Sign in

Yawning Angel

@yawning.bsky.social
79 followers 14 following 304 posts

Screaming into the void.

PostsRepliesMedia
Yawning Angel @yawning.bsky.social · 12/11/2024
Why is it that MacOS detects my keyboard as a JIS layout one, but refuses to apply the layout so all the punctuation is in the wrong places, and the only solution is to install a `.keylayout` file? Even Windows lets me select my keyboard layout manually. msyk.net/macos/winkey...
100
Yawning Angel @yawning.bsky.social · 08/10/2024
How do you fuck up AF_UNIX to the point where you can kernel panic from userland, when you steal your OS code from 30+ years of prior work (Not a Rust Bug, but an Apple bug). github.com/rust-lang/ru...
000
Yawning Angel @yawning.bsky.social · 20/09/2024
In a further sign of Japan's descent into the grim dark cyberpunk future, the Tokyo Govt is now running an AI powered matchmaking service/dating app. Signing up requires photo ID, proof of income, govt. issued proof of being single, and money. www.futari-story.metro.tokyo.lg.jp/ai-matching/
futari-story.metro.tokyo.lg.jp
AIマッチングシステム|TOKYOふたりSTORY|TOKYO縁結び
東京都が提供するAIマッチングシステムです。婚活を始める「最初の一歩」としてご利用ください。
100
Yawning Angel @yawning.bsky.social · 19/08/2024
And people say that panaceas are a myth.
000
Yawning Angel @yawning.bsky.social · 19/08/2024
Real life has been "interesting" for the last month in a not amazing way, apologies in advance if responses from me are going to be somewhat slower than usual.
020
Yawning Angel @yawning.bsky.social · 19/08/2024
If the TV loicense people are hurting so much for money as the news says, how can they afford to send me junk mail asking me to get a TV loicense. I do not own a TV or any device capable of receiving broadcast TV. NHK can Fuck Off.
000
Reposted by Yawning Angel
ePrint Updates @eprint.ing.bot · 10/07/2024
Switching Off your Device Does Not Protect Against Fault Attacks (Paul Grandamme, Pierre-Antoine Tissot, Lilian Bossuet, Jean-Max Dutertre, Brice Colombier, Vincent Grosso) ia.cr/2024/1123
Abstract. Physical attacks, and among them fault injection attacks, are a significant threat to the security of embedded systems. Among the means of fault injection, laser has the significant advantage of being extremely spatially accurate. Numerous state-of-the-art studies have investigated the use of lasers to inject faults into a target at run-time. However, the high precision of laser fault injection comes with requirements on the knowledge of the implementation and exact execution time of the victim code. The main contribution of this work is the demonstration on experimental basis that it is also possible to perform laser fault injection on an unpowered device. Specifically, we targeted the Flash non-volatile memory of a 32-bit microcontroller. The advantage of this new attack path is that it does not require any synchronisation between the victim and the attacker. We provide an experimental characterization of this phenomenon with a description of the fault model from the physical level up to the software level. Finally, we applied these results to carry out a persistent fault analysis on a 128-bit AES with a particularly realistic attacker model which reinforces the interest of the PFA.
Image showing part 2 of abstract.
043
Yawning Angel @yawning.bsky.social · 10/07/2024
It's kind of impressive that the only package I need to implement Dual_EC_DRBG in Go "securely" is @filippo.abyssdomain.expert 's bigmod package, since the `crypto/ecdh` package exposes just enough for the rest. nb: I do use `crypto/elliptic` for the scalar-field order, but that can be removed.
010
Yawning Angel @yawning.bsky.social · 10/07/2024
I just spent my afternoon trying to figure out how to use HTTP over AF_UNIX in Rust, and ran into a giant tire fire. My brain lacks wrinkles for Rust and it's ecosystem. ps: Thanks to comments in a still-open bug in reqwest from 2017, I think I figured it out at least.
110
Yawning Angel @yawning.bsky.social · 08/07/2024
Time to find out how much MS uses Github repos for training Copilot, and how many people blindly copy-paste code for things that they shouldn't.
