<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-17T12:41:02&#43;02:00</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by Filippo Valsorda</title>
  <author>
    <name>Filippo Valsorda</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1jzt0dcdqdhz0dmf3xk8fjn56kt45dqemtaz6rqzm9ycyz25p0nzqryjnwm.rss" />
  <link href="https://nostr.ae/npub1jzt0dcdqdhz0dmf3xk8fjn56kt45dqemtaz6rqzm9ycyz25p0nzqryjnwm" />
  <id>https://nostr.ae/npub1jzt0dcdqdhz0dmf3xk8fjn56kt45dqemtaz6rqzm9ycyz25p0nzqryjnwm</id>
  <icon>https://cdn.masto.host/abyssdomainexpert/accounts/avatars/109/472/682/376/441/460/original/ac66d0a023e6ef25.jpeg</icon>
  <logo>https://cdn.masto.host/abyssdomainexpert/accounts/avatars/109/472/682/376/441/460/original/ac66d0a023e6ef25.jpeg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqs00c90wpdzfkufz5494alkmfvz8jjprnwnm70fszdg7fezcc58f3qzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgkvsyaa</id>
    
      <title type="html">How much storage / bandwidth / CPU / memory does it take to run a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs00c90wpdzfkufz5494alkmfvz8jjprnwnm70fszdg7fezcc58f3qzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgkvsyaa" />
    <content type="html">
      How much storage / bandwidth / CPU / memory does it take to run a production Sunlight CT log? Surprisingly little!&lt;br/&gt;&lt;br/&gt;There&amp;#39;s now a public stats page, pulled every 5m from our Tuscolo prod metrics.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://stats.sunlight.geomys.org/&#34;&gt;https://stats.sunlight.geomys.org/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Less than 2 cores, 300 MB of memory, ~250 Mbps of bandwidth, 260 GiB of SSD.&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/116/454/308/251/297/764/original/fa07107842e1f9e8.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-23T15:42:06&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstfr5y29z5f8rh09mk34wtsy5hqe8myx3qxjz8wcypf9hy22jnleqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgl7pk2p</id>
    
      <title type="html">I wrote up in the TLS mailing list why I think composite ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstfr5y29z5f8rh09mk34wtsy5hqe8myx3qxjz8wcypf9hy22jnleqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgl7pk2p" />
    <content type="html">
      I wrote up in the TLS mailing list why I think composite signatures (ML-DSA &#43; ECDSA/RSA) are a net negative, will hurt the ecosystem, and should not be implemented.&lt;br/&gt;&lt;br/&gt;Hybrid key exchange was simple and self-contained. Hybrid signatures would be a mountain of complexity in code responsible for half of sev:crit in crypto libraries since 2020.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://mailarchive.ietf.org/arch/msg/tls/oh3jmmkHzHdp1hk4R4M9QjkmvBk/&#34;&gt;https://mailarchive.ietf.org/arch/msg/tls/oh3jmmkHzHdp1hk4R4M9QjkmvBk/&lt;/a&gt;
    </content>
    <updated>2026-04-15T14:51:01&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsru8tzlv7vg9sp9lqgv5sgh8d8xseflps30tr95waujmsynqgj6yszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgeyrsl7</id>
    
      <title type="html">Alright, it&amp;#39;s official! 💰 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsru8tzlv7vg9sp9lqgv5sgh8d8xseflps30tr95waujmsynqgj6yszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgeyrsl7" />
    <content type="html">
      Alright, it&amp;#39;s official! 💰&lt;br/&gt;&lt;br/&gt;[@matthew_d_green](&lt;a href=&#34;https://ioc.exchange/@matthew_d_green&#34;&gt;https://ioc.exchange/@matthew_d_green&lt;/a&gt; ) and I bet on what will break first, ML-KEM-768 or X25519. The loser donates to a 501(c)(3) picked by the winner.&lt;br/&gt;&lt;br/&gt;If you have an opinion on quantum computers or lattices, you can join with a side bet. Just submit a PR!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/FiloSottile/ecc-vs-lattices-long-bet&#34;&gt;https://github.com/FiloSottile/ecc-vs-lattices-long-bet&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/116/383/186/419/029/354/original/3a50e62fd0c6b1da.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-11T02:15:30&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstre0syswp7yf9hzkg6cfg2emhtmr39353s8x5tes0nzfezypek0qzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg3m6cxn</id>
    
      <title type="html">Two papers came out last week that suggest classical asymmetric ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstre0syswp7yf9hzkg6cfg2emhtmr39353s8x5tes0nzfezypek0qzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg3m6cxn" />
    <content type="html">
      Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years.&lt;br/&gt;&lt;br/&gt;That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn&amp;#39;t think PQ auth was so urgent until recently.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://words.filippo.io/crqc-timeline/&#34;&gt;https://words.filippo.io/crqc-timeline/&lt;/a&gt;
    </content>
    <updated>2026-04-06T17:14:07&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfsuv7fgv8exqr7vtgwcnwy3s4v559puxkh3p9x5mgcdl2gnst20gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vghuat9z</id>
    
      <title type="html">Last year, my position was that we still had time to design PQ ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfsuv7fgv8exqr7vtgwcnwy3s4v559puxkh3p9x5mgcdl2gnst20gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vghuat9z" />
    <content type="html">
      Last year, my position was that we still had time to design PQ authentication mechanisms.&lt;br/&gt;&lt;br/&gt;Now, based on the pace of progress and on statements like Google&amp;#39;s, I believe:&lt;br/&gt;&lt;br/&gt;1. we need to finish rolling out PQ key exchange yesterday&lt;br/&gt;2. we need to start rolling out PQ auth now&lt;br/&gt;3. it&amp;#39;s too late to ship any new non-PQ design or system&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/&#34;&gt;https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/&lt;/a&gt;
    </content>
    <updated>2026-03-26T16:43:15&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrfthmllpgvp9ax6v8n96s3erzt9jzrsvpl0ymr4625rpx363gxzczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgpu86qc</id>
    
      <title type="html">I can migrate to Pleroma/Akkoma without losing my posts?</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrfthmllpgvp9ax6v8n96s3erzt9jzrsvpl0ymr4625rpx363gxzczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgpu86qc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfwns69mk46lyyxg3pcxs59watmkjl7zke4u2nxhshzxa2d9lk66shegwmj&#39;&gt;nevent1q…gwmj&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I can migrate to Pleroma/Akkoma without losing my posts?
    </content>
    <updated>2026-03-20T17:16:00&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0emg4ysmkkdre2aah4dn2046r4s57j9vjelcrmc2qrtvvz242yxqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg09vt58</id>
    
      <title type="html">So uh, apparently $288/year is not enough to run a Mastodon ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0emg4ysmkkdre2aah4dn2046r4s57j9vjelcrmc2qrtvvz242yxqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg09vt58" />
    <content type="html">
      So uh, apparently $288/year is not enough to run a Mastodon service for ~3 users, and this is a known issue (&lt;a href=&#34;https://masto.host/mastodon-content-retention-settings/&#34;&gt;https://masto.host/mastodon-content-retention-settings/&lt;/a&gt;) with no solution (&lt;a href=&#34;https://github.com/mastodon/mastodon/discussions/19260&#34;&gt;https://github.com/mastodon/mastodon/discussions/19260&lt;/a&gt;)?!&lt;br/&gt;&lt;br/&gt;I just want to own my identity. On Bluesky, it takes a TXT record and a did:plc rotation key. A PDS takes like $25/yr. For $300/yr you can run a whole-network relay.&lt;br/&gt;&lt;br/&gt;Also, it&amp;#39;s unclear if I can move to non-Mastodon software without losing all my posts, despite owning the domain??&lt;br/&gt;&lt;br/&gt;And this ecosystem sneers at atproto?&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/116/262/370/987/395/643/original/51a35ef3b712e7ff.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-03-20T17:09:56&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs05c2wyh0qxmgupj0qnn5mp82cxytl0hckpgg5n6seqkyc8fpzweszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgu8t346</id>
    
