HN user

gioi

447 karma
Posts21
Comments30
View on HN
www.hitchbot.me 11y ago

A robot is travelling Canada coast-to-coast, hitchhiking for 6000 km

gioi
2pts0
lists.openstreetmap.org 12y ago

The biggest violation of OpenStreetMap, ever

gioi
4pts0
github.com 12y ago

Firefox Accounts using remote server as source of randomness

gioi
1pts1
arstechnica.com 12y ago

Diceware passwords now need six random words to thwart hackers

gioi
2pts0
monkey-project.com 12y ago

Monkey: a fast and lightweight HTTP server for embedded devices

gioi
2pts0
www.pwn2own.com 12y ago

Pwn2Own results for Thursday (Day Two)

gioi
14pts0
www.pwn2own.com 12y ago

Pwn2Own results for Wednesday (Day One)

gioi
52pts21
en.wikipedia.org 12y ago

ECHELON

gioi
3pts0
uk.reuters.com 12y ago

Italy cancels "Google tax" on web companies

gioi
80pts28
www.italovignoli.org 12y ago

Redmond, we have a problem...

gioi
1pts0
www.linuxjournal.com 12y ago

Bit Prepared: Boy Scouting and Free Software (2004)

gioi
1pts0
joinup.ec.europa.eu 12y ago

UK government set on ODF document standard

gioi
3pts0
www.sympygamma.com 12y ago

SymPy Gamma: an open-source, Python-based alternative to Wolfram Alpha

gioi
156pts59
www.newyorker.com 12y ago

How to Get Serious About Rising Inequality

gioi
2pts0
ideas.time.com 12y ago

How to Explain What’s Happening in Ukraine (2013)

gioi
1pts0
openfontlibrary.org 12y ago

Open Font Library – Promoting your freedoms as it relates to the use of type

gioi
2pts0
techcrunch.com 12y ago

For Those Of You About To Rock, We Offer The Guitar Wing

gioi
1pts0
rtc.io 12y ago

Rtc.io – Open source WebRTC library

gioi
54pts29
maikmerten.livejournal.com 12y ago

Tinkering with a H.261 encoder

gioi
3pts0
www.zdnet.com 12y ago

How to reuse and upcycle your old hardware

gioi
1pts1
www.retroprogramming.com 12y ago

A History of Programming Games 1961-1989

gioi
54pts6

I'm not a physicist either. As a student, some years ago I asked my physics teacher if this conception was right, but I only got pretty elusive answers. It turns out that general relativity and quantum mechanics are not 100% coherent on this point. I suggest you to read this short, a-bit-technical-but-not-too-much essay on the problem: http://quasars.org/photon.txt

Thank you for your answer and for your time.

My language of choice for the bot was Clojure. I was interfacing with libaxolotl-java and basically rebuilding libtextsecure in Clojure (that was months ago).

Yesterday, when I discovered libtextsecure-java (while exploring Github repositories, by the way, I didn't notice your website had been updated in the meantime), I started a rewrite, using README as my primary source of documentation (the only piece of doc I could find, actually).

Ok, so what's this `KeyHelper`? Ok, I'll search on Github. Fine, it's actually `org.whispersystems.libaxolotl.util.KeyHelper` - luckily I knew it was in a completely different project. The same goes for `AxolotlStore`, which is actually `org.whispersystems.libaxolotl.state.AxolotlStore`, and it's not even mentioned on libaxolotl-java README because the latter is outdated.

Then: what is `TrustStore`? Good luck finding out that! Basically it is a wrapper around a binary file - which I had to download from TextSecure source repo without knowing what there was inside, and which by the way is encrypted with the password whisper (documentation: nowhere - thank you @AsamK for your textsecure-cli sources on github).

Ok, and finally figuring out - turning to TextSecure-Server docs - what is a signaling key, what are the specifics for the client-generated password (which by the way is sent over SSL via Basic authentication - probably not the most secure method ever, but probably there are many reason for that) and what is an install ID, I finally had the opportunity to debug obscure security problems on Java and to meet in person a Fedora bug https://bugzilla.redhat.com/show_bug.cgi?id=1167153). Not to mention the fact that apparently libtextsecure-java doesn't work over websockets but only over GCM (https://github.com/WhisperSystems/libtextsecure-java/pull/5) - however I won't be surprised if it did.

A really nightmarish experience. Maybe this summer I'll try to reimplement libtextsecure in another language and then document thoroughly my efforts. Who knows.

Just yesterday I was trying to get a bot working on the TextSecure platform. A vastly disappointing experience: almost not existing libraries, sparse and incomplete documentation, unstable protocol breaking without any kind of notice (https://github.com/JavaJens/TextSecure/issues/6, for example). And still no way to register without a phone, which would be amazing for this kind of project: https://github.com/WhisperSystems/TextSecure/issues/1085

I think Telegram is succeeding in what TextSecure is failing: attracting a widespread community of developers. This is only a confirmation, in my opinion.

EDIT: and, by the way, while Telegram security is no good, I wonder why we cannot have both (security & developer-friendliness)

It makes me remember John Locke's An Essay Concerning Humane Understanding[0]

The Indian before mentioned [...], saying that the world was supported by a great elephant, was asked what the elephant rested on; to which his answer was—a great tortoise: but being again pressed to know what gave support to the broad-backed tortoise, replied—SOMETHING, HE KNEW NOT WHAT

-- [0] http://www.gutenberg.org/cache/epub/10615/pg10615.txt, 2nd book, chapter XXIII, paragraph 2

Reynold (Diceware creator) says:

"Five words are breakable with a thousand or so PCs equipped with high-end graphics processors (criminal gangs with botnets of infected PCs can marshal such resources). Six words may be breakable by an organization with a very large budget, such as a large country's security agency. Seven words and longer are unbreakable with any known technology, but may be within the range of large organizations by around 2030. Eight words should be completely secure through 2050."

http://world.std.com/~reinhold/dicewarefaq.html#howlong

Don't seriously use this tool.

"People shouldn't use passwords that have been generated by a remote service unless they have very very good reasons to trust the tool and the transmission of the data." [0]

Passphrases are generated server-side, and this mines at the heart the security of the system. Are password saved? Yes? No? Who knows?

And you can trust a pair of dice more than an unknown website. Look up diceware on the web and see what I mean.

--

[0] http://discussions.agilebits.com/discussion/10684/password-w...

To be fair, PD is the only italian party whose direction has been elected democratically (I'm Italian and I voted to the last PD primarie).

What's wrong with this democratic process? Internal debate started only after approving law. Don't you think this is... wrong?

A personal note:

Francesco Boccia (the proposer), Enrico Letta (old prime minister) and Matteo Renzi come all from the same politic party, Partito Democratico. Web tax was proposed when Matteo Renzi was already the secretary of the Party.

I think the best approach to single-page apps is simplicity and elegance (and often they coincide). You will need some abstraction to achieve simplicity and elegance, and in the end you will be more productive. That's it.

<rant>I have a personal aversion for jQuery... It's awful because you probably don't need 99% of it.</rant>

I asked what's wrong with the idea, not with the implementation. I completely agree with the fact that this law should have been discussed at international level (at least EU+USA). I can realize from your words all your discouragement for the global ethical crisis. I really hope that future generations will be able to enforce this kind of measures. (BTW, may I ask you where are you from?)