<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>David Cerezo Sánchez</title>
	<atom:link href="http://cerezo.name/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://cerezo.name/blog</link>
	<description></description>
	<lastBuildDate>Mon, 14 Oct 2024 12:47:27 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.7.15</generator>
	<item>
		<title>JUBILEE</title>
		<link>http://cerezo.name/blog/2021/09/16/jubilee/</link>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Thu, 16 Sep 2021 21:30:00 +0000</pubDate>
				<category><![CDATA[computer security]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[economics]]></category>
		<category><![CDATA[finance]]></category>
		<guid isPermaLink="false">https://cerezo.name/blog/?p=1510</guid>

					<description><![CDATA[וְהַעֲבַרְתָּ שׁוֹפַר תְּרוּעָה, בַּחֹדֶשׁ הַשְּׁבִעִי, בֶּעָשׂוֹר, לַחֹדֶשׁ; בְּיוֹם, הַכִּפֻּרִים, תַּעֲבִירוּ שׁוֹפָר, בְּכָל-אַרְצְכֶם. Leviticus 25:9 Once every 50 years comes the great day of the Jubilee, the day when all debts are forgiven. For this special year and for the first time, the latest cryptographic technology can be used to obtain better debt jubilees. Hallelujah!]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-image"><figure class="aligncenter size-large"><a href="http://cerezo.name/blog/wp-content/uploads/2024/09/angel-Cinquantenaire.png"><img loading="lazy" width="518" height="348" src="http://cerezo.name/blog/wp-content/uploads/2024/09/angel-Cinquantenaire.png" alt class="wp-image-1524" srcset="http://cerezo.name/blog/wp-content/uploads/2024/09/angel-Cinquantenaire.png 518w, http://cerezo.name/blog/wp-content/uploads/2024/09/angel-Cinquantenaire-300x202.png 300w" sizes="(max-width: 518px) 100vw, 518px"></a></figure></div>



<div style="text-align: right;"><span lang="hi-IN">וְהַעֲבַרְתָּ שׁוֹפַר תְּרוּעָה</span>, <span lang="hi-IN">בַּחֹדֶשׁ הַשְּׁבִעִי</span>, <span lang="hi-IN">בֶּעָשׂוֹר</span>, <span lang="hi-IN">לַחֹדֶשׁ</span>; <span lang="hi-IN">בְּיוֹם</span>, <span lang="hi-IN">הַכִּפֻּרִים</span>, <span lang="hi-IN">תַּעֲבִירוּ שׁוֹפָר</span>, <span lang="hi-IN">בְּכָל</span>-<span lang="hi-IN">אַרְצְכֶם</span>.</div>
<p align="right">Leviticus 25:9</p>
<p align="left">Once every 50 years comes the great day of the Jubilee, the day when all debts are forgiven.</p>
<p align="left">For this special year and for the first time, the latest cryptographic technology can be used to obtain <a href="https://www.calctopia.com/debt-settlement/" target="_blank" rel="noopener">better debt jubilees</a>.</p>
<p align="left">Hallelujah!</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Digital Golden Calf</title>
		<link>http://cerezo.name/blog/2019/12/25/the-digital-golden-calf/</link>
					<comments>http://cerezo.name/blog/2019/12/25/the-digital-golden-calf/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Wed, 25 Dec 2019 17:35:20 +0000</pubDate>
				<category><![CDATA[computer security]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[economics]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1502</guid>

					<description><![CDATA[וְעַתָּה, אִם‑תִּשָּׂא חַטָּאתָם; וְאִם‑אַיִן–מְחֵנִי נָא, מִסִּפְרְךָ אֲשֶׁר כָּתָבְתָּ Exodus 32:31 Erecting false idols leads to the fall: you don’t build an enduring house over pseudo-anonymity, inefficient Sybil-resistance, insecure scripts, and unstable policies. And what is worse, with entry limited to only a very limited few. Instead, when you build a great house, you invite everyone [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-image"><figure class="aligncenter is-resized"><img loading="lazy" src="http://cerezo.name/blog/wp-content/uploads/2019/12/btc-golden-calf.jpg" alt class="wp-image-1503" width="538" height="311" srcset="http://cerezo.name/blog/wp-content/uploads/2019/12/btc-golden-calf.jpg 726w, http://cerezo.name/blog/wp-content/uploads/2019/12/btc-golden-calf-300x174.jpg 300w" sizes="(max-width: 538px) 100vw, 538px"></figure></div>



