591 karma · joined September 9, 2007
jack@randombit.net
https://twitter.com/randombit https://github.com/randombit
[ my public key: https://keybase.io/jacklloyd; my proof: https://keybase.io/jacklloyd/sigs/tKaiJfvmYONF1UqbqHH1z-ZkqDn7M9Awbs2XrGcPV-c ]
Edit: fortunately it looks like certbot plans to support using the old intermediate https://github.com/certbot/certbot/issues/6971 so this should not prove necessary.
My wife runs a blog which generates substantial income and uses certs from Let's Encrypt. It's a non-tech blog with primarily US readership. Checking stats for this month, 7% of all visitors were using Android 4/5/6 (20% of all Android users). The percentage of users on old Android running Firefox was basically nil. Losing all these users would be very costly.
Hopefully certbot will be modified so it is possible to pick the current intermediate during automatic renewal. If I have to do a manual operation to switch intermediates each time the cert renews (currently done by cronjob) then it is probably safer (operationally speaking) to just buy a cert.
I don't really understand why Let's Encrypt is making this change now. Sure, the current root is expiring "soon", but not until September 2021. Switching roots could be safely pushed off to early 2021 at which point hopefully most of these older Androids would be cycled out.
Source: my house has 23 year old solar panels, my garage has 10 year old panels, they all still produce plenty of electricity.
There are plenty of reasons to avoid dealing with these companies, but this isn't one of them.
The existing Botan C API is in fact sufficient for OpenPGP already, https://github.com/riboseinc/rnp is in C++ now but was originally C and uses Botan's C API.
But Nettle is IMO quite solid and the developer is very skilled, so full steam ahead.
Is there any relation between Sequoia and the BoringPGP spec?
My only complaints would be slow Internet (though fiber is more common these days) and the ticks. And it gets cold sometimes, some people don't like that.
As to load, it manages just a household's worth of machines, maybe ~10 wireless clients and ~10 more devices on the LAN side. The load on the machine is effectively zero. I would personally be confident building such a setup for even 100 clients. The 2 PCI + 2 USB3 offers many expansion options and the SoC itself is tens of times faster than most home routers.
More about APU2 at http://www.pcengines.ch/apu2b4.htm
Within the constraints of zoning, which are very strict both at the state level (Act 250 would certainly come into play for a development this large) and often at the town level also (don't know about Sharon). Vermont's zoning is partially oriented towards keeping as much green space and working farmland available as possible... maybe there are places where you can just buy up hundreds of acres farmland and turn it into strip malls and high density housing but Vermont is thankfully not one of them.
As another example of what you cannot do with your land in Vermont - you cannot put up a billboard on it. There was a case recently where a mural painted on a barn wall within sight of the highway was declared a roadside ad and had to be removed. You don't realize how just ugly and tacky billboards are until you live in a place without them for a few years...
Remote: Yes (been remote full time for 5+ years)
Willing to relocate: No
Technologies (key): C++, Python, Unix systems programming, security review, cryptography
Technologies (hobbyist or occasional): Django, OCaml, Common Lisp, Java, C#
Email: jack.lloyd@gmail.com
CV: http://randombit.net/resume.pdf
GH: https://github.com/randombit
Currently engaged in building, debugging, and production support of low-latency trading systems. Prior to that I was a security consultant reviewing software systems and cryptographic implementations, as well as network exploitation. Security has remained my ongoing interest and passion, and I'm looking to apply what I've learned building systems to an unique security product, or alternately return to full time security consulting.
My background is somewhat twofold, in security/crypto review and building high performance distributed systems for trading. I'd be especially interested in projects involving reviewing code and protocols for security flaws, distributed systems development, low latency network code, and the design and coding of security critical components.
The majority of my production code has been in C++ and Python, but I'd be happy diving into a project in C, Java, Scala, Go, or Rust. I mostly use and develop for Linux.
Some past open source work is at https://github.com/randombit
Drop me a line at lloyd@randombit.net and we can talk about what you are trying to do and if I'm the right fit for your problem.
http://code.google.com/p/google-caja/source/browse/trunk/thi...
It's not always the case that a hash that is faster in software is easier or cheaper to implement in hardware. For instance Skein is very fast on x86-64 but apparently is less competitive in low power hardware implementations.
It's easy to forget that software is probably the least capital intensive industry that's open to a lone entrepreneur. Think about someone wanting to start, say, a basic small bakery operation. My wife did this, and the capital costs necessary to just get started and make that first batch of sales - ingredients, packaging materials, special implements like decorating tips - could easily be enough to deter someone who has little capital to work with. (And we already had a good kitchen with the majority of tools one would need). It's one thing to risk a month of time when you're otherwise idle, it's another to risk next month's rent payment as well.
I'm skeptical.
What's "magic" about structs of function pointers? This is a classic idiom in C, just given a specialized syntax in C++.
Whitfield Diffie proposed triple DES in 1975 (even before the FIPS was published), because it was obvious even then that a 56 bit key would not be sufficient for long term security against attackers with serious financial/technological resources. EFF's Deep Crack broke a DES key in less than a day 13 years ago. The AES selection process started in 1998, and a winner finalized in 2001. I'm not sure where you're getting your history from here.
The relevant portion is Article 7
""" Member States shall take the necessary measure to ensure that the production, sale, procurement for use, import, possession, distribution or otherwise making available of the following is punishable as a criminal offence when committed intentionally and without right for the purpose of committing any of the offences referred to in Articles 3 to 6:
(a) device, including a computer program, designed or adapted primarily for the purpose of committing any of the offences referred to in Articles 3 to 6;
(b) a computer password, access code, or similar data by which the whole or any part of an information system is capable of being accessed. """
Which seems to be saying that, say, nmap isn't illegal, unless you download it with the intent to run it against a machine you're not supposed to, in which case you've broken the law (even if you never actually use it). Kind of like laws against 'burglary tools' in some parts of the US, the crime seems to be based on context/intent.
(Obvious disclaimer about how I'm not a lawyer, European, or a unicorn.)
Because that's not a warning sign at all! boggles
Most people of course answer this question in the same way an interviewee does when asked 'Why did you leave your last position?'. Nobody will ever answer 'that jerk across the hall, I can't STAND that guy'. They will answer something that gives some insight into the company culture. I don't think it's a coincidence, for instance, that easily half the people at Google I've put this question to have answered something along the lines of 'management chaos/confusion', 'the tendency for two internal projects to be competing with each other without even knowing about it', etc.
I should have added the followup to my first question is what they like most. Both can be very informative, of course, and following up with that helps put them at ease for the rest of the interview, since many interviewers aren't expecting a question like this one. But it's really worth it. An interview isn't just to answer 'will you hire me', it also must answer 'will I enjoy working here'. The second is much more important to me.