cpu
@cpu.xkeyscore.club
π€ 96
π₯ 226
π 22
Recluse open source programmer. β. he/him.
https://github.com/cpu
https://hachyderm.io/@cpu
reposted by
cpu
Joe Birr-Pixton
20 days ago
We have a little blog post about this
rustls.dev/blog/2025-09...
add a skeleton here at some point
0
2
3
reposted by
cpu
The Rust Foundation
20 days ago
LIVE at
#rustconf
: The Rust Foundation has launched its new "Rust Innovation Lab" with Rustls, a leading TLS library, as the inaugural hosted project! The RIL provides comprehensive support for funded OSS projects, ensuring sustainable & community-led growth.
rustfoundation.org/media/rust-f...
0
19
10
reposted by
cpu
25 days ago
we lived
0
29
1
PowerDNS Recursor 5.3.0 has a nice note in the changelog: > The embedded webserver used to display the status page and process REST API calls has been rewritten in Rust and now supports multiple listen addresses and TLS. The new code is powered by Hyper+Rustls+Ring π¦ π (h/t Stefan Schmidt)
26 days ago
0
6
1
TIL the B root servers have deployed experimental DoT support for TLS on the recursor -> auth. server leg:
b.root-servers.org/research/tls...
loading . . .
Experimental DNS over TLS support
B.root-servers.net DNS operated by the University of Southern California
https://b.root-servers.org/research/tls.html
about 1 month ago
0
3
0
reposted by
cpu
Joseph Lorenzo Hall, PhD
about 2 months ago
TIL that the ITU has an annual "X.509 Day", wheeee
www.itu.int/md/T25-TSB-C...
1
3
2
reposted by
cpu
Filippo Valsorda
2 months ago
We announced the new native Go FIPS 140-3 mode today! FIPS 140, like it or not, is often a requirement, and I was increasingly sad about large deployments replacing the Go crypto packages with non-memory safe cgo bindings. Go is now one of the easiest and most secure ways to build under FIPS 140.
loading . . .
The FIPS 140-3 Go Cryptographic Module
Go now has a built-in, native FIPS 140-3 compliant mode.
https://go.dev/blog/fips140
12
201
54
reposted by
cpu
Joe Birr-Pixton
3 months ago
Today we released rustls 0.23.29
crates.io/crates/rustl...
-- highlights are better error reporting for unsupported signature algorithms in certificates, and quite a few performance improvements (via a set of changes that started almost 2 years ago!)
loading . . .
crates.io: Rust Package Registry
https://crates.io/crates/rustls/0.23.29
1
11
3
reposted by
cpu
Dirkjan Ochtman
3 months ago
Pretty excited about the release of instant-acme 0.8, with lots of work from
@cpu.xkeyscore.club
(who joined as a maintainer) on ARI, profiles, integration testing and a much improved API.
github.com/djc/instant-...
loading . . .
Release 0.8.0 Β· djc/instant-acme
The 0.8 release contains substantial changes to make the API more modular. It integrates full support for ACME Renewal Information (ARI, recently standardized as RFC 9773). Since the 0.7.2 release,...
https://github.com/djc/instant-acme/releases/tag/0.8.0
0
7
1
Nerd-sniped by bagder into looking at how rustls-ffi stacks up against OpenSSL on memory allocations/peak heap usage when plugged in as a curl vTLS backend. Headlines: * with rustls-ffi 0.15.0: 2,176 allocations. peak heap of 394kB. * with openssl 3.4.1: 308,132 allocations (!). peak heap of 2.1MB
add a skeleton here at some point
3 months ago
1
18
4
You love to see it.
loading . . .
Track two new CVE's of ogsudo by squell Β· Pull Request #1173 Β· trifectatechfoundation/sudo-rs
Two new CVE's were disclosed yesterday in ogsudo which do not apply to sudo-rs since they pertain to functionality we chose not to support.
https://github.com/trifectatechfoundation/sudo-rs/pull/1173
3 months ago
0
3
0
reposted by
cpu
3 months ago
I don't think they post here, but excited to be talking about what the Go Security team does, and why (hopefully) you don't hear much about us, at GopherCon UK in August.
2
35
7
IP address certificate subjects are coming to Let's Encrypt SOONβ’:
community.letsencrypt.org/t/getting-re...
