159 karma · joined August 1, 2013
* General cryptography http://www.metzdowd.com/mailman/listinfo/
* SSL/TLS news https://www.feistyduck.com/bulletproof-tls-newsletter/
* Cryptography concerns for ops (typically TLS) https://lists.eff.org/mailman/listinfo/crypto-ops
* General cryptography https://lists.randombit.net/mailman/listinfo/cryptography
I stopped following a bunch of cryptography twitter feeds, because the Bulletproof TLS newsletter was lower volume and higher signal.
I use Google Keep to store URLs, typically with some note, for example: * "Specialized Sirrus bike rear derailleur. Model number: DO20. URL: https://www.amazon.co.uk/dp/B0047D192E/ " * 2015-03-01: Visited doctor. They referred me to physio, and told me to read http://www.arthritisresearchuk.org/arthritis-information/con... for exercises/stretches to relieve pain."
Google Keep supports tagging and search, so I can usually find things. For things I want to read later, I either put it in Pocket or use Google Keeps' reminder functionality.
Chrome integration looks decent (save web pages as an image), but Firefox integration is lacking.
Do you have any links relating to this?
Sadly the source code for the book doesn't appear to be published. This is unlike David Mackay's otherbook, "Information Theory, Inference & Learning Algorithms", does have the LaTeX source published (see http://www.inference.phy.cam.ac.uk/mackay/itila/book.html ), though not in an open source license.
Apache's client doesn't have CompletableFuture, but it was easy to add one: https://gist.github.com/tomfitzhenry/4bb032f6a9f56d95f6fb544...
async-http-client is the HTTP client used by Gatling (same developer, in fact).
CompletableFuture is becoming supported in a bunch of other libraries: https://github.com/AsyncHttpClient/async-http-client/, https://github.com/ben-manes/caffeine , https://github.com/mp911de/lettuce .
I have both enabled on the sites that support both.
I use U2F when I have the key near me, and use HOTP on my phone otherwise (like you, my phone is typically closer to me than my U2F key).
A common response at this point goes "But then doesn't introducing HOTP remove the security benefits of U2F?" No. One of the main benefits of U2F is that it is phish-proof: the U2F key cryptographically authenticates the server, rather than the user eyeballing the address bar, which is how server "authentication" works with HOTP.
I outlined the factors in this decision in https://gist.github.com/tomfitzhenry/d73fef19752cbf6ccdda3eb... .
Yes, I'm using CloudFlare, for its trivial SSL, DDOS protection, and caching.
I have CloudFlare's DDOS protection (the thing that causes captchas) set to "Essentially Off", the lowest available setting on their free plan.
I just tried to query https://api.ctwatch.net/domain/ycombinator.com multiple times, each on multiple Tor circuits, but was unable to trigger the CloudFlare captcha.
Did you see the captcha on my site, or is it just that you've noticed captchas on some other CloudFlare sites?
I can look into setting up a Tor hidden service, which'll allow Tor users to bypass CloudFlare, if CloudFlare is actually causing issues.
Feel free to use that to check your own site's certificates!
(It's possible to directly query the multiple Certificate Transparency log servers for your site's certs, but non-trivial, hence why I implemented the above functionality.)
To see why this is a problem, see the ECB-encrypted Tux image on http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#...
Oops.
It has the server-level RAID you desire. The FAQ states: ``You know how with RAID-5 you can lose any one drive and still recover? And there is also something called RAID-6 where you can lose any two drives and still recover. Erasure coding is the generalization of this pattern: you get to configure how many drives you could lose and still recover. You can choose how many drives (actually storage servers) will be used in total, from 1 to 256, and how many storage servers are required to recover all the data, from 1 to however many storage servers there are. We call the number of total servers N and the number required K, and we write the parameters as "K-of-N".''
It's a very active open source project, with full-time contributors (I think?), funded by their commercial arm, https://leastauthority.com/ .
In particular, the changes in Execute.hs are where using a monad made this code more clear.
If you're new to the usefulness of monads, I don't suggest you read this code, however, and that instead you read:
1. "You Could Have Invented Monads!" http://blog.sigfpe.com/2006/08/you-could-have-invented-monad...
2. "Monad Transformers Step by Step" http://www.cs.virginia.edu/~wh5a/personal/Transformers.pdf
It parses a sed script into an AST, then interprets that AST. sed is simple enough that such an interpretor is easy to write. e.g. each input line is only processed once, and in order
Maybe one of the more interesting parts is the testing of the parser using specification-based testing. First, define how to generate an arbitrary sed script (in its AST form). Haskell's QuickCheck will then generate 100 random sed scripts, and check that upon being pretty printed (to a sed script in its usual textual form), and then parsed, produces the original AST.
Specification-based testing is a nice complement to unit-based testing, that I'm beginning to rely more on, to avoid the tedium of writing so many unit tests.
The parser does not yet support nested sed expressions that contain more than one subexpression. The qualifier "suchThat (\xs -> length xs == 1)" at https://github.com/tomfitzhenry/hs-sed/blob/master/tests/Pre... documents this, and as a side-effect serves as a todo list [which I have since ignored for months :)].
Suppose the target web server has an endpoint /foo?probeMe=bar such that the HTTPS response will include 'bar' in the HTML. (Quite an assumption, sure.)
Suppose the target web server compresses its responses.
Suppose the attacker can make requests to the target web server, on behalf of the target user (e.g. when the target user is on an attacker-controlled webpage, and the attacker can make AJAX requests to the target web server).
In the case that the HTTP response already contains 'bar', and doesn't contain 'cbs', then a HTTP response to /foo?probeMe=bar will have a shorter length, than a HTTP response to /foo?probeMe=cbs , since compression will mean 'bar' is deduplicated.
Using this, the attacker is able to mount an Oracle attack. That is, if they know something of the form *@gmail.com , and they want to know the whole email address, they can make 26 probes, with probeMe set to: a@gmail.com, b@gmail.com, ..., z@gmail.com
and whichever produces the shortest response is part of the response.
Suppose the shortest is the probe for probeMe=y@gmail.com . They try another letter: ay@gmail.com, by@gmail.com, ..., zy@gmail.com . Again, one probe will have a shorter response than the rest.
They continue, until they find larry@gmail.com .
Now they know larry@gmail.com appears in the response. Success!