Package dual_ec_drbg implements the NIST SP 800-90A Rev 1 Dual_EC_DRBG algorithm (also specified in ISO/IEC 18031:2005).
020
Yawning Angel @yawning.bsky.social · 03/07/2024
Neat.
000
Yawning Angel @yawning.bsky.social · 03/07/2024
Sending me a profanity laced tirade about how your software broke because a downstream dependency of something I maintain moved it's repo, is not an effective way to motivate me to help you.
200
Yawning Angel @yawning.bsky.social · 18/06/2024
www.bbc.com/news/article... 10k -> 13k SHU is enough to prompt a Govt. initiated recall? WTF.
bbc.com
Samyang: Denmark recalls Korean ramen for being too spicy
The food authorities said the instant ramen contained such high capsaicin levels consumers could be poisoned.
000
Reposted by Yawning Angel
Filippo Valsorda @filippo.abyssdomain.expert · 03/06/2024
Well damn, the era of compiler-introduced timing side-channels is here. In the Kyber reference implementation, Clang notices a bitmask is just selecting between zero and a constant and turns it into an if. Very happy the Go compiler is not that smart right now. groups.google.com/a/list.nist....
groups.google.com
Compiler-introduced timing leak in Kyber reference implementation
68916
Yawning Angel @yawning.bsky.social · 27/05/2024
An old friend noted that there is a distinct feeling of "I just lost a SAN point". Not only is that true, but lately I'm experiencing that a lot more than I should.
000
Yawning Angel @yawning.bsky.social · 22/05/2024
As an addendum, as far as personal (non-employer) projects go, Rust has been the safest language I have used because I rage-quit and delete everything due to friction before my code gets far enough to have bugs.
010
Reposted by Yawning Angel
Daniel Martí @handle.invalid · 22/05/2024
I feel like writing Go full-time for a decade has made me less capable of using difficult languages, but I like it this way - I can focus on what I'm trying to achieve instead.
192
Yawning Angel @yawning.bsky.social · 22/05/2024
After using Go for things that require concurrency and networking, dealing with async, tokio and hyper makes me seriously question my life decisions, and want to consume various mind altering substances in large quantities.
230
Yawning Angel @yawning.bsky.social · 02/05/2024
A ha. forums.developer.apple.com/forums/threa...
forums.developer.apple.com
DTrace freezes M1 MacOS Ventura 13… | Apple Developer Forums
000
Yawning Angel @yawning.bsky.social · 02/05/2024
If I ever design a programming language, my benchmark for success will be "pervasive enough that my terrible design decisions lead to dedicated silicon workarounds for performance reasons". developer.arm.com/documentatio...
developer.arm.com
Documentation – Arm Developer
010
Yawning Angel @yawning.bsky.social · 02/05/2024
I like how trying to use dtruss has a reasonable chance of making my system unusable till I power-cycle the thing.
000
Yawning Angel @yawning.bsky.social · 01/05/2024
> My investigator's motto is not "99% Mythos Lore, 1% Sanity- don't push me" Has become an increasingly accurate description of my professional career over the years.
000
Reposted by Yawning Angel
Filippo Valsorda @filippo.abyssdomain.expert · 22/04/2024
youtube.com
GopherCon 2023: Filippo Valsorda - High-Assurance Go Cryptography
The cryptography standard library is arguably some of the most critical code written in Go. How do we ensure it’s safe and bug-free? In this presentation, we...
0207
Yawning Angel @yawning.bsky.social · 22/04/2024
Comparing performance of RSA-2048 and secp256kr1 when: - Both are implemented in Mathematica - secp256k1: affine coordinate add/double - secp256k1: add then double scalar multiply Only shows that ECC is really fast, despite the best efforts to the contrary.
320
Yawning Angel @yawning.bsky.social · 22/04/2024
One of these years, I seriously should just give up on hosting my own e-mail. I just don't want to deal with the headache of migrating my mailserver state. :/
110
Reposted by Yawning Angel
ePrint Updates @eprint.ing.bot · 16/04/2024
A Note on Quantum Algorithms for Lattice Problems (Omri Shmueli) ia.cr/2024/583
Abstract. Recently, a paper by Chen (eprint 2024/555) has claimed to construct a quantum polynomial-time algorithm that solves the Learning With Errors Problem (Regev, JACM 2009), for a range of parameters. As a byproduct of Chen’s result, it follows that Chen’s algorithm solves the Gap Shortest Vector Problem, for gap g(n) = Õ(n^(4.5)). In this short note we point to an error in the claims of Chen’s paper.
