<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-04-05T15:39:00Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Filippo Valsorda</title>
  <author>
    <name>Filippo Valsorda</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1jzt0dcdqdhz0dmf3xk8fjn56kt45dqemtaz6rqzm9ycyz25p0nzqryjnwm.rss" />
  <link href="https://yabu.me/npub1jzt0dcdqdhz0dmf3xk8fjn56kt45dqemtaz6rqzm9ycyz25p0nzqryjnwm" />
  <id>https://yabu.me/npub1jzt0dcdqdhz0dmf3xk8fjn56kt45dqemtaz6rqzm9ycyz25p0nzqryjnwm</id>
  <icon>https://cdn.masto.host/abyssdomainexpert/accounts/avatars/109/472/682/376/441/460/original/ac66d0a023e6ef25.jpeg</icon>
  <logo>https://cdn.masto.host/abyssdomainexpert/accounts/avatars/109/472/682/376/441/460/original/ac66d0a023e6ef25.jpeg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsvm8fdpyef8jj786whwfucpl64wcgpvze8u5ew5uspehfn4jjpx7czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtt5v84</id>
    
      <title type="html">There&amp;#39;s a bit of commotion on Lobsters because an ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvm8fdpyef8jj786whwfucpl64wcgpvze8u5ew5uspehfn4jjpx7czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtt5v84" />
    <content type="html">
      There&amp;#39;s a bit of commotion on Lobsters because an unpleasant-but-technically-correct user finally got banned, and I realized that an unpopular opinion of mine is that moderators are always right.&lt;br/&gt;&lt;br/&gt;I don&amp;#39;t care about the letter of the CoC. I don&amp;#39;t care about transparency, even. Moderation is the fundamentally human and nuanced big-picture job that shapes a community.&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/abyssdomainexpert/media_attachments/files/115/123/712/178/230/773/original/42748b9cdd676f14.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-31T13:54:02Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsptp0z6ye6muqn6s54vf47pry9t7srxu72cu08haxaa9zydv4rquczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgjeuk6s</id>
    
      <title type="html">Looks like the same poorly implemented Android CT library that ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsptp0z6ye6muqn6s54vf47pry9t7srxu72cu08haxaa9zydv4rquczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgjeuk6s" />
    <content type="html">
      Looks like the same poorly implemented Android CT library that broke a lot of apps a couple years ago... did it again 🤦‍♂️&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/appmattus/certificatetransparency/issues/143#issuecomment-2993688741&#34;&gt;https://github.com/appmattus/certificatetransparency/issues/143#issuecomment-2993688741&lt;/a&gt;
    </content>
    <updated>2025-06-21T18:29:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstrz2579ha030f8yz8wmgck9d9xxj5tp7aqnd0dch92hmffqzzl2gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgt4vugh</id>
    
      <title type="html">If Certificate Transparency logs were available as torrents, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstrz2579ha030f8yz8wmgck9d9xxj5tp7aqnd0dch92hmffqzzl2gzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgt4vugh" />
    <content type="html">
      If Certificate Transparency logs were available as torrents, would you help seeding them?&lt;br/&gt;&lt;br/&gt;If so, with how much storage and with what client?&lt;br/&gt;&lt;br/&gt;I’m not sure how we’d update the torrent as the log grows. Does BEP 38 deduplication work with RSS feeds?
    </content>
    <updated>2025-05-20T22:08:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrp50w98pshfn7yqm3ahe0ljyzljwsd705eu70tac04cawtf4zfpqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgdar8nq</id>
    
      <title type="html">Three Trail of Bits engineers audited the core Go cryptography ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrp50w98pshfn7yqm3ahe0ljyzljwsd705eu70tac04cawtf4zfpqzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgdar8nq" />
    <content type="html">
      Three Trail of Bits engineers audited the core Go cryptography packages for a month, and found only one low-sev security issue... in the legacy unsupported Go&#43;BoringCrypto integration we&amp;#39;re replacing! 🍾 &lt;br/&gt;&lt;br/&gt;Years of team efforts on testing, limiting complexity, safe APIs, and readability have paid off! ✨ &lt;br/&gt;&lt;br/&gt;Yes I am taking a victory lap. No I am not sorry. 🏆&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://go.dev/blog/tob-crypto-audit&#34;&gt;https://go.dev/blog/tob-crypto-audit&lt;/a&gt;
    </content>
    <updated>2025-05-19T19:07:59Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdgl2yc46k0ve2dxdmx45a2rf4m8fzzxewtn6nwhwlekcw4j03kjgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgctu029</id>
    