      <title type="html">Dependabot security alerts have terrible signal-to-noise ratio, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs05c2wyh0qxmgupj0qnn5mp82cxytl0hckpgg5n6seqkyc8fpzweszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgu8t346" />
    <content type="html">
      Dependabot security alerts have terrible signal-to-noise ratio, especially for Go vulnerabilities. That hurts security!&lt;br/&gt;&lt;br/&gt;Just turn it off and set up a pair of scheduled GitHub Actions, one running govulncheck, and the other running CI against the latest version of your dependencies.&lt;br/&gt;&lt;br/&gt;Less work, less risk, better results!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://words.filippo.io/dependabot/?source=Mastodon&#34;&gt;https://words.filippo.io/dependabot/?source=Mastodon&lt;/a&gt;
    </content>
    <updated>2026-02-20T20:56:26&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst08pyalj67368mv2m2595xg9d0atuazcyqqx3x6mazeu5wmpttwczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgxu5u0a</id>
    
      <title type="html">Anyway, read Russ Cox&amp;#39;s take on AI tool use in the Go ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst08pyalj67368mv2m2595xg9d0atuazcyqqx3x6mazeu5wmpttwczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgxu5u0a" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs87skk4r6tm9t3kx7wyhd0408qp0xf4hc56wp4zx8mckfk2afxx0cs5tz9h&#39;&gt;nevent1q…tz9h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Anyway, read Russ Cox&amp;#39;s take on AI tool use in the Go project.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://groups.google.com/g/golang-dev/c/4Li4Ovd_ehE/m/8L9s_jq4BAAJ&#34;&gt;https://groups.google.com/g/golang-dev/c/4Li4Ovd_ehE/m/8L9s_jq4BAAJ&lt;/a&gt;
    </content>
    <updated>2026-02-16T14:35:07&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs87skk4r6tm9t3kx7wyhd0408qp0xf4hc56wp4zx8mckfk2afxx0czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgljxhax</id>
    
      <title type="html">One could go on! Do you fully trust third-party dependencies? Do ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs87skk4r6tm9t3kx7wyhd0408qp0xf4hc56wp4zx8mckfk2afxx0czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgljxhax" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs80fyja6qd35wv6g7t5eadf8vkcpnf7k7z42l4wgpslw6xnffatwsfcnqpx&#39;&gt;nevent1q…nqpx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;One could go on!&lt;br/&gt;&lt;br/&gt;Do you fully trust third-party dependencies?&lt;br/&gt;Do you always verify third-party dependencies?&lt;br/&gt;&lt;br/&gt;But somehow AI output is special and harbinger of all security issues.
    </content>
    <updated>2026-02-16T14:35:07&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs80fyja6qd35wv6g7t5eadf8vkcpnf7k7z42l4wgpslw6xnffatwszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgd2q6xp</id>
    
      <title type="html">I wish that those surveys so often cited by InfoSec pundits that ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs80fyja6qd35wv6g7t5eadf8vkcpnf7k7z42l4wgpslw6xnffatwszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgd2q6xp" />
    <content type="html">
      I wish that those surveys so often cited by InfoSec pundits that ask&lt;br/&gt;&lt;br/&gt;Do you fully trust AI output?&lt;br/&gt;Do you always verify AI output?&lt;br/&gt;&lt;br/&gt;also asked&lt;br/&gt;&lt;br/&gt;Do you fully trust your colleagues&amp;#39; output?&lt;br/&gt;Do you always verify your colleagues&amp;#39; output?&lt;br/&gt;&lt;br/&gt;Just to have comparative numbers, you know.
    </content>
    <updated>2026-02-16T14:35:07&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs99dge688ramw6ztm3u4rhnd2tg3ns76k3lcr734ck2hj63fq2faczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgmkwvna</id>
    
      <title type="html">I was indeed just venting about an annoying but manageable ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs99dge688ramw6ztm3u4rhnd2tg3ns76k3lcr734ck2hj63fq2faczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgmkwvna" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgh8u7ewh0sehdmef85quys2kup9kyw57fh03h62ysf5nkyumcrlgzfag53&#39;&gt;nevent1q…ag53&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I was indeed just venting about an annoying but manageable situation, thank you for the offer and for picking up on the intention :)
    </content>
    <updated>2026-01-24T12:59:16&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs076ta8697nkqtmahf0d4pty5xukq5vxgnalgdhrly3dpdfes3gtgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgvtt0ek</id>
    
      <title type="html">A wonderful twist on being an open source maintainer is when the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs076ta8697nkqtmahf0d4pty5xukq5vxgnalgdhrly3dpdfes3gtgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgvtt0ek" />
    <content type="html">
      A wonderful twist on being an open source maintainer is when the person engaging poorly and violating the CoC is a security reporter with some valid observations.&lt;br/&gt;&lt;br/&gt;You now have conflicting responsibilities to users&amp;#39; security and to your and your community&amp;#39;s safety.
    </content>
    <updated>2026-01-23T23:25:34&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9pa38whq7te4p4ymegd7n388u4gd8r85j52synyu3577ess9kpcszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgq03fkn</id>
    
      <title type="html">Do you have an idle cluster? Can you spare a couple core-years? ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9pa38whq7te4p4ymegd7n388u4gd8r85j52synyu3577ess9kpcszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgq03fkn" />
    <content type="html">
      Do you have an idle cluster? Can you spare a couple core-years?&lt;br/&gt;&lt;br/&gt;Help me bruteforce some test vectors for RSA key generation edge cases!&lt;br/&gt;&lt;br/&gt;Here are the instructions, it&amp;#39;s just a matter of running a single self-contained cross-compilable Go binary that will report the results autonomously.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://gist.github.com/FiloSottile/19e7ceb1fdcdaa128f7d3319ad0939fa&#34;&gt;https://gist.github.com/FiloSottile/19e7ceb1fdcdaa128f7d3319ad0939fa&lt;/a&gt;
    </content>
    <updated>2026-01-04T16:48:35&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqslrryz5ru00vd5q7wftfueys5x67mctenjdpgy0n36fwlg4pjgqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg7dz44t</id>
    
      <title type="html">I am the only one that can access the exe.dev account. Thank you ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqslrryz5ru00vd5q7wftfueys5x67mctenjdpgy0n36fwlg4pjgqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg7dz44t" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2e4vu8yj6rngvqzfzas0wmf5nxu989newkpwdynmmvdz2s70qjyqgagrxj&#39;&gt;nevent1q…grxj&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I am the only one that can access the exe.dev account. Thank you for your concern.
    </content>
    <updated>2026-01-02T18:39:02&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszz4ut4h4yaek2gxk0pqt2fxwjrce7x2ex9qr6h53fucgukzrr7xgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgkje5gn</id>
    
      <title type="html">1. yes. by using it. 2. yes, I trust I will survive 3. the code ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszz4ut4h4yaek2gxk0pqt2fxwjrce7x2ex9qr6h53fucgukzrr7xgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgkje5gn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy09qy2g524hvup7vrmc6haxez46h93gzq8w2xem7vlvm7jvc2y4cjsyneq&#39;&gt;nevent1q…yneq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;1. yes. by using it.&lt;br/&gt;&lt;br/&gt;2. yes, I trust I will survive&lt;br/&gt;&lt;br/&gt;3. the code is not public???
    </content>
    <updated>2026-01-02T18:35:41&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyrdppzcjx2v97x0en9g9x3l6m4cftnq7aqd8ghv5apnlunl486xczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgznfs9t</id>
    
