GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by jcoglan (jcoglan@mastodon.social)

  1. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Sunday, 08-Mar-2026 01:45:17 JST jcoglan jcoglan
    in reply to
    • Janneke

    @janneke not sure I understand what you mean by this, can you elaborate?

    In conversation about 3 months ago from mastodon.social permalink
  2. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Thursday, 05-Mar-2026 21:25:38 JST jcoglan jcoglan

    is there a critique of that Knuth article? lots of people are gushing about it just b/c it's him, but I'm not familiar enough with its subject matter to tell if it's legit. however, stuff like this feels really off:

    "Filip Stappers tested Claude’s Python program for all odd m between 3 and 101, finding perfect decompositions each time. Thus he concluded, quite reasonably, that the problem was indeed solved for odd values of m."

    like, that's not how maths works

    In conversation about 3 months ago from mastodon.social permalink
  3. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Thursday, 26-Feb-2026 01:29:48 JST jcoglan jcoglan
    in reply to
    • Soatok Dreamseeker
    • Rich Felker

    @dalias @be_far @soatok yeah the perf arguments for this are weak. a better argument is minimising the amount of material you need to decrypt for each task. if you need to index on a particular thing, build that index and stick it in an encrypted doc like anything else

    In conversation about 4 months ago from mastodon.social permalink
  4. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Thursday, 26-Feb-2026 01:26:07 JST jcoglan jcoglan
    in reply to
    • Soatok Dreamseeker
    • Rich Felker

    @dalias @be_far @soatok yeah I've always been skeptical of how much application structure is plaintext. in the doc store I work on, all docs are opaque and the ID index is also an encrypted blob

    In conversation about 4 months ago from mastodon.social permalink
  5. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Thursday, 26-Feb-2026 01:00:33 JST jcoglan jcoglan
    • Soatok Dreamseeker

    @be_far @soatok not using the AD in AEAD to pin the identities of such fields is also baffling

    In conversation about 4 months ago from mastodon.social permalink
  6. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Thursday, 26-Feb-2026 00:54:21 JST jcoglan jcoglan

    RE: https://furry.engineer/@soatok/116132036314035223

    it is astonishing to me that this (i.e. security under an untrusted server) is novel research to these systems. ever since I started developing vault (2012) my model has been: I want to sync my secrets with dropbox, and I do not trust dropbox either not to look at my data or to preserve its integrity. these are ideas you would get from any basic introduction to cryptography

    In conversation about 4 months ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Soatok Dreamseeker (@soatok@furry.engineer)
      from Soatok Dreamseeker
      https://eprint.iacr.org/2026/058 Wow
  7. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Thursday, 19-Feb-2026 00:19:45 JST jcoglan jcoglan

    RE: https://furry.engineer/@soatok/116092111810620052

    "Two popular AES libraries, aes-js and pyaes, “helpfully” provide a default IV in their AES-CTR API" nope. nope nope nope

    this isn't a "this is suboptimal" problem this is a "the encryption is completely pointless" problem

    In conversation about 4 months ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Soatok Dreamseeker (@soatok@furry.engineer)
      from Soatok Dreamseeker
      Oof. Big oof. https://blog.trailofbits.com/2026/02/18/carelessness-versus-craftsmanship-in-cryptography/
  8. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Tuesday, 06-Jan-2026 20:33:53 JST jcoglan jcoglan
    in reply to
    • ✧✦Catherine✦✧

    @whitequark I think you're supposed to learn it from tv shows about the police

    In conversation about 5 months ago from mastodon.social permalink
  9. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Tuesday, 25-Nov-2025 22:07:25 JST jcoglan jcoglan

    it is really astonishing that npm has not even publicly acknowledged the potentially ongoing credential-stealing worm attack. what is going on in there

    In conversation about 7 months ago from mastodon.social permalink
  10. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Tuesday, 25-Nov-2025 22:07:24 JST jcoglan jcoglan
    in reply to

    this doesn't mean you can't *automate* publishing; there's a lot to like about automation and I won't pretend I love doing my publishing "manually". but you do need it to be *actively supervised* and prove that the package owner has specifically authorised each release