021
Yawning Angel @yawning.bsky.social · 13/04/2024
The Bandai HG ATM-09-ST kit was pretty fun to build, and VOTMS (and the spinoffs) are in my top 3 giant robot animes of all time.
100
Reposted by Yawning Angel
Deirdre Connolly¹ ² @durumcrustulum.com · 11/04/2024
re: eprint.iacr.org/2024/555.pdf, a quick tl;dr: non-fancy crypto fine (Kyber, Dilithium); (efficient) fancy crypto (besides ZKP's) may be boned ~forever (if this attack holds) (based on lattices / LWE specifically, when your q vs n has a sufficient gap)
31711
Yawning Angel @yawning.bsky.social · 11/04/2024
Despite the automatic 2 month extension and using the "throw money at the problem and have an accountant do it" approach, having to file taxes twice every year fills me with immeasurable rage and hatred.
000
Reposted by Yawning Angel
ePrint Updates @eprint.ing.bot · 10/04/2024
Share with Care: Breaking E2EE in Nextcloud (Martin R. Albrecht, Matilda Backendal, Daniele Coppola, Kenneth G. Paterson) ia.cr/2024/546
Abstract. Nextcloud is a leading cloud storage platform with more than 20 million users. Nextcloud offers an end-to-end encryption (E2EE) feature that is claimed to be able “to keep extremely sensitive data fully secure even in case of a full server breach”. They also claim that the Nextcloud server “has Zero Knowledge, that is, never has access to any of the data or keys in unencrypted form”. This is achieved by having encryption and decryption operations that are done using file keys that are only available to Nextcloud clients, with those file keys being protected by a key hierarchy that ultimately relies on long passphrases known exclusively to the users.

We provide the first detailed documentation and security analysis of Nextcloud’s E2EE feature. Nextcloud’s strong security claims motivate conducting the analysis in the setting where the server itself is considered malicious. We present three distinct attacks against the E2EE security guarantees in this setting. Each one enables the confidentiality and integrity of all user files to be compromised. All three attacks are fully practical and we have built proof-of-concept implementations for each. The vulnerabilities make it trivial for a malicious Nextcloud server to access and manipulate users’ data.

We have responsibly disclosed the three vulnerabilities to Nextcloud. The second and third vulnerabilities have been remediated. The first was addressed by temporarily disabling file sharing from the E2EE feature until a redesign of the feature can be made. We reflect on broader lessons that can be learned for designers of E2EE systems.
Image showing part 2 of abstract.
041
Yawning Angel @yawning.bsky.social · 10/04/2024
I have a soft spot for hobbyist projects. github.com/SerenityOS/s...
010
Yawning Angel @yawning.bsky.social · 10/04/2024
大草原
nvd.nist.gov
NVD - CVE-2024-24576
000
Reposted by Yawning Angel
str4d @str4d.xyz · 02/04/2024
"Apologies, I cannot answer your maintenance inquiries for international security reasons."
0191
Reposted by Yawning Angel
Filippo Valsorda @filippo.abyssdomain.expert · 02/04/2024
Reading the timeline of the pressure campaign to convince the xz maintainer to hand over control is… awful. Merciless guilt-tripping. One lesson I’m taking from this is to be even more ruthless with blocks. Whining about maintenance? Blocked. Zero chances. research.swtch.com/xz-timeline
research.swtch.com
research!rsc: Timeline of the xz open source attack
612634
Yawning Angel @yawning.bsky.social · 01/04/2024
@durumcrustulum.com I read through the latest FROST IETF draft, and the bs255 Schnorr scheme isn't different in meaningful ways from Appendix C. The main difference is the choice of H2 and the inputs, but it would be easy to define FROST bs255.
