Skip to content
I T S S
  • Welcome
  • Hardware
  • Internet
  • Networking
  • Security
  • Data Recovery
  • Support
  • Contact
  • Webmail

A Nice Little Cryptography Primer

By itss | 28/06/2021
0 Comment

Pun Intended.

Category: Technology
Post navigation
← pfSense / Wireguard / Bad Code / Close Call Why Quake3 was so fast : Fast Inverse Square Root →

Recent Posts

  • Hardware Exploits?
  • Why Quake3 was so fast : Fast Inverse Square Root
  • A Nice Little Cryptography Primer
  • pfSense / Wireguard / Bad Code / Close Call
  • Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur)

Slashdot

News for nerds

  • Are Return-to-Office Mandates Killing Workers' Trust in Workplaces?
    by EditorDavid on 02/08/2026 at 11:34 am

    The Hill published the thoughts of Gleb Tsipursky, Ph.D., who serves as the CEO of the future-of-work consultancy Disaster Avoidance Experts: A recent EnhancV survey of 1,000 full-time U.S. workers subject to new or stricter return-to-office policies found that 72% suspect these mandates are really a voluntary attrition strategy — a strategy by their own employers to make them quit their jobs. A full 46% admit to the practice of coffee-badging. Thirty-six percent have applied for a new job while sitting at their current office desk. Thirty-six percent have started a side hustle since the mandate was announced, in anticipation of being let go or quitting. Those numbers do not prove that employees reject collaboration. They show that many employees no longer trust the official story... The central mistake in many in-office mandates is the assumption that proximity automatically produces commitment. It does not. A worker who spends two hours commuting to sit on video calls with colleagues in other cities is not experiencing culture. That worker is experiencing theater. When executives describe the office as a cure-all, many employees experience lost time, higher costs and lower autonomy. The policy's defining feature becomes its credibility gap. Research keeps undercutting the belief that more office time automatically means better performance. A University of Pittsburgh analysis of S&P 500 firms found that return-to-office mandates reduced employee satisfaction without improving firm performance or firm value.... Baylor University's reporting on office mandates and brain drain found that firms with mandates faced greater turnover among women, senior employees, managers and high-skilled workers, while job vacancy duration increased and hiring rates declined. In other words, the people with the most options are often the first to leave. The employees who remain may not be the most committed — they may simply be the least mobile... Attendance can be mandated, but commitment cannot. When leaders confuse the two, they do not rebuild workplace culture. They create a room full of people planning their exit. Read more of this story at Slashdot.

  • As New York Finalizes New Social Media Rules, US Senate Considers Nationwide 'SCREEN' Act
    by EditorDavid on 02/08/2026 at 7:34 am

    New York has finalized new rules that will govern social media apps in the state starting on January 25, 2027. The law prohibits social media platforms from sending notifications to minors between midnight and 6 a.m. without parental consent. And minors "will only be shown content from other accounts they follow or otherwise select in a set sequence, such as chronological order," rather than "the default algorithmically personalized feeds... unless they get parental consent for an addictive feed." (Social media companies "must offer at least one alternative method for age assurance besides providing a government-issued ID," the announcements points out, and any information used to determine age "must not be used for any other purpose and must be deleted or de-identified immediately after its intended use.") But meanwhile, the EFF writes that a committee in the U.S. Senate is considering the SCREEN ACT, "a sweeping age-verification bill that would require online services to verify users' ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech." Unlike many state-age verification laws — which have been harmful in their own right — the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content... Under the SCREEN Act, the "bouncer" will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time. The consequences of the bill won't be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people's private information... The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users' ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking... The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users. Read more of this story at Slashdot.

  • How 'Situational Awareness' Hedge Fund Dropped 67% in AI Stock Rout
    by EditorDavid on 02/08/2026 at 4:45 am

