GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 03-Jul-2026 16:27:12 JST Soatok Dreamseeker Soatok Dreamseeker

    https://mailarchive.ietf.org/arch/msg/tls/T7z8M-wL_2nOpbJtehTqtGYjuWg/

    This TLS thread is full of some of the dumbest fucking opinions I've read in a technical discussion in years.

    In conversation about 3 months ago from furry.engineer permalink

    Attachments


    • Embed this notice
      Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 03-Jul-2026 16:31:16 JST Soatok Dreamseeker Soatok Dreamseeker
      in reply to
      • Dr. Christopher Kunz

      @christopherkunz Yeah. Reasonable people can disagree on Pure PQ vs Hybrid PQ, but summoning unreasonable shit-stirrers into the thread is a huge waste of everyone's time and energy.

      In conversation about 3 months ago permalink
    • Embed this notice
      Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Friday, 03-Jul-2026 16:31:18 JST Dr. Christopher Kunz Dr. Christopher Kunz
      in reply to

      @soatok Jeez that thread is a trainwreck. I feel genuinely compelled to have ChatGPT write me a three-paragraph summary. Feels like some kind of "flood the zone with shit" approach by certain list members...

      In conversation about 3 months ago permalink
    • Embed this notice
      Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 03-Jul-2026 16:38:10 JST Soatok Dreamseeker Soatok Dreamseeker
      in reply to

      Like, I am NOT a fan of the NSA, in the same way that I'm not a fan of Meta, Palantir, and the data broker industry.

      Surveillance is bad for society. Privacy is good for society. Using technology to undermine privacy and surveil people is a bad thing, actually. And while the official story is roughly that NSA only spies on other governments, and not innocent civilians, we have no way of knowing if that's true. And there's no way in hell I'll ever trust that.

      So, like most cryptographers, I'm squarely in the "Fuck the NSA" camp. Just like I'm in the "Fuck the FSB" camp. And every other nation state's equivalent agency is on that list too.

      But spy agencies aren't fucking magical. They can't violate information theory, physics, or causality.

      They also aren't omniscient about mathematics, logic, or software vulnerabilities. If they were, they wouldn't have competition. And they can't wave a magic wand and get enthusiastic cooperation from international forums of cryptology experts. That's ridiculous.

      In conversation about 3 months ago permalink

      Attachments


    • Embed this notice
      Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 03-Jul-2026 16:42:10 JST Soatok Dreamseeker Soatok Dreamseeker
      in reply to

      Every one of these agencies has a mission and a budget. To your or I, that budget might seem like "damn near infinite", but they still have constraints.

      NSA has two missions. Everyone knows about SIGINT because of Snowden, but they also have a competing mission called COMINT.

      You can, very loosely, map these two terms to "red team" and "blue team".

      If NSA knew a top secret way to break ML-KEM and were fairly confident that no other country has thought of it, there is no way in hell the SIGINT people could get the COMINT people to agree on a plan to migrate the entire federal fucking government to use ML-KEM. It doesn't line up with their self-interest.

      In conversation about 3 months ago permalink
    • Embed this notice
      Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 03-Jul-2026 16:43:44 JST Soatok Dreamseeker Soatok Dreamseeker
      in reply to

      There are very intelligent and passionate engineers, cryptographers, and analysts that vehemently disagree with my conclusions about the Hybrid debate. That's okay!

      But Bernstein summoned a mob of ill-informed people with messages designed to alarm them into action.

      In conversation about 3 months ago permalink
    • Embed this notice
      Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 03-Jul-2026 16:44:00 JST Soatok Dreamseeker Soatok Dreamseeker
      in reply to
      • Spíosra

      @spiosra Either that, or people who get screenshotted a lot on /r/IAmVerySmart :P

      In conversation about 3 months ago permalink
    • Embed this notice
      Spíosra (spiosra@sylfox.one)'s status on Friday, 03-Jul-2026 16:44:02 JST Spíosra Spíosra
      in reply to
      @soatok Way beyond my capacity to grasp, but I can only assume they're probably a bunch of Hacker News regulars...
      In conversation about 3 months ago permalink
    • Embed this notice
      David Chisnall (*Now with 50% more sarcasm!*) (david_chisnall@infosec.exchange)'s status on Saturday, 04-Jul-2026 01:33:36 JST David Chisnall (*Now with 50% more sarcasm!*) David Chisnall (*Now with 50% more sarcasm!*)
      in reply to

      @soatok

      The NSA is handicapped by being a dual-mission agency. The same organisation is responsible for:

      • Making sure that the USA's signals are secure.
      • Making sure that no other country's signals are secure from the USA.

      These are in obvious tension when the USA and everyone else are using the same off-the-shelf standards and implementations of those standards.

      I'm generally happy that they now prioritise the former over the latter, if only because they now know that there is a good chance that any weakness that they put in will be exploited by the Chinese, but I'd be a lot more comfortable if they properly separated the two concerns.

      I am still curious about Heartbleed because a lot of the US government was vulnerable and I know the NSA did some review of OpenSSL, so I don't know which of the following options was true:

      • They didn't bother to review a core piece of security-critical software that a lot of the government's security depended on (I have some evidence that it wasn't this one).
      • They did review it and missed a really important bug.
      • They did review it, found the bug, and made a staggeringly bad call about whether it was better to fix the bug or keep it as a thing to attack other people with.

      None of these possibilities makes them look especially competent.

      In conversation about 3 months ago permalink
      Soatok Dreamseeker repeated this.
    • Embed this notice
      SuiGeneris3722 (suigeneris3722@mastodon.social)'s status on Saturday, 04-Jul-2026 05:05:19 JST SuiGeneris3722 SuiGeneris3722
      in reply to

      @soatok You’re spot on. The biggest victory of these agencies is often the 'myth of the omniscient NSA,' because it scares people into thinking encryption is futile. When people believe they have 'magic' capabilities, they stop trying to defend their own privacy. It’s important to distinguish between 'they have immense resources' and 'they can break the laws of physics.' The former is true, but the latter is exactly what keeps us pushing for better standards.

      In conversation about 3 months ago permalink
    • Embed this notice
      Graham Sutherland🎃 / Polynomial.pdf.exe (gsuberland@chaos.social)'s status on Saturday, 04-Jul-2026 07:09:51 JST Graham Sutherland🎃 / Polynomial.pdf.exe Graham Sutherland🎃 / Polynomial.pdf.exe
      in reply to
      • Q ✨

      @soatok I particularly enjoyed @q 's post in that thread. perfectly put.

      In conversation about 3 months ago permalink
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 04-Jul-2026 07:13:15 JST hanno hanno
      in reply to
      • David Chisnall (*Now with 50% more sarcasm!*)

      @david_chisnall I mean... they made a staggeringly bad call on EternalBlue, which led to WannaCry, so the third option seems plausible. However, I think reviewing code and missing a bug in an obscure feature and missing that it's enabled by default is also not implausible.

      In conversation about 3 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.