      <title type="html">I care deeply about the open source ecosystem, so I feel the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyrdppzcjx2v97x0en9g9x3l6m4cftnq7aqd8ghv5apnlunl486xczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgznfs9t" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspls4akjaaezhtxqm8z5wx0zdnwq68p4zhc8hvfgaw9hd423zh2fsdaugf2&#39;&gt;nevent1q…ugf2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I care deeply about the open source ecosystem, so I feel the argument that disposable personalized software is by definition not shared or reused.&lt;br/&gt;&lt;br/&gt;However, let&amp;#39;s be honest here: I would not have built this without LLMs, and no one was going to open source a FIPS 140 backoffice manager.&lt;br/&gt;&lt;br/&gt;This only displaced a spreadsheet, a local script, a Google Drive folder, a bunch of emails, and error-prone manual processes.
    </content>
    <updated>2026-01-02T18:16:41&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspls4akjaaezhtxqm8z5wx0zdnwq68p4zhc8hvfgaw9hd423zh2fszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgwsu44h</id>
    
      <title type="html">I just completely vibecoded with exe.dev and Opus 4.5 a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspls4akjaaezhtxqm8z5wx0zdnwq68p4zhc8hvfgaw9hd423zh2fszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgwsu44h" />
    <content type="html">
      I just completely vibecoded with exe.dev and Opus 4.5 a backoffice for our FIPS 140 validation, with a separate view for the lab (where they can also upload test vectors), public links for clients, guided scripts for testing, and APIs to upload test results to S3.&lt;br/&gt;&lt;br/&gt;I have not looked at the code once. It works great.&lt;br/&gt;&lt;br/&gt;I am... processing this.
    </content>
    <updated>2026-01-02T18:16:41&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxqemju4xjk5yyrzr8eehalpe4wrsj454hypzmvv4erx07qnuyuwqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg7f7wd0</id>
    
      <title type="html">This is what the Go team does, too, and we are similarly sad ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxqemju4xjk5yyrzr8eehalpe4wrsj454hypzmvv4erx07qnuyuwqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg7f7wd0" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstaz8rqz738mxft3e5snz26egg0zkgg4mzjqwrtvjzx23vkh8n0ys0nv3hp&#39;&gt;nevent1q…v3hp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This is what the Go team does, too, and we are similarly sad about the made-up scores being taken seriously.
    </content>
    <updated>2026-01-01T14:05:52&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfldl2dgru09mxslkymg5jauqc397aktpc9c9hp5aw0vat4036ghczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg64facx</id>
    
      <title type="html">💥💥💥💥💥 age v1.3.0 💥💥💥💥💥 Post-quantum ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfldl2dgru09mxslkymg5jauqc397aktpc9c9hp5aw0vat4036ghczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg64facx" />
    <content type="html">
      💥💥💥💥💥 age v1.3.0 💥💥💥💥💥&lt;br/&gt;&lt;br/&gt;Post-quantum keys, seeking DecryptReaderAt API, age-inspect CLI tool, built-in recipients compatible with hardware plugins, non-interactive passphrase input, Go framework for implementing plugins, and sooooo many improved errors.&lt;br/&gt;&lt;br/&gt;Our best release yet, six years to the day after the first beta, again released from the floor of #39c3!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/FiloSottile/age/releases/tag/v1.3.0&#34;&gt;https://github.com/FiloSottile/age/releases/tag/v1.3.0&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/115/793/950/663/179/629/original/fe91f9803674021d.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-12-27T23:44:30&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs074ntzsyydde9vfpdhqesf53e68c7l0fz6lwgk38zx64x0yqsr8gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgqqjucm</id>
    
      <title type="html">At the https://gpg.fail talk and omg #39c3 You can just put a \0 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs074ntzsyydde9vfpdhqesf53e68c7l0fz6lwgk38zx64x0yqsr8gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgqqjucm" />
    <content type="html">
      At the &lt;a href=&#34;https://gpg.fail&#34;&gt;https://gpg.fail&lt;/a&gt; talk and omg #39c3&lt;br/&gt;&lt;br/&gt;You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message.&lt;br/&gt;&lt;br/&gt;Won’t even blame PGP here. C is unsafe at any speed.&lt;br/&gt;&lt;br/&gt;gpg has not fixed it yet.&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/115/792/484/165/073/814/original/62c310403495b926.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-12-27T17:31:33&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvv5kdc27g86ak4xm7dd2mn8g5xq84h8rf9knyslyv674tcx8whaczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgvk7wlf</id>
    
      <title type="html">After reading https://commaok.xyz/ai/just-in-time-software/ I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvv5kdc27g86ak4xm7dd2mn8g5xq84h8rf9knyslyv674tcx8whaczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgvk7wlf" />
    <content type="html">
      After reading &lt;a href=&#34;https://commaok.xyz/ai/just-in-time-software/&#34;&gt;https://commaok.xyz/ai/just-in-time-software/&lt;/a&gt; I gave exe.dev a shot and the combination of cheap VMs, the HTTPS proxy with passkey auth and link sharing, and the built-in LLM agent is... incredible.&lt;br/&gt;&lt;br/&gt;Like, I know how to use each of these things individually, but combining them feels like when I first learned to script things.
    </content>
    <updated>2025-12-24T16:14:38&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx870fp5vauc44cs3jmx63q3dyg9hu58h2jqft0hu0ww9ruykmk6qzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg64rnf5</id>
    
      <title type="html">This Bernstein crap drives me up the wall because IT MAKES NO ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx870fp5vauc44cs3jmx63q3dyg9hu58h2jqft0hu0ww9ruykmk6qzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg64rnf5" />
    <content type="html">
      This Bernstein crap drives me up the wall because IT MAKES NO SENSE.&lt;br/&gt;&lt;br/&gt;Why would the NSA be picking weak crypto to protect US NatSec?!&lt;br/&gt;&lt;br/&gt;They have mathematicians and clusters in China, too!&lt;br/&gt;&lt;br/&gt;Dual_EC_DRBG was a NOBUS backdoor. There is NOWHERE to hide a NOBUS backdoor in ML-KEM. Look at the code, there is nothing even remotely public key shaped.
    </content>
    <updated>2025-11-24T22:27:14&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx48cyq4dzkg54th5d5yeyrrl373exnehhdf9f8pufjxyjsttj8tczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg059nqn</id>
    
      <title type="html">So tempted to write a troll thread on how this incident shows ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx48cyq4dzkg54th5d5yeyrrl373exnehhdf9f8pufjxyjsttj8tczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg059nqn" />
    <content type="html">
      So tempted to write a troll thread on how this incident shows Rust has bad error handling and wouldn’t have happened in Go, where we actually handle errors 🫣🫢😜&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.cloudflare.com/18-november-2025-outage/#memory-preallocation&#34;&gt;https://blog.cloudflare.com/18-november-2025-outage/#memory-preallocation&lt;/a&gt;
    </content>
    <updated>2025-11-19T11:14:07&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0ewhcp3eqqu7rk4hc2nxzf2sk3trq87flanh09elxljxkvads74gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgzeq9m5</id>
    
      <title type="html">Going live on https://www.twitch.tv/filosottile in 30 minutes! ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0ewhcp3eqqu7rk4hc2nxzf2sk3trq87flanh09elxljxkvads74gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgzeq9m5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdlp6h0hz2wvgm2ury7zksvnvnkzewlwwz2gc3dapfhpnz9m9s5kgr04cef&#39;&gt;nevent1q…4cef&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Going live on &lt;a href=&#34;https://www.twitch.tv/filosottile&#34;&gt;https://www.twitch.tv/filosottile&lt;/a&gt; in 30 minutes! 🔴&lt;br/&gt;&lt;br/&gt;Join me for some Go livecoding of the post-quantum signature scheme ML-DSA!
    </content>
    <updated>2025-10-26T15:02:47&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdlp6h0hz2wvgm2ury7zksvnvnkzewlwwz2gc3dapfhpnz9m9s5kgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgefrlmd</id>
    