<p class="has-text-align-right">וְעַתָּה, אִם‑תִּשָּׂא חַטָּאתָם; וְאִם‑אַיִן–מְחֵנִי נָא, מִסִּפְרְךָ אֲשֶׁר כָּתָבְתָּ</p>



<p class="has-text-align-right">Exodus 32:31</p>



<p>Erecting false idols leads to the fall: you don’t
build an enduring house over pseudo-anonymity, inefficient
Sybil-resistance, insecure scripts, and unstable policies. And what
is worse, with entry limited to only a very limited few.</p>



<p>Instead, when you build a great house, <a href="https://www.calctopia.com/2019/12/25/giving-cheerfully" target="_blank" rel="noreferrer noopener" class="broken_link">you invite everyone to enjoy it</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2019/12/25/the-digital-golden-calf/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Rise of Lex Cryptographia</title>
		<link>http://cerezo.name/blog/2017/09/14/the-rise-of-lex-cryptographia/</link>
					<comments>http://cerezo.name/blog/2017/09/14/the-rise-of-lex-cryptographia/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Thu, 14 Sep 2017 00:11:20 +0000</pubDate>
				<category><![CDATA[cryptography]]></category>
		<category><![CDATA[economics]]></category>
		<category><![CDATA[finance]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1494</guid>

					<description><![CDATA[לֹא, תִּגְנֹבוּ; וְלֹא‑תְכַחֲשׁוּ וְלֹא‑תְשַׁקְּרוּ, אִישׁ בַּעֲמִיתוֹ Lev. 19:11 As the human mind is inscrutable to others, so its elucubrations are the truly purest form of property. Raziel protects your secrets from the Adversary and provides proofs against its malicious machinations: you shall not be robbed neither of your data nor of your code, for they [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p><div id="attachment_1495" style="width: 626px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-1495" loading="lazy" class="size-full wp-image-1495" src="http://cerezo.name/blog/wp-content/uploads/2017/09/Rembrandt_-_Moses.jpg" alt width="616" height="768" srcset="http://cerezo.name/blog/wp-content/uploads/2017/09/Rembrandt_-_Moses.jpg 616w, http://cerezo.name/blog/wp-content/uploads/2017/09/Rembrandt_-_Moses-241x300.jpg 241w" sizes="(max-width: 616px) 100vw, 616px"><p id="caption-attachment-1495" class="wp-caption-text">Rembrandt — Moses Breaking the Tablets of the Law</p></div>
<p style="text-align: right;">לֹא, תִּגְנֹבוּ; וְלֹא‑תְכַחֲשׁוּ וְלֹא‑תְשַׁקְּרוּ, אִישׁ בַּעֲמִיתוֹ</p>
<p style="text-align: right;">Lev. 19:11</p>
<p style="text-align: justify;">As the human mind is inscrutable to others, so its elucubrations are the truly purest form of property. <a href="https://eprint.iacr.org/2017/878" target="_blank" rel="noopener">Raziel</a> protects your secrets from the Adversary and provides proofs against its malicious machinations: you shall not be robbed neither of your data nor of your code, for they are your inalienable property.</p>
<p>Hallelujah!</p>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2017/09/14/the-rise-of-lex-cryptographia/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Joy of Secure Computation</title>
		<link>http://cerezo.name/blog/2017/02/01/the-joy-of-secure-computation/</link>
					<comments>http://cerezo.name/blog/2017/02/01/the-joy-of-secure-computation/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Wed, 01 Feb 2017 14:08:42 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1482</guid>

