Live data from Hacker News

Viewing profile — ekr____

ekr____

HN member
Joined
Wed, Sep 22, 2021, 11:03 PM UTC
HN karma
858
Public activity
268 items

About ekr____

No profile information was provided.

Recent public activity

  1. comment
    Comment #49151020

    This isn't quite how TLS feature negotiation works. Version numbers are negotiated and some of the parameters are carried along with the version, but a lot of functionality (e.g., …

  2. comment
    Comment #49150872

    TLS is an extensible protocol. For instance, you can add new key establishment algorithms or cipher suites. What this specification is saying is that the IETF will not be publishin…

  3. comment
    Comment #48831958

    No disagreement there.

  4. comment
    Comment #48821606

    I have no opinion on ULA+NPTv6, other than Experimental doesn't mean you shouldn't use it. How else would people experiment. It does mean that the level of vetting by the IETF is p…

  5. comment
    Comment #48819788

    In fairness, I do think that this situation is somewhat different. As I noted above ( https://news.ycombinator.com/item?id=48812792 ), there are two main routes to an Informational…

  6. comment
    Comment #48813360

    This document actually is being advanced as Informational, though there are also non-IETF Informational RFCs (see upthread).

  7. comment
    Comment #48813356

    > What’s his next step if the authors publish as an information RFC? He can’t stop that, right? This is a slightly complicated question. There are several main routes to an Informa…

  8. comment
    Comment #48813004

    Good question. If the document is dropped by the IETF, nothing at all would happen. It's already a valid code point registration, and indeed the authors could have just published t…

  9. comment
    Comment #48812885

    You're right. Bad writing on my part. Edited to make it clear.

  10. comment
    Comment #48812831

    Adding a little color here... There are already code points registered for pure ML-KEM on the basis of the draft. The hybrid code point you reference is "preliminary" in the sense …

  11. comment
    Comment #48812792

    > (2) The RFC at issue documents the possibility of running TLS with pure MLKEM rather than in a hybrid configuration with ECDH. Hybrid TLS is already the mainstream, documented, s…

  12. comment
    Comment #48760756

    That's not really possible to explain in this space, unfortunately, but the overall idea is that there are mathematical techniques that allow you to prove that you have a valid cer…

  13. comment
    Comment #48756423

    This isn't correct. With ZKP-based systems even the CA can't track you. That's the "zero-knowledge" part.

  14. comment
    Comment #48756414

    The proof is bound to a cryptographic key stored in a tamper-resistant module (as in a phone). See https://educatedguesswork.org/posts/age-verification-id/#dev... for some more det…

  15. comment
    Comment #48712675

    Note that the EU is proposing to do this [0]. The ZKP part is a bit of a WIP and there have been some questions about the quality [1]. [0] https://digital-strategy.ec.europa.eu/en/…

  16. comment
    Comment #48712648

    My sense is that many jurisdictions do not consider this sufficient, as they want to prevent parents from allowing their children to access restricted material (as happens fairly f…

  17. comment
    Comment #48712636

    > You don't wind up in a database for buying alcohol. I don't think this is a good assumption. It's not uncommon for stores to scan your ID when you buy alcohol. > This proposal pu…

  18. comment
    Comment #48712515

    Note that California AB1043 isn't actually age verification; rather it just requires the OS to ask for your age, not check it.

  19. comment
    Comment #48710068

    Hence Encrypted Client Hello ( https://datatracker.ietf.org/doc/rfc9849/ ), though deployment is still thin.

  20. comment
    Comment #48647806

    Typically these APIs are designed so you can't make arbitrary queries, but rather there are fixed age brackets.

  21. comment
    Comment #48569955

    RFC 10000 will not be published. They're just going to skip past the number. https://mailarchive.ietf.org/arch/msg/tools-discuss/EpoQcVt_... RFC #s are issued sometime before publi…

  22. comment
    Comment #48498447

    Original author here: Yeah a lot of the evergreening techniques (chiral switch, etc.) don't prevent anyone from getting the original, though of course doctors may try to switch you…

  23. comment
    Comment #48494831

    That's amazing. A lot of people import them from Canada, but this is much more interesting.

  24. comment
    Comment #48466547

    Let's Encrypt certificates are free.

  25. story