      <title type="html">Alright, I put together a field implementation for the base ring ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdlp6h0hz2wvgm2ury7zksvnvnkzewlwwz2gc3dapfhpnz9m9s5kgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgefrlmd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvrnkt5z8ql7f5hcx43r3j7a6h7ph8qpsfhvxcuauups2teqg28rqj25amm&#39;&gt;nevent1q…5amm&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Alright, I put together a field implementation for the base ring using simple Montgomery multiplication, so we&amp;#39;ll not have to worry about that part.&lt;br/&gt;&lt;br/&gt;Will probably stream the actual ML-DSA implementation in the CET afternoon.&lt;br/&gt;&lt;br/&gt;Give &lt;a href=&#34;https://words.filippo.io/kyber-math/&#34;&gt;https://words.filippo.io/kyber-math/&lt;/a&gt; a read if you want to come prepared!
    </content>
    <updated>2025-10-26T12:59:30&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvrnkt5z8ql7f5hcx43r3j7a6h7ph8qpsfhvxcuauups2teqg28rqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgpm8kj2</id>
    
      <title type="html">I&amp;#39;ve added an appendix to my &amp;#34;Enough Polynomials and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvrnkt5z8ql7f5hcx43r3j7a6h7ph8qpsfhvxcuauups2teqg28rqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgpm8kj2" />
    <content type="html">
      I&amp;#39;ve added an appendix to my &amp;#34;Enough Polynomials and Linear Algebra to Implement Kyber&amp;#34; article with the little extra needed to implement Dilithium/ML-DSA.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://words.filippo.io/kyber-math/#appendix-a-bit-more-for-ml-dsa&#34;&gt;https://words.filippo.io/kyber-math/#appendix-a-bit-more-for-ml-dsa&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Maybe I&amp;#39;ll stream an ML-DSA implementation tomorrow at &lt;a href=&#34;https://www.twitch.tv/filosottile&#34;&gt;https://www.twitch.tv/filosottile&lt;/a&gt;.
    </content>
    <updated>2025-10-26T02:55:23&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy0k588ck6824u9lfwnzch4fuygx4fe0uggh5kf287wspsh8s8c6szyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg3gz5j3</id>
    
      <title type="html">&amp;#34;Lack of scalability is enough for us to disqualify QKD ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy0k588ck6824u9lfwnzch4fuygx4fe0uggh5kf287wspsh8s8c6szyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg3gz5j3" />
    <content type="html">
      &amp;#34;Lack of scalability is enough for us to disqualify QKD outright: if a technology can’t bring security to the whole Internet, we’re not going to spend much time on it.&amp;#34;&lt;br/&gt;&lt;br/&gt;Quantum Key Distribution (as opposed to post-quantum cryptography) has a number of problems, but this succinctly captures the core issue.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.cloudflare.com/you-dont-need-quantum-hardware/&#34;&gt;https://blog.cloudflare.com/you-dont-need-quantum-hardware/&lt;/a&gt;
    </content>
    <updated>2025-09-19T15:58:56&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyjkpkdfwv03ttr5zspwqu6zxjrp8tppy22akk5wm3gaqf6fgpjlqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg063v0a</id>
    
      <title type="html">Anytime I read something like “10,000 requests in a few ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyjkpkdfwv03ttr5zspwqu6zxjrp8tppy22akk5wm3gaqf6fgpjlqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg063v0a" />
    <content type="html">
      Anytime I read something like “10,000 requests in a few hours” or “one million requests in a week” I‘m immediately skeptical of the framing.&lt;br/&gt;&lt;br/&gt;That’s ~0.5 rps and ~1.7 rps, respectively. The disposable vape on HN right now claims 6.25 rps (160 ms page loads).
    </content>
    <updated>2025-09-16T03:33:16&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvm8fdpyef8jj786whwfucpl64wcgpvze8u5ew5uspehfn4jjpx7czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtt5v84</id>
    
      <title type="html">There&amp;#39;s a bit of commotion on Lobsters because an ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvm8fdpyef8jj786whwfucpl64wcgpvze8u5ew5uspehfn4jjpx7czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtt5v84" />
    <content type="html">
      There&amp;#39;s a bit of commotion on Lobsters because an unpleasant-but-technically-correct user finally got banned, and I realized that an unpopular opinion of mine is that moderators are always right.&lt;br/&gt;&lt;br/&gt;I don&amp;#39;t care about the letter of the CoC. I don&amp;#39;t care about transparency, even. Moderation is the fundamentally human and nuanced big-picture job that shapes a community.&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/115/123/712/178/230/773/original/42748b9cdd676f14.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-31T15:54:02&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrcj096gn0r6wdfcnlgtpaclvh8l0n77vfdaea9p8krf9txx9d3yczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgh0yaqc</id>
    
      <title type="html">Sometimes mods will do something I wouldn&amp;#39;t have. I&amp;#39;ll ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrcj096gn0r6wdfcnlgtpaclvh8l0n77vfdaea9p8krf9txx9d3yczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgh0yaqc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvm8fdpyef8jj786whwfucpl64wcgpvze8u5ew5uspehfn4jjpx7cn3txvl&#39;&gt;nevent1q…txvl&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Sometimes mods will do something I wouldn&amp;#39;t have. I&amp;#39;ll never know because I will never have the full context, but even then they&amp;#39;re not wrong.&lt;br/&gt;&lt;br/&gt;They are shaping the community. If I don&amp;#39;t like it (e.g. choosing borderline assholes over the rest of us), it&amp;#39;s just not my community.
    </content>
    <updated>2025-08-31T15:54:02&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdzg3379s7668pe9q0zuye2nju8lpxteace7wn5rhcjusr5s6facczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgaxud8t</id>
    
      <title type="html">I edited my Cross-Site Request Forgery countermeasures research ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdzg3379s7668pe9q0zuye2nju8lpxteace7wn5rhcjusr5s6facczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgaxud8t" />
    <content type="html">
      I edited my Cross-Site Request Forgery countermeasures research into a stand-alone article, including recommendations reusable by other projects.&lt;br/&gt;&lt;br/&gt;tl;dr: no need for tokens or keys, modern browsers tell you if a request is cross-origin!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://words.filippo.io/csrf?source=Mastodon&#34;&gt;https://words.filippo.io/csrf?source=Mastodon&lt;/a&gt;
    </content>
    <updated>2025-08-13T18:07:51&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr20fkfju9kxsar85la2k5e9swhrry02zjz5n2tegqgy6k0gkvzwgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg9cr7ed</id>
    
      <title type="html">This is pretty well executed phishing. The Copy button copies to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr20fkfju9kxsar85la2k5e9swhrry02zjz5n2tegqgy6k0gkvzwgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg9cr7ed" />
    <content type="html">
      This is pretty well executed phishing.&lt;br/&gt;&lt;br/&gt;The Copy button copies to the clipboard&lt;br/&gt;&lt;br/&gt;echo &amp;#34;Y3Vy[...]ggJg==&amp;#34; | base64 -d | bash&lt;br/&gt;&lt;br/&gt;which in turn curls this script &lt;a href=&#34;https://gist.github.com/FiloSottile/385137f5ca2eabb51fd206bde2ff1d0a&#34;&gt;https://gist.github.com/FiloSottile/385137f5ca2eabb51fd206bde2ff1d0a&lt;/a&gt; into bash.&lt;br/&gt;&lt;br/&gt;They even detect piping, so to read it you have to run &amp;#34;curl | cat&amp;#34;.&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/114/868/224/746/439/839/original/67b6eec46293826c.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-07-17T13:00:13&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2xqv4akxn0az6a3uhamwh45yle0q7w92cryry7m5l53rdu4jrp7czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgekdpnk</id>
    
