Posts by jaseg@chaos.social
 (DIR) Post #B4pS7evFupPcKR6E3E by jaseg@chaos.social
       0 likes, 0 repeats
       
       @delta thanks for the clarification. speaking from my network security background, the whole timing leakage is what i’d call metadata and what your “zero metadata” thing is protecting (AFAIU timestamps and cryptographic identities) in a cryptographic protocol i’d consider straight up data, not metadata.thinking about an average user of a secure comms tool, i’d expect they would be surprised to learn that something that is “zero metadata” still leaks timing and through correlation identities.
       
 (DIR) Post #B4qIzFc1QhRn5HykKW by jaseg@chaos.social
       0 likes, 0 repeats
       
       @delta but it reveals timing, which everyone but you considers metadata, to servers
       
 (DIR) Post #B525T7oBwP0U6jXbWa by jaseg@chaos.social
       0 likes, 0 repeats
       
       I have a pretty robust BGA layout extractor working locally now. You give it a datasheet with a large BGA, and it spits out a YAML file compatible with KiCad's footprint generator code that includes the size of the layout along with any missing balls and cutouts. I might polish that up and package it as a re-usable tool at some point.#electronics
       
 (DIR) Post #B60lJfPU0iFaz4kgRU by jaseg@chaos.social
       1 likes, 0 repeats
       
       TIL the European Space Agency has a research program developing tech for shooting space debris with really, really bright lasers to adjust its orbit using the photons’ impulse, and that the name of that program is OMLET 🤣https://conference.sdo.esoc.esa.int/proceedings/sdc9/paper/219/SDC9-paper219.pdf
       
 (DIR) Post #B6GBPC7pJcoU4lBl2m by jaseg@chaos.social
       5 likes, 6 repeats
       
       Stopping the system fans to heat up the system to shift clock phase by a few femtoseconds is one of the less hinged ideas I’ve seen come out of CERN lol. (AFAIU this was an experiment for a software retrofit to hardware otherwise incapable of such adjustments)
       
 (DIR) Post #B6IOjLKAVixg7NoqTg by jaseg@chaos.social
       0 likes, 0 repeats
       
       delta.chat advertises that they provide “🔒 Audited end-to-end encryption safe against network and server attacks”, but if you click through it turns out that supposed audit:(1) didn’t actually cover their e2ee but only a key establishment protocol and (2) wasn’t actually an audit. Instead, unprompted, some researchers took a look at that key establishment protocol and found 20(!!) separate flaws. This research was not intended as an audit, nor was it commissioned or paid by delta.chat.
       
 (DIR) Post #B6IOjN0kEuc3LikMTo by jaseg@chaos.social
       0 likes, 0 repeats
       
       I just noticed that looking at their marketing materials. If you ask me, as someone who has worked both in industry and in academia in the privacy & security space, this is super shady behavior.
       
 (DIR) Post #B6IWLnjq12HwvT6xEm by jaseg@chaos.social
       0 likes, 0 repeats
       
       @delta weird mistake. Why do you list that paper as an “audit” on the page you linked? It was not an audit. Also the actual audits you list there lack a direct link to the report in at least one case, and they do not support your assertion that your e2ee implementation as such was audited as they only cover small components of your system.
       
 (DIR) Post #B6IYsopRBO8NlvbO1Q by jaseg@chaos.social
       0 likes, 0 repeats
       
       @delta this isn’t about “refining” something. calling a scientific paper an audit is an incorrect statement. calling your e2ee audited when it was not is also an incorrect statement. these marketing statements need to be removed not refined.
       
 (DIR) Post #B6PrAOp1luQjbkf8Vc by jaseg@chaos.social
       0 likes, 1 repeats
       
       at the day job, a supplier of highly advanced and very expensive bits and pieces is desperately confused what we’re trying to buy from them so I’m left to having to email an mspaint drawing of the very expensive, highly advanced bit we need 🤪
       
 (DIR) Post #B6YhlJQNYIMiSmjeYC by jaseg@chaos.social
       0 likes, 0 repeats
       
       @niconiconi I have a merge request cooking that fixes this exact issue with STM32 symbols in Kicad by splitting them up 😅
       
 (DIR) Post #B6YiAV8J9o1W14IHFA by jaseg@chaos.social
       0 likes, 0 repeats
       
       @niconiconi yeah I agree. TBH for ICs like these, I don’t see the point in the symbol file containing an actual graphical representation of the rectangle. I think they should just have an interface where you drag and drop the pins where you want them.
       
 (DIR) Post #B6iwtZDyc1PI2Tg7F2 by jaseg@chaos.social
       0 likes, 0 repeats
       
       @azonenberg I’m really curious to read what your experience with them will be. I think they’re really interesting, too and I’m looking forward to seeing their upcoming 25G transceiver variants.
       
 (DIR) Post #B6ope5N1nDvoNFLHcW by jaseg@chaos.social
       0 likes, 0 repeats
       
       @ariadne I feel like it’s import to distinguish vibe coding the odd one-time script or tool for personal use, and slopping out parts of essential, load-bearing infrastructure. The latter just has much higher stakes.
       
 (DIR) Post #B6ope5ieUpEFSJSYKG by jaseg@chaos.social
       0 likes, 0 repeats
       
       Small infrastructure announcement: git.jaseg.de has moved hosts. If you notice any broken links, please reach out here or via email.
       
 (DIR) Post #B6uxLq5ZprDMLfkXfE by jaseg@chaos.social
       0 likes, 0 repeats
       
       @lethalbit go for it!
       
 (DIR) Post #B9IHKYHQo7qwMN6GW0 by jaseg@chaos.social
       0 likes, 0 repeats
       
       @mntmn I’d imagine the challenge would be to design a transform that forces the LLM to process its output directly, and that is resistant to the LLM discovering and reversing the transform.In the limit, this sounds similar to indistinguishability obfuscation, a cryptographic technique that while it has been around for a long time hasn’t reached anywhere near practicality yet.
       
 (DIR) Post #B9IHZGuzdnOQrAcjnU by jaseg@chaos.social
       0 likes, 0 repeats
       
       @mntmn I think if you want it to be useful you’d have to assume the LLM can call tools
       
 (DIR) Post #B9lmx7BLpxULz9NaCG by jaseg@chaos.social
       0 likes, 0 repeats
       
       @mntmn i’ve noticed that secondhand DDR3 is still reasonably cheap. Also XC7Z020 and XCKU3P are currently available for cheap second hand, the former because I think it’s used a lot in war drones, the latter because it was in a batch of data center accelerators that recently got written off.
       
 (DIR) Post #BAIDQxAaXo1FSy2jBo by jaseg@chaos.social
       0 likes, 0 repeats
       
       @mntmn it sounds like the next reform is sure going to have some interesting features