      <title type="html">Running a full-network Bluesky relay costs less ($19) than my ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdgl2yc46k0ve2dxdmx45a2rf4m8fzzxewtn6nwhwlekcw4j03kjgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgctu029" />
    <content type="html">
      Running a full-network Bluesky relay costs less ($19) than my beefy but ~single user Mastodon hosted instance ($24).&lt;br/&gt;&lt;br/&gt;People underestimate how much data optimized software can move through efficient protocols on modern non-cloud hardware.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://whtwnd.com/bnewbold.net/3lo7a2a4qxg2l&#34;&gt;https://whtwnd.com/bnewbold.net/3lo7a2a4qxg2l&lt;/a&gt;
    </content>
    <updated>2025-05-02T21:36:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdpgp53f7lzhjlvqj4z8nvhtkthshv2qxn06ywcwcma95xq8wtvgczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtt7wz8</id>
    
      <title type="html">The relay is the supposedly centralized part of Bluesky because ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdpgp53f7lzhjlvqj4z8nvhtkthshv2qxn06ywcwcma95xq8wtvgczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtt7wz8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdgl2yc46k0ve2dxdmx45a2rf4m8fzzxewtn6nwhwlekcw4j03kjg08e0ak&#39;&gt;nevent1q…e0ak&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The relay is the supposedly centralized part of Bluesky because “too big” to run! $19/month!&lt;br/&gt;&lt;br/&gt;The bsky.app AppView is bigger but every Mastodon instance is an AppView (and PDS), and if you were ok with Mastodon-style partial views of the network, AppViews would be cheap too.
    </content>
    <updated>2025-05-02T21:36:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd0j73kykmw75cly9r4z79jz07w0rkjp74g5ckvppz9zjgh7c4fxgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg94ndfu</id>
    
      <title type="html">It’s disheartening to see AI reactionism lead my community to a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd0j73kykmw75cly9r4z79jz07w0rkjp74g5ckvppz9zjgh7c4fxgzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg94ndfu" />
    <content type="html">
      It’s disheartening to see AI reactionism lead my community to a 180° on copyright.&lt;br/&gt;&lt;br/&gt;Everyone is merrily attacking LibGen now. If it didn’t exist, big tech companies would still find training data, it just wouldn’t be accessible to regular people.
    </content>
    <updated>2025-03-21T09:22:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst8e4wsqpylajuukxyjtzrnllgn3a9p7u7v96ms6kywts2ezqdn0czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgyfrza3</id>
    
      <title type="html">Would you pay for Cryptography Dispatches? I am considering using ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst8e4wsqpylajuukxyjtzrnllgn3a9p7u7v96ms6kywts2ezqdn0czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgyfrza3" />
    <content type="html">
      Would you pay for Cryptography Dispatches? I am considering using Buttondown&amp;#39;s new per-email subscriptions to trick myself into writing more in 2025.&lt;br/&gt;&lt;br/&gt;This would be voluntary. Max 1–3 issues per month.&lt;br/&gt;&lt;br/&gt;There would be no subscriber-only issues. What you get for your money is motivating me to write more, if that&amp;#39;s something you like.&lt;br/&gt;&lt;br/&gt;Conversely, this would not be a major source of income. What I get out of it is tricking my brain into doing more writing by setting up a reward system.
    </content>
    <updated>2024-12-11T19:12:39Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdlmz9pp369zjrd42gv9atns2exuy40rsvz929lgr7hswmudtfd6czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgxwn32s</id>
    
      <title type="html">Is there an open-source web UI for servers that displays system ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdlmz9pp369zjrd42gv9atns2exuy40rsvz929lgr7hswmudtfd6czyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgxwn32s" />
    <content type="html">
      Is there an open-source web UI for servers that displays system information like pstree, zpool status, fdisk -l, df, ip addr, etc?&lt;br/&gt;&lt;br/&gt;I want it to just show current info about the machine it&amp;#39;s running on, not rely on a metrics pipeline.&lt;br/&gt;&lt;br/&gt;Ideally it would be read-only, extensible, and a single-binary Go program, or something as simple to deploy.
    </content>
    <updated>2024-11-23T13:52:05Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstzmjaa0p4cv6ak65wuj5kp4qzk7j74v6tqjq0quldhe8nmuj8dvczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgcgwkva</id>
    
