Viewing profile — galadran
galadran
HN member- Joined
- Sat, Apr 16, 2016, 4:40 PM UTC
- HN karma
- 1,056
- Public activity
- 83 items
- HN profile
- View on Hacker News ↗
About galadran
Recent public activity
-
comment
Comment #48773401
In effect, yes it does. The Recommended flag is set for X25519MLKEM768. It is not set for any of the pure PQ key exchanges. https://www.iana.org/assignments/tls-parameters/tls-para…
-
comment
Comment #48766911
I'm afraid you've misunderstood. These codepoints are for the pure MLKEM key establishment that DJB is railing against. All of these libraries also support the hybrid forms, which …
-
comment
Comment #48764739
This is garbage from start to finish. There are already codepoints assigned for MLKEM 512/768/1024 (0x0200, 0x0201, 0x0202) and nearly every major library supports it already: - Op…
-
comment
Comment #48652505
> If nothing changes, users will increasingly be forced to choose between their privacy and their access to the web Shorter post: https://blog.mozilla.org/en/privacy-security/keepi…
-
comment
Comment #48651795
More details: https://blog.mozilla.org/en/privacy-security/keeping-the-web...
- story
-
comment
Comment #38203283
EU Commission FAQ (emphasis mine): Recognition means that web browsers are required to ensure support and interoperability for the QWAC for the sole purpose of displaying identity …
-
comment
Comment #38128958
As I commented there, you've misunderstood this change. There's a difference between certificates distributed with the OS and certificates added to the OS by a user. Right now Fire…
-
comment
Comment #38128943
There's a difference between certificates distributed with the OS and certificates added to the OS by a user. Right now Firefox ignores both. This change ONLY picks up the certific…
-
comment
Comment #38111601
"Agreed behind closed doors" would probably be better than "Secret Law" but I guess its a question of brevity.
-
comment
Comment #38111589
https://en.wikipedia.org/wiki/Formal_trilogue_meeting
-
comment
Comment #38111119
https://eidas-open-letter.org The open letter signed by 300+ researchers, professors and experts.
-
comment
Comment #38110633
Title should probably be: "Last Chance to fix eIDAS: Secret EU law threatens Internet security"
-
comment
Comment #38110526
https://last-chance-for-eidas.org/
-
comment
Comment #38012063
This isn't the right summary. Firefox uses it own root store still and ignores any certificates distributed by default in the OS. However, if the user installs their root to the OS…
-
comment
Comment #37794320
Mozilla's launch earlier this week: https://blog.mozilla.org/en/products/firefox/encrypted-hello...
- story
-
comment
Comment #37705596
I believe CF and others buckled under pressure from major websites which didn't want to be used as fronts for other website's traffic. ECH fixes this because individual sites get t…
-
comment
Comment #37705574
Any provider can deploy ECH, it's standardized at the IETF. Cloudflare are just first.
-
comment
Comment #37705530
The point is that network operators can't tell which website the user is visiting, as it could be any of the sites hosted by the ECH provider. In this case, Cloudflare are acting a…
-
comment
Comment #29408069
The disclosure and test cases: https://www.openwall.com/lists/oss-security/2021/12/01/4
-
comment
Comment #29406449
More details: https://www.openwall.com/lists/oss-security/2021/12/01/4
-
comment
Comment #27940409
> It is not fun but frustrating to work in Rust. Deeply subjective. Rust has been the most loved language on Stack Overflow for 5 years in a row now. > add a new huge dependency Su…
-
comment
Comment #26778111
1. Of the literally hundreds of maps on his site, there are only two which are actually based on Middle Earth. 2. 'Style' is not copyrightable. No one owes royalties to Picasso for…
-
comment
Comment #24495433
The associated paper [1] summarises the information revealed by Signal succinctly: The Signal messenger is primarily focused on user privacy, and thus exposes almost no information…