HNHacker News
TopNewBestAskShowJobs

upofadown

6,998 karma · joined December 17, 2013

submissionscomments
upofadown··on Forging 1024-bit RSA signatures in nearly SNFS time [pdf]
From the article:

>Still, some real-world systems continue to use blind-signature, also known as textbook, RSA.

I think those are two different things.

upofadown··on Transit rewards
Once you are in the Waymo, why bother getting out just to get on a bus?

In New York, increases in the use of ride services like Uber mostly came from bus and subway riders[1]. If we are being charitable to Google, we might assume that this initiative is intended to reduce the same sort of trend. If we are not being charitable, we might assume that this initiative is intended to encourage current bus riders to expose themselves to the product.

[1] https://www.6sqft.com/mta-says-uber-use-is-the-cause-of-nyc-...

upofadown··on RSA-896
Hard to judge. The bottleneck is the phase of the algorithm where a really big linear system needs to be solved. That takes a lot of communication between nodes. The breakthrough in using GPUs is that there is good communication between nodes[1]. At the scale of 1024 bit RSA the communication might become a bottleneck again.

[1] https://cognition.com/blog/factoring-rsa-260

upofadown··on RSA-896
Is someone providing prize money again? RSA ended the contest in 2007.
upofadown··on Keys Not Included: recovering the signing keys for US driver's license barcodes
Well most people don't verify identity with some sort of physical key. So it doesn't work as an analogy in the first place for signatures...
upofadown··on How Trail of Bits helps verify the integrity of Signal chats
Allegedly, Signalgate was caused by Apple helpfully mapping the wrong number to a name. Then Signal mapped that number to the wrong cryptographic identity.

A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers https://www.dropsitenews.com/p/intercept-signal-tip-line-bre...

Twilio Incident: What Signal Users Need to Know https://support.signal.org/hc/en-us/articles/4850133017242-T...

Russian State-Backed Hackers Intensify Attacks on Signal Messenger Accounts https://thecyberexpress.com/signal-attacks-russian-fackers-t...

upofadown··on How Trail of Bits helps verify the integrity of Signal chats
Unfortunately, in an end to end encrypted messaging system, an identity is denoted by some sort of long number. That is an inescapable fact. Trusting a third party to correctly map, say, a phone number to a cryptographic identity number eventually results in the sort of attacks we have been seeing with phone oriented encrypted messengers recently like WhatsApp and Signal. The PGP people were doing the right thing when they were doing education in the form of key signing parties. That is something the user needs to know.

Anonymous messengers have no real choice and have to use some sort of number for identity. See Briar, Session or Tox for examples.

My comments on Signalgate 1.0:

https://articles.59.ca/doku.php?id=em:sg

upofadown··on I've factored the RSA keys of a Certificate Authority from the 90s
What does the speed of RSA have to do with anything?
upofadown··on I've factored the RSA keys of a Certificate Authority from the 90s
My article:

2048 Bit RSA and the Year 2030 https://articles.59.ca/doku.php?id=em:20482030

We don't have any way to predict when and if 2048 bit RSA would be factorable at this time. We would need a breakthrough in hardware and/or algorithms. The common estimation that it is equivalent to the difficulty of brute forcing symmetrical 112 bit encryption seems to be based on some sort of straightforward extrapolation. It doesn't take into account the amount of memory required for the poorly reducible matrix reduction step in the currently known best algorithm. That's 10^18 bytes of memory, or a million terabytes, somehow coupled to enough processing power to actually make anything possible.

Even if you accept the 112 bit estimate, that works out to something like 400 thousand years using the Bitcoin network as a reference to what we could reasonably achieve.

upofadown··on I've factored the RSA keys of a Certificate Authority from the 90s
This article from 2000 is about estimating what would be required to factor 1024 bit RSA:

A Cost-Based Security Analysis of Symmetric and Asymmetric Key Lengths https://cr.yp.to/bib/2000/silverman.pdf

It was a response to the idea that 1024 bit RSA was under threat at the time.

upofadown··on A/I shuts down
I note that that extensive list only contains a single death, due to a power failure. Extreme civil disobedience, but not really terrorism.
upofadown··on IBM Quantum Nighthawk R2
You can attempt 15 yourself if you want:

https://towardsdatascience.com/where-are-we-with-shors-algor...

If you run it over and over again you will eventually get 3 or 5...

upofadown··on RSA-260 Factorized
This article (mine) is about this:

2048 Bit RSA and the Year 2030 https://articles.59.ca/doku.php?id=em:20482030

I guess it could be updated to include this latest factoring result. Said result would not change the conclusion of the article.

upofadown··on RSA-260 Factorized
It's not just because the GPG user is small fry that 1024 bit RSA is low risk for them. It is mostly because there is only one of them. A nation state attacker would have to spend billions of dollars and years of lost opportunity to use their resource more effectively to get the messages/files of a single person. There are much cheaper and faster ways to accomplish the same thing.

If, say, Gmail was using some static 1024 bit RSA based scheme things would be different. Then an attacker would get the messages of billions of users.

upofadown··on Run OpenBSD on DigitalOcean for $4/month
OBSD Amsterdam is pretty cool. I am currently running an instance on it. One feature that could also be considered a bug is that the VPSes run on the native OpenBSD virtualization scheme. My instance has suffered a few crashes over the years. It's been solid more recently. I suspect that OBSD Amsterdam and users have contributed to improvements to the native virtualization.

