Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
FiloSottile
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
61.
▲
by
FiloSottile
11mo ago
It's not that simple! What about intermediate values during arithmetic computations? What about registers spilling during signal handling? I honestly thought it could not be done safely, but the runtime/secret proposal discussion
62.
▲
by
FiloSottile
11mo ago
You might find this proposal and the upcoming runtime/secret package interesting. https://github.com/golang/go/issues/21865
63.
▲
by
FiloSottile
11mo ago
> I don't know why the standard library crypto packages insist on passing around `[]byte` for things like a seed value These are actually very deliberate choices, based on maybe unintuitive experience. We use []byte instead of e.g.
64.
▲
by
FiloSottile
11mo ago
128 bits of symmetric keys are enough for post-quantum security. See https://words.filippo.io/post-quantum-age/ . The public key algorithm has been frustratingly blocked on the IETF and CFRG, which are taking more than
65.
▲
Show HN: Run a GitHub Actions step in a gVisor sandbox
(github.com)
85 points
by
FiloSottile
1y ago
|
3 comments
66.
▲
by
FiloSottile
1y ago
No, in CSRF the browser is not the adversary, it is a confused deputy, and it’s perfectly reasonable to collaborate with it against the attacker (which is another site). You might want to read https://words.filippo.io/csrf .
67.
▲
Root causes of 2024/2025 open source supply chain compromises
(words.filippo.io)
4 points
by
FiloSottile
1y ago
|
0 comments
68.
▲
by
FiloSottile
1y ago
> Users can move their follows, followers and posts to zeppelin.social fron BlueSky transparently? Yes, even if Bluesky was down (as long as they have a backup) which is not the case for ActivityPub.
69.
▲
by
FiloSottile
1y ago
For CSRF (and for SameSite), you are not looking at what cookies are sent to attacker.example.com, but what cookies are sent to target.example.com if a request is originated from attacker.example.com (or from attacker.com).
70.
▲
by
FiloSottile
1y ago
Same-Site cookies are, well, same-site. Not same-origin. This is already a deal-breaker for many deployments, because they don't trust blog.example.com and partner.example.com as much as admin.example.com (both in the strict sense of t
71.
▲
by
FiloSottile
1y ago
I have never seen real Go code (i.e. not code written purposefully to be exploitable) that was exploitable due to a data race. This doesn’t prove a negative, but is probably a good hint that this risk is not something worth prioritizing for
72.
▲
by
FiloSottile
1y ago
Thomas and I are both talking about the Go cryptographic library overall, not about the ChaCha20 implementation in particular. Anyway, I don’t find arguing semantics around the “soup-to-nuts” expression particularly productive. We avoided t
73.
▲
by
FiloSottile
1y ago
Well, ML-KEM has zero assembly and was written entirely from scratch, for example, so it must be more than you'd think if you think we "reuse the same machine code for this that you'd find in everybody else's implementat
74.
▲
by
FiloSottile
1y ago
Yes, it calls out to OpenSSL on Linux and to CNG on Windows. I think, but I am not certain, that at least the OpenSSL cgo bindings are derived from the Go+BoringCrypto ones (which makes sense, since the BoringSSL and OpenSSL APIs are still
75.
▲
by
FiloSottile
1y ago
Off the top of my head, there might be some old assembly by Andy Polyakov and by Vlad Krasnov that was contributed to both Go and OpenSSL. Even there, we’ve been working for years to port hand-written assembly to higher level generators, an
76.
▲
by
FiloSottile
1y ago
[ Big I am a cryptographer, not your cryptographer disclaimer ] It depends, but if you are targeting Security Level 1 (which is what most folks think about when they think about FIPS 140) you generally don't need your entire applicat
77.
▲
by
FiloSottile
1y ago
To nitpick, there is no special crypto/fips140 package. (Ok, there is, but it just has an Enabled() bool function.) FIPS 140-3 mode is enabled by building with GOFIPS140=v1.0.0 (or similar, see https://go.dev/doc/s
78.
▲
by
FiloSottile
1y ago
No, the Go 1.24 native module effort that they talk about in https://devblogs.microsoft.com/go/go-1-24-fips-update/ is this effort, which Microsoft was not involved in. We simply decided to delay the official anno
79.
▲
by
FiloSottile
1y ago
> Applications that have no need for FIPS 140-3 compliance can safely ignore [this page], and should not enable FIPS 140-3 mode. https://go.dev/doc/security/fips140 Yup.
80.
▲
The FIPS 140-3 Go Cryptographic Module
(go.dev)
196 points
by
FiloSottile
1y ago
|
71 comments
81.
▲
by
FiloSottile
1y ago
You'll never believe what I (and a bunch of folks) have been working on for years :) https://www.sigsum.org https://github.com/FiloSottile/torchwood/tree/main/cmd/apt-t... https:&#
82.
▲
by
FiloSottile
1y ago
Huh, iCloud Keychain supports the prf extension when used with Chrome, so I had assumed they added support to Safari as well, but I just tested it and sure enough, you're right. Edit: well https://webauthn-passkeys-prf-demo.
83.
▲
by
FiloSottile
1y ago
That instead was a draft that should have not gone out yet, but the API filter didn’t work :) I’ll mail that one towards the end of the week.
84.
▲
by
FiloSottile
1y ago
I added a footnote about it. It’s indeed read traffic, so it’s (certificate volume x number of monitors x compression ratio) on average. But then you have to let new monitors catch up, so you need burst. It’s unfortunately an estimate, beca
85.
▲
by
FiloSottile
1y ago
My bad! This is what I get for doing a deploy to fix the layout while the post is on HN. Back up now.
86.
▲
by
FiloSottile
1y ago
Team sharing with a non-technical person, mostly. I still have high-value passwords and CLI credentials in passage + age-plugin-yubikey.
87.
▲
by
FiloSottile
1y ago
Currently it just fetches latest if a version is not specified. It should be pretty easy to use the current project version if available, assuming llm plugins stay in the working directory of the main call. PRs welcome :) Once the module ve
88.
▲
by
FiloSottile
2y ago
1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially incon
89.
▲
by
FiloSottile
2y ago
Privacy Pass is an anonymous credential scheme that does exactly what you describe.
90.
▲
by
FiloSottile
2y ago
I'm not involved in the OpenSSL/CNG-based Microsoft Go fork. I've managed and implemented—along with Daniel McCarney, Roland Shoemaker, and Russ Cox—the native upstream Go validation mentioned in the intro, which is shipping
More ›