Hacker Newsnew | past | comments | ask | show | jobs | submit | more _yy's commentslogin

Does it support hardening flags by now? (ASLR etc.)


It does. We build mpv with hardening flags (--dynamicbase, --nxcompat, etc.) and it can build in MSYS2.


Other protocols are probably just as broken, we just haven't found the vulnerabilities yet. Few protocols (if any) get as much scrutiny as SSL/TLS.


The NIST curves also have constants which may or may not be manipulated.

Bruce Schneier recommends against using them.


Even Bernstein doesn't argue that the NIST curve seeds are actually backdoors. Schneier isn't a curve researcher; in fact, he's more like an anti-curve pundit. I'm not sure his opinion is all that powerful.

Regardless, I'm not suggesting new cryptosystems should use the NIST P-curves. They shouldn't; those curves are just as tricky to use as RSA.


What about the NSA "freaking out"[1] about ECC in general?

[1]: http://blog.cryptographyengineering.com/2015/10/a-riddle-wra...


Rodents of unusual size? I don't think they exist.


Your vote of confidence is overwhelming. ;)


I would recommend against using them if your adversary is the NSA and your threat model comes wrapped in tin foil (and if I didn't, I'd get ignored anyway).

If so, use NaCl/libsodium at the application layer and don't rely on ECDSA alone.

If your threat model is "criminals", ECDSA is less insane than RSA (provided, once again, you're not implementing it yourself, you're relying on developed by a team of cryptographers and security engineers).


Threat model wrapped in tin foil? I don't understand what you mean, are you suggesting paranoia?

My threat model includes NSA dragnets but not being specifically targeted by the NSA.


In that case, active attacks against Weierstrass field arithmetic isn't part of your threat model and ECDSA/ECDH over the NIST curves is fine.


So this is something that can't be done en masse? Okay, thanks.


>> Threat model wrapped in tin foil? I don't understand what you mean, are you suggesting paranoia?

That term likely means one of two things: guarding against a particularly capable attacker or paranoia for others


NSA dragnets won't decrypt things using dodgy curves for signatures (ECDSA), only things using dodgy curves for key exchange (ECDH).


Zulip (https://zulip.org/), a recently open-sourced Slack alternative, has a clever solution for this. They have a light-weight threading model which ensure that discussions stay within context. That way, you can just ignore discussions about topics you're not concerned with without missing anything else. It's great.

> Sometimes, important things get discussed when you’re not around. Unfortunately, so do a lot of unimportant things.

> Zulip makes it easy to review the conversations you missed, so you can focus on that important project without having to catch up on how Jim’s guitar lessons are going.

Someone on HN described it very well:

https://news.ycombinator.com/item?id=10281065


This will have the same problem, slack, by design is a time black hole where you have to dance when the other side say you must. Email allows you to prioritize tasks in your own time.


Having used Slack for over a year and a half, you nailed it.


Google Hangouts is a great alternative. It only needs a browser, too.


...and a Google account - which not everyone has / wants.

Also, from my experiences, it needs a more powerful computer to run smoothly.


I've run Hangouts on a 1st gen netbook (Asus EEE PC) without any performance issues. The only times where performance could be an issue is when you are running a video conference call which technically Skype doesn't really supports (w/o a premium or business account).


In fact years ago I switched from Skype to Hangouts because Skype on Linux would crash all the time on my EEE PC, whereas Hangouts just worked.


It depends on the video driver.


It depends on allot of things if you are using some fancy super duper HD camera and hanging out with 10 other people all using the highest possible bit rate streaming also you'll need a good computer with graphics hardware that will support all the required features for hardware acceleration in Chrome.

Back then there was almost no video HW acceleration in hangouts anyhow (well in Chrome) not on the silly 1st gen Atom for sure and it still worked fairly well (at about 60% CPU usage IIRC) even with the 720p camera on the EEE PC.

And it's not that Skype would be any better in that regards Skype might have slightly bigger selection of video codecs (Google probably had too back when Google Talk had actually a thick client) but Hangouts is limited more or less to video streams that Chrome can handle which usually means current web video formats.


Well, Skype needs a skype account. Though Google's interconnect between its services is maybe undesirable and a hassle to work around.


Skype is not accepting new accounts, you have to make a Microsoft account of some type.


> I remember not long ago Mint included just about every browser media plugin ever made, including RealMedia, WindowsMedia etc., stuff that was obsolete 15 years ago. Maybe it still does.

Weren't those just VLC wrappers?


Your project reminds me of 0install.


> WP has the ability to use (S)FTP to update the files rather than direct file access.

Well that doesn't help at all with security.


This is exactly what any company using Debian in production does.


> testing is Debian's rolling release.

Except for when it freezes.


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: