Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bwesterb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
bwesterb
11mo ago
It indeed is!
32.
▲
by
bwesterb
11mo ago
Landmarks are generated every hour, but I expect clients to pull them perhaps once or twice per day. Servers will keep two signatureless MTCs around a few days apart, so even if your client didn't update in a few days you can still use
33.
▲
by
bwesterb
11mo ago
The biggest blocker for DANE at the moment is that it doesn't have a transparency story. There is no good visibility into whether your TLD advertises a second pair of zone signing keys to few you don't control. We can add some tra
34.
▲
by
bwesterb
11mo ago
You only need to send one treehead per MTCA. From that one treehead the server can infer it must also have the previous few. If that's still too much, we can compress it even further by only sending "I trust the standard CAs of Mo
35.
▲
by
bwesterb
11mo ago
I agree that there is a big gap between what browsers offer today, and a non-browser client. This is a good moment to improve things. There is no reason that we can't have system service populating /etc/ssl/treeheads, wh
36.
▲
by
bwesterb
11mo ago
If your browser is online on an unrestricted network, then the tree heads will be kept up to date, and this will leak nothing. If you had your laptop closer for a weekend, open it up immediately and visit a website before your browser had a
37.
▲
Cloudflare: You don't need quantum hardware for post-quantum security
(blog.cloudflare.com)
4 points
by
bwesterb
1y ago
|
0 comments
38.
▲
by
bwesterb
1y ago
It's also trusted as an EU Trust Service Provider. https://eidas.ec.europa.eu/efda/trust-services/browse/eidas/... That's basically QWACS. <ins>Ah, of course you mentioned it in the other
39.
▲
by
bwesterb
1y ago
We definitely should have, and that is on us. We'll fix it. https://blog.cloudflare.com/unauthorized-issuance-of-certifi...
40.
▲
by
bwesterb
1y ago
https://blog.cloudflare.com/unauthorized-issuance-of-certifi...
41.
▲
by
bwesterb
2y ago
If you don't mind a one terabyte public key. https://eprint.iacr.org/2017/351.pdf
42.
▲
by
bwesterb
2y ago
About 8x just for key agreement and 40x for signatures. It's a lot. For key agreement it's worth it, and now about 1/3 of browsers in the wild use it. http://radar.cloudflare.com/adoption-and-u…
43.
▲
by
bwesterb
2y ago
One third of all human traffic with Cloudflare is using a post-quantum KEM. I'd say that counts as enabled. We want that to be 100% of course. Chrome (and derivates) enabled PQ by default. https://radar.cloudflare.com/a
44.
▲
by
bwesterb
2y ago
About one third of traffic with Cloudflare is already using post-quantum encryption. https://x.com/bwesterb/status/1866459174697050145 Signatures still have to be upgraded, but that's more difficult. We'
45.
▲
NIST's first post-quantum standards
(blog.cloudflare.com)
1 points
by
bwesterb
2y ago
|
0 comments
46.
▲
The state of the post-quantum Internet
(blog.cloudflare.com)
4 points
by
bwesterb
3y ago
|
0 comments
47.
▲
by
bwesterb
3y ago
Go patches are out. (1.21.3, 1.20.10)
48.
▲
by
bwesterb
3y ago
Cool! Caddy support incoming. https://github.com/caddyserver/caddy/pull/5852
49.
▲
by
bwesterb
3y ago
I'll take the compliment, thank you :).
50.
▲
by
bwesterb
4y ago
If there is an n^(100^100) algorithm that solves an NP-complete problem, then P=NP, but public-key cryptography is still safe because for any practical n it's still too hard to break. There are also public-key systems that are based on
51.
▲
by
bwesterb
4y ago
Kyber is lead by Crypto Jedi: https://cryptojedi.org/peter/ :)
52.
▲
by
bwesterb
4y ago
It's hard to say. Here is a great paper that tries to answer this question. https://arxiv.org/pdf/2009.05045v1.pdf See Figure 11. Optimistically 15 years. Pessimistically 35 years. But anything can happen.
53.
▲
NIST post-quantum picks Kyber and Dilithium in Go
(github.com)
7 points
by
bwesterb
4y ago
|
0 comments
54.
▲
by
bwesterb
4y ago
And a Go implementation I wrote for Cloudflare. https://github.com/cloudflare/circl/tree/main/kem/kyber
55.
▲
by
bwesterb
4y ago
NTRU-Prime, NTRU, Kyber and SABER are all great KEMs. NIST could've chosen any one of them. NIST never standardised Ed25519 and OpenSSH still uses it, which is perfectly fine.
56.
▲
Future-Proofing SaltStack ( CVE 2022-22934 2022-22935 2022-22936 )
(blog.cloudflare.com)
3 points
by
bwesterb
5y ago
|
0 comments
57.
▲
by
bwesterb
11y ago
I am writing one. You should use the C one, if you can. https://github.com/bwesterb/argon2pure