					<description><![CDATA[הַנִּסְתָּרֹת לַיהֹוָה אֱלֹהֵינוּ וְהַנִּגְלֹת ֹלָֹנוֹּ ֹוֹּלְֹבָֹנֵֹיֹנֹוּ עַד עוֹלָם לַעֲשׂוֹת אֶת כָּל דִּבְרֵי הַתּוֹרָה הַזֹּאת Deut. 29, 29 There is a pain, a void in your heart, an aching to be safe: the Adversary covets your secrets, with weapons not of this world, trying to read your mind to keep it blind. And predominantly helped by [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p><div id="attachment_1483" style="width: 275px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-1483" loading="lazy" class="wp-image-1483 size-full" src="http://cerezo.name/blog/wp-content/uploads/2017/01/samson-and-delilah.jpg" width="265" height="210"><p id="caption-attachment-1483" class="wp-caption-text">Samson, betrayed by Delilah after revealing the secret of his <em>strength</em></p></div>
<p style="text-align: right;"><span class="co_VerseText">הַנִּסְתָּרֹת לַיהֹוָה אֱלֹהֵינוּ וְהַנִּגְלֹת ֹלָֹנוֹּ ֹוֹּלְֹבָֹנֵֹיֹנֹוּ עַד עוֹלָם לַעֲשׂוֹת אֶת כָּל דִּבְרֵי הַתּוֹרָה הַזֹּאת</span></p>
<p style="text-align: right;">Deut. 29, 29</p>
<p style="text-align: justify;">There is a pain, a void in your heart, an aching to be safe: the Adversary covets your secrets, with weapons not of this world, trying to read your mind to keep it blind. And predominantly helped by the “information revelation” dilemma: when you loose the lock that keep your lips closed, you risk to loose that precious treasure that you own even more than the clothes that dress you; your thoughts and information. On the other hand, as the mind is inscrutable to other humans, your information is rendered your property under a Higher Law. So let it be this fundamental dilemma of human existence: what to say or what to keep; how to reconcile talking and keeping secrets?</p>
<p style="text-align: justify;">Rejoice! I bring you good news of great joy which will be for all! From now on and thanks to <a href="https://www.calctopia.com" target="_blank" rel="noopener">secure computation</a>, <em>deus ex machina</em>, you can use other’s information without falling into the temptation of misappropiating it; or let others use your own information without it being stolen from you!</p>
<p>Hallelujah!</p>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2017/02/01/the-joy-of-secure-computation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Best Practices on Hadoop</title>
		<link>http://cerezo.name/blog/2014/04/11/best-practices-on-hadoop/</link>
					<comments>http://cerezo.name/blog/2014/04/11/best-practices-on-hadoop/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Fri, 11 Apr 2014 00:22:28 +0000</pubDate>
				<category><![CDATA[bigdata]]></category>
		<category><![CDATA[hadoop]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1469</guid>