    CNN tells the unfortunate tale of hedge fund Situational Awareness, "founded in 2024 by German-born Leopold Aschenbrenner when he was in his early 20s." Aschenbrenner, a former OpenAI employee, founded the hedge fund on the premise that "AI will be the dominant driver of global market returns over the next decade," according to the firm's site... Aschenbrenner managed to turn hundreds of millions of dollars into tens of billions of dollars over the course of roughly two years... That streak ended on Thursday, though, when the fund was forced to sell the bulk of its public holdings to a bigger rival after many of its investments went south. But that's only part of the story. The fund employed a risky strategy of borrowing money to purchase stocks. When the investments appreciate, the payoff can be massive. But when the investments sour, the losses can be catastrophic. The downturn in AI stocks over the course of this month, like chip makers and cloud computing providers, hit the hedge fund extra hard. It was forced to sell off many investments at a steep discount to rival hedge fund Citadel in what Aschenbrenner reportedly compared to a "bank run" in a letter to investors. "Critics pointed out that Aschenbrenner had no experience running money prior to launching his fund in July 2024, calling him more lucky than smart," writes CNBC: Some noted that his early work experience was at the doomed crypto firm FTX, where he helped now-disgraced founder Sam Bankman-Fried run a charity out of a Bahamas penthouse. Others on Wall Street, including former traders at global investment banks, noted that in light of reports Situational Awareness used as much as 400% leverage, the collapse wasn't shocking. The Wall Street Journal reports that Situational Awareness "also used options to amplify its returns. That meant that even small declines in individual names could have big impacts on Situational's portfolio." And so, as the New York Post put it, "The celebrated crystal ball of the 'Nostradamus of AI' hasn't merely gone cloudy — it has rolled off the table and shattered on the parlor floor." Wall Street breathed a huge sigh of relief last week as an AI-focused hedge fund called Situational Awareness reportedly sold most of its portfolio — reportedly down 67% last month on the backfiring of debt-fueled bets on chipmakers and assorted artificial-intelligence firms — to billionaire Ken Griffin's Citadel... The prevailing sentiment was best summed up by a veteran Wall Street sage who has seen a lot of flameouts in his day. Let's just say he wasn't impressed by Leopold Aschenbrenner, the 25-year-old German-born "Nostradamus" figure who is the founder of Situational Awareness... "Just your typical leveraged Âidiot who was right until he was wrong," the source said, adding that the implosion is a "one-off..." [Another trusted source] felt there was room for conversation: "A significant issue. Not viewed as systemic right now. I wonder if that changes as more problems arise." Indeed, the fact is that most of Wall Street is closely monitoring the Situational Awareness situation because they were holding many of the same positions as ÂAschenbrenner. Another top hedge fund manager I won't name tells me he has been getting crushed on similar investments in chipmakers essential to the AI supply chain, as well as other companies feeding off this technology. Thanks to Slashdot reader joshuark for sharing the news. Read more of this story at Slashdot.

  • Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken
    by EditorDavid on 02/08/2026 at 1:48 am

    "A hardware wallet is supposed to be the safest place to keep Bitcoin," writes The Street, since it never connects to the internet, its keys never leave the device, and "the whole point is that an attacker would need to physically hold it to steal anything." The problem is that anyone who can reproduce the recovery seed doesn't need to possess the COLDCAR, Nerds.xyz points out. More from The Street: [The recovery seed] is supposed to come from a hardware random number generator producing 128 bits of entropy, a number so large that guessing it is computationally impossible. It wasn't. According to Block's engineering team a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure and called it preliminary. The gap between 128 bits and 40 bits is not a matter of degree. It is the difference between a lock that cannot be picked and one that can be brute-forced by anyone with rented cloud computing.... Chainalysis found the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes. Within about 25 minutes, roughly 594 BTC had moved out of some 500 single-signature wallets. One victim lost around $1.8 million... Coinkite has shipped fixed firmware, but with a warning that matters more than the patch itself. Updating does not repair an existing seed. A seed created with weak entropy stays weak forever. Affected users have to generate an entirely new wallet on updated hardware and move their coins to it. By Saturday morning Galaxy research was tracking 1,158.66 BTC, worth roughly $75.1 million, taken from 2,673 addresses, according to the article. And "The Coldcard exploit is ONGOING," Galaxy Research posted an hour ago on X.com. "Move Coldcard single-sig funds to safe locations immediately!" We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators. Thanks to Slashdot reader BrianFagioli for sharing the news. Read more of this story at Slashdot.

