Show newer

@benaryorg The problem is that just about everything seems to require a nonce nowadays. Which is understandable, given how important it is for typical cases, but convergent encryption is very much an edgecase.

@bananas Right, but I'm looking to understand the actual cryptographic implications, rather than just following a rule of thumb, which may or may not apply here.

My understanding, for example, is that the *reason* for nonces being single-use, is that if you reuse them across plaintexts/ciphertexts, you can end up divulging information about the key used. But in this case, there is still a guarantee that they are not reused between *different* plaintexts, only identical ones (since it is derived from the plaintext with a cryptographic hash).

So does that mean that the actual necessary property of a nonce is still upheld here? Or is there some *other* reason why nonces need to be unique, that this is not accounting for?

question: I would like to use libsodium for secret-key encryption, but it requires a nonce, and I need the encryption to be deterministic/convergent (for deduplication).

Is "deriving the nonce from the data by hashing it" a reasonable solution to this problem, or does that have some issue I am not aware of?

#OH: a transfem card costs 49eur in germany i think

@Sh41 @aral That's their problem, though, and they shouldn't make their ignorance the problem of marginalized folks. The effect is the same regardless of whether it's with malice or not.

By all means, if you can afford the time and energy, try and turn people around, because yes, it's often possible. But it's not a thing you can expect of anyone else, and it's not helpful to raise it as a 'defense' against this sort of criticism.

re: Neil Gaiman 

@afewbugs It doesn't make the problem you describe any less real, of course, and there are much longer conversations that can be had about "watching things from shitty creators" in general, but perhaps piracy could serve as an individual immediate-term solution?

@Qyriad@chaos.social (I've long been experiencing browser-breaking issues about once a day with Firefox, often seems like some kind of internal IPC process crashes and some UI / notification integration / set of tabs / whatever just freezes up permanently, but that's been true in X11 and remains true under Wayland, and has been a problem for years now)

@Qyriad@chaos.social Firefox has been giving me trouble since forever, previously under KWin X11, but under KWin Wayland it has grown a new failure mode - constant intermittent <1 sec freezes of the (UI/page) rendering (sound and background processes not affected), and occasional total hangs of videos on YouTube until I refresh the page or change the video stream. NixOS stable with amdgpu.

🦾 How Much Is a Browser Worth?
@wezm

「 Apparently people are excited about funding independent browser efforts this week. I have little interest in funding yet another browser built in C++ in 2024 but Servo is still alive. Since Mozilla refuse to let us directly fund Firefox I shall set up a recurring donation to Servo 」

wezm.net/v2/posts/2024/how-muc

#Servo #Browser #Opensource #Rust

re: CW-boost: nlpol 

@bananas I wonder if we might actually end up beating Liz Truss

re: CW-boost: nlpol 

I don't think we're allowed to make fun of Belgian politics anymore, going forward

Show thread

@kescher Apparently Network Solutions suspended their domain due to a bodged phishing complaint, and is not responding to attempts to get it unsuspended...

which is pretty hilarious considering it's very likely that HE folks and Network Solutions folks have likely literally sat next to each other at some conference table in the past, I don't understand how they could fuck that one up

re: LLM-meuk 

@bananas For what it's worth, this is almost guaranteed to be the outcome of such a case in NL as well. The law is pretty clear that if a corporation chooses unreliable spokespeople, that's the corporation's problem.

@ktemkin ..and if we change the room number, it shows the checkin information for that room instead :p

LLM-meuk 

Ligt het aan mij of is deze tekst (en vele andere productteksten op de Gamma-site) gegenereerd met een LLM? gamma.nl/assortiment/suki-mask

“Ik weet het niet. Het is een soort guilty pleasure. Alleen hoef je je er niet schuldig over te voelen en dat het nou een pleasure is kan ik ook niet echt zeggen.”

Show thread

Oh, also:
- Put together and installed two desks, for the other creatures in this house

Show thread

Home improvement update log, since last post:
- Put together and installed several cabinets (finally! storage!)
- Installed a fake plant for decoration (helpfully, those don't die)
- Replaced the shower head pin with one that isn't decaying and half hanging out of the wall (this required dealing with expired wall filler)
- Replaced the vibration dampening for my air conditioner with washing machine dampeners, which turns out to work much better than my previous homebrew styrofoam solution

Show thread

I've seen a lot of odd choices in GDPR implementation, but "the privacy policy is a Vimeo-hosted video" is a new one to me

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.