In the NSA's defense, combining cryptosystems also creates attack surfaces, timing problems, additional complexity, etc
Actually, Dr. Nadim Kobeissi formally proved that hybrid is secure, even if ML-KEM fails. [1]
HN user
The only VPN that can’t spy on you is VP.NET since you can verify what is running on the servers using Intel SGX attention.
My comments are my own and do not reflect any of the organizations, or nations, I belong to unless I specifically clarify as such in a comment.
In the NSA's defense, combining cryptosystems also creates attack surfaces, timing problems, additional complexity, etc
Actually, Dr. Nadim Kobeissi formally proved that hybrid is secure, even if ML-KEM fails. [1]
I certainly find it fascinating that the majority of those in favor come from signal intelligence agencies, while the majority of those against are PhD cryptographers.
I was happy to see the lead of Europe’s PQC team also voted with the cryptographers.
It’s been like this for a while. Take a technology, call it a weapon and control it. Same playbook.
To be fair, whenever I join a pre-existing code-base [1], it's the same. I have no idea and have to map it out ;)
[1] Not AI codebases (and of course, AI code bases I guess)
The UK can’t block Dissent [1] since it looks like normal HTTPS traffic.
I agree hw attestation is net negative when forced upon end users. OTOH, when service providers use it, it results in transparency to end users [1] so it's really about how it is used.
TPM-backed full-disk encryption
This is going to be very useful for servers hosted in third party DCs.
Great question! We rebuild if there's a security update or otherwise every few weeks. We're working on a better method, but right now a few templates can be kept warm so users aren't forced to reboot.
Sounds like a good way to waste the only scarce resource: time.
Use latch to ssh, mosh or web into your machine. latch multiplexes terminal windows (like screen or tmux).
We built this for use on UnixShells [1].
All remote connections are verified against the authorized_keys and are, of course, end to end encrypted.
This is MIT licensed. There is also a relay that lets you connect to your latch sessions that are behind NAT - this has a small cost to it for infrastructure. However, you can use tailscale/ngrok or your own external IP for free.
I don't know if I agree or not with his views, but the fact that he's moving from complaining about something, to doing something about his beliefs, has convinced me to move from a negative to a significantly positive view of him, as a person; to reiterate, regardless of whether I agree with said views.
The will to fight for what one believes in - I think we can all agree that is an admirable human trait that would result, for those who do follow his views, in him being labeled as a hero and defender of people's rights.
Bravo, Garry.
I thought I was reading the Onion. :(
This reminds me of https://wiki.devilfruit.com
Cool project!
Some IRC networks still use naming as such like "server.state.country.dal.net."
This is a terrible day for the archival of the internet. Under the guise of copyright, significant information has been de-platformed.
There’s the VPN technologies and then there are VPN services [1]. Technology alone does not give you the service.
[1] https://vp.net/l/en-US/blog/The-History-of-VPNs-and-Logging
In the end, it's the same for Windows too since you need to pay for a cert.
We are introducing Verifiably Private AI [1] which actually solves all of the issues you mention. Everything across the entire chain is verifiably private (or in other words, transparent to the user in such a way they can verify what is running across the entire architecture).
This follows after djb pointed out that the NSA was weakening encryption by recommending and demanding PQ encryption alone instead of the hybrid PQ+ECC pair that is safer, with this being blocked despite considerable opposition by the actual experienced researcher participants in the group.
Bad times for the internet.
At various times in history, the White House has been known as the “President’s Palace,” the “President’s House,” and the “Executive Mansion.”
I wonder how much longer the structure will be known by its current name, given the growing trend of letting slanderous/fringe uses of words dictate their dominant meanings [1].
[1] For example, the end of the master branch.
The way digital data is decaying [1], books are disappearing and so on, the Internet Archive is critical infrastructure.
Happy Internet Archive Day! :-)
[1] servers gone, hosting sites gone, etc.
If a VPN provider can and does log when it receives complaints, it is no longer a “no log” VPN.
The archived posts are literally linked in the post.
Ad hominem does not change the fact that ProtonVPN admits to monitoring their users: "we check the network traffic on the server in question in realtime to verify the abuse report. If we see a VPN connection engaged in abusive behavior when we check, we find the userid associated with that connection and terminate the account." [1]
[1] https://www.reddit.com/r/ProtonVPN/comments/93pp40/comment/e...
Edit: Archived for posterity https://archive.is/xi92E
This is a great list of academic attacks, but it proves less than you think.
Yes, TEEs have been broken in dozens of ways. Side channels, transient execution, voltage manipulation, interrupt timing... etc. To be fair, you could make an equally impressive list for many security primitives.
The question isn't "can TEEs be broken?" since clearly they can, but rather what's your threat model and what are your alternatives?
What TEEs actually defend against is passive compromise. They force an attacker to actively exploit rather than just read memory. That legal and operational distinction matters enormously in practice.
The alternative to TEE is "no hardware isolation at all," and that's strictly worse for every threat model where TEEs provide value.
Additionally, you still get attestation which gives you cryptographic proof of what code is running.
Getting on the public suffix list is easier said than done [1]. They can simply say no if they feel like it and are making sure to be able to keep said rights as a "project" vs a "business," [2] which has its pros and cons.
[1] https://github.com/publicsuffix/list/blob/main/public_suffix...
[2] https://groups.google.com/g/publicsuffix-discuss/c/xJZHBlyqq...
Surveillance is the occupation of the mental space and results in modification of behavior. Default mass surveillance, or in other words suspicionless surveillance, then leads to the end of mental sovereignty and, therefore, freedom.
That is not a state governed by rule of law, but instead, a peoples being ruled by the power of surveillance.
They worked pretty hard as detailed in an archived article changing names and any records they could [1], but you're right - not good enough [2].
As pointed out on this reddit post [3], Proton's appears to contradict itself a number of times.
It's a good thing trust based VPN's are obsolete. After all, trust isn't constant [4] as seen in this article showing how Proton supplied IP addresses to "authorities."
[3] https://www.reddit.com/r/technology/comments/8x9aik/protonvp...
[4] https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
My comment still applies regardless of any level of “explaining” [1]:
1. Either Nord/Teso are loose with keys (horrible)
Or
2. Proton isn’t being truthful.
I don’t think it’s a conspiracy or anything that it is Tesonet/Nord. Rather, the problem is you cannot trust someone with your privacy if they can’t even manage their own keys.
[1] The explanation is poor at best and doesn’t explain why they worked so hard to try to delete all of the evidence (all of which was archived already). Additionally, nothing can explain away the lack of security with key management across these two orgs.