					<description><![CDATA[A quick summary from my experiences with Hadoop: Don’t lost focus on what really matters: not to efficiently store and retrieve fabulous amount of data, but to extract useful insights from it. The quickest way to start analyzing big amounts of data is by re-using R code from CRAN with the help of Cascading, a [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>A quick summary from my experiences with Hadoop:</p>
<ul>
<li>Don’t lost focus on what really matters: not to efficiently store and retrieve fabulous amount of data, but to extract useful insights from it.
<ul>
<li>The quickest way to start analyzing big amounts of data is by re-using R code from CRAN with the help of <a href="http://www.cascading.org" target="_blank" rel="noopener" class="broken_link">Cascading</a>, a tool that generates PMML models. Mahout is a very good alternative, but not very efficient at the moment.</li>
<li>Most Hadoop deployments in the world are in experimental phases and not in production: they are proof of concepts. Many projects will fail to meet expectations because they expect too much too soon, even when basic functionality is not mature enough (real-time querying –Impala, Stinger v3, Drill‑, processing of graph structures ‑Giraph‑, granular security ‑Accumulo-).</li>
</ul>
<p><span id="g25598792">&nbsp;</span></p></li>
<li><span style="line-height: 1.5em;">Hadoop is not a replacement for the traditional DataWarehouse: the strength of Hadoop is that it handles massive amounts of unstructured data that DWHs weren’t designed for. It’s true that Hadoop is less expensive than any DWH, but that doesn’t mean that it will replace all their workloads: redesign the DW architecture to make a place for Hadoop.</span></li>
<li><span style="line-height: 1.5em;">HBase and HDFS are very different: use HBase to serve content on websites and reference data, since it’s designed for key/value lookups, fast range scans and maintaining versions; use HDFS for ETL and heavy workloads, since it’s designed for batch processing and large data scans.</span></li>
<li><span style="line-height: 1.5em;">Basic architectural tips:</span>
<ul style="line-height: 1.5em;">
<li>Faster healing time for larger clusters.</li>
<li>More racks offer more failure domains.</li>
<li>Plan for high-availability for the master/name node: configure a secondary NameNode for a HA standby architecture with periodical updating.</li>
<li>The <i>raison d’être</i> of the cloud is elasticity: reserve the floor of measured demand and spin up capacity on-demand. Consider the automation of the removal of datanodes when not in use.</li>
<li>The namespace node is factor that could limit growth since it keeps the entire namespace in RAM: more than 100 GB may be necessary for very large deployments (1 GB metadata is typically used for to 1 PB of storage).</li>
<li>Plan for enough capacity: storage should never reach 80%, or the cluster will start to get slower. Spare nodes enable the cluster to run on failures.</li>
<li>Nodes must be NTP-synchronized.</li>
<li>When everything is properly setup, an operator should manage 5K nodes.</li>
</ul>
</li>
<li><span style="line-height: 1.5em;">The performance of Hadoop tasks is I/O‑bound by design: beware that public cloud servers (Azure/Amazon) are not designed for I/O intensive tasks, just for in-memory processing. Usually, the storage is separated from the CPUs by a network (NAS): this architecture impacts the performance more than disk virtualization so, whenever possible, try to use local storage with storage optimized instances.</span>
<ul style="line-height: 1.5em;">
<li>On the other hand, using cloud storage (S3, AVS) also has its advantages: you will be able to re-use the stored files for different clusters without needing to create a copy for each cluster; also, the availability of these cloud storages is much higher.</li>
</ul>
</li>
<li><span style="line-height: 1.5em;">Many times, processing is memory-bound and not IO/CPU-bound (real-time queries are memory hungry) so take extra care to conserve precious memory while architecting and coding.</span></li>
<li><span style="line-height: 1.5em;">Only consider to write Map/Reduce code for the most common of Hive/Pig queries: Map/Reduce is the assembly of Hadoop, use it as last recourse.</span></li>
<li><span style="line-height: 1.5em;">Operations</span>
<ul style="line-height: 1.5em;">
<li>Balance data periodically, in particular after growing a cluster.</li>
<li>Cold data should be archived and hot-data over-replicated.</li>
<li>Set quotas for everything: they will help you to stop domino failures.</li>
</ul>
</li>
<li><span style="line-height: 1.5em;">Always backup the namenode. Also, consider to mount several redundant directories for its metadata (NFS).</span></li>
<li><span style="line-height: 1.5em;">Monitoring and performance tuning: the only way to start optimizing your code is to collect statistics while running jobs using the best available tools (Nagios, Operations Manager, …). There’s also specialized software to monitor Hadoop loads (Ambari):</span>
<ul style="line-height: 1.5em;">
<li>You should monitor everything: disk I/O and SMART statistics, size and number of open files over time, network I/O, CPU, memory, RPC metrics, JVM statistics, etc… Analyze and correlate these with Hadoop statistics (HDFS, MapReduce, Hive).</li>
<li>You will discover that enabling compression, using a better algorithm for task scheduling, incrementing the number of threads, parallel copies and the size of the HDFS blocksize/map are common changes: every Hadoop distribution seems to keep them too low. Note that larger blocks per map imply larger heap-sizes for the map-outputs to be sort in the map’s sort-buffer.</li>
<li>The number of map tasks should be less than half the number of available processor cores, and the number of reduce tasks half the number of map tasks. Avoid having too many maps or many maps with a very short run-time.</li>
<li>The number of reduces is a decisive factor: too many reduces produce countless small files that decrease performance; on the other hand, if there are a very little number of reduces, each may have too process too big loads per reduce.</li>
<li>Correct JVM configuration is a must (and it’s not only about the maximum amount of memory per virtual machine): only use a 64bit JVM with low-latency garbage collector.</li>
<li>Find and analyze failed datanodes: long term, it could help save a cluster in case the problem starts replicating.</li>
</ul>
</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2014/04/11/best-practices-on-hadoop/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Assorted Links (Algorithms)</title>
		<link>http://cerezo.name/blog/2014/04/10/assorted-links-algorithms-2/</link>
					<comments>http://cerezo.name/blog/2014/04/10/assorted-links-algorithms-2/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Thu, 10 Apr 2014 15:33:15 +0000</pubDate>
				<category><![CDATA[links]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1466</guid>

