Skip to content
0
  • Home
  • Piero Bosio
  • Blog
  • World
  • Fediverso
  • News
  • Categories
  • Old Web Site
  • Recent
  • Popular
  • Tags
  • Users
  • Home
  • Piero Bosio
  • Blog
  • World
  • Fediverso
  • News
  • Categories
  • Old Web Site
  • Recent
  • Popular
  • Tags
  • Users
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
soatok@furry.engineerundefined

Soatok Dreamseeker

@soatok@furry.engineer
About
Posts
21
Topics
11
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • This post did not contain any content.
    soatok@furry.engineerundefined soatok@furry.engineer

    @SwiftOnSecurity I don't even know which crowdstrike thing this is meant to callback to

    Uncategorized

  • We should talk about Werner Koch's response https://gpg.fail on the oss-security mailing list.
    soatok@furry.engineerundefined soatok@furry.engineer

    I think 2026 should be the year that we make PGP irrelevant.

    Not just GnuPG (Koch's implementation), but the entire OpenPGP ecosystem.

    Most cryptographers I talk to gave up on PGP over a decade ago.

    (After seeing the arrogance and dismissiveness that bled through Koch's oss-security email, who can blame them?)

    If you're a country whose government mandates the use of PGP, even in obscure places, let's talk about how to replace PGP.

    Uncategorized

  • We should talk about Werner Koch's response https://gpg.fail on the oss-security mailing list.
    soatok@furry.engineerundefined soatok@furry.engineer

    We should talk about Werner Koch's response https://gpg.fail on the oss-security mailing list.

    https://www.openwall.com/lists/oss-security/2025/12/29/9

    Yes, and actually the only serious bug from their list.

    Koch either didn't watch the talk, he is in such defense of his own ego that he can't see how serious the bugs were, or he's tacitly admitting that PGP is not a serious recommendation.

    Can you distinguish between these three explanations?

    Could it be all of them are true?

    Impact

    While this may allow remote code execution (RCE), it definitively causes memory corruption.

    Good research.

    I think this sarcastic quip is what reveals Werner Koch's opinion about the security researchers and their work.

    The rest of his email is measured (and partly responding to other mailing list participants rather than the disclosure directly).

    Uncategorized

  • On this day, all signatures should use the XMSS (hash-based signature system)
    soatok@furry.engineerundefined soatok@furry.engineer

    On this day, all signatures should use the XMSS (hash-based signature system)

    #XMSS #Xmas

    Uncategorized xmss xmas

  • I don't believe that's a part of the current spec (https://swicg.github.io/activitypub-e2ee/mls)
    soatok@furry.engineerundefined soatok@furry.engineer

    @evan @benpate @bonfire Such attacks are rare to begin with, so I don't know how well their behavior maps to game theory, but if I were prone to gamble, I would bet on "they found an easier attack" sooner than "the possibility that someone might compare fingerprints is enough to dissuade the tactic". Social engineering is unreasonably effective on most people.

    Uncategorized

  • I don't believe that's a part of the current spec (https://swicg.github.io/activitypub-e2ee/mls)
    soatok@furry.engineerundefined soatok@furry.engineer

    @benpate @risottobias @bonfire But for posterity:

    https://github.com/soatok/mastodon-e2ee-specification

    I started this in 2022 and then shifted gears to Key Transparency with the intent to switch back once that problem was solved. KT slots neatly into the "Federated PKI" vacancy on the 2022 repo

    Uncategorized

  • I don't believe that's a part of the current spec (https://swicg.github.io/activitypub-e2ee/mls)
    soatok@furry.engineerundefined soatok@furry.engineer

    @benpate @risottobias @bonfire I think you misunderstood.

    I'm suggesting that the decision to not include secure public key management will tie your hands to support whatever insecure thing you're doing now for the sake of backwards compatibility, so I'm probably better off working on my own thing than trying to participate.

