HN user

baby

15,239 karma

cryptologie.net

Posts229
Comments8,675
View on HN
blog.zksecurity.xyz 10h ago

AI meets Cryptography 3: What AI Found in Bron Labs's bron-crypto

baby
7pts0
blog.zksecurity.xyz 1d ago

Nine Years to Halve a Hash Function: RFC 9861 Is Out

baby
5pts0
www.youtube.com 1d ago

Explanation about Groth16, the most used zero-knowledge proof [video]

baby
6pts0
blog.zksecurity.xyz 20d ago

Zk.golf: Fearless and Collaborative Optimization of Circuits

baby
4pts2
blog.zksecurity.xyz 1mo ago

Explainer of the most widely used zero-knowledge proof system

baby
3pts0
blog.zksecurity.xyz 2mo ago

Breaking Jolt's Verifier with an Unbound Uni-Skip Claim

baby
2pts0
blog.zksecurity.xyz 2mo ago

Groth16, Intuitively

baby
8pts0
blog.zksecurity.xyz 2mo ago

The Final Form of Software Development

baby
7pts1
blog.zksecurity.xyz 2mo ago

Sum-Check as an Algebraic Tensor Reduction: Part I

baby
2pts0
mimoo.github.io 4mo ago

Ghostmd: Ghostty but for Markdown Notes

baby
24pts44
blog.zksecurity.xyz 5mo ago

Lean4 Formalization of "A Simplified Round-by-Round Soundness Proof of Fri"

baby
1pts0
techpants.io 9mo ago

Techpants.io

baby
3pts0
www.theregister.com 10mo ago

Feds say 100k-card farms could have killed cell towers in NYC near the UN

baby
3pts3
news.ycombinator.com 10mo ago

Ask HN: Is America Going to Become an Autocracy?

baby
59pts51
www.cryptologie.net 10mo ago

Supply chain attacks are the new big thing (2022)

baby
1pts0
plonk.zksecurity.xyz 11mo ago

How to PLONK (zero-knowledge proofs tutorial)

baby
3pts0
www.cryptologie.net 1y ago

Messing with AIs

baby
5pts1
blog.zksecurity.xyz 1y ago

Bug Hunt: Zero-Knowledge, Full-Paranoia, and the AI That Stares Back

baby
4pts0
blog.zksecurity.xyz 1y ago

Proofs on a Leash: Post-Quantum Lattice Snark with Greyhound

baby
2pts0
news.ycombinator.com 1y ago

Ask HN: Which agentic framework/tool do you prefer and why?

baby
1pts0
www.cryptologie.net 1y ago

The trap of the top-down approach

baby
11pts1
davidwong.fr 1y ago

Learn How to Break AES

baby
179pts54
www.zksecurity.xyz 1y ago

Bugs.zksecurity.xyz a knowledge base for ZK bugs

baby
1pts0
simpy.readthedocs.io 1y ago

SimPy is a process-based discrete-event simulation framework in Python

baby
11pts3
news.zksecurity.xyz 1y ago

ZkNews: HN for Advanced Cryptography

baby
3pts0
en.wikipedia.org 1y ago

Joseph Stalin's Cult of Personality

baby
1pts0
www.cryptologie.net 2y ago

Why I'm Writing a Book on Cryptography (2020)

baby
35pts8
news.zksecurity.xyz 2y ago

Show HN: Tired of pump and dump and scammy crypto news? Here's ZK news

baby
2pts5
www.youtube.com 2y ago

Short introduction to secure multi-party computation (MPC) in two videos

baby
2pts0
news.ycombinator.com 2y ago

Google Maps' saved places is capped at 2k

baby
3pts0

I don't think they value displaying nationalism more, nationalists tend to be very vocal and visible, it's just that the US is full of nationalists. It really is the biggest issue with the US, and why the orange man is president.

The US is weird about its flag, I think because nationalism wasn't seen as a bad thing up until recently. These days it's much weirder to see an American flag, and usually you know it has something to do with MAGAs. The weird thing to me is how you see one massive one in the luggage retrieval area when you arrive in JFK (in New York). Always makes me sigh

I've owned a bunch of gopros and I feel like they've always had the same kind of bugs. Random crashes, things not working anymore. It's really bad, so bad that I had plenty of videos that were missing sound, or just corruption in general.

Then they started this subscription thing and I was like, finally, they're going the SaaS way, they will make so much money, and they will be able to improve that camera that basically never seems to improve much version after version. I bought a bunch of put options, and I lost all my money, every time I put back some in the put options.

Now I have the insta360 go ultra and... I think go pro is going to die. It's just so good.

I've been very curious about these, because of course these are measures that are anti-tech in a number of ways (or at least unpopular in the tech circle).

I have trouble understanding why Sanders has decided to be vocal about these, especially as he's been on the right side of the societal debate fence since forever. My guess is that he cares more about what AI is going to do for the common people, and he knows that we need to have this debate early (obviously, technology seems to increase disparity in places like the US). But still I'm not sure he's taking a stab at it in the right way.

For New York state (not city, no Mamdani), it seems like it's a much more pragmatic view: it increases people's costs (energy, water, etc.) and there's too much tax exemption(/evasion) for data centers currently.

I work on www.zkao.io so I can expand on this: it's basically like an audit, you click a button and ~9h later you get a report with findings. It's supposed to be better at finding bugs (especially cryptographic bugs) than frontier models AND it's supposed to be better at discarding false positives.

It might not be super clear for people who don't know about formal verification with Lean or about arithmetic circuits, but this project let's you optimize code in a secure way: if you have code that's faster, not only you have a proof that it is indeed faster, but you also have a proof that it is correct and secure by construction!

It's important that the circuits implement the logic "securely" because arithmetic circuits are used in cryptography (in ZKP, MPC, FHE, for example) to implement programs with additions and multiplications (instead of NAND gates for example)

There are different ways to think about this:

1. Imagine what the protocol would look like without privacy (zk allows you to “sign” a computation, so just do the computation in the clear)

2. Imagine what the protocol would look like by revealing a hash of the passport only (the idea of a “nullifier”, a unique identifier that hides the data and and can be revealed to prevent replays)

The first one should already answer your question: the way you would prevent replays or portability (I use your proof) is to attach some sort of session context to your proof

Tried playing split fiction on the switch 2 and it was so horrible I haven’t played anything since then. I’m picking it up again today for starfox but basically only use it for nintendo games.

Sounds like you never tried the deck and the switch. So many games are unplayable on the switch besides nintendo official games. I dropped split fiction because it ran so horribly on the switch

The deck is such a good console compared to the switch and switch 2 that I can’t be stop being happy that they released this now. How is Valve, a tiny company, doing so much better than Nintendo?

Lefty tenant here. I def. stopped paying my rent a few times until my landlord fixed their shit or agreed to stop scamming me.

Last time I did it I signed a lease for a year, with 2 months of advance notice if I decided to leave (in the UK). I told them 2 months before the end of my lease, and they told me I had to wait for the end of my lease, then wait 2 months, and then I could be out.

I just stopped paying rent, and left them a horrible one star review on gmaps.

One day he showed up at my place (with soup who was coming to fix something) and tried to enter. I told him to stay out. And then he started crying and telling me how I could not just stop paying rent. I could tell how hard it was to be a small landlord.

I told him that I would resume paying if they signed smthg to agree to let me break the lease at the year end AND reimburse me the fees that appeared at the least minute, a year ago, right as I was signing the lease in front of them.

They agreed, reimbursed me my caution/deposit at the end, easy.

Would recommend just stop paying your rent if anything ever happens. I would do it again.

Our experience has been that without a good harness you don't really get much out of codex/claude. And you really need to spend time and energy figuring out why coding agents can't find bugs like you can.

Every week I see bugs (as an auditor) that our own harness (https://zkao.io/) can't find, and we have to figure out pretty interesting techniques in order to make the tool find them. Mind you I'm talking mostly about cryptographic vulnerabilities, not just webapp bugs. So IMO it's going to make a lot of sense for companies to have both their own harness (as tptacek is talking about) and pay for services that focus on making a good harness from experience (and audit firms are going to be the best at doing this, as they see a lot of bugs and can spend time "teaching" their harness about these bugs)

On the other hand, you have to find equally as good techniques to triage, because otherwise you just have some machinery that I call "vibe auditing" that just produces enough false positives to tire all the developers (who are already overwhelmed with crappy AI submissions in bugbounties and other AI tool that review all of their PRs).

At the end of the day, when your harness doesn't return any bug, you're left wondering "does it mean there's no bugs?" We're basically back in this reputation game, where you want to use the best tool, or the best team (that knows what the best tools are), and need to figure out which one is.