					<description><![CDATA[The Matching Polytope has Exponential Extension Complexity. A perfect matching polytope cannot be written as a linear program with polynomially many constraints, only exponentially, so P!=NP cannot be proven using these methods. An Almost-Linear-Time Algorithm for Approximate Max Flow in Undirected Graphs. This breakthrough algorithm applies the electrical flow method to analyze the full graph [&#8230;]]]></description>
										<content:encoded><![CDATA[<ul>
<li style="text-align: justify;"><a href="http://arxiv.org/abs/1311.2369" target="_blank" rel="noopener">The Matching Polytope has Exponential Extension Complexity</a>. A perfect matching polytope cannot be written as a linear program with polynomially many constraints, only exponentially, so P!=NP cannot be proven using these methods.</li>
<li style="text-align: justify;"><a href="http://math.mit.edu/~kelner/Publications/Docs/1304.2338v2.pdf" target="_blank" rel="noopener" class="broken_link">An Almost-Linear-Time Algorithm for Approximate Max Flow in Undirected Graphs</a>. This breakthrough algorithm applies the electrical flow method to analyze the full graph at the same time, the inventive step now being that it identifies the paths that create bottlenecks.</li>
<li style="text-align: justify;"><a href="http://eccc.hpi-web.de/report/2013/026/" target="_blank" rel="noopener">Arithmetic circuits: a chasm at depth three</a>. Any algebraic circuit can be expressed as depth‑3 formulas of sub-exponential size.</li>
<li style="text-align: justify;"><a href="http://www.tara.tcd.ie/bitstream/2262/67834/1/Stratus_v2.pdf" target="_blank" rel="noopener" class="broken_link">Stratus: Load Balancing the Cloud for Carbon Emissions Control</a>. Arbitrage between clouds and their physical locations will become so competitive that even electricity costs and their taxes will be priced on.</li>
</ul>

]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2014/04/10/assorted-links-algorithms-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Preventing more Heartbleeds</title>
		<link>http://cerezo.name/blog/2014/04/09/preventing-more-heartbleeds/</link>
					<comments>http://cerezo.name/blog/2014/04/09/preventing-more-heartbleeds/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Wed, 09 Apr 2014 14:07:34 +0000</pubDate>
				<category><![CDATA[computer security]]></category>
		<category><![CDATA[programming]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1464</guid>

