Same old tired song and dance.
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
It will be funny to see the ietf tls wg realize that they only have a tenuous grasp of control over the protocol. The very complexity that makes tls suck can be used to just ignore them, create their own suits, disable or not implement the trash they are peddling.
It's kind of crazy to see them basically ignore DJB and justify it with a technicality. This could go badly for them in the court of public opinion.
Nice username. I remember when they got away with using that name (minus the numbers) for the handshake to WPA3, and were deeply suspicion-inducing about whether the mathematician who authored that was on the NSA payroll or not.
We fight wars to live in peace, we grow sheep to eat lamb chops, and we keep trust to gain reputation to then spend it. That quote about stones.
Still very good to see someone as famous as Bernstein say this.
But yes, it's weird, TLS allows whatever the software on two sides of the negotiation allow and support. GOST, something Chinese, something you've made yourself. Anything.
Except if there's somehow a vulnerability in TLS hidden in the open, but, eh, that's a bit too conspiracy-minded for a post not discussing TLS itself.
Excuse me for being denser than a neutron star here… but that mean we won’t be able to “home brew” some sort of our own equipment and our own double encryption system (crowd sourcing like where Linux is right now from where it started) is that feasible? Or am I way off the mark here?
Of course we do and that's what Signal did. But if your platform doesn't care (like most), then the NSA can see everything