[video]
Distraction is the only thing that consoles us for our miseries, and yet it is itself the greatest of our miseries. — Blaise Pascal
[video]
[video]
[video]
Amazon War Story #1: Jeff Bezos -
People like Jeff are better regarded as hyper-intelligent aliens with a tangential interest in human affairs.
Remember: sometimes the people who are not on the same page as you have simply read more of the book than you have. — Not on the Same Page
How to Break XML Encrypttion -
We show that an adversary can decrypt a ciphertext by performing only 14 requests per plaintext byte on average. This poses a serious and truly practical security threat on all currently used implementations of XML Encryption. In a sense the attack can be seen as a generalization of padding oracle attacks (Vaudenay, Eurocrypt 2002). It exploits a subtle correlation between the block cipher mode of operation, the character encoding of encrypted text, and the response behaviour of a Web Service if an XML message cannot be parsed correctly.
the old is dying and the new cannot be born — Antonio Gramsci
By the way, nice sig; mind if I steal it? :P
> > A: Yes.
> > >Q: Are you sure?
> > > >A: Because it reverses the logical flow of conversation.
> > > > >Q: Why is top posting frowned upon?
— Someone’s sig. !
The security impact of a new cryptographic library (pdf) -
AES-128, RSA-2048, etc. are widely accepted standards.
Obviously infeasible to break by best attacks in literature.
Implementations are available in public cryptographic libraries such as OpenSSL.
Common security practice is to use those implementations. But cryptography is still
a disaster! Complete failures of confidentiality and integrity
We have designed+implemented a new cryptographic library, NaCl (“salt”), to address
the underlying problems. http://nacl.cace-project.eu, http://nacl.cr.yp.to: source
and extensive documentation.
In this paper, we show how to exploit real-time communication applications to determine the IP address of a targeted user. We focus our study on Skype, although other realtime communication applications may have similar privacy issues. We first design a scheme that calls an identified targeted user inconspicuously to find his IP address, which can be done even if he is behind a NAT. By calling the user periodically, we can then observe the mobility of the user. We show how to scale the scheme to observe the mobility patterns of tens of thousands of users. We also consider the linkability threat, in which the identified user is linked to his Internet usage. We illustrate this threat by combining Skype and BitTorrent to show that it is possible to determine the filesharing usage of identified users. We devise a scheme based on the identification field of the IP datagrams to verify with high accuracy whether the identified user is participating in specific torrents. We conclude that any Internet user can leverage Skype, and potentially other real-time communication systems, to observe the mobility and filesharing usage of tens of millions of identified users.
To farishte poochhenge mehshar mein paakbaazon se
Gunah kyoon na kare, kya khuda rahim na tha?
Trust me, the angels will ask the pious on judgement day:
“Why didn’t you sin? Didn’t you trust in God’s mercy?”
Mont Saint-Michel. More pics here.