					<description><![CDATA[It’s all over the news: a vulnerability has been found on OpenSSL that leaks memory contents on server and clients. Named Heartbleed, it has a very simple patch&#160;and some informative posts have already been written about it (Troy Hunt, Matthew Green). What nobody is saying is that the real root cause is the lack of [&#8230;]]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">It’s all over the news: a vulnerability has been found on OpenSSL that leaks memory contents on server and clients. Named <a href="http://heartbleed.com/" target="_blank" rel="noopener">Heartbleed</a>, it has a <a href="https://github.com/openssl/openssl/commit/96db9023b881d7cd9f379b0c154650d6c108e9a3" target="_blank" rel="noopener">very simple patch</a>&nbsp;and some informative posts have already been written about it (<a href="http://www.troyhunt.com/2014/04/everything-you-need-to-know-about.html" target="_blank" rel="noopener">Troy Hunt</a>, <a href="https://blog.cryptographyengineering.com/2014/04/08/attack-of-the-week-openssl-heartbleed/" target="_blank" rel="noopener">Matthew Green</a>).</p>
<p style="text-align: justify;">What nobody is saying is that the real root cause is the lack of modern memory management in the C language: OpenSSL added a wrapper around <em>malloc()</em> to manage memory in a more secure and efficient way, effectively bypassing some improvements that have been made in this area during a decade; specifically, it tries to improve the reuse of allocated memory by avoiding to <em>free()</em> it. Now enter <a href="http://heartbleed.com/" target="_blank" rel="noopener">Heartbleed</a>: by a very simple bug (intentional or not), the attacker is able to retrieve chosen memory areas. What was the real use of that layer?</p>
<p style="text-align: justify;">Face it: it’s a no-win situation. No matter how many ways these layers are going to be written, there will always be a chance for error. You can’t have secure code in C.</p>
<p style="text-align: justify;">But re-writing and/or throwing away thousands of security related programs written in C is no-brainer: the only way to securely run these programs is with the help of some <a href="http://en.wikipedia.org/wiki/Memory_debugger" target="_blank" rel="noopener">memory debuggers techniques</a>, like those used by Insure++ or Rational Purify. For example, the next technical report contains a detailed analysis of some of these techniques that prevent these kind of vulnerabilities:</p>
<p style="text-align: justify;"><iframe src="//docs.google.com/viewer?url=http%3A%2F%2Fwww.cl.cam.ac.uk%2Ftechreports%2FUCAM-CL-TR-798.pdf&amp;hl=en_US&amp;embedded=true" class="gde-frame" style="width:100%; height:500px; border: none;" scrolling="no"></iframe>
</p><p class="gde-text"><a href="http://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-798.pdf" class="gde-link">Download (PDF, 1.99MB)</a></p>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2014/04/09/preventing-more-heartbleeds/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Assorted Links (Crypto)</title>
		<link>http://cerezo.name/blog/2014/04/07/assorted-links-crypto-3/</link>
					<comments>http://cerezo.name/blog/2014/04/07/assorted-links-crypto-3/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Mon, 07 Apr 2014 21:30:49 +0000</pubDate>
				<category><![CDATA[computer security]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[links]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1462</guid>

					<description><![CDATA[Building Web Applications on Top of Encrypted Data Using Mylar: practical CryptDB for the web, just adding some lines of code! More attacks on WPA2:&#160;Exposing WPA2 security protocol vulnerabilities Identity based encryption for secure and accountable warrant execution If the backdooring of Dual EC DRBG wasn’t enough, now a TLS extension named Extended Random makes [&#8230;]]]></description>
										<content:encoded><![CDATA[<ul>
<li><a href="https://www.usenix.org/conference/nsdi14/technical-sessions/presentation/popa" target="_blank" rel="noopener" class="broken_link">Building Web Applications on Top of Encrypted Data Using Mylar</a>: practical <a href="http://css.csail.mit.edu/cryptdb/" target="_blank" rel="noopener">CryptDB</a> for the web, just adding some lines of code!</li>
<li>More attacks on WPA2:&nbsp;<a href="http://inderscience.metapress.com/content/d566077551229663/" target="_blank" rel="noopener">Exposing WPA2 security protocol vulnerabilities</a></li>
<li>Identity based encryption for <a href="https://freedom-to-tinker.com/blog/felten/secure-protocols-for-accountable-warrant-execution/" target="_blank" rel="noopener">secure and accountable warrant execution</a></li>
<li>If the <a href="http://blog.0xbadc0de.be/archives/155" target="_blank" rel="noopener">backdooring of Dual EC DRBG</a> wasn’t enough, now a <a href="http://dualec.org/" target="_blank" rel="noopener">TLS extension named Extended Random</a> makes it worse.</li>
<li>An illuminating story on <a href="http://www.bbc.com/news/magazine-26838177" target="_blank" rel="noopener">freedom and spying under totalitarian regimes</a>: What would current records say about you?</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2014/04/07/assorted-links-crypto-3/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>From Big Data to Big Reasoning</title>
		<link>http://cerezo.name/blog/2014/03/31/from-big-data-to-big-reasoning/</link>
					<comments>http://cerezo.name/blog/2014/03/31/from-big-data-to-big-reasoning/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Mon, 31 Mar 2014 21:37:59 +0000</pubDate>
				<category><![CDATA[bigdata]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1459</guid>

