HNHacker News
TopNewBestAskShowJobs

sweis

3,318 karma · joined January 18, 2009

My name is Steve Weis. I live in San Francisco and am interested in security, cryptography, and privacy.

http://saweis.net

submissionscomments
sweis··on Show HN: ZuccNet – Encrypted Facebook Messaging
Also, ZuccNet is using RSA-2048-OAEP to encrypt each message: https://github.com/tomquirk/zuccnet/blob/master/src/util/cry...

This is not forward secure. It will also only work for messages under 256 bytes. I don't know what happens in this code if you exceed that message length.

You want to use ephemeral session keys here. Read the Secret Conversations whitepaper as an example.

sweis··on Show HN: ZuccNet – Encrypted Facebook Messaging
Facebook Messenger already has Secret Conversations, which is end-to-end encrypted mode based on the Signal protocol.

Here's the technical whitepaper: https://about.fb.com/wp-content/uploads/2016/07/messenger-se...

Here's some of the academic work on messaging franking that it has driven: https://eprint.iacr.org/2017/664.pdf

Here's the instructions how to use it: https://www.facebook.com/help/messenger-app/1084673321594605

Of course, you need to trust that the client from the app store and no, the implementation is not open source.

sweis··on How to Write Usefully
This is brilliant unintentional parody.
sweis··on Tech companies will post incoherent ads for open positions in tiny local papers
You are right. I was ill-informed. This is for green cards.

My intent is opposite of nativist propaganda. I think the regulations are silly and companies are minimally complying with them.

sweis··on Tech companies will post incoherent ads for open positions in tiny local papers
I think you’re right. It’s for green cards and E visas.
sweis··on Tech companies will post incoherent ads for open positions in tiny local papers
OP here.

Yes, Apple is certainly saving a bundle on classified ads in the free community paper with circulation of 6,000.

These ads are just to go through the motions to get someone a visa.

They don’t actually want anyone to reply to the ad. That’s why they have mailing addresses in the ad instead of email addresses or URLs.

sweis··on IBM will soon launch a 53-qubit quantum computer
It not exactly a young research area. We have had post-quantum public key cryptosystems based on linear codes for over 40 years.

Classic McEliece (https://classic.mceliece.org) was created in 1978 and is in the 2nd round of NIST's PQ-crypto contest ( https://csrc.nist.gov/projects/post-quantum-cryptography/rou...).

The PQCrypto conference started 13 years ago: https://pqcrypto.org/conferences.html

Chrome ran large scale experiments with NewHope support 3 years ago: https://security.googleblog.com/2016/07/experimenting-with-p...

sweis··on Get Paid to Learn Tech Policy -Aspen Institute Pays You $18k; 10wk Program in SF
I'm part of the first cohort and the program is great. Highly recommended.
sweis··on Masterminding the largest lottery scam in American history
Before he even backdoored it, the lottery was using a Mersenne Twister?

The random number is called the seed, and the seed is plugged into the algorithm, a pseudorandom number generator called the Mersenne Twister. At the end, the computer spits out the winning lottery numbers.

sweis··on What are some innovative encryption methods?
Your friend is not going to get PhD thesis topics by asking his friend to post on HN.

Regardless, here's what I think are interesting areas in recent crypto:

- Performance improvements in fully homomorphic encryption, starting with Gentry's work in 2009.

- Practical applications of secure multiparty computation, e.g. Dyadic Security and Google's SMC work.

- Non-NIST standards with actual adoption like Curve25519 and Chacha20-Poly1305

- Functional Encryption: http://eprint.iacr.org/2010/543

- Post-quantum crypto like New Hope (https://eprint.iacr.org/2015/1092) and Supersingular Isogenies (http://eprint.iacr.org/2011/506)

- Candidate functions for Multilinear Maps, e.g. https://eprint.iacr.org/2012/610

- Hardware-based secure enclaves like SGX

sweis··on What are some innovative encryption methods?
Nobody uses anything related Wolfram's cellular automata. I don't think there are any robust security proofs.
sweis··on What was it like to self-learn programming before Stack Overflow? (2016)
I went to the library and checked out books with code you would type in by hand, like this one: https://en.wikipedia.org/wiki/BASIC_Computer_Games
sweis··on Show HN: Kryptonite – a new home for your SSH private key
I don't know if you've done it correctly.

You can use the built-in signature digest support and still add support for whatever you want in the future.

sweis··on Show HN: Kryptonite – a new home for your SSH private key
Why are you doing this instead of SHA[N]withRSA? https://github.com/KryptCo/kryptonite-android/blob/master/ap...
sweis··on Tech Workers' Values
See also https://techsolidarity.org/
sweis··on The Forgotten 'China Girls' Hidden at the Beginning of Old Films
Did you ever notice the 5th Young Ones roommate?
sweis··on Google Infrastructure Security Design Overview
Keyczar is no longer being maintained and should probably be deprecated.

Either that or someone can take the reins and update it to use modern algorithms.

sweis··on Practical Cryptography
This site contains little practical information about cryptography.
sweis··on Secret Management with Vault
You don't know anything about their internal network.

TLS is not the only game in town.

sweis··on Introducing osquery for Windows
Except that it works on Linux and Mac.
sweis··on Introducing osquery for Windows
osquery originated with Facebook and Kolide was founded by ex-Facebookers.
sweis··on Why there is no Facebook killer: the death of the P2P dream (2014)
This sounds like something you could have proposed 15 years ago. It assumes local, custom email clients for "enabled-by-default encryption" and XMPP support. People have moved onto web and mobile email clients, and you can only use whatever is compatible across all platforms.

I also think it overlooks mobile adoption. Many people using the internet today have only accessed it from a phone. They don't necessarily have email addresses. They may not have ever used a full sized keyboard.

sweis··on AMD’s Virtualization Memory Encryption Technology [video]
I think Intel backed away from the documentation that implied all signed enclaves had to go through them. I think people can attest their own SGX enclaves.
sweis··on The Age of the Never-Ending Performance Review
This sounds familiar.
sweis··on Facebook Messenger begins testing end-to-end encryption using Signal Protocol
Facebook supports PGP too, by the way: https://www.facebook.com/notes/protect-the-graph/securing-em...

And runs as a Tor hidden service at https://facebookcorewwwi.onion/: https://www.facebook.com/notes/protect-the-graph/making-conn...

sweis··on Facebook Messenger begins testing end-to-end encryption using Signal Protocol
And we had some smart outside people review it: https://twitter.com/matthew_d_green/status/75140316340882636...
sweis··on Facebook Messenger begins testing end-to-end encryption using Signal Protocol
Here's a whitepaper to start: https://fbnewsroomus.files.wordpress.com/2016/07/secret_conv...
sweis··on Facebook Messenger begins testing end-to-end encryption using Signal Protocol
Hi. To move all messages to be E2E encrypted, we need credible solution for web clients and every other platform, including old feature phones. This is easier said than done, but is something we are thinking about.

Secret Conversations is a step in the right direction.

sweis··on Facebook Messenger begins testing end-to-end encryption using Signal Protocol
I am confident Facebook will meet your high standards when it comes to E2E encryption for Messenger.
sweis··on Show HN: Passbolt – open-source password manager for teams
Got it. Here's the code: https://github.com/passbolt/passbolt/blob/master/app/Control...

I didn't know gpgauth existed, but this is what they appear to be using (the site has a broken cert): https://gpgauth.org/

← PreviousPage 2 of 9Next →