HNHacker News
TopNewBestAskShowJobs

mykhal

127 karma · joined April 22, 2011

submissionscomments
mykhal··on OpenBSD 6.1 song – “Winter of 95”
oh, https://news.ycombinator.com/item?id=14207815
mykhal··on OpenBSD just added initial support for the RaspberryPi 2 and 3 devices
This doesn't work yet. But when it does, you'll need recent firmware from the Raspberry Pi Foundation git repository
mykhal··on Microsoft to acquire LinkedIn for $26B
/me done. finally.
mykhal··on DSA-3417-1 bouncycastle – security update
fixing this one https://news.ycombinator.com/item?id=10232282
mykhal··on Signal for Android: RedPhone and TextSecure in one app
regarding to excessive amount of required permissions, and the fact that contact == phone number, for now i am preferring ChatSecure.
mykhal··on OpenBSD: theo.c from mg source code
o@puffy$ mg<Ret>M-x theo<Ret><Ret><Ret>...
mykhal··on One-Time SSH Keys
an attacker might already have stolen his keys (why only one?), because the script checksums do not match :)
mykhal··on Romantic Cryptography: how to say “I love you” only if the other person does too [pdf]
The title had to be shortened, was:

  Romantic Cryptography, i.e. how to say "I love you" but only if the other person is going to say "me too"
.. and sorry for the direct PDF link.

now i found out that the article was published in the Journal of Craptology:

  http://www.anagram.com/jcrap/Volume_7/
mykhal··on SHA-3 Standard [pdf]
XOF, nice.. but what is the point of expanding SHAKE256 to e.g. 4096 bits, if its security remains 256 bits ?
mykhal··on SHA-3 Standard [pdf]
recap: http://keccak.noekeon.org/fips202final.html
mykhal··on Hack.chat – A minimal, distraction-free chat application
Nice, but I bet nobody is currently able to write there a proof for

  $\Re(s) = \frac{1}{2}$ for all s where $\zeta(s) = 0$ and $0 < \Re(s) < 1$
.. I mean, where zeta is the Riemann's one :)
mykhal··on OpenSSL Security Advisory
s/old/recent/
mykhal··on OpenSSL Security Advisory
from test/verify_extra_test.c:

    Test for CVE-2015-1793 (Alternate Chains Certificate Forgery)
   
    Chain is as follows:
   
    rootCA (self-signed)
      |
    interCA
      |
    subinterCA       subinterCA (self-signed)
      |                   |
    leaf ------------------
      |
    bad
   
    rootCA, interCA, subinterCA, subinterCA (ss) all have CA=TRUE
    leaf and bad have CA=FALSE
   
    subinterCA and subinterCA (ss) have the same subject name and keys
   
    interCA (but not rootCA) and subinterCA (ss) are in the trusted store
    (roots.pem)
    leaf and subinterCA are in the untrusted list (untrusted.pem)
    bad is the certificate being verified (bad.pem)
   
    Versions vulnerable to CVE-2015-1793 will fail to detect that leaf has
    CA=FALSE, and will therefore incorrectly verify bad
mykhal··on OpenSSL Security Advisory
Changes between 1.0.2c and 1.0.2d [9 Jul 2015]

  *) Alternate chains certificate forgery

     During certificate verfification, OpenSSL will attempt to find an
     alternative certificate chain if the first attempt to build such a chain
     fails. An error in the implementation of this logic can mean that an
     attacker could cause certain checks on untrusted certificates to be
     bypassed, such as the CA flag, enabling them to use a valid leaf
     certificate to act as a CA and "issue" an invalid certificate.

     This issue was reported to OpenSSL by Adam Langley/David Benjamin
     (Google/BoringSSL).
     [Matt Caswell]
mykhal··on FIFA Officials Arrested on Corruption Charges; Face Extradition to U.S
WTF? am I still at HN?
mykhal··on Unprocessed Foods Cut into Precise 2.5cm Cubes
unfortunately, it is annoyingly orthographic, no perspective.. :)
mykhal··on PHP: md5('240610708') == md5('QNKCDZO')
slightly off topic:

  $a = "DjBlYVWap4fQC8b3C73+NATPA2We"."c"."E+FNMAP+2WcTIdAzJQv6y2hFaP0F"."V"."y7hgdJc4ZlbX0fNKQgWdePWo3R7w";
  $b = "DjBlYVWap4fQC8b3C73+NATPA2We"."d"."E+FNMAP+2WcTIdAzJQv6y2hFaP0F"."d"."y7hgdJc4ZlbX0fNKQgWdePWo3R7w";
  var_dump($a === $b); // false
  var_dump(md5(base64_decode($a)) === md5(base64_decode($b))); // true
:-P
mykhal··on PHP: md5('240610708') == md5('QNKCDZO')
it's not _that_ broken
mykhal··on Mg: an Emacs-like editor in 160 kb
i you're lonely, just M-x theo ^M ^M ^M ...
mykhal··on DSLR – Damn Small Linux Remake
ADF (acronym design failure)
mykhal··on The Satoshi Nakamoto SourceForge account has been hacked
more relevant link: https://archive.today/odPyB
mykhal··on Slow and Steady is Bullshit
bullshit
mykhal··on The Best Programming Font: M+
i think that Terminus is yet bester
mykhal··on DuckDuckGo Regex Search
s/Search/Eval/
mykhal··on Google was down for 15 minutes (+/- from 09:35 UTC)
g search is occasionally failing with HTTP 500, in CZ
mykhal··on Heatmaps, contours, and 2D histograms in Plot.ly
yet another interesting project from libya..
mykhal··on Announcing Unicode 7.0
https://news.ycombinator.com/item?id=7902924
mykhal··on 9m.no – Short URLs for the Unicode Age
why would anyone in the unicode age have to shorten the urls? (:
mykhal··on In about 2 hours it’s 1400000000 unix time
duplicity (https://news.ycombinator.com/item?id=7736739)
mykhal··on Today at 16:53:20 GMT, it'll be 1400000000 in Unix time.
numerology is not my cup of tea.
Page 1 of 2Next →