					<description><![CDATA[Big Data is shaking up everything, from education, economics, businesses and the sciences: the changes may be as big as the ones introduced by the printing press. As promoted, its biggest impact is that now we don’t need to research how to automate and teach a computer to do things: just inferring probabilities from big [&#8230;]]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">Big Data is shaking up everything, from education, economics, businesses and the sciences: the changes may be as big as the ones introduced by the printing press. As promoted, its biggest impact is that now we don’t need to research how to automate and teach a computer to do things: just inferring probabilities from big amounts of data is enough.</p>
<p style="text-align: justify;">In the past, data collection, storing and analyzing methods were expensive and time consuming: in the year 2000, digital information was just one-quarter of the world’s stored information. Now we can easily capture and store ever-growing amounts of data: today, only 1% of all the stored information is non-digital, since the digital data is growing exponentially.</p>
<p style="text-align: justify;">But behind the Big Data hype, there’s also Big Unawareness of statistical sciences:</p>
<ul style="text-align: justify;">
<li>Big data may allow to cheat and work backward (data-&gt;analysis-&gt;conclusions from correlations), but correlation does not imply causation and the traditional scientific method is not to be forgotten. The same statistical error may be made on a grander scale.</li>
<li>Statistical models and scientific understanding are yet needed, since more data brings more spurious patterns that obscure a constant number of the genuine insights: the signal to noise ratio quickly drops to zero without careful analysis. The mind frame of the researcher is as important as always: the only answers to be found are the ones that the researcher is looking for.</li>
<li>More data doesn’t always mean more accuracy: the bigger the data set, the more likely it is to have errors and the higher the number of false positives inferred. More data may not cancel out errors and carefully sampled subsets may still outperform.</li>
<li>Not everything can be captured, the question about what is missing is still there and sampling bias and error must still be considered: sampling bias is more impactful that sampling error, since there always the question of what underlying population has been captured by the data.</li>
</ul>
<p style="text-align: justify;">In the other words, Big Data does not equal Big Insights: science, deep reasoning and proper inferencing are as necessary as ever, and statisticians are beginning to modify and fine-tune their toolsets: as a remedy, I predict that tools from the <a href="http://plato.stanford.edu/entries/reasoning-automated/" target="_blank" rel="noopener">Automated Reasoning field</a> will also be increasingly adopted to fight this data avalanche.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2014/03/31/from-big-data-to-big-reasoning/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Assorted Links (Maths)</title>
		<link>http://cerezo.name/blog/2014/03/19/assorted-links-maths-2/</link>
					<comments>http://cerezo.name/blog/2014/03/19/assorted-links-maths-2/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Wed, 19 Mar 2014 21:30:18 +0000</pubDate>
				<category><![CDATA[links]]></category>
		<category><![CDATA[mathematics]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1455</guid>

					<description><![CDATA[The 2013 Turing Award goes to Leslie Lamport, author of LaTeX and the Paxos family of protocols The research program Univalent Foundations of Mathematics by the famed Vladimir Voevodsky is a really ambitious one: it would revolutionise automated theorem proving A mechanised proof of Fermat’s Little Theorem (HOL4) I have recently learnt that the beautiful [&#8230;]]]></description>
										<content:encoded><![CDATA[<ul>
<li style="text-align: justify;">The 2013 Turing Award goes to <a href="http://www.lamport.org/" target="_blank" rel="noopener" class="broken_link">Leslie Lamport</a>, author of LaTeX and the <a href="http://en.wikipedia.org/wiki/Paxos_(computer_science)" target="_blank" rel="noopener">Paxos family of protocols</a></li>
<li style="text-align: justify;">The research program <em><a href="http://www.math.ias.edu/~vladimir/Site3/Univalent_Foundations.html" target="_blank" rel="noopener">Univalent Foundations of Mathematics</a></em> by the famed Vladimir Voevodsky is a really ambitious one: it would revolutionise automated theorem proving</li>
<li style="text-align: justify;">A <a href="http://www.nicta.com.au/pub?doc=6061" target="_blank" rel="noopener">mechanised proof of Fermat’s Little Theorem</a> (HOL4)</li>
<li style="text-align: justify;">I have recently learnt that the beautiful books [amazon_link id=“0883857006” target=“_blank” ]Proofs without Words I[/amazon_link]&nbsp;and&nbsp;[amazon_link id=“0883857219” target=“_blank” ]Proofs without Words II[/amazon_link] by Roger B. Nelsen have an historical precedent from a more impressive mid-19th century book:&nbsp;<a href="http://www.math.ubc.ca/~cass/Euclid/byrne.html" target="_blank" rel="noopener">Oliver Byrne’s edition of Euclid</a>.</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2014/03/19/assorted-links-maths-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How Languages are Changing Programs (et vice versa)</title>
		<link>http://cerezo.name/blog/2014/03/18/how-languages-are-changing-programs-et-vice-versa/</link>
					<comments>http://cerezo.name/blog/2014/03/18/how-languages-are-changing-programs-et-vice-versa/#respond</comments>
		
