is relatively simple to explain in the context of a generic group. It's sort of intuitive that elliptic curve groups are a pretty good instance of a generic group. So I don't think it is simpler to explain the security of RSA than the security of ECC.

Additionally, the best attack on ECDLP (Pollard's rho) is much easier to understand than the best attack on RSA (the number field sieve).

jameswryan··on FBI is warning people against using public phone-charging stations
That isn't sufficient to protect you on a charger you don't control: https://www.usenix.org/conference/usenixsecurity21/presentat...
jameswryan··on ELF hash function may overflow
For the cryptography & theory? https://toc.cryptobook.us/

For the design and internals of hash functions? The finalists for the SHA3 competition have extensive design documentation. There's an archive at https://web.archive.org/web/20170829225940/http://csrc.nist....

Cryptographic hash functions are designed to resist existing attacks, so you'll want an understanding of differential & linear cryptanalysis, as well as a variety of algebraic attacks. I don't know of a good textbook on the subject, so you might find yourself searching keywords on https://eprint.iacr.org/

jameswryan··on Will Carbon Replace C++?
> And C++ just... doesn't have that many real problems.

70% of security bugs are memory safety issues. That's a lot of real problems.

> It has a lot of irks, but the problems people run into are problems that others already solved, a thousand times, over the last half century, in many different ways for many different iterations of the language.

People run into memory safety issues more often in new C++ code.

https://www.chromium.org/Home/chromium-security/memory-safet...

https://security.googleblog.com/2021/09/an-update-on-memory-...

https://github.com/microsoft/MSRC-Security-Research/blob/mas...

https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI...

https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20pre...

https://advocacy.consumerreports.org/research/report-future-...

https://alexgaynor.net/2020/may/27/science-on-memory-unsafet...

https://github.com/google/sanitizers/blob/master/hwaddress-s...

https://security.googleblog.com/2022/12/memory-safe-language...

jameswryan··on NIST selects ‘lightweight cryptography’ algorithms to protect small devices
Joan Daemen even lost twice in one competition! Subterranean 2.0, another Duplex, didn't make it past round 2.
jameswryan··on Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
There is as of Git 2.34 [0][1].

[0] https://github.blog/2021-11-15-highlights-from-git-2-34/#tid... [1] https://git-scm.com/docs/git-config#Documentation/git-config...