    Uncategorized

  • I don't believe that's a part of the current spec (https://swicg.github.io/activitypub-e2ee/mls)
    soatok@furry.engineerundefined soatok@furry.engineer

    @benpate @risottobias @bonfire Ah, I guess that means I should dust off my original draft from 2022

    Uncategorized

  • Tell me about something cool you're working on in 2026.
    soatok@furry.engineerundefined soatok@furry.engineer

    Tell me about something cool you're working on in 2026.

    Uncategorized

  • This "UK watchdog" can eat shit.
    soatok@furry.engineerundefined soatok@furry.engineer

    This "UK watchdog" can eat shit.

    https://www.techradar.com/vpn/vpn-privacy-security/creating-apps-like-signal-or-whatsapp-could-be-hostile-activity-claims-uk-watchdog

    Uncategorized

  • The Revolution Will Not Make the Hacker News Front Page
    soatok@furry.engineerundefined soatok@furry.engineer

    The Revolution Will Not Make the Hacker News Front Page

    (with apologies to Gil Scott-Heron) If you get all of your important technology news from "content aggregators" like Hacker News, Lobste.rs, and most subreddits, you might be totally unaware of the important but boring infrastructure work happening largely on the Fediverse, indie web, and other less-centralized communities. This is no accident. The rough consensus of these spaces has been strongly in favor of the…

    http://soatok.blog/2025/12/17/the-revolution-will-not-make-the-hacker-news-front-page/

    Uncategorized

  • Yo, check this out.
    soatok@furry.engineerundefined soatok@furry.engineer

    Yo, check this out.

    https://blog.trailofbits.com/2025/12/02/introducing-constant-time-support-for-llvm-to-protect-cryptographic-code/

    Uncategorized

  • Moving Beyond the NPM elliptic Package
    soatok@furry.engineerundefined soatok@furry.engineer

    Moving Beyond the NPM elliptic Package

    If you're in a hurry, head on over to soatok/elliptic-to-noble and follow the instructions in the README in order to remove the elliptic package from your project and all dependencies in node_modules. Art: CMYKat Why replace the elliptic package? Yesterday, the Trail of Bits blog published a post about finding cryptographic bugs in the elliptic library (a Javascript package on NPM) by using the Wycheproof.

    http://soatok.blog/2025/11/19/moving-beyond-the-npm-elliptic-package/

    #npm #crypto #cryptography #elliptic #security #infosec #cve #mitigation #appsec #javascript #js #npm #npmsecurity #npmpackages

    Uncategorized npm crypto cryptography elliptic security infosec cve mitigation

  • 2015: "Not using AWS or CloudFlare is an availability risk, because DDoS"
    soatok@furry.engineerundefined soatok@furry.engineer

    2015: "Not using AWS or CloudFlare is an availability risk, because DDoS"

    2025: "Using AWS or CloudFlare is an availability risk, because surprise outages"

    Uncategorized

  • Of fucking course it was DNS
    soatok@furry.engineerundefined soatok@furry.engineer

    It was DNS
    Of course it was DNS
    Fuck Andy Jassy

    (A new haiku to consider)

    Uncategorized awsoutage

  • Of fucking course it was DNS
    soatok@furry.engineerundefined soatok@furry.engineer

    Of fucking course it was DNS

    #awsoutage

    Uncategorized awsoutage

  • @cadey Look what you inspired'nhttps://github.com/fedi-e2ee/pkd-server-go/pull/6
    soatok@furry.engineerundefined soatok@furry.engineer

    @cadey Look what you inspired

    https://github.com/fedi-e2ee/pkd-server-go/pull/6

    Uncategorized

  • https://swicg.github.io/activitypub-e2ee/mlsholy crap, MLS in ActivityPub if the Fediverse becomes end to end encrypted, it may legitimately become The Best way to communicate online in any sort of fashion
    soatok@furry.engineerundefined soatok@furry.engineer

    @jhwgh1968 @anthropy Well, @evan is well aware of it

    https://github.com/swicg/activitypub-e2ee/issues/35

    Uncategorized

  • I've just been informed that I'm not allowed to refer to platonic friend groups as a "palicule"
    soatok@furry.engineerundefined soatok@furry.engineer

    I've just been informed that I'm not allowed to refer to platonic friend groups as a "palicule"

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post