Replies

This profile is from a federated server and may be incomplete. Browse more on the original instance.

atoponce, to mastodon
@atoponce@fosstodon.org avatar

Is there a instance dedicated to amateur ? Races, training, etc.

I need to get some thoughts and opinions on training and racing out of my head. I could post them here, but this instance is primarily dedicated to Free Software. Most of my followers are probably either expecting posts related to that or cybersecurity, math, science, cryptography, etc. IE, not running.

Posting to a fitness-dedicated instance probably makes the most sense. Or setting up a blog.

atoponce,
@atoponce@fosstodon.org avatar

@oliviersaraja If you search my timeline, you'll see I've posted intermittently my training and races. But there are some other things I want to discuss that would come up a little more frequently than in the past.

This would possibly turn my timeline into less of a security and software focused timeline, to a more "general" microblog.

Maybe mastodon.social would be the place to set up that account now that I think about it.

atoponce, to random
@atoponce@fosstodon.org avatar
atoponce,
@atoponce@fosstodon.org avatar

@bitwarden Where to begin?

The first is that this is a password strength meter, and they should not be built. Troy Hunt agrees:

https://www.troyhunt.com/password-strength-indicators-help-people-make-dumb-choices/

Instead, this "game" isn't educating users about why randomness is critical to password security, Instead, it's spreading common misconceptions about password strength through an entertaining game.

As demonstrated, it's not difficult to find trivial 3-word phrases that are obviously weak, but your game says are strong.

1/2

atoponce, to linux
@atoponce@fosstodon.org avatar

Just sent in my first patch to the kernel.

This changes the kernel CSPRNG from ChaCha20 to ChaCha8 providing ~2x performance improvement without sacrificing security.

https://lore.kernel.org/lkml/20240429134942.2873253-1-aaron.toponce@gmail.com/T/#u

atoponce,
@atoponce@fosstodon.org avatar

Got some push back on my kernel patch, which I expected, so I argued my position. Curious to see if others chime in and where the discussion goes, if anywhere. So far though, I would say my patch looks like it probably won't get implemented.

atoponce,
@atoponce@fosstodon.org avatar

Ted Ts'o thinks I'm a shill sent by a nation state, ala Jia Tan of xz infamy, to weaken the RNG. Talk about an immature knee-jerk. Heh.

https://lore.kernel.org/lkml/20240429134942.2873253-1-aaron.toponce@gmail.com/T/#m286677449488f1e0195ba81234e47090a8a3474a

atoponce, to crypto
@atoponce@fosstodon.org avatar

Shor's algorithm (1994) is a speedup for finding the prime factors of a composite number, applicable to asymmetric keys.

Grover's algorithm (1996) is a quantum search speedup against symmetric key spaces.

Chen's algorithm (2024) is a new and not yet peer-reviewed quantum speedup for solving a couple shortest vector problems in lattices, previously thought to be quantum-safe.

Curious if his approach gets improved upon in coming years.

https://eprint.iacr.org/2024/555

atoponce,
@atoponce@fosstodon.org avatar

A bug has been found, the author updated the paper:

"Step 9 of the algorithm contains a bug, which I don’t know how to fix. See Section 3.5.9 (Page 37) for details. I sincerely thank Hongxun Wu and (independently) Thomas Vidick for finding the bug today. Now the claim of showing a polynomial time quantum algorithm for solving LWE with polynomial modulus-noise ratios does not hold."

atoponce, to emacs
@atoponce@fosstodon.org avatar

TIL Richard Stallman stole source code from Gosling EMACS, replaced the license headers with his own, and integrated it into his . Over time he eventually replaced all the original code, but only after initially replacing the license headers first.

Why wasn't he sued? How do you sue a homeless man? What do you sue him for?

atoponce,
@atoponce@fosstodon.org avatar

@Mehrad It was a rhetorical question.

atoponce, to programming
@atoponce@fosstodon.org avatar

I had a dream last night about ChaCha20.

> "Here's your 512-bit state array."
> ...
> "Don't forget your quarter round."
> ...
> "Not 20 quarter rounds, 80 you nitwit!"
> ...
> "Yes, increment the counter."
> ...
> "Stop using the all-zero key."
> ...
> "An all-zero nonce isn't any better."

I've been putting it together in JavaScript, just because, so it is on my mind.

atoponce,
@atoponce@fosstodon.org avatar

Speaking of which, why did RFC 8439 pick the nonce as "00:00:00:09:00:00:00:4a:00:00:00:00" when verifying test vectors for the block function?

https://datatracker.ietf.org/doc/html/rfc8439#section-2.3.2

Similarly, "00:00:00:00:00:00:00:4a:00:00:00:00" when verifying test vectors for the encryption function?

https://datatracker.ietf.org/doc/html/rfc8439#section-2.4.2

0x4a is "J" in ASCII. Significant?

atoponce, to random
@atoponce@fosstodon.org avatar

I've never met a customer service representative that was so eager to get me off the chat as the one I just received from .

