4 ms·
I love how proactive the crypto team is about post quantum. They released https://pkg.go.dev/crypto/mldsa https://pkg.go.dev/crypto/mldsa. The lead maintainer F
by teabee89 2mo ago
I love how proactive the crypto team is about post quantum. They released https://pkg.go.dev/crypto/mldsa https://pkg.go.dev/crypto/mldsa. The lead maintainer Filippo Valsorda wrote a nice piece here[1] to urge the tech world to start deploying good enough versions of post quantum crypto.
[1] https://words.filippo.io/crqc-timeline/ https://words.filippo.io/crqc-timeline/
- halJordan 2mo agoWhile I'm highly sympathetic to competing priorities crowding out movement to pq cryptography. At the same time it's not sudden at all. It's been 10 years since nist first said "move shit over"?
- Valodim 2mo agoYes, and at that time the answer was "move over where?" now it's 2026 and x-wing is a draft still
- halJordan 2mo agoAh. This is a bold faced lie. There were plenty of options in 2016. Nist released final candidates in 2024 and published the candidates this year. ssh (as noted in tfa) has had pq defaults since 2022.
- blandflakes 2mo agoIn case you wanted to know, the expression is actually "bald-faced lie", i.e. unmasked, shameless.
- Joel_Mckay 2mo agoThey are also lying, it is an Italics-Faced lie... thank you, I will see myself out. =3
- saghm 2mo agoIf we wanted to make things really clear, we'd use strikethrough text for the lies!
- stryan 2mo ago"bold-faced lie" and "bald-faced lie" are both valid expressions. The original expression is "bare-faced lie" but they're all pretty similar to each other.
- blandflakes 2mo agobold-faced lie is just the usual English drift that was actually questioned as incorrect when it first surfaced. If a lie is bold, you don't have to suggest that the user's face is bold when doing it. You can in thirty seconds of google searching find numerous sources explaining that "bold-faced" is a malapropism.
- stryan 2mo agoIt's the usual English drift perhaps, but "bold faced lie" has been used since the 17th century, which is also apparent from "thirty seconds of Google searching". Three hundred years is enough usage for me to count it as correct. On a side note, "bold faced" does not mean the persons face is bold, only that it is said boldly, which implies a level of rudeness that "bald-faced" or "bare-faced" does not.
- Joel_Mckay 2mo agoColloquialisms and slang have unstable meaning over history, location, and cultures. Generally, something to be avoided by people striving for clearer communication. =3
- saghm 2mo ago> Generally, something to be avoided by people striving for clearer communication Their communication seemed pretty clear to me. If anyone actually claims that they didn't understand what they meant but would have understood it by using the other form of the expression, I think that's a bold-faced lie.
- freedomben 2mo ago
- taybin 2mo agoCalling it a lie is pretty heavy.
- hoppp 2mo agoYeah the deadline to move everything is drawing near I am actually not impressed by how fast things are going but all progress is good.
- calvinmorrison 2mo agoits ok we are still rawdogging ftp every day in the business world. The fax machines of the future truly
- eterm 2mo agoThe .NET team have been similarly busy on post-quantum lately, it completely dominated the .NET API reviews for the dotnet 11 release. It seems there's a big push happening behind the scenes.
- amelius 2mo agoOk, but when is it coming to our web browsers and email clients?
- Retr0id 2mo agoI don't know about mail clients, but it's in most web browsers already.
- amelius 2mo agoThen I'm wondering why they don't simply use the same crypto libraries as the web browsers.
- OoooooooO 2mo agoPreventing CGO overhead maybe?
- dolmen 2mo agoGo features cleaner crypto APIs (than OpenSSL for example) with less footguns.
- Retr0id 2mo agoChromium uses BoringSSL, which opens its readme as follows: > BoringSSL is a fork of OpenSSL that is designed to meet Google's needs. > Although BoringSSL is an open source project, it is not intended for general use, as OpenSSL is. We don't recommend that third parties depend upon it. Doing so is likely to be frustrating because there are no guarantees of API or ABI stability. OpenSSL itself is a clusterfuck that doesn't really meet anyone's needs: https://cryptography.io/en/latest/statements/state-of-openssl/ https://cryptography.io/en/latest/statements/state-of-openss...
- purpleidea 2mo agoThis person was public on the recent nist list against hybrid solutions. I simply don't understand why they would oppose the safer option. Yes I've read the mailing list, it just all seems quite suspicious.