120
Yawning Angel @yawning.bsky.social · 30/03/2024
Is there a way to make implementing all the Web PKI stuff not an absolute nightmare? Being doomed to dealing with P-384. P-521, RSA, ASN.1 and X.509 is depressing.
000
Yawning Angel @yawning.bsky.social · 22/03/2024
On the GoFetch note. It's depressing that the only way to get microcode updates for consumer AMD CPUs is via BIOS update. The linux-firmware/amd-ucode etc packages do absolutely nothing, because those only include updates for EPYC/Threadripper.
110
Yawning Angel @yawning.bsky.social · 14/03/2024
This is the draft bs255 specification. I will likely add to it at some point, and I still need to double check that the reference implementation matches the spec, and generate test vectors. Hopefully it's at least readable. gitlab.com/yawning/bs25...
000
Yawning Angel @yawning.bsky.social · 14/03/2024
Been using OSX on the side for about a week, and I don't totally hate it. - The scroll-wheel was inverted by default. - Choosing between "my tinfoil hat crinkles less" and "dtruss works" sucks, as does the 2x reboots to switch. - Super instead of Ctrl really screws with muscle memory.
010
Yawning Angel @yawning.bsky.social · 11/03/2024
How do you manage to fuck up your programming language's ecosystem to the point where there is a package manager for package managers?
010
Yawning Angel @yawning.bsky.social · 10/03/2024
Design question: How to handle cryptographically insignificant probability internal failures (Eg: deriving a nonce via wide-reduction, it produced 0)? Rejection sampling or abort? I currently do the former (read more from the XOF) with `MAY choose to abort instead`. > Abort, Retry, Fail?
321
Yawning Angel @yawning.bsky.social · 10/03/2024
bs255 progress: - Tweaked the synthetic nonce generation to include the per-signature domain separator (Fix for the deterministic signature case). - Added test cases so all reasonable cases/failure modes are covered. - Misc code cleanups. Next: - Write a specification document.
140
Yawning Angel @yawning.bsky.social · 09/03/2024
While batch verification is out of scope atm for bs255, 4-way parallel keccak (AVX2) fits in nicely when re-deriving the `e` values. If ds/msg in a batch are the same, `e = H(ds, msg, R, P) mod n` would allow more optimization for large ds and msg, but large is like > 89-ish bytes combined...
210
Yawning Angel @yawning.bsky.social · 08/03/2024
As promised: gitlab.com/yawning/bs255 This still is a work in progress and probably has stupid bugs, and needs: - More test cases. - A specification document. But, it was relaxing to write, and I think illustrates "it is possible to do better".
321
Yawning Angel @yawning.bsky.social · 07/03/2024
I went and wrote a Schnorr signature implementation on top of ristretto25519, because "Ed25519 also caused me a lot of pain". Given first-class support for domain separation, do I need explicit separate support for pre-hashed messages? ie: Why does Ed25519ph exist when Ed25519ctx exists?
200
Reposted by Yawning Angel
Filippo Valsorda @filippo.abyssdomain.expert · 06/03/2024
It's been MORE THAN FIFTEEN YEARS and we are still grappling with the clusterfuck of Ed25519 underspecified validation criteria. I think "safecurves" might go down as my all-time pet peeve. A curve with a cofactor is not safe. ESPECIALLY if you don't specify how to handle it and provide no tests.
0132
Yawning Angel @yawning.bsky.social · 06/03/2024
Am I the only one that finds that it takes more time documenting something than doing a functional/correct implementation?
020
Yawning Angel @yawning.bsky.social · 04/03/2024
Peak Shitcoins is the former Safemoon CEO being free on a 3M USD bond, to go live with his parents, and using a Public Defender because the law firm he originally retained withdrew representation for lack of payment.
000
Yawning Angel @yawning.bsky.social · 20/02/2024
Whowa. I find myself needing an OSX test-target, but even the low-end Mac mini quickly gets kind of expensive. Maybe I need to be looking at the used/refurb market.
000
Yawning Angel @yawning.bsky.social · 01/02/2024
Having used it for about a week, the Thonkpad X13 Gen 4 AMD is indeed, quite nice.
010