The groundwork for this was started ~2020 so it's extremely cool to see it coming to fruition !
3 months ago
0
6
0
Harsh but fair
3 months ago
0
5
0
reposted by
cpu
xan || roguesys
3 months ago
Wrote some notes on self-hosting an Atuin sync server and getting to it via Tailscale
hackd.net/posts/atuin-...
0
4
1
reposted by
cpu
elizaπ»
3 months ago
βͺ*slaps roof of libcrypto* this bad boy can fit so much global mutable state inside it!β¬
1
61
1
reposted by
cpu
James Munns
3 months ago
Had a gig wrap up a little earlier than expected, I should have availability starting July or so. As always: if you need help with Embedded, Rust, or similar things, shoot me a message! If you're a user of postcard, p-rpc, or are interested in the more experimental new ergot: shoot me a message!
2
36
22
reposted by
cpu
Filippo Valsorda
3 months ago
I implore folks to apply a better theory of the mind than "they dumb or evil" to experienced Chrome engineers entrusted with the security of 3.5B people. You can still disagree! But if you can't articulate their technical motivations, please pause for a second and consider you might be missing it.
1
50
3
Today I thought I would try the Spotify Linux desktop client instead of the web UI. It's only _slightly_ disconcerting to find after an hour of listening that it's been spewing stack smashing errors π¬
3 months ago
1
2
1
reposted by
cpu
Go
3 months ago
π Go 1.25 Release Candidate 1 is released! πββοΈ Run it in dev! Run it in prod! File bugs!
go.dev/issue/new
π’ Announcement:
groups.google.com/g/golang-ann...
π¦ Download:
go.dev/dl/#go1.25rc1
3
90
34
reposted by
cpu
Joe Birr-Pixton
4 months ago
Here's my talk on Graviola --
youtu.be/n6gA93iSj68
add a skeleton here at some point
0
9
1
reposted by
cpu
Sovereign Tech Agency
4 months ago
In case you missed it, hereβs the second in-depth interview with open source maintainer Stefan Eissing
@icing.bsky.social
from the first cohort of the Sovereign Tech Fellowship. Stefan has been building connections since the days of dial-up modems. (1/2)
1
3
1
reposted by
cpu
James Munns
4 months ago
Whenever I get self conscious about naming libraries silly things, I remind myself that Arm (the acorn risc machine) released the ARM (architecture reference manual) for their A/R/M (application/realtime/microcontroller) processors, making the document the Arm A/R/M ARM.
2
161
23
Woodfrogs are great. i) they can survive -6Β°C temps and having 60% of the water in their bodies freeze ii) they have kvlt face paint I rest my case
4 months ago
0
1
0
This week I've been working on adding Pebble integration tests to Go's /x/crypto/acme package:
github.com/cpu/crypto/b...
Not as complete yet, but fun to contrast the resulting code with the version I cooked up in Rust in collaboration w/
@djc.ochtman.nl
for instant-acme:
github.com/djc/instant-...
4 months ago
1
4
0
It's been a minute π«
4 months ago
0
2
0
The "L" key on my keyboard has been dropping keystrokes ately and you can probably te from the mess of typos ike this I'm eaving everywhere in my wake
4 months ago
1
1
0
Fiddling with x509-limbo this morning for rustls-webpki (
github.com/C2SP/x509-li...
). Between Wycheproof, BoGo, BetterTLS and x509-limbo there's no shortage of excellent cryptography/TLS test frameworks these days.
loading . . .
Add CRL verification support to rustls-webpki, fixup CRL test case by cpu Β· Pull Request #441 Β· C2SP/x509-limbo
π Hi folks, One of the features that distinguishes the Rusts fork of webpki from its predecessor is support for revocation checking with CRLs. This branch updates the x509-limbo harness to take adv...
https://github.com/C2SP/x509-limbo/pull/441
4 months ago
0
10
1
Hello! I'm Daniel/@cpu I <3 open source and split my time between working for
@geomys.org
on Go cryptography, and hacking on various other bits of applied cryptography (notably
github.com/rustls/rustls
& friends). I'm new to Bluesky. Let's see how it goes?
4 months ago
1
24
1
you reached the end!!
feeds!
log in