  • Is Big Tech's AI Gamble Starting to Look Riskier?
    by EditorDavid on 02/08/2026 at 12:12 am

    The Washington Post looks at giant tech companies "feeding every available dollar into the cash-incinerating maw of AI machines." They warn "Tech superstars that once had oodles of cash left over at the end of each year are now flipping into the red..." [While optimists expect] huge corporate profits and a society-wide boost to wealth and well-being... questions about that AI vision are now growing more urgent: When, if ever, will this payoff arrive? And what will the fallout be for Americans if the titanic investment doesn't quickly deliver? "This AI thing better work out because if it doesn't ... we're going to have a problem," said Torsten Slok, chief economist at investment firm Apollo Global Management. AI costs and doubts are spreading. The U.S. stock market has swooned this summer over fear of the AI bubble going bust... The AI gamble sweeping up American fortunes is led by tech companies splurging on hulking data centers packed with computer chips and equipment needed to develop sophisticated AI models and deliver them to customers. In investor calls in the past week, Google, Microsoft, Meta and Amazon pointed to soaring AI-related sales and business deals. Advertisers are using the technology to tailor marketing pitches and corporations and start-ups are buying access to chatbots and other AI software to boost productivity... But this spending can only continue if AI generates an even larger avalanche of new revenue to pay for it all. Financial results released over the past week show that the AI titans' mammoth costs are largely swamping the sales boost from the technology. At Google, for every dollar of cash its business generated in the past three months, $1.15 went out the door to pay for AI computer chips and equipment, land for AI data centers and other big-ticket purchases. The company is covering the difference partly by borrowing money and selling more of its stock. Next year, five leading AI companies — Google, Amazon, Microsoft, Meta and Oracle — are projected to have negative free cash flow, which measures the cash left over after paying expenses and AI infrastructure costs. The figures, based on investment analyst projections compiled by S&P Global Market Intelligence, show a stunning reversal for what have been some of the world's most cash-generating corporations... The companies remain profitable by standard financial accounting measures that spread out the costs of their AI infrastructure spending over many years... Pessimists see a bet so gargantuan that it cannot possibly pay off. The pessimists are growing louder. The Bank for International Settlements, a typically measured institution in Switzerland that advises government bankers around the world, recently warned there was risk of "economy-wide recessions" if the AI boom falters. That could mean pain for workers and communities across the United States. "I'm not saying AI is going to go away, it's just not clear to me these guys are going to make money on it," said Christopher Wood, global head of equity strategy at investment bank Jefferies who has correctly predictedpast financial bubbles. Read more of this story at Slashdot.

  • 150-Game Discount Bundle Raises $57,000 for Videogame Workers 'Hardship Fund'
    by EditorDavid on 01/08/2026 at 10:42 pm

    "An itch.io game bundle put together by Necrosoft Games and The United Videogame Workers-CWA union is a new way gamers can show their support for developers who have been let go amidst the ongoing video game industry labor crisis," writes Kotaku. Launched Thursday, it's already raised $57,859 from 3,984 contributors. (Average contribution size: $14.52) The bundle is pay-what-you-want with a minimum purchase price of $10, offering DRM-free PC versions of games including A Short Hike, SkateBIRD, and my favorite game in the pack, Arranger: A Role-Puzzling Adventure ... The bundle will be available through August 13. The gaming blog Rock Paper Shotgun shares more details, starting with this quote from the bundle's page on itch.io: "Reports say 33% of the industry lost their jobs in the last two years, and the jobs they could fill are disappearing as CEOs try to replace them with AI. It's hard for companies to adjust to the new shape of the game industry, but even harder for the people they should be employing... To address this in some small way, we have created a bundle with almost 150 games. The proceeds of this bundle will go toward a hardship fund for those experiencing layoffs." Games industry workers currently out of work or under-employed can apply to this fund, which is distributed by the United Videogame Workers, to help out with basic necessities like food and rent. As a note, this is only available to US and Canada-based devs, but there's an FAQ explaining who can apply for the fund. Read more of this story at Slashdot.

Archives

  • September 2022
  • November 2021
  • June 2021
  • March 2021
  • November 2020
  • October 2020
  • September 2020
  • February 2020
  • January 2020
  • October 2019
  • August 2018
  • July 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2016
  • July 2016
  • March 2016
  • February 2016
  • August 2015
  • May 2015

Categories

  • Innovation
  • Security
  • Software
  • Technology

Tags

backdoor cisco coding json laziness patterns public information announcement security vulnerability
© 2017 IT Sales & Services Ltd
Quality IT solutions in Tanzania since 2010
Iconic One Theme | Powered by Wordpress