      <title type="html">Cat&amp;#39;s out of the bag: I am pursuing a native FIPS 140-3 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstzmjaa0p4cv6ak65wuj5kp4qzk7j74v6tqjq0quldhe8nmuj8dvczyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgcgwkva" />
    <content type="html">
      Cat&amp;#39;s out of the bag: I am pursuing a native FIPS 140-3 validation for the Go standard library.&lt;br/&gt;&lt;br/&gt;Trying to do it right, making it seamless and without compromising on security.&lt;br/&gt;&lt;br/&gt;First time a Go module is validated. Wish me well. And consider sponsoring!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://go.dev/issue/69536&#34;&gt;https://go.dev/issue/69536&lt;/a&gt;
    </content>
    <updated>2024-09-19T15:03:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0dxq0cywqxyls99jk2ewdqxxf5k68dq9mucx5wayj3yjetskpfqszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgv0tuul</id>
    
      <title type="html">Oh shit the vDSO implementation of getrandom() landed in Linux ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0dxq0cywqxyls99jk2ewdqxxf5k68dq9mucx5wayj3yjetskpfqszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgv0tuul" />
    <content type="html">
      Oh shit the vDSO implementation of getrandom() landed in Linux 6.11.&lt;br/&gt;&lt;br/&gt;Might remove one of the last performance objections ot using the kernel CSPRNG for everything, the syscall overhead.&lt;br/&gt;&lt;br/&gt;I have a large CL chain for crypto/rand, might as well add support for that...
    </content>
    <updated>2024-09-16T13:35:58Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsde7dx3u2jypzd3dzjyaz455uq2v4afqa8d99nd56r2pzj4g0wnyszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg0aeljx</id>
    
      <title type="html">A couple notes about the Infineon timing side channel affecting ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsde7dx3u2jypzd3dzjyaz455uq2v4afqa8d99nd56r2pzj4g0wnyszyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vg0aeljx" />
    <content type="html">
      A couple notes about the Infineon timing side channel affecting most YubiKeys.&lt;br/&gt;&lt;br/&gt;1. yubikey-agent is unaffected in the evil maid threat model as the attacker needs physical access *and PIN*&lt;br/&gt;&lt;br/&gt;2. lol, Infineon&lt;br/&gt;&lt;br/&gt;3. Go mitigates timing side-channels in ECDSA nonce inversion by not being clever and just using Fermat&amp;#39;s little theorem, which is as simple as a constant time exponentiation by p - 2 (which can be optimized with &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub18qvc5gvnn04pk9g5cwksjqdadfrhk63f04rkndcr0a27778q7mjq4cvtfq&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Michael McLoughlin&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub18qv…vtfq&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s addchain)&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://ninjalab.io/eucleak/&#34;&gt;https://ninjalab.io/eucleak/&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://www.yubico.com/support/security-advisories/ysa-2024-03/&#34;&gt;https://www.yubico.com/support/security-advisories/ysa-2024-03/&lt;/a&gt;
    </content>
    <updated>2024-09-03T16:44:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsymzemg0jdvj0zxf3lg6f3q3jw47mn6a3yskxampvag8nmdhz7hngzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtzj5sa</id>
    
      <title type="html">I’d argue PuTTY is just wrong. No one should use DSA keys, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsymzemg0jdvj0zxf3lg6f3q3jw47mn6a3yskxampvag8nmdhz7hngzyzgfdahp5pkufahdxy6cax2wn2ewk35r8d05tgvqtv5nqsf2s97vgtzj5sa" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0ug6jrdmsj2htxrnzvvllj680k2qlw8kwkapljy5geezwu34j4jczjz9jg&#39;&gt;nevent1q…z9jg&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I’d argue PuTTY is just wrong. No one should use DSA keys, Ed448 is mostly unimplemented, and what does EdDSA even mean as a separate option.
    </content>
    <updated>2024-08-05T22:19:49Z</updated>
  </entry>

</feed>