HN user

MrXOR

2,546 karma
Posts257
Comments187
View on HN
dwheeler.com 5y ago

The Apple goto fail vulnerability: lessons learned (2014)

MrXOR
102pts39
www.cs.virginia.edu 5y ago

Time Management by Randy Pausch [pdf]

MrXOR
86pts6
caiorss.github.io 5y ago

C++ Papyrus

MrXOR
1pts0
harmful.cat-v.org 5y ago

Richard Stallman Agrees That C++ Sucks (2010)

MrXOR
1pts0
algmyr.se 5y ago

Algorithms in C++ (book) [pdf]

MrXOR
3pts1
github.com 5y ago

Tell HN: Fabrice Bellard Joined GitHub

MrXOR
2pts2
fs.blog 5y ago

E.O. Wilson on Becoming a Great Scientist

MrXOR
89pts27
math.ucr.edu 5y ago

Open Questions in Physics (2012)

MrXOR
2pts0
dl.acm.org 5y ago

Dennis Ritchie: Reflections on Software Research (1984)

MrXOR
3pts1
csgordon.github.io 5y ago

Computer Science textbooks that are freely available online

MrXOR
574pts53
eprint.iacr.org 5y ago

Cryptographic Competitions

MrXOR
3pts1
www.vox.com 5y ago

How to fight the Dunning-Kruger effect (2019)

MrXOR
2pts1
www.wired.com 5y ago

FBI Bitcoin Wallet (2013)

MrXOR
1pts1
howmuch.net 5y ago

Centralization of Bitcoin Wealth (2017)

MrXOR
1pts1
en.wikipedia.org 5y ago

List of Long Mathematical Proofs

MrXOR
1pts0
olvid.io 5y ago

Olvid: The most secure messenger in the world

MrXOR
1pts1
www.usenix.org 5y ago

Which Browsers Protect Your Privacy?

MrXOR
5pts3
www.mit.edu 5y ago

Metadata-Private Communication for the 99% [pdf]

MrXOR
1pts0
github.com 5y ago

Pung: A fully untrusted private communication system

MrXOR
11pts3
github.com 5y ago

Mundane: Rust cryptography library that is difficult to misuse

MrXOR
217pts77
github.com 5y ago

Dalek cryptography: Fast, safe, pure-Rust elliptic curve cryptography

MrXOR
1pts0
www.maths.ed.ac.uk 5y ago

Alan Turing's Letter to Winston Churchill (1941) [pdf]

MrXOR
1pts0
github.com 5y ago

RustCrypto: cryptographic algorithms written in pure Rust

MrXOR
5pts1
www.vice.com 5y ago

Nearly All of Wikipedia Is Written by Just 1 Percent of Its Editors (2017)

MrXOR
11pts1
andreaforte.net 5y ago

Why Do People Write for Wikipedia? (2005) [pdf]

MrXOR
3pts0
www.coindesk.com 5y ago

What Bitcoin’s White Paper Got Right, Wrong and What We Still Don’t Know (2018)

MrXOR
150pts210
web.archive.org 5y ago

Show HN: HN's Anti-Procrastination Features

MrXOR
1pts0
fpgawars.github.io 5y ago

FPGAwars: Exploring the Open Side of the FPGAs

MrXOR
121pts46
arxiv.org 5y ago

PageRank: Standing on the Shoulders of Giants (2010)

MrXOR
2pts1
spectrum.ieee.org 5y ago

How Europe Missed The Transistor (2005)

MrXOR
1pts1

Excuse me for changing the title of your essay. I should not do that.

The title was just my opinion. Some days ago, I read the excellent newsletter [1] of Filippo Valsorda about a Telegram's bug [2]. Yesterday, I googled for bugdoors and read about them and found this Apple's bug and your excellent essay (with many useful hyperlinks) about it.

[1] https://news.ycombinator.com/item?id=25726068

[2] https://habrahabr.ru/post/206900

My notes:

1- Competitions should not reduce security for the speed.

2- We need a portfolio of winners, not one winner.

3- Put the experts onto the selection committee.

4- The world has a limited number of cryptographic experts capable of carrying out, and willing to carry out, "public" security analysis.

5- The design of DES takes 17 man-years works and 6 years R&D by IBM and NSA.

6- Narrowing the encryption problem to a single, influential algorithm might drive out competitors, and that "would reduce the field that NSA had to be concerned about".

7- NSA primary mission has always been signals intelligence.

8- What if NIST/NSA know a weakness in 1/10000000 elliptic curves?

9- F^^k publish or perish.

10- We need Boring crypto, crypto that simply works, solidly resists attacks, never needs any upgrades.

djb is top expert in high speed cryptography. He was writing a book[1] on this topic, but I can't find his book. What happened to this book?

PS. It seems he prefers Serpent to Rijndael!

[1] https://cr.yp.to/highspeed.html

Niels Abel: "The divergent series are the invention of the devil, and it is a shame to base on them any demonstration whatsoever. By using them, one may draw any conclusion he pleases and that is why these series have produced so many fallacies and so many paradoxes."