HN user

savara

103 karma
Posts17
Comments4
View on HN
thesciencemuseum.github.io 5y ago

Objects from the UK's Science Museum that have zero views: “Never Been Seen”

savara
2pts0
www.pathsensitive.com 7y ago

Book Review: Practical TLA+

savara
3pts0
support.apple.com 7y ago

Apple to require Certificate Transparency logged certs for apps and Safari

savara
3pts0
blog.cloudflare.com 8y ago

Cloudflare: Introducing Certificate Transparency and Nimbus

savara
1pts0
www.bloomberg.com 8y ago

Theranos Misled Investors and Consumers Who Used Its Blood Test

savara
97pts98
www.cs.ox.ac.uk 8y ago

Authentication vulnerability in most recent 5G drafts, found by formal methods

savara
4pts0
cr.yp.to 8y ago

DJB: “Some thoughts on security after ten years of qmail 1.0” (2007) [pdf]

savara
2pts0
alxdavids.xyz 8y ago

No Comments

savara
99pts22
www.diffblue.com 9y ago

Diffblue (Oxford University AI spin-out) raises $22M in Series A funding

savara
1pts0
github.com 9y ago

One-End Encryption (OEE): Stronger Than End-To-End Encryption

savara
2pts0
news.ycombinator.com 9y ago

Ask HN: What's the collective noun for Computer Scientists?

savara
2pts2
amazonfctours.com 9y ago

Amazon Fulfillment Center Tours

savara
5pts1
advances.sciencemag.org 9y ago

Blueprint for a microwave trapped ion quantum computer [pdf]

savara
1pts0
twitter.com 9y ago

Levchin Prizes: Joan Daemen (AES and SHA-3) and Moxie Marlinspike and Trevor Perrin

savara
17pts9
www.cs.ox.ac.uk 9y ago

Tracking anyone via mobile phone (WiFi-based IMSI Catcher)

savara
5pts0
eprint.iacr.org 9y ago

A Formal Security Analysis of the Signal Messaging Protocol

savara
2pts0
crcs.cz 9y ago

Classify Your RSA Key

savara
4pts0

Some questions I ask myself when reading random posts with grand and important claims on any subject:

Where is this from? Who originally wrote it? Is this text’s origin really a random Facebook post, from a pseudonymous author with a cartoon profile picture and no claim of any serious credentials in the subject at hand? (Whether epidemiology or anything else)

Regardless of the merits of the text’s post (which I do not claim to be able to judge) all evidence has to be analysed for context as well as content. Simple “common sense” claims (with a couple of big words to impress non-epidemiologists like me) are made to debunk the models: where is the evidence rather than rhetoric, even some basic citations, and/or examples of or links to counter-modelling? The post doesn’t even link to the original model files from Imperial that they’re claiming to critique.

It’s perfectly _possible_ that the claims made in this Facebook post are correct, but it doesn’t mean anyone should take this post (and its conclusions) remotely seriously without asking some very robust questions of it.

Sure, I agree -- but that's not what the page claims. It says "insecure protocol versions and choices of algorithms are not supported, by design" -- the protocols and modes that I listed are known to have various insecurities, and it still supports them. I agree that to be useful it's necessary to support old, less secure or even insecure modes, but this is at odds with the above stated goal.

My point is about the imprecise description.

The page claims: "[...] insecure protocol versions and choices of algorithms are not supported, by design",

followed by:

"TLS 1.0, TLS 1.1 and TLS 1.2 are supported", "3DES/CBC encryption algorithms are supported", and "SHA-1 [is supported]"

Sad-face.