So you control your instance by sshing into a BSD account on the server. You configure your reverse DNS the same way. It's OpenBSD all the way down. So, as mentioned, pretty cool. Possibly not for the OBSD user who prefers some sort of web based configuration for their VPS.

It comes with access to a server you can copy your backups to. You of course do that from your instance using ssh.

upofadown··on Run OpenBSD on DigitalOcean for $4/month
OVH doesn't seem to directly support installation of arbitrary images. So installing OpenBSD can be a bit awkward. A relevant search:

* https://searxng.shreven.org/search?q=openbsd+ovhcloud

upofadown··on Jabber/XMPP: 25 Years of Digital Independence
You can always send and receive messages no matter what XEPs are supported. Not that that is a problem in practice. There is a fairly well established subset of XEPs that everyone supports.

https://xmpp.org/extensions/xep-0479.html

https://compliance.conversations.im/

upofadown··on Bluesky's active user base is shrinking as its focus expands beyond the app
Wait, Mastodon has 10 million users and 8000 servers? That's way more than I would of guessed. So Mastodon is a real thing in the world now.

Twitter has something like a half a billion users. So it wins I guess...

upofadown··on CSS: The bomb inside your inbox
It was never allowed. Microsoft just started doing it in their email client and obnoxiously made it default. There was no standards process where anyone spent time considering the potential downsides with the aim of making HTML email practical and secure.

HTML email is just something that people semi-randomly do. It should be rejected/ignored if you are at all concerned about privacy and/or security.

upofadown··on Decimen Optical Transfer: fountain-coded QR file transfer
>Neither mode is encrypted: whatever is on the sending screen is readable by any camera pointed at it.

Something like this would be good for transferring the public key(s) associated with some cryptographic messaging identity. This would allow that to happen entirely offline. The optical nature of the transfer would prevent a potential MITM. The idea that an identity is being transferred would be fairly easy to impart to the user.

So the lack of encryption would be a feature and not a bug. This would enable later encryption which could then use any medium for the transfer in a completely secure way.

upofadown··on Civilian plane crash in New Mexico tied to military GPS blocking
GPS is direct sequence spread spectrum. You might be thinking of frequency hopping, jamming that is harder, but you are only working against super weak signals from satellites. It would still be quite possible.
upofadown··on Civilian plane crash in New Mexico tied to military GPS blocking
A rehash of the paywalled Wired article:

* https://futurism.com/science-energy/us-military-gps-jamming-...

upofadown··on GrapheneOS protections against data extraction from locked devices
The point of the comic is pretty obviously to make fun of the expectations of cryptography geeks; you know, the sort of people who use 4096 bit RSA keys for the coolness factor. It is a stretch to imply it is suggesting that encryption is somehow futile.
upofadown··on Government orders GitHub to remove Bluetooth-based chat app Bitchat: Jack Dorsey
To avoid a potential misunderstanding, the maintenance mode is intended to continue indefinitely. Briar project is not shutting down.

* https://briarproject.org/news/2026-maintenance-mode/

upofadown··on Aluminum foil (2021)
>...and conductive, rivaling copper.

That isn't true for either thermal or electrical conductivity. So I don't know what is meant here.

upofadown··on Web-based cryptography is always snake oil
But claiming that your system is end to end encrypted means that you are claiming protection from you and your system. This is mainly a truth in advertising issue.
upofadown··on Web-based cryptography is always snake oil
>...pretty much any E2E system is falling under this definition.

The definition is quite clear. It does not apply when the implementation is not distributed by the same entity that creates it for example. There are other related issues but the message here is that web based cryptography has a particular weakness when it comes to things like end to end encrypted messaging which makes it so bad as to be worthless.

upofadown··on Web-based cryptography is always snake oil
If, say, Signal was completely controlled by the CIA[1] and was thus evil, then having incoherent cryptography as described in the article would be a feature, not a bug. Being able to reject law enforcement requests would produce a false sense of security for the people the CIA was interested in surveilling. Responding effectively to law enforcement requests would reduce the value to the CIA of the ability to secretly backdoor Signal.

This effect was seen in the Apple vs FBI incident described in the article. The public perception of Apple as a brave defender of user privacy was greatly increased due to that dispute. For all we know, the FBI was in on the conspiracy. In return they might receive the fruits of such surveillance with the only limitation that they would have to disguise the source with parallel construction[2].

[1] https://en.wikipedia.org/wiki/Crypto_AG

[2] https://en.wikipedia.org/wiki/Parallel_construction

upofadown··on Web-based cryptography is always snake oil
How about GPG distributed with a Linux distribution like Debian as a counterexample? It would be fairly difficult to backdoor GPG in that case without getting caught. Everything happens in the open both at the GPG level and the Linux distribution level. The binaries are signed by the distribution and are distributed by a bunch of mirrors. An evil Debian maintainer would have to make a change that was well enough disguised as something else to evade scrutiny.
upofadown··on “Beyond the limit”: Satellites and mirrors in space pose threat to the night sky
>SpaceX plans to send one million more satellites into orbit, for space-based data centres, ...

I think we should wait to see how the first satellite data centre works out. It seems fairly unlikely that it could be practical. It seems kind of nuts...

>Reflect Orbital, a US start-up, aims to launch a constellation of very large mirror-like satellites to provide sunlight at night, with reflected beams that span at least five kilometres on Earth's surface.

Straight up nuts with no practical value, even if it did work out.

Page 1 of 34Next →