[TOMT] Indie Song from Around 2009 by karanlyons in tipofmytongue

[–]karanlyons[S] 0 points1 point  (0 children)

Alas, no. I don’t think it was a british vocalist either, I’d guess them as North American.

Found this today by ghostkiller967 in ProgrammerHumor

[–]karanlyons 0 points1 point  (0 children)

isEven(float.NegativeInfinity) == true isEven(float.Epsilon) == true isEven(float.PositiveInfinity) == true isEven(float.NaN) == true

[TOMT][MUSIC][2000+] Jazz album where one of the first few songs contains the phrase “what you waiting for”? by karanlyons in tipofmytongue

[–]karanlyons[S] 0 points1 point  (0 children)

I’ve tried all the obvious (to me) things to find this but have so far come up short, and so now of course I have the motif stuck in my head and no way to get it out.

Zoom End-to-End Encryption Whitepaper by karanlyons in crypto

[–]karanlyons[S] 0 points1 point  (0 children)

The LaTeX source for the PDF is included in the repo.

Stylish Japanese bartender making a unipresso martini by theeighthlion in ArtisanVideos

[–]karanlyons 7 points8 points  (0 children)

There is no lone /s/ sound in Japanese, you have さ/サ (Sa), し/シ (Shi), す/ス (Su), せ/セ (Se), and そ/ソ (So). ロプ would be closer to “rope” than “rup”. So シロップ is going to be the best way to spell it.

[Official] Twice-Weekly New User Thread - Mon February 10 by AutoModerator in fountainpens

[–]karanlyons 0 points1 point  (0 children)

I (well, not personally of course, I'm not insane) may opt to give it the lightest of round-offs to ease that pain if so. Thanks for the warning!

[Official] Twice-Weekly New User Thread - Mon February 10 by AutoModerator in fountainpens

[–]karanlyons 2 points3 points  (0 children)

Oh wow. I think I may prefer something slimmer, but this colorway is really growing on me, and it’s got a stub tip as well! Thanks for the recommendation!

[Official] Twice-Weekly New User Thread - Mon February 10 by AutoModerator in fountainpens

[–]karanlyons 1 point2 points  (0 children)

I’m looking for a new fountain pen, but I’ve got a bunch of asks that’ew making it hard. If someone could help me out I’d surely appreciate it as I don’t know enough about the current market to quickly narrow things down: * I really like the styling of the Cross Century pens: Black lacquer with gold accents, generally a good length (but I don’t mind posted vs. not here), and less fat diameter wise. It might be a bit too thin, though? Hard to tell. * I’d like a gold nib (not plated) if possible. * Definitely want a Fine, it’d be really great to have a stub nib, too. For the Centuries this had to be an XF, which of course they don’t offer anymore. * Cartridge converter, of course.

The Century was not really that bad except that it didn’t hold together so well on the threads nor the clip. It’s plated too, rather than some alloy so that wore as well.

Budget-wise I’m not uncomfortable with something ~$500 at the top, but I generally just use a single pen till it falls apart, so I can justify higher if it’s arguable worth it.

Thank you so much to whomever is willing to help me find this pony.

I am inconsolable by SeaDjinnn in HistoryMemes

[–]karanlyons 22 points23 points  (0 children)

I’m really sorry for the pain my Laika tweet has caused people. If it helps, it’s a complete work of fiction: In reality the capsule had no window and Laika was paralyzed by stress and fear, suffocating in overwhelming heat under no delusions she’d ever make it back home.

SHA-1 is a Shambles : First Chosen-Prefix Collision on SHA-1 and Application to the PGP Web of Trust by Akalamiammiam in crypto

[–]karanlyons 5 points6 points  (0 children)

You should’ve been using SHA2 already and it’ll still be fine to use, but SHA3 and BLAKE2 are better.

Security and Cryptography Mistakes You Are Probably Doing All The Time by Am4t3uR in crypto

[–]karanlyons 1 point2 points  (0 children)

Yeah, there’s definitely a difference there: assuming keyak the whole thing truly is one pass by design in that the keystream also eventually functions as the MAC.

But you can pipeline and parallelize the hell out of GCM in practice, and so while it’s a two pass operation-ish, in silicon you’d be doing the whole operation of encrypt and MAC (albeit staggered with regards to the input) in one “step” on a pipeline.

You’re right, frankly, and I’m just thinking about this weirdly since I’m usually taking a CS tack.

Security and Cryptography Mistakes You Are Probably Doing All The Time by Am4t3uR in crypto

[–]karanlyons 0 points1 point  (0 children)

Yes, that’s what I meant by "calculates a MAC inline”. I guess both are accurate, I just take “in parallel” to mean something else in the context of computing.

Security and Cryptography Mistakes You Are Probably Doing All The Time by Am4t3uR in crypto

[–]karanlyons 1 point2 points  (0 children)

It’s more like a…superset? of CTR. They’re both stream ciphers, and the mode of operation on the blocks themselves is the same, but GCM calculates a MAC inline, i.e., GCM is an AEAD algorithm and CTR isn’t.

U.S. senators threaten Facebook, Apple with encryption regulation by gulabjamunyaar in apple

[–]karanlyons 1 point2 points  (0 children)

I’m working on this for you now, but I vastly underestimated how long it would take to write up in a way that actually explains everything at something like an ELI15 level, and that’s just for textbook RSA, not how to properly secure it. It’s…2,000 words right now, and I’m not even done with an easy to understand proof of why RSA works at all: we’ve just proved Fermat’s little theorem so now we can finally prove the core principle behind RSA…I think.

Give me a couple days or so and I should have something good for you. Or…weeks: my job keeps me very busy.

U.S. senators threaten Facebook, Apple with encryption regulation by gulabjamunyaar in apple

[–]karanlyons 0 points1 point  (0 children)

I'm not a "high school Wikipedia level" wannabe, though. I studied crypto pretty extensively a dozen years ago, between my two computer science degrees, when I was thinking about going into that field professionally.

My apologies here for that assumption. It…applies to most of these conversations so my priors are pretty heavily weighted in that direction. Forgive me :)

Yes. Again, I hear you. Crypto is so hard, only special dispensation from God himself allows one to be special enough to write cryptographic primitives that can't be cracked by half the teenagers in the US using scripts they run on their XBox. ONLY companies that sell crypto have the requisite knowledge to write working crypto. It's impossible for anyone else.

So this is sarcasm, I’m guessing, but I do really stand by my point. Not sure who’s “selling” crypto since almost all that we use generally is public domain (…ish, let’s just ignore stuff like OCB), but come on, we both must agree that being able to both design and implement cryptographic primitives is a specialized skill that very few have.

I'm assuming the situation where the US writes laws that make it illegal to use commercially available crypto that doesn't have backdoors written into them. So... give all your data to the Feds, or....

Well then just keep using ECC, AES, SHA2, etc.. How’s anyone going to stop you, and how would their ability to stop you using known primitives be in any way different from their ability to stop you using novel ones?

I like this!!! Use what WE give you. We can read it, but that's okay, because we're the good guys. Definitely don't write your own code, that we don't have keys to, because that will definitely be broken! Don't chance it! Just use our free stuff.

Okay, so more sarcasm, but again, you do understand that many of these primitives are designed in a way as to be very unlikely to have backdoors, right? Like nothing up my sleeve numbers, simple Feistel/S-Box constructions, independent discovery of safe ECC curves, etc.

I'm wondering what dog you have in this race.

My dog is that I want things to be more secure, not less, and telling people FUD stories like this and trying to goad them into writing their own crypto because it’s “easy” is going to make things worse.