log☇︎
18 entries in 0.633s
asciilifeform: arguably this kind of thing doesn't belong at all in a production vtron, it is uncomfortably close to the proverbial 'null cipher flag'(tm)(r)
zx2c4: because IPsec's null cipher mode is for transport data. what youre asking about with 7.4 is the payload parameter of the handshake messages
zx2c4: a null cipher mode? it doesnt...
asciilifeform: the q , then : why does 'noise' include a null-cipher mode ?
a111: Logged on 2017-08-22 12:07 asciilifeform: the 'noise protocol' link is hilarious -- even features the classic leper's bell of nsa committee , the null-cipher
a111: Logged on 2017-08-22 12:07 asciilifeform: the 'noise protocol' link is hilarious -- even features the classic leper's bell of nsa committee , the null-cipher
a111: 10 results for "null cipher", http://btcbase.org/log-search?q=null%20cipher
asciilifeform: !#s null cipher
ben_vulpes: use more null-cipher cryptosuites: https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/
mircea_popescu: the point re thompson's compiler is easily misunderstood, in the sense of being conceptualized too narrowly. that unwarranted narrowness then permits you to handwave his objection re null ciphers in the actual technical discussion ; but look how you fell for an obfuscated null cipher yourself right here!
mircea_popescu: http://btcbase.org/log/2017-08-22#1701957 << no, his objection actually is "tls ingredient sucks and recipe sucks whereas noise is not a recipe and it doesn't have ingredients". he is correclty rejecting what, contrary to elaborately crafted appearance, is a null cipher. ☝︎
a111: Logged on 2017-08-22 15:31 valentinbuza: noise is a framework for creating protocols. you have the option to create NOISE_NULL_CIPHER_TOTAL_BS protocol which is totally different from NOISE_ANOTHER_SANE_CHOICE
mircea_popescu: right. that reverts to the null cipher.
valentinbuza: it is different from TLS, where whatever version you are using it has null cipher. The question should be: does someone deployed NOISE_NULL_CIPHER_TOTAL_BS? then you can blame them
valentinbuza: noise is a framework for creating protocols. you have the option to create NOISE_NULL_CIPHER_TOTAL_BS protocol which is totally different from NOISE_ANOTHER_SANE_CHOICE ☟︎
valentinbuza: linked noise as a partial response to spyked http://thetarpit.org/posts/y03/05b-https-war-declaration.html. Noise null cipher is an different context than TLS null cipher.
asciilifeform: the 'noise protocol' link is hilarious -- even features the classic leper's bell of nsa committee , the null-cipher ☟︎☟︎
asciilifeform: PeterL: one of the most comical failure modes, ubiquitous in usg crypto, is the null cipher