Father, Hacker (Information Security Professional), Open Source Software Developer, Inventor, and 3D printing enthusiast

  • 2 Posts
  • 12 Comments
Joined 1 year ago
cake
Cake day: June 23rd, 2023

help-circle




  • Riskable@programming.devtoCasual Conversation @lemm.ee*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    3 months ago

    Good idea! Here’s some popular genres of today’s anime:

    • Harem
    • Reverse Harem
    • Isekai harem
    • Reverse Isekai harem
    • Slice of life harem
    • Reincarnated as a normally-inanimate object (slice of life, adventure, and harem options available)
    • Awkward teen gets overpowered (usually with harem)
    • Awkward adult gets overpowered (usually with harem)
    • Awkward teen almost gets a girlfriend (wannabe harem)
    • Slime destroying/taming/breeding/harem
    • Romance: Girl “tames” dark, mysterious/misunderstood boy, girl falls for awkward teen who has secret talent/power, and rich/powerful boy falls for awkward girl
    • Period drama from period in Japanese history that no one cares about (even the Japanese) but features samurai!
    • Food obsession (actually this can be any anime these days) / Japanese people fantasizing about eating weird shit
    • Protagonists with special powers fighting bad guys with special powers and/or spirits/yokai
    • Useless gods using mortals to complete tasks that would only take them moments
    • Trying to sell toys/video games
    • Pseudo anime: Chinese animations re-telling the same three stories approved by China’s censors (I hope you like cultivation, the Monkey King, and immortals in “the heavens”!)
    • Pseudo anime: Korean animations that obsess over beauty (endless male and female versions available!)


  • This is a, “it’s turtles all the way down!” problem. An application has to be able to store its encryption keys somewhere. You can encrypt your encryption keys but then where do you store that key? Ultimately any application will need access to the plaintext key in order to function.

    On servers the best practice is to store the encryption keys somewhere that isn’t on the server itself. Such as a networked Hardware Security Module (HSM) but literally any location that isn’t physically on/in the server itself is good enough. Some Raspberry Pi attached to the network in the corner of the data center would be nearly as good because the attack you’re protecting against with this kind of encryption is someone walking out of the data center with your server (and then decrypting the data).

    With a device like a phone you can’t use a networked HSM since your phone will be carried around with you everywhere. You could store your encryption keys out on the Internet somewhere but that actually increases the attack surface. As such, the encryption keys get stored on the phone itself.

    Phone OSes include tools like encrypted storage locations for things like encryption keys but realistically they’re no more secure than storing the keys as plaintext in the application’s app-specific store (which is encrypted on Android by default; not sure about iOS). Only that app and the OS itself have access to that storage location so it’s basically exactly the same as the special “secure” storage features… Except easier to use and less likely to be targeted, exploited, and ultimately compromised because again, it’s a smaller attack surface.

    If an attacker gets physical access to your device you must assume they’ll have access to everything on it unless the data is encrypted and the key for that isn’t on the phone itself (e.g. it uses a hash generated from your thumbprint or your PIN). In that case your effective encryption key is your thumb(s) and/or PIN. Because the Signal app’s encryption keys are already encrypted on the filesystem.

    Going full circle: You can always further encrypt something or add an extra step to accessing encrypted data but that just adds inconvenience and doesn’t really buy you any more security (realistically). It’s turtles all the way down.