Viewing profile — ekr____
ekr____
HN member- Joined
- Wed, Sep 22, 2021, 11:03 PM UTC
- HN karma
- 858
- Public activity
- 268 items
- HN profile
- View on Hacker News ↗
About ekr____
No profile information was provided.
Recent public activity
-
comment
Comment #49151020
This isn't quite how TLS feature negotiation works. Version numbers are negotiated and some of the parameters are carried along with the version, but a lot of functionality (e.g., …
-
comment
Comment #49150872
TLS is an extensible protocol. For instance, you can add new key establishment algorithms or cipher suites. What this specification is saying is that the IETF will not be publishin…
-
comment
Comment #48831958
No disagreement there.
-
comment
Comment #48821606
I have no opinion on ULA+NPTv6, other than Experimental doesn't mean you shouldn't use it. How else would people experiment. It does mean that the level of vetting by the IETF is p…
-
comment
Comment #48819788
In fairness, I do think that this situation is somewhat different. As I noted above ( https://news.ycombinator.com/item?id=48812792 ), there are two main routes to an Informational…
-
comment
Comment #48813360
This document actually is being advanced as Informational, though there are also non-IETF Informational RFCs (see upthread).
-
comment
Comment #48813356
> What’s his next step if the authors publish as an information RFC? He can’t stop that, right? This is a slightly complicated question. There are several main routes to an Informa…
-
comment
Comment #48813004
Good question. If the document is dropped by the IETF, nothing at all would happen. It's already a valid code point registration, and indeed the authors could have just published t…
-
comment
Comment #48812885
You're right. Bad writing on my part. Edited to make it clear.
-
comment
Comment #48812831
Adding a little color here... There are already code points registered for pure ML-KEM on the basis of the draft. The hybrid code point you reference is "preliminary" in the sense …
-
comment
Comment #48812792
> (2) The RFC at issue documents the possibility of running TLS with pure MLKEM rather than in a hybrid configuration with ECDH. Hybrid TLS is already the mainstream, documented, s…
-
comment
Comment #48760756
That's not really possible to explain in this space, unfortunately, but the overall idea is that there are mathematical techniques that allow you to prove that you have a valid cer…
-
comment
Comment #48756423
This isn't correct. With ZKP-based systems even the CA can't track you. That's the "zero-knowledge" part.
-
comment
Comment #48756414
The proof is bound to a cryptographic key stored in a tamper-resistant module (as in a phone). See https://educatedguesswork.org/posts/age-verification-id/#dev... for some more det…
-
comment
Comment #48712675
Note that the EU is proposing to do this [0]. The ZKP part is a bit of a WIP and there have been some questions about the quality [1]. [0] https://digital-strategy.ec.europa.eu/en/…
-
comment
Comment #48712648
My sense is that many jurisdictions do not consider this sufficient, as they want to prevent parents from allowing their children to access restricted material (as happens fairly f…
-
comment
Comment #48712636
> You don't wind up in a database for buying alcohol. I don't think this is a good assumption. It's not uncommon for stores to scan your ID when you buy alcohol. > This proposal pu…
-
comment
Comment #48712515
Note that California AB1043 isn't actually age verification; rather it just requires the OS to ask for your age, not check it.
-
comment
Comment #48710068
Hence Encrypted Client Hello ( https://datatracker.ietf.org/doc/rfc9849/ ), though deployment is still thin.
-
comment
Comment #48647806
Typically these APIs are designed so you can't make arbitrary queries, but rather there are fixed age brackets.
-
comment
Comment #48569955
RFC 10000 will not be published. They're just going to skip past the number. https://mailarchive.ietf.org/arch/msg/tools-discuss/EpoQcVt_... RFC #s are issued sometime before publi…
-
comment
Comment #48498447
Original author here: Yeah a lot of the evergreening techniques (chiral switch, etc.) don't prevent anyone from getting the original, though of course doctors may try to switch you…
-
comment
Comment #48494831
That's amazing. A lot of people import them from Canada, but this is much more interesting.
-
comment
Comment #48466547
Let's Encrypt certificates are free.
- story