HNHacker News
TopNewBestAskShowJobs

mahemm

168 karma · joined July 30, 2017

submissionscomments
mahemm··on AurionMail: E2EE suite (CryptPad/Stalwart) with single-password UX
I'm not sure this really hits E2EE. E2EE is a claim about who cannot read your mail, so the test is whether confidentiality survives a hostile operator. This model fails that test twice, and the choice of PGP decides how bad the second failure gets.

Take an operator that ships bad code first. The crypto runs in JavaScript that AurionMail serves on every page load, and nothing pins that bundle: no reproducible build, no signature the browser enforces, no way for a user to verify what ran. One build that posts the master passphrase to a host they control ends it. Password strength, the 5-minute TTL, and the non-extractable CryptoKey all stop mattering. Every guarantee in the document becomes a promise about operator behaviour, and E2EE exists to remove those promises. Signed reproducible clients fix this, or published bundle hashes in a transparency log. Their security model never mentions its own delivery channel.

Ignoring that/assuming an honest build pipeline--what does a breach, an insider, or a subpoena yields later. The server holds the wrapped OpenPGP private key, the 16-byte master salt (cross-device unlock needs it), and Argon2id(password, "auth_salt_${username}") from every login. That last value verifies the same password protecting the vault, so you can grind offline at Argon2id cost, derive the master key, unwrap the PGP key, and read the mail. auth_salt_${username} is public and known before any breach, so an attacker can precompute against a named target. A random per-user salt served at login removes that discount. Proton and Bitwarden share the general ceiling, so what follows is what makes this design worse.

In addition, PGP has no forward secrecy. Combine that with a server-side mail archive and a server-side copy of the long-term private key. One password recovery at any future point then decrypts the entire history in one pass. A long-term key is only as strong as the weakest security practice across its whole lifetime, and an attacker who eventually wins reads the full back catalogue. Remote backups of the long-term key are a pattern to avoid here, but AurionMail ships that backup as a sync feature. The document reasons carefully about a 5-minute TTL on a transport blob while the real exposure window is the account's entire lifetime, applied backwards.

Rotation makes it stickier. The same post argues that people keep keys they suspect are compromised because rotating costs too much. Here the master password derives both the PGP wrapping key and the CryptPad seed, so a password change orphans CryptPad documents, and replacing the PGP key means re-establishing it with every correspondent. Two coupled rotation costs, and the document specifies neither procedure.

Coverage is the other limit. PGP over SMTP leaves envelope recipients and timestamps in clear, and it only protects mail where the other party also runs PGP. Most folks see very few encrypted emails a year, and correspondents generally resend in plaintext given any excuse. The other end decides your coverage. The security model also never says how a user authenticates a correspondent's public key, and encrypting to an attacker's key defeats everything upstream of it. Web of trust does not close that gap in practice.

Two parts of the design are correct. The cross-origin handoff keeps the seed off the network, so the server holds ciphertext it cannot open, and burn-on-read with a short TTL layers sensibly on top. One Argon2id pass feeding domain-separated HKDF labels is standard, and separate salts for auth and for the master key keep the login hash from being the vault key.

From my POV, this is client-side encryption with a trusted operator, built on a key model that competent advocates were publicly abandoning ten years ago. That property is real and it beats server-side encryption, and it requires trusting their build pipeline, their hosting, and their users' passwords. "Zero-knowledge" claims none of that trust is needed, but their security model doesn't support this claim.

mahemm··on Can AI do novel security research? Meet the HTTP Terminator
I found this to be a really informative piece about how people at the forefront of their field (in this case, AppSec) can move themselves farther with LLMs, as well as the limits to be dealt with and handled in that process.
mahemm··on Trusted URLs via Cryptographic Signatures
How does this differ from e.g. S3 pre-signed URLs?
mahemm··on Obfuscation: Building the final boss of cryptography (Part I)
The tl;dr on why IO is important is you can just use (effectively) one program, but stuff different secrets inside them with a guarantee that no one can pull those secrets back out.

Cryptographers have proven that it's possible to use this as a primitive from which you can rebuild the rest of common cryptographic primitives (public encryption, symmetric encryption, etc). So--if it's possible to put this together it'll be a novel construction for every cryptographic primitive that also dodges some of the problems with key distribution and negotiation.

mahemm··on US posts another month of strong job gains in May
It's interesting to see such ongoing strong jobs data in the face of unprecedentedly negative sentiment[1]. Not only do the numbers fail to look as bad as the sentiment, the numbers are actually fantastic and (AFAICT) fully uncorrelated with sentiment.

I've been thinking that this is basically a result of people being overexposed to aspirational lifestyle marketing influencers--even though they're doing better than ever, they're more aware than ever that others are doing even massively better. Since it's influencer marketing, they're seeing people do better in specific ways that appeal to them instead of just being passively aware that others are richer.

