Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Loup-Vaillant wrote this on Lobste.rs in a dumb rant about my Matrix disclosure:

Loup-Vaillant wrote this on Lobste.rs in a dumb rant about my Matrix disclosure:

Scheduled Pinned Locked Moved Uncategorized
5 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • soatok@furry.engineerS This user is from outside of this forum
    soatok@furry.engineerS This user is from outside of this forum
    soatok@furry.engineer
    wrote last edited by
    #1

    Loup-Vaillant wrote this on Lobste.rs in a dumb rant about my Matrix disclosure:

    Personally I would actively avoid the check,

    Hmm. What a weird thing to say.

    Loup-Vaillant wrote a cryptography library called Monocypher, which famously had an EdDSA vulnerability mostly caused by their insistence on rolling their own custom EdDSA variant to avoid SHA512.

    "I wonder how Monocypher holds up in 2026?"

    Who said that? Well, anyway:

    https://github.com/LoupVaillant/Monocypher/issues/285

    rusty__shackleford@mastodon.socialR soatok@furry.engineerS 2 Replies Last reply
    0
    • soatok@furry.engineerS soatok@furry.engineer

      Loup-Vaillant wrote this on Lobste.rs in a dumb rant about my Matrix disclosure:

      Personally I would actively avoid the check,

      Hmm. What a weird thing to say.

      Loup-Vaillant wrote a cryptography library called Monocypher, which famously had an EdDSA vulnerability mostly caused by their insistence on rolling their own custom EdDSA variant to avoid SHA512.

      "I wonder how Monocypher holds up in 2026?"

      Who said that? Well, anyway:

      https://github.com/LoupVaillant/Monocypher/issues/285

      rusty__shackleford@mastodon.socialR This user is from outside of this forum
      rusty__shackleford@mastodon.socialR This user is from outside of this forum
      rusty__shackleford@mastodon.social
      wrote last edited by
      #2

      @soatok

      Holy shit

      Link Preview Image
      1 Reply Last reply
      1
      0
      • R relay@relay.infosec.exchange shared this topic
      • soatok@furry.engineerS soatok@furry.engineer

        Loup-Vaillant wrote this on Lobste.rs in a dumb rant about my Matrix disclosure:

        Personally I would actively avoid the check,

        Hmm. What a weird thing to say.

        Loup-Vaillant wrote a cryptography library called Monocypher, which famously had an EdDSA vulnerability mostly caused by their insistence on rolling their own custom EdDSA variant to avoid SHA512.

        "I wonder how Monocypher holds up in 2026?"

        Who said that? Well, anyway:

        https://github.com/LoupVaillant/Monocypher/issues/285

        soatok@furry.engineerS This user is from outside of this forum
        soatok@furry.engineerS This user is from outside of this forum
        soatok@furry.engineer
        wrote last edited by
        #3

        I guess I should just tap the sign whenever I encounter this sort of personality:

        Link Preview Image
        Cryptography Engineering Has An Intrinsic Duty of Care - Dhole Moments

        To understand my point, I need to first explain three different cryptography attack papers / blog posts. I promise this won't be boring. Three Little Disclosures Misuse-Prone Ciphers For All In a blog post titled Carelessness versus craftsmanship in cryptography, cryptography analyst and Queer in Cryptography emcee Opal Wright delves into the misuse-prone and side-channel-riddled…

        favicon

        Dhole Moments (soatok.blog)

        deetwenty@todon.nlD 1 Reply Last reply
        0
        • soatok@furry.engineerS soatok@furry.engineer

          I guess I should just tap the sign whenever I encounter this sort of personality:

          Link Preview Image
          Cryptography Engineering Has An Intrinsic Duty of Care - Dhole Moments

          To understand my point, I need to first explain three different cryptography attack papers / blog posts. I promise this won't be boring. Three Little Disclosures Misuse-Prone Ciphers For All In a blog post titled Carelessness versus craftsmanship in cryptography, cryptography analyst and Queer in Cryptography emcee Opal Wright delves into the misuse-prone and side-channel-riddled…

          favicon

          Dhole Moments (soatok.blog)

          deetwenty@todon.nlD This user is from outside of this forum
          deetwenty@todon.nlD This user is from outside of this forum
          deetwenty@todon.nl
          wrote last edited by
          #4

          @soatok in this article you in passing mention something that has frustrated me for some time in software engineering as someone with a bit more of a hardware background, and that is how much important stuff doesn't build on formal specifications, even big infrastructure projects! And when I have brought this up I'm often met with something along the lines of "but that is not very agile" or "we moved away from waterfall". Sure that small backyard shed you can yolo together, but why are we doing the same thing for the highway bridges of the software world?

          bersl2@furry.engineerB 1 Reply Last reply
          1
          0
          • deetwenty@todon.nlD deetwenty@todon.nl

            @soatok in this article you in passing mention something that has frustrated me for some time in software engineering as someone with a bit more of a hardware background, and that is how much important stuff doesn't build on formal specifications, even big infrastructure projects! And when I have brought this up I'm often met with something along the lines of "but that is not very agile" or "we moved away from waterfall". Sure that small backyard shed you can yolo together, but why are we doing the same thing for the highway bridges of the software world?

            bersl2@furry.engineerB This user is from outside of this forum
            bersl2@furry.engineerB This user is from outside of this forum
            bersl2@furry.engineer
            wrote last edited by
            #5

            @deetwenty @soatok I think the most frustrating thing I heard from my boss on Monday is the sentiment of "Oh, the transition to AI coding means that we have to throw away all of the Agile we've been working on and basically go back to waterfall. The best way to use it is to write out your specifications first."

            So, the planning that we should have been doing a long time ago is only worth bothering to do once the robots are here?

            This is how I know we're in hell.

            1 Reply Last reply
            1
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups