HNHacker News
TopNewBestAskShowJobs

regd006

19 karma · joined July 18, 2014

submissionscomments
regd006··on Malicious SHA-1
> Think about how many sets of constants can be generated in a nondescript way

One example of this is the BADA55 curves[0]:

> The name "BADA55" (pronounced "bad-ass") is explained by the appearance of the string BADA55 near the beginning of each BADA55 curve. This string is underlined in the Sage scripts above

> We actually chose this string in advance and then manipulated the curve choices to produce this string. The BADA55-VR curves illustrate the fact that, as pointed out by Scott in 1999, "verifiably random" curves do not stop the attacker from generating a curve with a one-in-a-million weakness. The BADA55-VPR curves illustrate the fact that "verifiably pseudorandom" curves with "systematic" seeds generated from "nothing-up-my-sleeve numbers" also do not stop the attacker from generating a curve with a one-in-a-million weakness.

[0] http://safecurves.cr.yp.to/bada55.html

regd006··on Tor security advisory: “relay early” traffic confirmation attack
> but an entity with global network insight will always be able to correlate users by the timing of their transmissions alone.

For what it's worth, this type of adversary is explicitly excluded in Tor's threat model[0].

[0] https://svn.torproject.org/svn/projects/design-paper/tor-des...

regd006··on Bypass t.co, go straight to real links on Twitter
t.co is incredibly annoying IMO.

It allows twitter to easily track which links you're clicking on, which some might consider to be a violation of privacy.

On mobile, t.co makes it so that you end up always launching a browser before launching the appropriate application (i.e. YouTube)

When you copy and paste and send a link to someone, they have no (easy) way of knowing what you're sending them without description or visiting, and it gives Twitter a mechanism for tracking who you send the link to. (One could posit a "malicious" tracking twitter where they serve up t.co links to people which are dependent on the logged in user to track that user's social network... fortunately I don't think this has happened yet.)

regd006··on The getrandom(2) system call was requested by the LibreSSL Portable developers
Linux Kernel Coding Style - https://www.kernel.org/doc/Documentation/CodingStyle