HNHacker News
TopNewBestAskShowJobs

mstef

399 karma · joined November 22, 2008

submissionscomments
mstef··on Ask HN: Alternatives to 1Password
the thing is. sphinx is designed by people with outstanding crypto protocol design credentials, the guys who came up with hmac and hkdf cryptographic primitives. the nice thing about sphinx is that it comes with "information theoretic security" - a very strong guarantee, not sure how the competition stacks up against this though...
mstef··on Ask HN: Alternatives to 1Password
not sure, by looking at the sqrl wikipedia page it's not immediately obvious how this works. but yeah, "derived password generator" sounds correct, with one important detail. the there is (almost) no state at the client, and there is a mandatory online component where part of the derivation happens.
mstef··on Ask HN: Alternatives to 1Password
There's a new kid in town: https://www.ctrlc.hu/~stef/blog/posts/sphinx.html

pro: it has much stronger security guarantees than the rest, it's self-hosted, but you can use other peoples servers!

cons: there is no UI frontend for macs, and UI integration in browser could also be improved.

(i'm the author, ama)

mstef··on Sven Guckes Has Died
my .vimrc is originally from him, it still says:

> " Last update: Thu Dec 10 02:02:02 CET 1998

thank you so much sven! r.i.p.

mstef··on NSA's Backdoor of the PX1000-Cr
if you read the linked page, you will see the story and how the nsa replaced the DES algorithm with a completely new algorithm.
mstef··on Ask HN: Why should I trust password managers?
i am the author of a password manager which you don't have to trust: https://www.ctrlc.hu/~stef/blog/posts/sphinx.html
mstef··on NSA's Backdoor of the PX1000-Cr
see the section "Different Versions" on this page: https://cryptomuseum.com/crypto/philips/px1000/
mstef··on NSA's Backdoor of the PX1000-Cr
thank you! may i return the compliments? i love playing on cryptohack.org so many fun and educational challenges! kudos!
mstef··on NSA's Backdoor of the PX1000-Cr
sorry, no. but there is an emulator[1], so you can test the roms, or you can write your own code and test it without having the hw.

[1] https://github.com/iddq/sim68xx/tree/px1000

mstef··on NSA's Backdoor of the PX1000-Cr
it's a pocket telex from the early 80ies, you can read more about the device here: https://www.cryptomuseum.com/crypto/philips/px1000/index.htm
mstef··on NSA's Backdoor of the PX1000-Cr
fascinating details, happy to have stirred up these memories!
mstef··on NSA's Backdoor of the PX1000-Cr
also interesting might be this generic link unrelated to the NSA backdoor: https://cryptomuseum.com/crypto/philips/px1000/
mstef··on NSA's Backdoor of the PX1000-Cr
afaik the firmware was developed by philips ufsa[1] based on directions (test vectors?) by the NSA, lots of effort was put into making the algo run efficiently on the CPU in the px1000.

[1] https://www.cryptomuseum.com/crypto/philips/usfa.htm

mstef··on NSA's Backdoor of the PX1000-Cr
nice summary of my post! thank you very much
mstef··on NSA's Backdoor of the PX1000-Cr
author of the break here, ama.
mstef··on NSA's Backdoor of the PX1000-Cr
i mean an algebraic full key recovery out of 17 ciphertext chars is nothing else but catastrophic. and i'm sure this can be done much more efficiently.
mstef··on NSA's Backdoor of the PX1000-Cr
actually since large parts of my addendum blog post were quoted here, here is another quote:

> lets me conclude that the PX1000cr algorithm is indeed a confirmed backdoor.

I guess, me and the cryptomuseum people had a misunderstanding about this.

mstef··on Teleguard: Swiss Made Safe Messaging
Crypto AG. https://archive.is/d6z6l
mstef··on UN special rapporteur on torture on his investigation into the case of Assange
no, it is not. you are mixing up the two cases, one were there was no condom indeed with S.W., and the other case with the other woman A.A. where the condom was allegedly damaged.
mstef··on Briar Project
the main dev of tox is kinda toxic to it's own project with kneejerk responses like these: https://github.com/TokTok/c-toxcore/issues/426 and https://github.com/irungentoo/toxcore/issues/121 showing much more enthusiasm than competence when it comes to security and crypto. while the people behind briar i got to know as reasonable and deliberate people.

can't say much about ring, but a few years back i looked at the crypto and it was boring, which some people argue is good, i was not sure about that in this case. dunno how much they evolved since then.

mstef··on What3words, the GPS app that can find anyone anywhere
it has been done ages ago, is called the maidenhead locator system, it is better in many ways, for example you can choose the granularity of the grid providing some privacy: https://en.wikipedia.org/wiki/Maidenhead_Locator_System
mstef··on Warning.js: the opposite of noscript warnings
that would be less funny and lack the educational aspect.
mstef··on Qwant: A European search engine that respects privacy
searx protects your privacy much better.
mstef··on Qwant, a European search engine that respects your privacy
you should have a look at searx instead, is also from the eu, and is completely free software, so free, that you as a user can demand the source code of the instance running due to the agpl license.
mstef··on PGP needs to be retired in honor
according to http://keys.mayfirst.org/pks/lookup?op=stats there's currently 4594571 keys on the bulk of public keyservers. considering the rumors that facebook and others also do signal and their user base is around a rumored billion, the k that i glossed over is around 217. even if we assume that there's dark masses that never ever used a keyserver, we ignore the fact that out of those 4.5 million pgp keys most are expired, revoked or simply lost, so the active keys on the keyservers are probably much less, and thus k is also much bigger.
mstef··on PGP needs to be retired in honor
some of these tools actually fully replace pgp (see opmsg for example) however that is actually a very low bar to master. it seems pgp is seen as a silver bullet handling all use-cases like a charm, this is far from reality, actually it fails in many cases, and specialized tools might actually fit the purpose much better, also surpassing pgp in their special niche.
mstef··on PGP needs to be retired in honor
if you knew the story you'd know that Phil did actually an abysmal implementation which had to fixed by others.
mstef··on PGP needs to be retired in honor
pgp does not provide anonymity at least not in the widely accepted form. every message has the recipient keyid in plaintext, unless you --throw-keyids but then you run into incompatibilities and inconveniences that make the whole exercise user unfriendly and widely unsupported.
mstef··on PGP needs to be retired in honor
the protocol is very generic and does not require anything related to phones. it is actually 3 parts, a key exchange, a signature mode and a ratchet. how you combine these is up to you. the app is one way to combine them with phones. there's other ways to use the protocol, that could also be applied to emails
mstef··on PGP needs to be retired in honor
count the keys on the keyservers, apply some multiplier, chances are that it's still less than signal users today.
← PreviousPage 2 of 3Next →