		<dc:creator><![CDATA[dcerezo]]></dc:creator>
		<pubDate>Tue, 18 Mar 2014 21:29:20 +0000</pubDate>
				<category><![CDATA[books]]></category>
		<category><![CDATA[programming]]></category>
		<guid isPermaLink="false">http://cerezo.name/blog/?p=1449</guid>

					<description><![CDATA[A graphical summary to Caspers Jones’ latest book, “[amazon_link id=“0321903420” target=“_blank”]The Technical and Social History of Software Engineering[/amazon_link]”, aggregating the data of thousands of projects: Note how application size is lowering in terms of number of lines of code, in direct correlation to the linear increase in the expressive power of programming languages. This observation [&#8230;]]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">A graphical summary to <a href="http://en.wikipedia.org/wiki/Capers_Jones" target="_blank" rel="noopener">Caspers Jones</a>’ latest book, “[amazon_link id=“0321903420” target=“_blank”]The Technical and Social History of Software Engineering[/amazon_link]”, aggregating the data of thousands of projects:</p>
<p style="text-align: justify;"><a href="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers1.png"><img loading="lazy" class="aligncenter size-full wp-image-1452" src="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers1.png" alt="caspers1" width="819" height="463" srcset="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers1.png 819w, http://cerezo.name/blog/wp-content/uploads/2014/03/caspers1-300x169.png 300w" sizes="(max-width: 819px) 100vw, 819px"></a></p>
<ul style="text-align: justify;">
<li>Note how application size is lowering in terms of number of lines of code, in direct correlation to the linear increase in the expressive power of programming languages. This observation fits well the growing number of web/mobile application that only do a very limited number of functions.</li>
</ul>
<p><a href="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers2.png"><img loading="lazy" class="aligncenter size-full wp-image-1453" src="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers2.png" alt="caspers2" width="819" height="460" srcset="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers2.png 819w, http://cerezo.name/blog/wp-content/uploads/2014/03/caspers2-300x168.png 300w" sizes="(max-width: 819px) 100vw, 819px"></a></p>
<ul style="text-align: justify;">
<li>The maximum percentage of code reuse is growing very fast, due to a higher number of libraries and open-source, but spotting projects with a 85% of reuse is a yet a rarity.</li>
<li>Defect removal efficiency has steadily improved, but I expected a steeper line due to static analysis and better compiler warnings</li>
<li>The percentage of personal dedicated to maintenance has surpassed that of the initial development, but there’s little research on the success factors of this stage.</li>
</ul>
<p><a href="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers3.png"><img loading="lazy" class="aligncenter size-full wp-image-1450" src="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers3.png" alt="caspers3" width="819" height="509" srcset="http://cerezo.name/blog/wp-content/uploads/2014/03/caspers3.png 819w, http://cerezo.name/blog/wp-content/uploads/2014/03/caspers3-300x186.png 300w" sizes="(max-width: 819px) 100vw, 819px"></a></p>
<p style="text-align: justify;">As languages improved (and their number, so more languages are available for specific tasks), so did the programmer’s productivity, lowering the defect potential at the same time: <a href="http://namcookanalytics.com/wp-content/uploads/2014/02/SoftwareLaws2014.pdf" target="_blank" rel="noopener">this document about software engineering laws</a> also provides another interesting outlook of the same datasets.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://cerezo.name/blog/2014/03/18/how-languages-are-changing-programs-et-vice-versa/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/


Served from: cerezo.name @ 2026-06-08 09:19:09 by W3 Total Cache
-->