      <title type="html">Operating a Certificate Transparency log is now within reach of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2xqv4akxn0az6a3uhamwh45yle0q7w92cryry7m5l53rdu4jrp7czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgekdpnk" />
    <content type="html">
      Operating a Certificate Transparency log is now within reach of many organizations.&lt;br/&gt;&lt;br/&gt;I wrote up the requirements: essentially one small server process, a couple people, and the capacity to host 3-5 TB of static files. &lt;a href=&#34;https://words.filippo.io/run-sunlight/&#34;&gt;https://words.filippo.io/run-sunlight/&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;I&amp;#39;d love to chat with anyone who&amp;#39;s considering running one!
    </content>
    <updated>2025-07-08T20:23:39&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdrueuhazvhk5mvx9wfkdstgk05g0hr5n4ucna50ff8czl0tw9m7qzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgnj0syu</id>
    
      <title type="html">I released version 0.2.4 of Typage, the TypeScript implementation ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdrueuhazvhk5mvx9wfkdstgk05g0hr5n4ucna50ff8czl0tw9m7qzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgnj0syu" />
    <content type="html">
      I released version 0.2.4 of Typage, the TypeScript implementation of age for Node/Deno/Bun and browsers.&lt;br/&gt;&lt;br/&gt;encrypt and decrypt now accept and return ReadableStreams to encrypt/decrypt large files on the fly. The returned object also has an additional method to compute the expected output size from the input size.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/FiloSottile/typage/releases/tag/v0.2.4&#34;&gt;https://github.com/FiloSottile/typage/releases/tag/v0.2.4&lt;/a&gt;
    </content>
    <updated>2025-07-06T17:10:23&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqmm5mm9tyd22h083ujk46wfr2mep3w4jmqhwtty3tksg3psegyugzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgrpajy3</id>
    
      <title type="html">I wish we had spaces to collaborate on technical work where being ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqmm5mm9tyd22h083ujk46wfr2mep3w4jmqhwtty3tksg3psegyugzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgrpajy3" />
    <content type="html">
      I wish we had spaces to collaborate on technical work where being a jerk was just not allowed. Like, actual proper fearless moderation.&lt;br/&gt;&lt;br/&gt;Your reply starts with &amp;#34;No.&amp;#34; on its own line? Two weeks ban. Learn to behave.&lt;br/&gt;&lt;br/&gt;You go on a tear about another participant? One year ban. No warning.&lt;br/&gt;&lt;br/&gt;I&amp;#39;m a privileged white dude with 20k followers and even I hesitate to contribute to some spaces because of the mailing list hand-to-hand combat.&lt;br/&gt;&lt;br/&gt;Imagine how many contributions by talented folks we are wasting!
    </content>
    <updated>2025-06-30T18:11:12&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrxptpgj80mry3qxarc8x9wkwzedvy7dyzyy6zw38tctse5ejm3aczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg0snfvr</id>
    
      <title type="html">gee, trying new ideas for open source maintenance sustainability, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrxptpgj80mry3qxarc8x9wkwzedvy7dyzyy6zw38tctse5ejm3aczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg0snfvr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqj2lclhz9vgvc7q46659n48w8svcx3k2szymmc5c6awud3fkc5tcsyacry&#39;&gt;nevent1q…acry&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;gee, trying new ideas for open source maintenance sustainability, I should consider trying that
    </content>
    <updated>2025-06-23T00:41:14&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdjvh5tjp6m3essua6qvgzlnu3f4ym5jvr7xa6tk5u0qsy3hj0v6gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgnxlh6u</id>
    
      <title type="html">it’s not so black and white. If you are an unpaid maintainer ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdjvh5tjp6m3essua6qvgzlnu3f4ym5jvr7xa6tk5u0qsy3hj0v6gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgnxlh6u" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfd342rfa4u80vnd4lpqyjuh6tytjf00ejg4ac077dw2u6fqtarkqrp0jef&#39;&gt;nevent1q…0jef&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;it’s not so black and white. If you are an unpaid maintainer you have no obligation to put in extra work, for sure. But if you do take down the banking system of a country once (still not your fault!) and people tell you your library is broken… I think you start having a responsibility to either deprecate it, fix it, or at least warn users. We live in a society.
    </content>
    <updated>2025-06-21T23:22:02&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsptp0z6ye6muqn6s54vf47pry9t7srxu72cu08haxaa9zydv4rquczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgjeuk6s</id>
    
      <title type="html">Looks like the same poorly implemented Android CT library that ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsptp0z6ye6muqn6s54vf47pry9t7srxu72cu08haxaa9zydv4rquczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgjeuk6s" />
    <content type="html">
      Looks like the same poorly implemented Android CT library that broke a lot of apps a couple years ago... did it again 🤦‍♂️&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/appmattus/certificatetransparency/issues/143#issuecomment-2993688741&#34;&gt;https://github.com/appmattus/certificatetransparency/issues/143#issuecomment-2993688741&lt;/a&gt;
    </content>
    <updated>2025-06-21T20:29:26&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf2488ftrhgavmv42gldct0l5qgl4wj7rfmnqxwtesd7qpgwx4weqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg5q8gvs</id>
    
      <title type="html">The Sketch blog has become the one thing you need to read—along ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf2488ftrhgavmv42gldct0l5qgl4wj7rfmnqxwtesd7qpgwx4weqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg5q8gvs" />
    <content type="html">
      The Sketch blog has become the one thing you need to read—along with &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1gv26rplqyjqcfyhxryuqjwaxs0dwve3y6gpv6smn3hjm3wse3s8squtlwl&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Simon Willison&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1gv2…tlwl&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;—to keep the pulse of LLM-assisted development.&lt;br/&gt;&lt;br/&gt;Senior engineers putting in the work and giving no-bullshit perspectives.&lt;br/&gt;&lt;br/&gt;Read this one by &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1zlv43zfyah2arh89x0d67gh7xlep4lm9u6ggvw2sje6c95aravtq0hlytv&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;David Crawshaw&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1zlv…lytv&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; through. Not skim. Not half. Especially if you are a skeptic.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sketch.dev/blog/programming-with-agents&#34;&gt;https://sketch.dev/blog/programming-with-agents&lt;/a&gt;
    </content>
    <updated>2025-06-09T11:52:45&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsylrsfwkuyvuez2gey3h2yd2rglukfcgj7nkz7dc9acz7q5djgy9szyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg88mgty</id>
    
      <title type="html">Another nice use case for Fetch Metadata headers (which we used ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsylrsfwkuyvuez2gey3h2yd2rglukfcgj7nkz7dc9acz7q5djgy9szyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg88mgty" />
    <content type="html">
      Another nice use case for Fetch Metadata headers (which we used for anti-CSRF in the last episode): server-side analytics.&lt;br/&gt;&lt;br/&gt;On the client-side, any rendered HTML is a browser pageview, but on the server-side how do you tell pageviews from API calls from resource loads?&lt;br/&gt;&lt;br/&gt;Sec-Fetch-Mode: navigate!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Sec-Fetch-Mode&#34;&gt;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Sec-Fetch-Mode&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;I&amp;#39;m a fan of server-side analytics because they are more accurate, they don&amp;#39;t waste client resources, and let you also count things like redirect URLs pointing to other sites.
    </content>
    <updated>2025-06-07T23:11:08&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx0kh9lcee95cd4jh9llnsf34quxsph4dtp0cyf4hzwnz0qv6cu9gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg7dp6s2</id>
    