[1]: https://www.sca.isr.umich.edu/files/chicsh.pdf

mahemm··on Could a Claude Code routine watch my finances?
I'm surprised y'all stopped at the personal finance layer. I've been thinking for awhile that LLMs would be really effective as personal financial advisers, and this kind of hookup (plus I guess another one for investment accounts?) seems like all that's needed to bootstrap reasoning.
mahemm··on I'm OK being left behind, thanks
Would you be comfortable using this same logic to invest most of your net worth in lottery tickets/betting on black in a casino? If not, I'd be curious to hear what is different in that for you.
mahemm··on Why Are We Still Doing This?
My FAANG employer launched a service ~6 months ago that today seems millions of DAUs. This service was 100% vibe coded. This service was created 20x faster than the median launch, and had notably fewer issues than the median launch. If AI stopped improving today, it would be a technological leap equivalent to a new high-level language paradigm for us.
mahemm··on A brief history of random numbers (2018)
The property you're talking about (next bit unpredictability) is important for a CSPRNG, but it doesn't matter at all for a PRNG. A PRNG just needs to be fast and have a uniform output. LCGs, for instance, do not have next bit unpredictability and are a perfectly fine class of PRNG.
mahemm··on It's insulting to read AI-generated blog posts
What game is played? To me it seems pretty straightforward that for both the actual caloric content is ~0.
mahemm··on A brief history of random numbers (2018)
To me this is completely unrelated to the quality of the PRNG, because security is explicitly a non-goal of the design. A general-purpose non-cryptographically secure PRNG is evaluated primarily on speed and uniformity of output. Any other qualities can certainly be interesting, but they're orthogonal to (how I would evaluate) quality.
mahemm··on Subverting Telegram's end-to-end encryption (2023)
You replied to a claim that Telegram doesn't do E2EE for groups saying 'Neither does Whatsapp/Signal'.

That's wrong as `tptacek noted. If you meant something else, that wasn't clear.

mahemm··on Perfect Random Floating-Point Numbers
Why not just read 64 bits off /dev/urandom and be done with it? All this additional complexity doesn't actually buy any "extra" randomness over this approach, and I'm skeptical that it improves speed either.
mahemm··on Ask HN: Who is hiring? (November 2024)
Yep! We're lucky to be part of an org that's growing across a few teams, so there's several jobs up for the wider Stores AppSec umbrella
mahemm··on Ask HN: Who is hiring? (November 2024)
Amazon | Full-time | Security Engineering/Management | Austin, TX | On-Site

I am hiring a new Application Security team in Austin to focus on making the highest-privilege applications in the non-AWS side of the company the planet's most secure.

This team will be joining a 9-month old effort to collaborate with developers of key apps on security assessment, architecture improvement, design and code review, and automation of the security process.

The pros of our team are technical excellence, a culture of sustainable work (we are working hard here, but strictly 9-5), the opportunity to have a significant influence on the security posture of the company as a whole, and the chance to hack on applications operating at a global scale, and low (1x/month) oncall expectations.

The cons of our team are moderate process debt (arising from our newness and some unexpected demand)and higher-than-normal ambiguity in tasks (we hold too many task definitions/bars in our head and haven't written them down yet).

Please apply to these roles through the links below:

* Security Engineering Manager: https://www.amazon.jobs/en/jobs/2769965/security-engineering...

* Senior Security Engineer: https://www.amazon.jobs/en/jobs/2778970/senior-security-engi...

* Security Engineer: https://www.amazon.jobs/en/jobs/2777245/security-engineer-ii...

I'll check this post periodically and respond to any questions (concerning non-confidential info about this job) if people are interested.

mahemm··on The Anxiety of Influencers
Who do you think declassifies and releases information? Who do you think passed and enforces the Freedom of Information Act?
mahemm··on Why There Aren't More Googles (2008)
>Money breeding laziness ... killed ICOs

ICOs were killed by Solidity and the Ethereum ecosystem more generally being insufficiently expressive to create anything of value other than pyramid schemes (insofar as those have value).

mahemm··on Large-scale Abuse of Contact Discovery in Mobile Messengers [pdf]
This is the exact sort of thing that allows people to think that things like Telegram are acceptable equivalents to Signal instead of disastrously poor imitators. It's a shame the discourse around secure messengers has become so polluted.
mahemm··on Why I’m Writing a Book on Cryptography
Can't do crypto without visualizations; I can't say how many times I've wanted someone to draw stuff out! Great article
mahemm··on Education Without Truth in Postmodern Perspectivism
The ideas that "culture is a matter of individual experience" and that "there was no dichotomy to begin with and nothing to deny" seem to affirm the postmodern idea from my POV. That's basically what they argue.

By contrast, many Modernist philosophers believed that human history moved inexorably towards more-just society or that human knowledge moved towards perfect understanding of all phenomena.

