RE: https://mastodon.social/@lobsters/116280125863583032
One of our maintainers, @zoef, makes a really strong visual case on the importance of Web of Trust especially in 2026
RE: https://mastodon.social/@lobsters/116280125863583032
One of our maintainers, @zoef, makes a really strong visual case on the importance of Web of Trust especially in 2026
Famous cryptographer Daniel J. Bernstein has a minicourse for a hypothetical new overlord how to keep an eye on "eight billion potential terrorists" using "surreptitious surveillance". A long, amusing, but also sobering read.
cr.yp.to: 2025.09.30: Surreptitious surveillance
IETF RFC draft for #TLS 1.4. PQC support, 0-RTT, and more fun stuff:
This document specifies a new version of the Transport Layer Security (TLS) protocol, version 1.4. It is designed to address key challenges that have emerged since the standardization of TLS 1.3, specifically related to the mobility of devices, the need for enhanced 0-RTT security, the integration of post-quantum cryptography, and the refinement of downgrade protection mechanisms. TLS 1.4 introduces a fundamental architectural shift by decoupling the cryptographic session state from the underlying transport-layer connection. This is achieved through a new, transport-agnostic Connection ID (CID). The protocol also provides a new, cryptographically-enforced replay defense for 0-RTT handshakes based on an atomic "read-compare-write" operation on a single-use Session Nonce. A native hybrid post-quantum key exchange framework is integrated into the handshake, offering a robust "safety net" against future cryptanalytic threats. This specification formally obsoletes TLS 1.3 (RFC 8446) and all its related mechanisms. This document updates RFCs 5705, 6066, 7627, and 8422 and obsoletes RFCs 5077, 5246, 6961, 8422, and 8446. This document also specifies new requirements for TLS 1.2 implementations.
I am thinking of making a two-factor authenticated system with NFC on iOS. Are there any side effects or vulnerabilities?
What are the links between #cryptanalysis and #literacy?
In what way is learning to read in English more like learning a #cipher, rather than a code?
#reading #research #crytography
https://write.as/manderson/learning-to-read-an-unnatural-act
#latetotheparty #intro
I’ve been lurking/playing a bit in/on the various fediverse technologies.
I’m interested in #security, #privacy, #crytography, and #selfhosting #homelab. I’ve been tinkering with #RPI cluster, fitlet2, #picade, #pinephone.
Outside of the digital world, I have an affinity for the outdoors, #MTB, #bikepacking, #backpacking, #kayaking, #snowshoeing and #skiing.
Working toward a nomadic lifestyle. #tinyhome, #vanlife, #traveling dreams.