    In conversation about 7 months ago from mastodon.social permalink
  11. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Tuesday, 25-Nov-2025 22:07:24 JST jcoglan jcoglan
    in reply to

    as long as npm continues to allow any form of unsupervised publishing, this will continue to be a problem. I don't think that reducing token lifetime will help; it is an annoyance that people will just work around. you have to *require* the active participation of the publisher

    In conversation about 7 months ago from mastodon.social permalink
  12. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Tuesday, 25-Nov-2025 22:07:24 JST jcoglan jcoglan
    in reply to

    I'll also note that this is being framed as "supply chain security" when the actual problem is the combined set of capabilities of npm and github, both of which are the property of microsoft. this is a microsoft problem

    In conversation about 7 months ago from mastodon.social permalink
  13. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Thursday, 20-Nov-2025 18:10:38 JST jcoglan jcoglan

    no. no!

    In conversation about 7 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/577/612/703/007/313/original/f4bca39890860cb9.jpg
  14. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Saturday, 15-Nov-2025 22:03:20 JST jcoglan jcoglan
    in reply to
    • ✧✦Catherine✦✧

    @whitequark right, just put nginx on any old commodity cloud server and you get instant page loads. all my own stuff is hosted like this. I'm only using github pages because it seemed slightly more convenient for publishing stuff about some work in progress but I'll probably move it

    In conversation about 7 months ago from mastodon.social permalink
  15. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Saturday, 15-Nov-2025 21:58:15 JST jcoglan jcoglan
    in reply to
    • ✧✦Catherine✦✧

    @whitequark and then it's still slow as hell to serve pages even when you know it cannot possibly be generating them on the fly because it doesn't know about the build tool you used

    In conversation about 7 months ago from mastodon.social permalink
  16. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Saturday, 15-Nov-2025 21:54:45 JST jcoglan jcoglan
    in reply to
    • ✧✦Catherine✦✧

    @whitequark the odd thing is that it's not even a lot of effort to use any other tool; I use mdbook for a bunch of things. but the workflow is very, uh, non obvious

    In conversation about 7 months ago from gnusocial.jp permalink
  17. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Saturday, 08-Nov-2025 07:20:51 JST jcoglan jcoglan

    a while ago I tested chatgpt specifically on the details of using AES-GCM correctly and it gave multiple dangerously wrong answers. a password manager dev should at least know to ask such questions, so they're better off than a naive user who doesn't even know what to check for, but this does not fill me with confidence https://blobfox.coffee/@Ember/115507736529184708

    (disclosure: I make my own pw manager and encrypted DB and am generally hostile to genAI)

    In conversation about 7 months ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Ember :catplant:​ (@Ember@blobfox.coffee)
      from Ember :catplant:​
      Content warning: password manager PSA (keepassxc)
  18. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Friday, 17-Oct-2025 23:11:24 JST jcoglan jcoglan

    the ruby ecosystem, in particular the people running the package repo, have set a precedent that if you make something and it becomes important, it can be taken from you with no due process

    In conversation about 8 months ago from mastodon.social permalink
  19. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Friday, 17-Oct-2025 23:11:23 JST jcoglan jcoglan
    in reply to

    like, nobody at RC seems to think they owe anyone an explanation for how they even came to have ownership of rubygems and bundler. they have never demonstrated any basis for this claim

    In conversation about 8 months ago from mastodon.social permalink
  20. Embed this notice
    jcoglan (jcoglan@mastodon.social)'s status on Friday, 17-Oct-2025 22:09:30 JST jcoglan jcoglan

    the rubygems and bundler projects continue to change hands with nobody having ever explained how they came to be in the possession of ruby central https://www.ruby-lang.org/en/news/2025/10/17/rubygems-repository-transition/

    In conversation about 8 months ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      The Transition of RubyGems Repository Ownership
  • Before

User actions

    jcoglan

    jcoglan

    he/him : you may know me as @mountain_ghosts on twitter : I wrote some books you can buy from https://shop.jcoglan.com

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          290469
          Member since
          30 Oct 2024
          Notices
          86
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.