Filippo ValsordaGeverifieerd account

@FiloSottile

I mess with cryptography. urandom ambassador. Crypto Team (but opinions ...). That TLS guy. HS/RC F'13. Cold DM :) cold email :(

London
Geregistreerd in juni 2009

@FiloSottile is geblokkeerd

Weet je zeker dat je deze Tweets wilt bekijken? @FiloSottile wordt niet gedeblokkeerd door Tweets te bekijken.

  1. Vastgemaakte Tweet

    Want to know what the TLS 1.3 excitement is about and how it works? Watch my talk (or read the transcript)!

  2. On my way to Hamburg for another CCC. If you're there, come see and I talk about TLS 1.3 at 21:45 on Dec 27 in Saal 2.

  3. A stronger commitment than ever seen from Google. Might be good for pinning + refresh. Part of their new PKI FAQ:

  4. 2600: be proud of being hackers. "Hacker" News: what's wrong with Trump?

  5. So you want to expose Go on the Internet Excellent advice from and

  6. "Crypto timing attacks are impractical over WAN." Nope. Very low latency is achievable to major providers from rented VPS's.

  7. TIL you can take over a twitter acct if you know their phone # & have SS7 access. Password reset via SMS (w/o email)

  8. This is interesting. I submitted a broken HTTPS link (GitHub Pages) to HN and it got to #4 anyway

  9. Oh, wonderful, a Top 1m Websites list based on data instead of the skewed toolbar thingy. Fascinating data.

  10. macOS 10.12.2 comes with important physical-attack protections: Option ROMs opt-out and a FileVault cold boot fix

  11. So, is not joking when he says that issues in Go 1.8betaX will be fixed fast. Test the beta, don't wait!

  12. I'm honestly glad Evernote sparked outrage adding this to the privacy policy: we need more awareness that company-readable is the *default*.

  13. ProTip: in install instructions, use $(go env GOPATH) instead of , to work with the 1.8 default GOPATH

  14. Halderman universally respected; this is basically a threat to damage the crown jewel of Michigan’s education system, over politics.

  15. Wow, , really? Personal attacks and no mention of my main point, the needless problems of long term keys?

  16. The installer creates a CA that is used to verify the IPSEC cert, but can also sign HTTPS certs for any site. The key sits on the server.

  17. Something to know about Algo: the VPN box operator, or whoever pwns it, can MitM all your TLS (!!) connections

  18. I need to make a new version of that Go HTTP timeouts post with 1.6-1.7 H/2 warnings and all this 1.8 goodness

  19. Wow, essentially no one must be using ReadTimeout because it breaks HTTP/2 in 1.6 and 1.7 and nobody noticed 😨

  20. From my DMs, an important question I need help answering: > What marks when a person is ready for employment in computer security?

  21. This is silly, but I can’t get over the “biggest victory” thing. It’s just false. We thought internet would make lies useless, and instead…

Het laden lijkt wat langer te duren.

Twitter is mogelijk overbelast of ondervindt een tijdelijke onderbreking. Probeer het opnieuw of bekijk de Twitter-status voor meer informatie.

    Je bent misschien ook geïnteresseerd in

    ·