Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

tomgag@infosec.exchangeT

tomgag@infosec.exchange

@tomgag@infosec.exchange
About
Posts
4
Topics
3
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Today Letsencrypt announced their plans for PQC migration and, oh boy, it's refreshing!
    tomgag@infosec.exchangeT tomgag@infosec.exchange

    Today Letsencrypt announced their plans for PQC migration and, oh boy, it's refreshing! TL;DR, Letsencrypt considers migration to quantum-resistant certificates a priority, and lays down a reasonable path to migrate. In so doing, they take the time to explain how, so far, the security community has been mainly focused on the problem of quantum-resistant secrecy (encryption) rather than authentication (signatures/certificates), and they explain why the sentiment is changing now, and why it is particularly relevant for Letsencrypt.

    Link Preview Image
    A Post-Quantum Future for Let's Encrypt

    Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (“MTCs”), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. This post is about these plans and why we believe MTCs are worth pursuing as a key to a post-quantum future. An increasingly urgent problem For much of the last several years, the conversation about post-quantum cryptography has been a conversation about encryption. The reasoning was straightforward: an attacker who records encrypted traffic today might be able to decrypt it years from now once quantum computers can break the underlying math. Authentication, the part of TLS that indicates a server is who it says it is, has been a less urgent problem. A quantum computer needs to forge a signature in real time, not retroactively, so threats to authentication hinge on the existence of a cryptographically relevant quantum computer (CRQC).

    favicon

    (letsencrypt.org)

    Not wanting to be the "told you so" guy, I've been saying this for at least 2 years now:

    Link Preview Image
    Tommaso Gagliardoni's Homepage

    favicon

    (gagliardoni.net)

    This is not to say that Harvest-Now-Decrypt-Later is a less urgent threat, but it's not as asymmetric as people have been believing so far. Glad to see things are changing!

    #cryptography #crypto #security #quantum #pqc #postquantum #quantumsecurity #letsencrypt #ai

    Uncategorized cryptography crypto security quantum pqc

  • I have been dragged into the rabbit hole of GnuPG/LibrePGP VS Sequoia/OpenPGP and, boy it is ugly.
    tomgag@infosec.exchangeT tomgag@infosec.exchange

    @andrewg oh, I didn't mean to propose a solution, I understand there are complex governance and social dynamics involved. Just I was blissfully unaware of the situation until yesterday, which I can't say made my day.

    Uncategorized pgp gpg sequoia crypto cryptography

  • I have been dragged into the rabbit hole of GnuPG/LibrePGP VS Sequoia/OpenPGP and, boy it is ugly.
    tomgag@infosec.exchangeT tomgag@infosec.exchange

    I have been dragged into the rabbit hole of GnuPG/LibrePGP VS Sequoia/OpenPGP and, boy it is ugly. Yeah, yeah, I know, PGP is bad, but of all the ugly things that could have happened to the FOSS crypto space, this is really unwelcome. I wish people would just sit at a table and talk.

    #pgp #gpg #sequoia #crypto #cryptography #security #foss #floss #libre #drama #ietf #privacy #openpgp #librepgp

    Uncategorized pgp gpg sequoia crypto cryptography

  • Rise and Fall of Hosting Provider Gandi.net
    tomgag@infosec.exchangeT tomgag@infosec.exchange

    Rise and Fall of Hosting Provider Gandi.net

    Link Preview Image
    Tommaso Gagliardoni's Homepage

    favicon

    (gagliardoni.net)

    The sad story of Gandi.net is a textbook example of enshittification, which I think is interesting to talk about, because of the many expectations that were betrayed, and the deeper reflection linking to vampire capitalism. I also report the user-hostile process that I had to undergo in order to migrate away from them.

    #gandi #gandi_net #enshittification #capitalism #it #france #privacy #privateequity

    Uncategorized gandi gandinet enshittificatio capitalism
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups