Posts by jas@fosstodon.org
(DIR) Post #B4BdRkKArtQu2y8ewK by jas@fosstodon.org
0 likes, 0 repeats
”Cryspen’s Approach to TLS: A Critical Analysis” https://symbolic.software/blog/2026-03-07-cryspen-tls/ - I feel less confident about OpenSSH’s ML-KEM libcrux approach now
(DIR) Post #B4BdRkeNelb13danR2 by jas@fosstodon.org
0 likes, 0 repeats
“verification theatre” - https://eprint.iacr.org/2026/192
(DIR) Post #B4BdRkoJ3rXHYQEiuG by jas@fosstodon.org
0 likes, 1 repeats
@kpcyrd @djc Another concern is the Rust to C conversion, that could introduce fun stuff. Reading the 10+kloc https://github.com/openssh/openssh-portable/blob/master/libcrux_mlkem768_sha3.h is not pleasant. Generated by https://github.com/AeneasVerif/eurydice
(DIR) Post #B4KCMh2qgWWc5X2YZU by jas@fosstodon.org
0 likes, 0 repeats
@MartiniMoe @mntmn Does it run without non-free DDR RAM training blobs?
(DIR) Post #B4OTOp7K7STzYWZgKO by jas@fosstodon.org
0 likes, 0 repeats
@mntmn @davec555 Please include non-free blob status in the comparison. You are doing amazing work, so I don’t think there is any need to hide things that aren’t yet optimal.
(DIR) Post #B4PEzC1P8MOSrbeMgC by jas@fosstodon.org
0 likes, 0 repeats
@mntmn @davec555 Yay! Thank you. What about QCS8550? Any known blobs required for it?
(DIR) Post #B9AAe5dWoP6Dbvg2s4 by jas@fosstodon.org
0 likes, 0 repeats
@ariadne @zacchiro That is a great paper! To unlock wizard mode: achieve the same but don’t rely on a modified strip binary, but place the payload in obfuscated source code that everyone rebuilds. Trusting trust issue without binaries involved: only a source code audits can expose this, neither reproducible or bootstrappable builds would catch that.