Edit: not sure I understand what you mean when you say "The pattern is much broader that postmodernism claims it to be. "; the project of postmodernism is in part to show that there is no pattern.

mahemm··on Education Without Truth in Postmodern Perspectivism
Ironically, Nietzsche is considered (by some) to be one of the fathers of postmodern thought. His criticism of the objectivity of science in "On Truth and Lies in a Nonmoral Sense", his deconstruction of the Western concept of self in "The Anti-Christ", and to some extents his criticism of 19th-century historiography in “On the Uses and Disadvantage of History for Life” and other books are touchstones which presage a lot of postmodern discussion of these topics.

Check out https://muse.jhu.edu/article/27340 for the argument against though!

mahemm··on Education Without Truth in Postmodern Perspectivism
A postmodern critique of this argument might start with your identification of a single "culture" that has a pattern. Who decides what this culture is and who its adherents are? What if there are exemplars of the culture that do not fit this pattern; are they inherently excluded from the culture by the fact that they do not fit the pattern? If so, it may be the case that we are fitting a pattern we would like to see onto a culture that is in fact varied and diverse, and which does not in fact have a particular direction.
mahemm··on Education Without Truth in Postmodern Perspectivism
Lots of people ITT seem to have an incorrect understanding of the term postmodernism. It basically boils down to the observation that history and human experience don't really move towards a single goal, but instead consists of lots of independent narratives going nowhere in particular.

These observations invalidate Modernist ideas that held that human historical development lead toward specific outcomes or followed observable patterns. For instance, postmodernist thought argues Marx was wrong in thinking that history followed a dialectical pattern, and instead holds that history follows no pattern.

mahemm··on Top three requirements for OTA software updates for IoT
While this article does do a good job of illuminating the potential challenges, it's a bit frustrating that there's such scant discussion of solutions.

IMO, this problem has been solved pretty comprehensively by the TUF framework[1], which has a number of solid implementations[2][3]. Many of these implementations even have reliable third-party reviews, so should be pretty trustworthy.

[1]: https://theupdateframework.github.io/ [2]: https://github.com/flynn/go-tuf [3]: https://github.com/theupdateframework/notary

mahemm··on Show HN: Differential Fuzzing of Cryptographic Libraries
I use the high level concept pretty regularly in my day-to-day as a security consultant specializing in cryptography, and this project is a fantastic way to democratize the use of differential fuzzing. The only negative thought I have about this is that I didn't think of it first!
mahemm··on A Telegram bug that disclose phone numbers of any users in public groups
The widespread usage of Telegram in a situation as sensitive as the Hong Kong protests is a failure on behalf of the security industry in educating the public.

Even WhatsApp is miles better, but in reality it should be a no-brainer for the relevant people to use Signal or perhaps Threema/Wire. What a shame that charlatans have successfully marketed themselves to the top of this segment with a distinctly inferior product.

mahemm··on Facebook to Launch “GlobalCoin” Cryptocurrency in 2020
I think it will be interesting to see the details of this project. Most of the current offerings do not have anywhere near the technical sophistication that FB can bring, and especially as they iterate I think they will leave every other cryptocurrency in the dust.
mahemm··on Selfie: reflections on TLS 1.3 with PSK
The attack can only happen in an unusual setting (nodes using external PSKs that can act as both client and server simultaneously), meaning that this vulnerability will not have too much impact on the open internet.

The more interesting issue here is that this sort of vulnerability should/could have been found through the numerous proofs of security that were created for TLS1.3.

IMO the most interesting insights that can be found in this paper come from section 6, where they consider how the proofs missed. It turns out that the proofs did not consider the possibility that a client and a server would simultaneously possess the same PSK, but IRL the sub-entities of a single node will do so.

mahemm··on EverCrypt, a cryptographic library that is provably secure against known attacks
Moving past the silly headline, there is actually a pretty substantial achievement here. Using formal verification tools, the team proved the following properties for the library:

* Memory safety (no buffer overruns etc)

* Type safety (all compiler-visible interfaces/abstractions used as per spec)

* Functional correctness (all the crypto implementations are faithful to their algorithms)

* Side-channel resistance (all crypto is constant time)

This has been confirmed by fallible tools and is checked against human-made models which are also fallible, but this code is still likely to be about as close to bug-free as currently possible.

I think Barghavan's work in this area are the future of cryptographic coding in the medium term and likely all security-sensitive code long term.

mahemm··on How to Make Other Developers Hate to Work with You
Sounds like insufficient testing to me. This kind of deep/far reaching issue should have been crashing tests written before others would have seen it.

Assuming that there is some testing in their work (if not; there's the answer), my guess would be that it's largely sanity testing of each functionality in a vaccuum. The coaching would probably be to demonstrate more integration-style testing, possibly using whatever tests caught system-level issues that the dev has pushed in the past.

Page 1 of 2Next →