Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
FiloSottile
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
FiloSottile
6mo ago
How do you do revocation or software updates securely if your current signature algorithm is compromised?
32.
▲
by
FiloSottile
6mo ago
That was my position until last year, and pretty much a consensus in the industry. What changed is that the new timeline might be so tight that (accounting for specification, rollout, and rotation time) the time to switch authentication has
33.
▲
by
FiloSottile
6mo ago
If you want something book-shaped, the 2nd edition of Serious Cryptography is updated to when the NIST standards were near-final drafts, and has a nice chapter on post-quantum cryptography. If you want something that includes details on how
34.
▲
by
FiloSottile
7mo ago
That’s a fun list, the only hits in the top 100 are actually Cloudflare, for whom automatic DNSSEC is a feature, and would be a bad look not to dogfood it. (I did a lot of the work of shipping that product in a past life. We had to fight th
35.
▲
by
FiloSottile
8mo ago
For regular updates, because you can minimize but not eliminate risk. As I say in the article that might or might not work for your requirements and practices. For libraries, you also cause compounding churn for your dependents. For securit
36.
▲
by
FiloSottile
8mo ago
> I've got such an aversion to use anyone else's actions, besides the first-party `actions/*` ones Yeah, same. FWIW, geomys/sandboxed-step goes out of its way to use the GitHub Immutable Releases to make the git tag h
37.
▲
by
FiloSottile
8mo ago
All of these small block ciphers have regularly large keys.
38.
▲
by
FiloSottile
8mo ago
I would love to learn more. What's the package integrity story of Java and .NET? All I can find is documentation about artifacts on e.g. Maven Central being signed with any PGP key, which can freely change across package versions. If
39.
▲
by
FiloSottile
8mo ago
There is no criticism of GitHub in the post, aside from throwing a bit of shade at them using mutable git tags for Actions instead of actually building a package manager. The lack of verification of ecosystem-specific authenticity is natura
40.
▲
by
FiloSottile
8mo ago
This article has nothing to do with the Bluesky lexicon or with the bsky.app AppView. What does “they will block you” even mean: this article is talking about hosting your data on your PDS and presenting it on your domain.
41.
▲
by
FiloSottile
9mo ago
> While the minimum versions specified in go.mod are not necessarily the version of the dependencies used This has not been true since Go 1.17 with the default -mod=readonly, which is why go.mod is a reliable lockfile.
42.
▲
by
FiloSottile
9mo ago
It's tricky, to the point that I made a little playground to explore it. https://github.com/FiloSottile/mostly-harmless/tree/main/dep... The example.com/mod2 go.mod does not in fact affect vers
43.
▲
by
FiloSottile
9mo ago
No. As explained in the post, if a transitive dependency asks for a later version than you have in go.mod, that’s an error if -mod is readonly (the default for non-get non-tidy commands). I encourage you to experiment with it! This is exact
44.
▲
by
FiloSottile
9mo ago
If that PR were merged, whoami.filippo.io would still work the same. It would just receive signed requests instead of queries.
45.
▲
by
FiloSottile
9mo ago
Frank does great work that is critical to many businesses, and should get funded to do it professionally. However, donating money to an open collective is prohibitively hard for most big companies. Maybe the world should be different (or ma
46.
▲
by
FiloSottile
9mo ago
Browser vendors have absolutely thought about this, at length. The web platform is intricate, legacy, and critical. Websites by and large can’t and don’t break with browser updates, which makes all of these things like operating on the engi
47.
▲
by
FiloSottile
9mo ago
It's why I like Sec-Fetch-Site: the #1 risk is for the developer to make a mistake trying to configure something more complex. Sec-Fetch-Site delegates the complexity to the browser.
48.
▲
by
FiloSottile
9mo ago
See the same-site section of https://words.filippo.io/csrf/
49.
▲
by
FiloSottile
9mo ago
SameSite doesn’t protect against same-site cross-origin requests, so you are staking your app’s security on the security of the marketing blog.
50.
▲
by
FiloSottile
10mo ago
You don’t, but remember you monitor your own keys: if you know you didn’t upload a poisoned key and the log refuses to serve a key preimage for your email, you’ve caught it misbehaving.
51.
▲
by
FiloSottile
10mo ago
Fixed (1) in https://github.com/FiloSottile/torchwood/commit/8b61ef967 , thank you! I'll add a note to the part of the article that mentions non-majority policies.
52.
▲
by
FiloSottile
10mo ago
No, the point of the Merkle tree inclusion proofs and of the witness cosignatures is precisely that the operator can't show a different view of the log to different parties.
53.
▲
by
FiloSottile
10mo ago
The SKS network is append-only in aspiration. There is nothing like a Merkle tree stopping a server in the pool (or a MitM) from serving a fake key to a client. The whole point of tlogs is holding systems like that accountable. Also, the se
54.
▲
by
FiloSottile
10mo ago
Honestly not sure why I didn't do that once the tool had stabilized. Switched to go install filippo.io/torchwood/cmd/age-keylookup@main age -r $(age-keylookup alice@example.com) age is designed to be composa
55.
▲
by
FiloSottile
10mo ago
>:)
56.
▲
by
FiloSottile
10mo ago
I am a CT log operator and I hands down support short-lived certificates. Automation and short lifetimes solve a lot of the pain points of the WebPKI. We can solve the storage requirements, it’s fine.
57.
▲
by
FiloSottile
10mo ago
Ignoring the damaging and self-serving behavior of Bernstein for a moment, and focusing only on the technical claim at the core of the conspiracy theory: it makes absolutely no sense. The assertion is that the NSA is subverting standards pr
58.
▲
by
FiloSottile
11mo ago
There are definitely better cryptographers than me working at Zcash, for example.
59.
▲
by
FiloSottile
11mo ago
A cloud service that lets users upload their certificates and private keys, to be served by the service's CDN. Here the attacker is attacking the system's availability, not the key. (But also, it's easy to see how this is a p
60.
▲
by
FiloSottile
11mo ago
I'm not sure what you are referring to, but we were talking about keys, not IVs. Also, "an unambiguous key type that can be constructed from a []byte or responsibly generated on your behalf" is exactly what crypto/mlkem
More ›