      <title type="html">Fascinating retrospective read on an iOS exploit, but the most ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx0kh9lcee95cd4jh9llnsf34quxsph4dtp0cyf4hzwnz0qv6cu9gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg7dp6s2" />
    <content type="html">
      Fascinating retrospective read on an iOS exploit, but the most interesting part might be the Aftermath section.&lt;br/&gt;&lt;br/&gt;Apparently Apple shifted gears with iOS 14 and started implementing deep mitigations, which despite not perfect really changed the game.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.siguza.net/tachy0n/#:~:text=4.-,Aftermath&#34;&gt;https://blog.siguza.net/tachy0n/#:~:text=4.-,Aftermath&lt;/a&gt;
    </content>
    <updated>2025-05-25T13:32:29&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstrz2579ha030f8yz8wmgck9d9xxj5tp7aqnd0dch92hmffqzzl2gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgt4vugh</id>
    
      <title type="html">If Certificate Transparency logs were available as torrents, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstrz2579ha030f8yz8wmgck9d9xxj5tp7aqnd0dch92hmffqzzl2gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgt4vugh" />
    <content type="html">
      If Certificate Transparency logs were available as torrents, would you help seeding them?&lt;br/&gt;&lt;br/&gt;If so, with how much storage and with what client?&lt;br/&gt;&lt;br/&gt;I’m not sure how we’d update the torrent as the log grows. Does BEP 38 deduplication work with RSS feeds?
    </content>
    <updated>2025-05-21T00:08:34&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrp50w98pshfn7yqm3ahe0ljyzljwsd705eu70tac04cawtf4zfpqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgdar8nq</id>
    
      <title type="html">Three Trail of Bits engineers audited the core Go cryptography ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrp50w98pshfn7yqm3ahe0ljyzljwsd705eu70tac04cawtf4zfpqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgdar8nq" />
    <content type="html">
      Three Trail of Bits engineers audited the core Go cryptography packages for a month, and found only one low-sev security issue... in the legacy unsupported Go&#43;BoringCrypto integration we&amp;#39;re replacing! 🍾 &lt;br/&gt;&lt;br/&gt;Years of team efforts on testing, limiting complexity, safe APIs, and readability have paid off! ✨ &lt;br/&gt;&lt;br/&gt;Yes I am taking a victory lap. No I am not sorry. 🏆&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://go.dev/blog/tob-crypto-audit&#34;&gt;https://go.dev/blog/tob-crypto-audit&lt;/a&gt;
    </content>
    <updated>2025-05-19T21:07:59&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs83ty9cxz4w3u6mdv48z4xlmssge4xjf6wchq853ceel5ztm9uceqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgdld7me</id>
    
      <title type="html">The AWS team published a key-committing variant of XAES ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs83ty9cxz4w3u6mdv48z4xlmssge4xjf6wchq853ceel5ztm9uceqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgdld7me" />
    <content type="html">
      The AWS team published a key-committing variant of XAES (&lt;a href=&#34;https://words.filippo.io/xaes-256-gcm/&#34;&gt;https://words.filippo.io/xaes-256-gcm/&lt;/a&gt;)!&lt;br/&gt;&lt;br/&gt;Still FIPS-compliant, and with a proof.&lt;br/&gt;&lt;br/&gt;Key commitment ensures the ciphertext can only be decrypted with one key, to avoid issues in higher-level protocols.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://eprint.iacr.org/2025/758.pdf&#34;&gt;https://eprint.iacr.org/2025/758.pdf&lt;/a&gt;
    </content>
    <updated>2025-05-08T14:01:25&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdgl2yc46k0ve2dxdmx45a2rf4m8fzzxewtn6nwhwlekcw4j03kjgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgctu029</id>
    
      <title type="html">Running a full-network Bluesky relay costs less ($19) than my ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdgl2yc46k0ve2dxdmx45a2rf4m8fzzxewtn6nwhwlekcw4j03kjgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgctu029" />
    <content type="html">
      Running a full-network Bluesky relay costs less ($19) than my beefy but ~single user Mastodon hosted instance ($24).&lt;br/&gt;&lt;br/&gt;People underestimate how much data optimized software can move through efficient protocols on modern non-cloud hardware.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://whtwnd.com/bnewbold.net/3lo7a2a4qxg2l&#34;&gt;https://whtwnd.com/bnewbold.net/3lo7a2a4qxg2l&lt;/a&gt;
    </content>
    <updated>2025-05-02T23:36:51&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdpgp53f7lzhjlvqj4z8nvhtkthshv2qxn06ywcwcma95xq8wtvgczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtt7wz8</id>
    
      <title type="html">The relay is the supposedly centralized part of Bluesky because ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdpgp53f7lzhjlvqj4z8nvhtkthshv2qxn06ywcwcma95xq8wtvgczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtt7wz8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdgl2yc46k0ve2dxdmx45a2rf4m8fzzxewtn6nwhwlekcw4j03kjg08e0ak&#39;&gt;nevent1q…e0ak&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The relay is the supposedly centralized part of Bluesky because “too big” to run! $19/month!&lt;br/&gt;&lt;br/&gt;The bsky.app AppView is bigger but every Mastodon instance is an AppView (and PDS), and if you were ok with Mastodon-style partial views of the network, AppViews would be cheap too.
    </content>
    <updated>2025-05-02T23:36:51&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdjpluh2z5vfe57ym8tff30t93eumauxska2zrjr0344q6v3lfhqczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg3cvllj</id>
    
      <title type="html">Here&amp;#39;s something counterintuitive to non-practitioners: curve ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdjpluh2z5vfe57ym8tff30t93eumauxska2zrjr0344q6v3lfhqczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg3cvllj" />
    <content type="html">
      Here&amp;#39;s something counterintuitive to non-practitioners: curve P-521 is often less secure in practice than curve P-256.&lt;br/&gt;&lt;br/&gt;The latter is more popular, and so better tested. The risk of implementation bugs dwarfs the risk of partial cryptanalysis of ECC, so picking P-521 optimizes for the wrong thing.
    </content>
    <updated>2025-05-01T19:40:27&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9h4jutgm3qcde8akra2get0ym0lf4gkgyjzxnnl7k5jvdu8ekfhgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgshj695</id>
    
      <title type="html">I am writing an application that really cares about durability of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9h4jutgm3qcde8akra2get0ym0lf4gkgyjzxnnl7k5jvdu8ekfhgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgshj695" />
    <content type="html">
      I am writing an application that really cares about durability of created files (a Certificate Transparency log), and... oof.&lt;br/&gt;&lt;br/&gt;I fsync the file. I fsync the directory. Ok.&lt;br/&gt;&lt;br/&gt;But... how do I test it? Even targeting a specific filesystem, I have to make VMs and try to race killing them?
    </content>
    <updated>2025-04-22T11:17:16&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd29l7m56e0dzpcwu2vnc533n0leapwmvt72hyc0cxz8kfcmcpvzszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgxzryza</id>
    
      <title type="html">Oof. Reportedly, if you got a certificate from SSL.com by putting ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd29l7m56e0dzpcwu2vnc533n0leapwmvt72hyc0cxz8kfcmcpvzszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgxzryza" />
    <content type="html">
      Oof. Reportedly, if you got a certificate from SSL.com by putting “example[@]gmail.com” at _validation-contactemail.example.com, they would add gmail.com (!!!) to your verified domains.&lt;br/&gt;&lt;br/&gt;A good reminder to use the CAA record, and to sign up for CT monitoring (e.g. Cert Spotter).&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://bugzilla.mozilla.org/show_bug.cgi?id=1961406&#34;&gt;https://bugzilla.mozilla.org/show_bug.cgi?id=1961406&lt;/a&gt;
    </content>
    <updated>2025-04-19T12:30:45&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgncu8vvfpwt8kyxc0f76dmu0qxmrkeqa24qgd8vcnxjtpwht3m6gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgpqzv7k</id>
    
