Add nginx/apache with client certificate authentication in front of this and most of those concerns go away. Plus this way you don't have to worry about exposing the port but you need to distribute your client keys before hand.
HN user
andyrj
[ my public key: https://keybase.io/andyrj; my proof: https://keybase.io/andyrj/sigs/LLQp2XTAsfqGq9mcKtVAhztJ75PejCmA8zpeDCYghU8 ]
So next we will hear about this amazing new armor (aka. mirrors) on all our enemies vehicles?
Suspicious that aiohttp has peewee async, but falcon gets synchronous sqlalchemy for its orm test? Seems like a fairly biased way to benchmark. Too many variables to actually compare the frameworks as things beside the framework are drastically different.
I understand that this is not an attack on DH. I have not analyzed telegram but the statement I quoted seems to indicate it would need to be able to quickly generate many DH params. That doesn't seem to be a a computationally trivial task. http://security.stackexchange.com/questions/51129/can-you-ge...
It seems like for this attack to be realistic you would need the math underlying DH to be broken somehow. At which point I think there are many applicatons who's security would be compromised that are far more disturbing than the security of telegram.
Again I am asking for clarification because I may be misunderstanding the use of the quoted text and I have not looked at the code myself.
As I read it, this analsis seems akin to someone stating that, a wall provides no security if we lived in an alternative universe where solids could freely pass through one another. That statement maybe true but who cares, that universe wouldn't continue using walls for security measures anyways. Excuse my metaphor there, I hope it clears up what I was asking about.
Do we really need to make all threads with any relation to Google about the whole "90 days vs. Patch Tuesday"?
Google expended their resources to find a flaw in a MS product, in which MS was treated as any other vendor. If MS requires the ability to dictate the time alloted to fix their own mistakes, and are unwilling to change their own internal priorities for the sake of their own user base. Then perhaps, they should have found and fixed this prior to Google needing to point it out for them? I am amazed at the blind hatred for Google on this when MS has had a less than spectacular performance with its patches in the last year. Did all the MS fanbois forget about the bsod's just a few months back from MS's own "flawless", as you all seem to believe, patch schedule? (MS14-045 and MS13-036) If this deadline, self imposed by MS, is so greatly beneficial to MS patching why didn't the magic of patch Tuesday prevent those incidents?
Sounds like quite an amazing and brave individual. We need more of his caliber. Is there a translation of his writing available in English? I would be very interested in reading more of his "Crops and Seeds"
It isn't just the tor browser bundle that causes this. I believe it has more to do with either bots using tor to access google or google forcing captcha on access from known tor exit nodes. I have seen the same behaviour from vanilla firefox while trying to use google from tor. I would still rather input captcha than use bing!
I remembered hearing of the signal but thought it still had other plausible explainations. You are right the article does make it seem like everything but ET's is off the board, or atleat thats how I read it. Thanks for clarifying.
"If there was a way to efficiently cycle through DH parameters, an active man-in-the-middle attacker could spoof the fingerprint."
Isn't this a rather big if? In my limited understanding of the math involved, the whole reason dhe is still secure is because this isn't the case. Which means an attacker couldn't just use any old sha1 collision, it would have to corellate to a valid set of dh params, which would have an effect on the computational complexity, right?
So when do we start building the giant gyroscope to send Jody Foster through some wormholes? :) Joking aside, this is the first that I have read about any signals being unidentified in origin and not having an explaination other than ET's. Why isn't this bigger news here in the USA? I am hesitant to trust this information due to their own use of language like, "perhaps the WOW! signal." Is the bbc turning into the UK'S version of our "History" channel?
Anything other than your speculation to back up your belief in individuals neural plasticity having anything to do with the social advances you mention? Young people have not had a great record of voting. So those changes you are attributing to neural plasticity are likely brought about by those old frozen minds you mention, and less so the young plyable ones if you ask me. But everyone has a right to an opinion I suppose.
This is obviously the second stage of NORK's sophisticated cyber attacks.