Posts by filippo@abyssdomain.expert
 (DIR) Post #AjjDls8eEyP2UKZ4AS by filippo@abyssdomain.expert
       0 likes, 0 repeats
       
       In 2022, I left Google in search of a sustainable approach to open source maintenance. A year later, I was a full-time independent professional open source maintainer.Today I’m announcing the natural progression of that experiment: Geomys, a small firm of professional maintainers with a portfolio of critical Go projects.Nicola Murino, the maintainer of x/crypto/ssh, and @dominik, the maintainer of Staticcheck and Gotraceui, are Geomys’ first Associate Maintainers ✨https://words.filippo.io/dispatches/geomys/?source=Mastodon
       
 (DIR) Post #B42Bis8wVNTa52cjpY by filippo@abyssdomain.expert
       0 likes, 0 repeats
       
       Dustin Moody from NIST: “you don’t need more than 128 bits of symmetric keys for post-quantum security” #rwc2026Say it louder, for the people in the back!
       
 (DIR) Post #B51ynbmzU4OZCfndCq by filippo@abyssdomain.expert
       1 likes, 0 repeats
       
       Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years.That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.https://words.filippo.io/crqc-timeline/
       
 (DIR) Post #B520oOUOcNiA9VbWt6 by filippo@abyssdomain.expert
       1 likes, 0 repeats
       
       @neverpanic oh Debian oldstable is not gonna make it. stable might not make it! I have a secret, over-optimistic wish that this will kill the "constantly run software 3-5 years out of date" model of distribution, and free us upstreams from having to deal with its fallout, but I know it won't.
       
 (DIR) Post #B5ASdjE3X2YNGFLLyS by filippo@abyssdomain.expert
       1 likes, 1 repeats
       
       Alright, it's official! 💰@matthew_d_green and I bet on what will break first, ML-KEM-768 or X25519. The loser donates to a 501(c)(3) picked by the winner.If you have an opinion on quantum computers or lattices, you can join with a side bet. Just submit a PR!https://github.com/FiloSottile/ecc-vs-lattices-long-bet
       
 (DIR) Post #B5kxxJ8kJqa4Q3EWGW by filippo@abyssdomain.expert
       1 likes, 0 repeats
       
       Looks like GitHub silently corrupted some index.PR #237 definitely exists and is closed (https://github.com/C2SP/C2SP/pull/237) but is just... not in the list (https://github.com/C2SP/C2SP/pulls?q=is%3Apr+is%3Aclosed) regardless of filters.I briefly doubted my own sanity. This is bad.
       
 (DIR) Post #B7WoRBXLdlTDs2NLsm by filippo@abyssdomain.expert
       1 likes, 0 repeats
       
       In 2020, OpenSSL had a vulnerability in handling the signature_algorithms_cert extension. https://openssl-library.org/news/secadv/20200421.txtPalo Alto apparently "solved" this in their IPS by blocking connections with "unknown" algs in signature_algorithms_cert.Six years later, we can't add ML-DSA to signature_algorithms_cert in Go. signature_algorithms_cert is dead.Sigh.Thanks to @cks for diagnosing this. Sometimes it takes us months to figure out things like this.https://github.com/golang/go/issues/79626#issuecomment-4754225610
       
 (DIR) Post #B9tVZSc0ivtwfJqe3s by filippo@abyssdomain.expert
       0 likes, 0 repeats
       
       @ariadne @dee > I said that the typical case will be raising inxperienced engineers to median levels of productivitySorry but I am re-reading your post and it's not what you said.You said it "could, perhaps" do that in some cases, but that in general it will "freeze the commons as it is today" and "it will not let the commons grow."Maybe you meant something else, but you didn't say it.