      <title type="html">OpenSSH 10.0 (a regular bump from 9.9) is out, and it makes the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgncu8vvfpwt8kyxc0f76dmu0qxmrkeqa24qgd8vcnxjtpwht3m6gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgpqzv7k" />
    <content type="html">
      OpenSSH 10.0 (a regular bump from 9.9) is out, and it makes the post-quantum ML-KEM hybrid mlkem768x25519-sha256 the default. &lt;a href=&#34;https://www.openssh.com/txt/release-10.0&#34;&gt;https://www.openssh.com/txt/release-10.0&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The next release of x/crypto/ssh will support it, too, when used with Go 1.24, making SSH sessions quantum resistant! ⛓️ &lt;a href=&#34;https://go.dev/cl/646075&#34;&gt;https://go.dev/cl/646075&lt;/a&gt;
    </content>
    <updated>2025-04-10T11:57:50&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd0j73kykmw75cly9r4z79jz07w0rkjp74g5ckvppz9zjgh7c4fxgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg94ndfu</id>
    
      <title type="html">It’s disheartening to see AI reactionism lead my community to a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd0j73kykmw75cly9r4z79jz07w0rkjp74g5ckvppz9zjgh7c4fxgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg94ndfu" />
    <content type="html">
      It’s disheartening to see AI reactionism lead my community to a 180° on copyright.&lt;br/&gt;&lt;br/&gt;Everyone is merrily attacking LibGen now. If it didn’t exist, big tech companies would still find training data, it just wouldn’t be accessible to regular people.
    </content>
    <updated>2025-03-21T10:22:48&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst8e4wsqpylajuukxyjtzrnllgn3a9p7u7v96ms6kywts2ezqdn0czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgyfrza3</id>
    
      <title type="html">Would you pay for Cryptography Dispatches? I am considering using ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst8e4wsqpylajuukxyjtzrnllgn3a9p7u7v96ms6kywts2ezqdn0czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgyfrza3" />
    <content type="html">
      Would you pay for Cryptography Dispatches? I am considering using Buttondown&amp;#39;s new per-email subscriptions to trick myself into writing more in 2025.&lt;br/&gt;&lt;br/&gt;This would be voluntary. Max 1–3 issues per month.&lt;br/&gt;&lt;br/&gt;There would be no subscriber-only issues. What you get for your money is motivating me to write more, if that&amp;#39;s something you like.&lt;br/&gt;&lt;br/&gt;Conversely, this would not be a major source of income. What I get out of it is tricking my brain into doing more writing by setting up a reward system.
    </content>
    <updated>2024-12-11T20:12:39&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswkr9u7pzm8e5yc38g4pu0c68j9sek0l68hq2rqfa64ah6e80earqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgyr9ah3</id>
    
      <title type="html">I wrote up how my NAS is now just a big initramfs based on Alpine ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswkr9u7pzm8e5yc38g4pu0c68j9sek0l68hq2rqfa64ah6e80earqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgyr9ah3" />
    <content type="html">
      I wrote up how my NAS is now just a big initramfs based on Alpine Linux.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s been pretty great. Immutable, declarative, and very very simple. Just some files, a list of packages, and a short script.&lt;br/&gt;&lt;br/&gt;Turns out you don&amp;#39;t need overlays, or special DSLs.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://words.filippo.io/dispatches/frood/?source=Mastodon&#34;&gt;https://words.filippo.io/dispatches/frood/?source=Mastodon&lt;/a&gt;
    </content>
    <updated>2024-12-05T22:30:22&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdvk5kqe27u0t3v3zsnpl4hahwyas2f2an4mdma2awtgnr48j9ywgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgw5myd3</id>
    
      <title type="html">only when you poll it though, right? And here I would only query ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdvk5kqe27u0t3v3zsnpl4hahwyas2f2an4mdma2awtgnr48j9ywgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgw5myd3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsduau5c7uym6udddr3y4lrxhavs9kdlzm2tm44hplahehylh2d5mq9qvccq&#39;&gt;nevent1q…vccq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;only when you poll it though, right? And here I would only query it manually.
    </content>
    <updated>2024-11-23T15:16:29&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfzdthkzqeycpgs39d56mj23sp4dmxd4pep29huqh9n0r5nev2fagzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vggm3m4l</id>
    
      <title type="html">Hmm, it occurs to me that what I need is probably all in ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfzdthkzqeycpgs39d56mj23sp4dmxd4pep29huqh9n0r5nev2fagzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vggm3m4l" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdlmz9pp369zjrd42gv9atns2exuy40rsvz929lgr7hswmudtfd6c9ftgeh&#39;&gt;nevent1q…tgeh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Hmm, it occurs to me that what I need is probably all in node_exporter already. Is there such a thing as a web UI for instantaneous Prometheus metrics?&lt;br/&gt;&lt;br/&gt;i.e. a web service that just does a single poll of a Prometheus endpoint, and shows you the current values of the available metrics, with no history.&lt;br/&gt;&lt;br/&gt;Hell, maybe even a CLI that I point to the remote Prometheus endpoint.
    </content>
    <updated>2024-11-23T15:11:56&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdlmz9pp369zjrd42gv9atns2exuy40rsvz929lgr7hswmudtfd6czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgxwn32s</id>
    
      <title type="html">Is there an open-source web UI for servers that displays system ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdlmz9pp369zjrd42gv9atns2exuy40rsvz929lgr7hswmudtfd6czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgxwn32s" />
    <content type="html">
      Is there an open-source web UI for servers that displays system information like pstree, zpool status, fdisk -l, df, ip addr, etc?&lt;br/&gt;&lt;br/&gt;I want it to just show current info about the machine it&amp;#39;s running on, not rely on a metrics pipeline.&lt;br/&gt;&lt;br/&gt;Ideally it would be read-only, extensible, and a single-binary Go program, or something as simple to deploy.
    </content>
    <updated>2024-11-23T14:52:05&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxeap0zk33pne4u4e9hrx8hs6shmt3vdtx9yf0sa2dklh05hlahvszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgncafp8</id>
    
      <title type="html">&amp;#34;On behalf of the WordPress security team, ...&amp;#34; and then ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxeap0zk33pne4u4e9hrx8hs6shmt3vdtx9yf0sa2dklh05hlahvszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgncafp8" />
    <content type="html">
      &amp;#34;On behalf of the WordPress security team, ...&amp;#34; and then many mentions of &amp;#34;fixing a security issue&amp;#34; without specifying what it is. (The patch is, presumably, public since the plugin is OSS and PHP?)&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://wordpress.org/news/2024/10/secure-custom-fields/&#34;&gt;https://wordpress.org/news/2024/10/secure-custom-fields/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;I don&amp;#39;t have an opinion on the broader Wordpress situation, but seeing a security exception used to wield power in a broader controversy is extremely worrying.&lt;br/&gt;&lt;br/&gt;Open source communities trust security teams with exceptional powers, and weakening that trust damages everyone.
    </content>
    <updated>2024-10-12T22:12:39&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstzmjaa0p4cv6ak65wuj5kp4qzk7j74v6tqjq0quldhe8nmuj8dvczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgcgwkva</id>
    
