HN user

bascule

4,104 karma
Posts54
Comments575
View on HN
www.reddit.com 6y ago

Audit of the RustCrypto `aes-gcm` and `chacha20poly1305` crates by NCC group

bascule
1pts0
tonyarcieri.com 8y ago

The Tether Conundrum: a look into a suspicious cryptocurrency

bascule
80pts70
blog.chain.com 8y ago

Introducing Sequence: a cryptographicaly secure ledger-as-a-service

bascule
2pts0
blog.chain.com 9y ago

Introducing Ivy: a new smart contract language

bascule
60pts13
www.rfc-editor.org 9y ago

RFC 6920 – Naming Things with Hashes

bascule
3pts0
blog.chain.com 9y ago

Blockchains in a Quantum Future: Preventing Post-Quantum Cryptographic Attacks

bascule
13pts0
medium.com 9y ago

Hidden in Plain Sight: Transacting Privately on a Blockchain

bascule
28pts0
tonyarcieri.com 9y ago

Key rotation, user experience, and crypto reporting

bascule
4pts0
tonyarcieri.com 9y ago

Flaws in deterministic password managers

bascule
196pts102
tonyarcieri.com 9y ago

Introducing TJSON, a stricter, typed form of JSON

bascule
140pts129
www.spinute.org 9y ago

Automatic-selection mechanism for data structures in MRI (Ruby GSoC project)

bascule
11pts0
tonyarcieri.com 10y ago

A gentle introduction to nio4r: low-level portable asynchronous I/O for Ruby

bascule
6pts0
tonyarcieri.com 10y ago

A tale of two cryptocurrencies: Ethereum and Bitcoin’s ongoing challenges

bascule
144pts73
tonyarcieri.com 10y ago

On the dangers of a blockchain monoculture

bascule
195pts63
tonyarcieri.com 11y ago

Speculation About The Eventual Death Of Bitcoin

bascule
72pts108
square.github.io 11y ago

Keywhiz: Square's system for distributing and managing secrets

bascule
232pts31
tonyarcieri.com 11y ago

Volapük: A Cautionary Tale for Any Language Community

bascule
3pts0
tonyarcieri.com 11y ago

CREAM: the SSL attack you’ve probably never heard of

bascule
90pts48
clearcryptocode.org 12y ago

Nuke TLS from Orbit

bascule
5pts0
tonyarcieri.com 12y ago

What's wrong with in-browser cryptography?

bascule
73pts43
pornblur.com 13y ago

Show HN: my friend made an adult blog search engine but was afraid to post it

bascule
13pts4
tonyarcieri.com 13y ago

Imperfect Forward Secrecy: The Coming Cryptocalypse

bascule
22pts8
tonyarcieri.com 13y ago

The cloud isn't dead. It just needs to evolve

bascule
2pts1
www.youtube.com 13y ago

Whistleblower William Binney on NSA Internet surveillance program Stellar Wind

bascule
9pts1
en.wikipedia.org 13y ago

Stellar Wind (code name)

bascule
404pts167
blog.gmane.org 13y ago

Any data structure can now be automatically "Merkelized" via new compiler

bascule
2pts0
tonyarcieri.com 13y ago

Let's figure out a way to start signing RubyGems

bascule
8pts0
blog.twelephone.com 13y ago

How We Survived TechCrunch

bascule
2pts0
tonyarcieri.com 13y ago

"DCI" in Ruby is completely broken

bascule
83pts66
tonyarcieri.com 13y ago

2012: The year Rubyists learned to stop worrying and love threads

bascule
99pts26

It's almost quaint how this December 2019 article talks about "the concern surrounding the creation of large swaths of Tether in 2017", when about $2.5 billion of Tether was issued.

In the time since it was published, when Tether had issued about $4.5 billion total, there have been over $14 billion additional Tether, a 4X expansion of the total supply, or 7.5X what was described as "large swaths of Tether" in this article.

There's an entire section in my 2019 blog post about this:

https://tonyarcieri.com/rust-in-2019-security-maturity-stabi...

rust-crypto has the most upstream dependencies, but is an unmaintained, abandoned project.

There are a number of other awesome cryptography projects in Rust (in fact some of the most advanced cryptography in the world is being developed in Rust), but they suffer from an awareness problem.

The Go standard library's cryptography, while full-featured and very mature, does suffer from a particular problem: it's a mixture of high-level and low-level APIs all within a single namespace / module. This makes it difficult to compare to Rust projects, because it's an enormous omnibus library, whereas in Rust there is no equivalent to that because the projects are more compartmentalized, and in my opinion that arrangement is preferable to what the Go standard library is doing. See also:

https://cryptocoding.net/index.php/Coding_rules#Avoid_mixing...

The closest thing to an all-in-one crypto library is ring. There's a notable difference between ring and the Go standard library though: ring presents a very high-level, hard-to-misuse API. This makes ring unsuitable for usages where you want "shoot yourself in the foot" cryptographic primitives which are difficult to use correctly and fail catastrophically unless used as such.

For the Rust equivalent of these "shoot yourself in the foot" cryptographic interfaces like Go "crypto/cipher" types such as Block, BlockMode, and Stream, take a look at the Rust Cryptography project:

https://github.com/RustCrypto

Miscreant is built on top of these, and presents an AEAD interface, which could eventually be upstreamed into RustCrypto so Miscreant just implements it.

I think what you're after is:

https://docs.rs/miscreant/0.4.2/miscreant/aead/trait.Aead.ht...

These take a byte slice, and return an (allocated) byte vector.

The APIs you're talking about are special in-place ones for Miscreant's #![no_std] support, i.e. for embedded use or other usages which want to avoid heap allocations.

It's nice to support both of these usage patterns, because the allocating version has nicer ergonomics, but not everyone in the world has a heap.

One possible solution: get Bluetooth headphones instead, such as the equivalent Bluetooth Audio-Technica headphones to what's pictured in the post, the ATH-DSR9BT:

https://www.audio-technica.com/cms/headphones/6117c014c965cd...

"The ATH-DSR9BT over-ear wireless headphones employ Audio-Technica’s new Pure Digital Drive system, which allows the headphones to operate without a sound-degrading D/A converter that conventional wireless headphones rely upon. Instead, the ATH-DSR9BT utilizes Trigence Semiconductor’s Dnote chipset to receive the digital audio signal from a Bluetooth wireless transmission, process and transfer it to the driver where the digital pulses of the chipset move the voice coil and diaphragm forward and backward to create the sound waves heard by the listener."

you need a remedy for the inherent insecurity of credit cards

Fraud and theft are fairly general problems. I would direct your attention to /r/sorryforyourloss

In other words, are merchants eating all the costs of fraudulent credit card transactions?

If the goods cannot be recovered, then yes, the merchant eats the costs.

I guess either way the cost really gets passed on to us consumers in the end.

Someone will always be left holding the short end of the stick when fraud occurs. The alternative to shifting the liability to the merchant is the consumer being directly accountable (rather than vicariously as you're suggesting).

Dropping Acid 8 years ago

The TB-03 provides a fairly faithful and accurate reproduction of the TB-303's sound.

The TT-303, on the other hand, despite being "circuit identical", can sound downright weird at times (as can Roland's other "analog modeling" 303 reproduction, the TB-3)

Here is a 4 way comparison of the 4 synths I just mentioned complete with waveform visualizations:

https://www.youtube.com/watch?v=r8CAEUU_ics

Dropping Acid 8 years ago

Most early house songs were ~120BPM. This includes:

Frankie Knuckles - Your Love, Jesse Saunders - On and On, Mr. Fingers - Can You Feel It, Marshal Jefferson - Move Your Body (The House Music Anthem)

This article covered more than I was expecting, but still manages to squeeze a small amount of substance into a relatively large article. Here's a tl;dr:

- Penrose and Hameroff postulate microtubules might have quantum mechanical behavior in their Orch-OR hypothesis. This hypothesis was refuted by Max Tegmark in the 90s. Penrose doesn't care and keeps preaching his hypothesis, and has not put forth any new scientifically compelling arguments in the past 2 decades.

- Photosynthesis is shown to be quantum mechanical. I'm not sure quantum mechanical behavior in plants is the best argument that quantum mechanics are responsible for consciousness.

- Fischer hypothesizes that phosphate ions in biological cells might exhibit distinctly quantum mechanical behavior, but is wary about any link to "quantum consciousness".

This is pretty much all of the substance of the article.

Even if there were a conclusively demonstrated link between quantum mechanical behavior in human cells (there isn't), using that to argue that our brains are quantum computers and that consciousness is a fundamentally quantum phenomenon would be a huge non sequitur.

From my benchmarks (oh hi I'm the author of a multi-provider elliptic curve digital signature library for Rust), ed25519-dalek (with curve25519-dalek's AVX2 backend) seems to be winning:

https://twitter.com/bascule/status/1024313525554925568

...for both signing and verification, beating out the fiat-crypto P-256 implementation (in ring, a Rust cryptography library that wraps BoringCrypto).

libsecp256k1 seems slightly slower than fiat-crypto's P-256, even with the endomorphism optimization enabled. The Rust crate presently provide knobs for either of these things, hence the low Signatory benchmarks.

These curves predate Broker-Stevanhagen, however all of the implementations I'm comparing are production(-ish) quality.

There have been some poorly received hypotheses to this effect, most notably Roger Penrose's Orch-OR: https://en.wikipedia.org/wiki/Orchestrated_objective_reducti...

That said, most attempts at quantifying whether or not distinctly quantum mechanical processes in the brain related to things like microtubules and NMDA receptors are significant to cognition (i.e. is the brain a quantum computer?) have generally concluded the answer is no:

See:

https://arxiv.org/abs/quant-ph/9907009

https://onlinelibrary.wiley.com/doi/pdf/10.1207/s15516709cog...

I want to be a fan of csexps. I'm a big fan of SPKI/SDSI conceptually. Unfortunately I lack your enthusiasm for trying to evangelize them, and think JSON is probably here to stay.

That said, regarding JSON and the inclusion of self-describing encoding information for e.g. Base64, I created a microformat for that:

https://www.tjson.org/

Spoilers: it was (at least in regard to software development)

At least post-1975 software development had the Mythical Man-Month to reflect on.

Furthermore, advances in memory safe languages and type safe languages can both be considered good things. Unfortunately, Go is "almost there but not quite" in these two departments.

"Works" in a one-off trial or with daily use? What I'm talking about is an unacceptable failure rate in the course of daily usage (by which I mean failures at least once or twice a day, sometimes considerably worse, over the course of establishing several dozen SSH connections daily)

If your OS X daily driver setup is truly stable, can you share all of the details? What OS X version? Yubikey model? GPG version? OpenSSH version?

I know at least a dozen people who have shared my experience so if there is a magic path to stabilizing it, I'm all ears.