My Suunto 9 Baro Titanium has crashed on me four times since Aug 2022, while executing structured workouts; the most recent, last Saturday.

I sent in diagnostic logs via SuuntoLink and give him the log ID, of which he responded "Thanks. Is there anything else I can help you with?"

Uh, yeah. My crashing watch.

Don't buy Suunto. This has been a 2 year irritation.

atoponce,
@atoponce@fosstodon.org avatar

The 2nd crash was the worst.

I was doing speed work interval sessions on my run and the watch crashed in the middle of one of the recoveries. At least it wasn't during the interval itself.

However, it hard reset the watch. I had to go through the watch introduction, set my language, re-enter my age, weight, and sex, etc.

I no longer had the workout programmed, so had to press the lap button manually, keeping an eye on the time. Then stitch the activities together post run.

atoponce,
@atoponce@fosstodon.org avatar

This isn't the only irritation I've had with this watch.

Setting watch displays can only be done through the mobile app, and they don't define the difference between "laps" and "intervals".

When snowboarding, it doesn't ignore vertical ascent (usually on a chair lift), so it records high TSS for the activity. It also fails to accurately count the number of runs you made down the mountain.

When lap swimming, it also can't count pool lengths reliably, over-counting by dozens.

atoponce, to ChatGPT
@atoponce@fosstodon.org avatar

Why large language models are not intelligent, exhibit .

atoponce,
@atoponce@fosstodon.org avatar
atoponce,
@atoponce@fosstodon.org avatar

@mina

It's not as simple as proving sqrt(2) is irrational, but it could be a lot worse. If you know you integration from calculus class, you can learn it without too much trouble.

https://crypto.stanford.edu/pbc/notes/pi/irrationalpi.html

@JCBlubaugh

atoponce, to AeroPress
@atoponce@fosstodon.org avatar

$10 for 200 unbleached papers? Hard pass.

I get that they're more environmentally friendly than bleached, but have you tried them? I need to really rinse them before use, or your coffee tastes real weird.

So, even though they require less processing by the manufacturer, it requires more water use for the consumer.

Further, again, even though they require less processing by the manufacturer, they cost more. Weird.

https://aeropress.com/products/aeropress-paper-micro-filters

atoponce,
@atoponce@fosstodon.org avatar

As an observation, it seems like the new VC-owned company is doing everything Alan Adler did NOT want to do with the company.

  • Metal filters
  • Unbleached paper filters
  • Flow control cap
  • XL size
  • ...

I get it. Some of these, such as the XL, have been requested for years by consumers, and Alan stuck to his guns, even if he might have been wrong.

On the other hand, I can't help but feel like the company is going down enshitification. I mean...

  • Pink AeroPress

Yeah.

atoponce,
@atoponce@fosstodon.org avatar

@brianokken I use my funnel every time I pour the grinds into the chamber.

atoponce, to random
@atoponce@fosstodon.org avatar

A breakdown of generic password subreddits (ignoring software-specific subs, like r/1Password):

  • r/password
  • r/passwords
  • r/Passwords_Are_Private
  • r/Passkeys
  • r/PasswordManager
  • r/PasswordManagers
  • r/passwordmanagerapps
  • r/passwordvault

Le sigh.

atoponce,
@atoponce@fosstodon.org avatar

@patterfloof Yeah, that's basically the point.

You could break it down to one about passwords and another about password managers. Passkeys are technically different from passwords, although the end goal is the same, so you could make that a 3rd sub I guess.

Something like:

  • r/Passwords
  • r/Passkeys
  • r/PasswordManagers

Everything else is a duplicate. But I guess some people really want to be mods?

governa, to random
@governa@fosstodon.org avatar
atoponce,
@atoponce@fosstodon.org avatar

@governa What a dumb article. This is nothing more than a fluff opinion piece with no real interesting technical criticisms of the browsers mentioned.

Arc: Mac-only.

Brave: An ad hominem attack against its founder.

Edge: An ad hominem attack against Windows users.

Opera: Why mention it if you're not going to discuss it?

Vivaldi: Subjective opinion and no objective critique.

:eyeroll:

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • everett
  • Durango
  • mdbf
  • magazineikmin
  • InstantRegret
  • rosin
  • modclub
  • Youngstown
  • slotface
  • thenastyranch
  • cubers
  • kavyap
  • DreamBathrooms
  • JUstTest
  • khanakhh
  • GTA5RPClips
  • osvaldo12
  • ngwrru68w68
  • normalnudes
  • cisconetworking
  • Leos
  • ethstaker
  • tester
  • tacticalgear
  • provamag3
  • anitta
  • lostlight
  • All magazines