      <title type="html">Cat&amp;#39;s out of the bag: I am pursuing a native FIPS 140-3 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstzmjaa0p4cv6ak65wuj5kp4qzk7j74v6tqjq0quldhe8nmuj8dvczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgcgwkva" />
    <content type="html">
      Cat&amp;#39;s out of the bag: I am pursuing a native FIPS 140-3 validation for the Go standard library.&lt;br/&gt;&lt;br/&gt;Trying to do it right, making it seamless and without compromising on security.&lt;br/&gt;&lt;br/&gt;First time a Go module is validated. Wish me well. And consider sponsoring!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://go.dev/issue/69536&#34;&gt;https://go.dev/issue/69536&lt;/a&gt;
    </content>
    <updated>2024-09-19T17:03:10&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0dxq0cywqxyls99jk2ewdqxxf5k68dq9mucx5wayj3yjetskpfqszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgv0tuul</id>
    
      <title type="html">Oh shit the vDSO implementation of getrandom() landed in Linux ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0dxq0cywqxyls99jk2ewdqxxf5k68dq9mucx5wayj3yjetskpfqszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgv0tuul" />
    <content type="html">
      Oh shit the vDSO implementation of getrandom() landed in Linux 6.11.&lt;br/&gt;&lt;br/&gt;Might remove one of the last performance objections ot using the kernel CSPRNG for everything, the syscall overhead.&lt;br/&gt;&lt;br/&gt;I have a large CL chain for crypto/rand, might as well add support for that...
    </content>
    <updated>2024-09-16T15:35:58&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9dx5m2mln0zkee9369euqf8qw0je8n92p9lejtpcx26e6t2mnpjszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgj5ctl0</id>
    
      <title type="html">I use restic to backup my MacBook but I increasingly feel like ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9dx5m2mln0zkee9369euqf8qw0je8n92p9lejtpcx26e6t2mnpjszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgj5ctl0" />
    <content type="html">
      I use restic to backup my MacBook but I increasingly feel like it&amp;#39;s not integrated enough into the system. For example it doesn&amp;#39;t use APFS snapshots to make atomic backups, and doesn&amp;#39;t download missing iCloud documents.&lt;br/&gt;&lt;br/&gt;Are there robust solutions to all this? Happy to pay for commercial solutions but I would like to still end up with plain restic backups.
    </content>
    <updated>2024-09-15T16:58:59&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2p9rwp77wjku458ezvwcdm3yu3z4h42htwcum6fw2zvz6t075jqszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg3tvr5h</id>
    
      <title type="html">I would like to pay $250, or $500 to a 501(c)(3) of your choice, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2p9rwp77wjku458ezvwcdm3yu3z4h42htwcum6fw2zvz6t075jqszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg3tvr5h" />
    <content type="html">
      I would like to pay $250, or $500 to a 501(c)(3) of your choice, for anyone to update the Dash for macOS [1] RFC docset [2]. See [3]. Any takers?&lt;br/&gt;&lt;br/&gt;EDIT: Done! &lt;a href=&#34;https://s.waq.dk/@Tenzer/113124619204569421&#34;&gt;https://s.waq.dk/@Tenzer/113124619204569421&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;[1]: &lt;a href=&#34;https://kapeli.com/dash&#34;&gt;https://kapeli.com/dash&lt;/a&gt;&lt;br/&gt;[2]: &lt;a href=&#34;https://github.com/Kapeli/Dash-User-Contributions/tree/master/docsets/RFCs&#34;&gt;https://github.com/Kapeli/Dash-User-Contributions/tree/master/docsets/RFCs&lt;/a&gt;&lt;br/&gt;[3]: &lt;a href=&#34;https://github.com/willnorris/rfcdash/issues/10&#34;&gt;https://github.com/willnorris/rfcdash/issues/10&lt;/a&gt;
    </content>
    <updated>2024-09-12T11:04:30&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfmz554x9mw7hykmd8gwmd54c768l3tzd8mpvz5urrwtk9nkfu4yqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg7pjj7j</id>
    
      <title type="html">Hey all, I turned 30 this week! 🎈 I feel a bit weird asking ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfmz554x9mw7hykmd8gwmd54c768l3tzd8mpvz5urrwtk9nkfu4yqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg7pjj7j" />
    <content type="html">
      Hey all, I turned 30 this week! 🎈&lt;br/&gt;&lt;br/&gt;I feel a bit weird asking for a &amp;#34;present&amp;#34; but if my code, writing, or talks reached you over the years, I would love to receive a postcard from wherever you live 📮&lt;br/&gt;&lt;br/&gt;Open source is deeply rewarding, but sometimes I miss a physical reminder of the people on the other side of the wire ✨&lt;br/&gt;&lt;br/&gt;Also, if you mention in the card making a donation to a US 501(c)(3) that aligns with my values, I will match it!&lt;br/&gt;&lt;br/&gt;Mailing addresses, both US and EU: &lt;a href=&#34;https://filippo.io/#addresses&#34;&gt;https://filippo.io/#addresses&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/113/090/223/920/873/152/original/56b10982413b7a3d.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-09-06T13:07:14&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsde7dx3u2jypzd3dzjyaz455uq2v4afqa8d99nd56r2pzj4g0wnyszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg0aeljx</id>
    
      <title type="html">A couple notes about the Infineon timing side channel affecting ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsde7dx3u2jypzd3dzjyaz455uq2v4afqa8d99nd56r2pzj4g0wnyszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg0aeljx" />
    <content type="html">
      A couple notes about the Infineon timing side channel affecting most YubiKeys.&lt;br/&gt;&lt;br/&gt;1. yubikey-agent is unaffected in the evil maid threat model as the attacker needs physical access *and PIN*&lt;br/&gt;&lt;br/&gt;2. lol, Infineon&lt;br/&gt;&lt;br/&gt;3. Go mitigates timing side-channels in ECDSA nonce inversion by not being clever and just using Fermat&amp;#39;s little theorem, which is as simple as a constant time exponentiation by p - 2 (which can be optimized with &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub18qvc5gvnn04pk9g5cwksjqdadfrhk63f04rkndcr0a27778q7mjq4cvtfq&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Michael McLoughlin&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub18qv…vtfq&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s addchain)&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://ninjalab.io/eucleak/&#34;&gt;https://ninjalab.io/eucleak/&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://www.yubico.com/support/security-advisories/ysa-2024-03/&#34;&gt;https://www.yubico.com/support/security-advisories/ysa-2024-03/&lt;/a&gt;
    </content>
    <updated>2024-09-03T18:44:40&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswcuq8xk856xmvdazed4uas2zhdgdtphwq834aqk3s82e2zjg49wczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgyxx45a</id>
    
      <title type="html">pq key exchange is urgent because of store-now-decrypt-later, pq ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswcuq8xk856xmvdazed4uas2zhdgdtphwq834aqk3s82e2zjg49wczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgyxx45a" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgsw5w87w9uvfmqvp3e7tkg0jedwuf4at9p4kqu0ynv6ur5c56asck8gfuc&#39;&gt;nevent1q…gfuc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;pq key exchange is urgent because of store-now-decrypt-later, pq auth is not, it makes sense
    </content>
    <updated>2024-08-06T00:35:26&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsymzemg0jdvj0zxf3lg6f3q3jw47mn6a3yskxampvag8nmdhz7hngzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtzj5sa</id>
    
      <title type="html">I’d argue PuTTY is just wrong. No one should use DSA keys, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsymzemg0jdvj0zxf3lg6f3q3jw47mn6a3yskxampvag8nmdhz7hngzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtzj5sa" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0ug6jrdmsj2htxrnzvvllj680k2qlw8kwkapljy5geezwu34j4jczjz9jg&#39;&gt;nevent1q…z9jg&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I’d argue PuTTY is just wrong. No one should use DSA keys, Ed448 is mostly unimplemented, and what does EdDSA even mean as a separate option.
    </content>
    <updated>2024-08-06T00:19:49&#43;02:00</updated>
  </entry>

</feed>