Sign in

Brian Smith

@briansmith.bsky.social
907 followers 137 following 66 posts

briansmith.org

PostsRepliesMedia
Reposted by Brian Smith
Isaac Levin @isaacrlevin.com · 02/04/2026
In my conversation with @williammorgan.me on @coffeeandopensource.com, we talked about the decision to better enable a commercial version of Linkerd, and how it saved the project. www.tiktok.com/@isaacrlevin...
tiktok.com
In my conversation with William Morgan on Coffee and Open Source, we talked about the decision to better enable a commercial version of Linkerd, and how it saved the project. Full episode below https...
TikTok video by Isaac Levin
031
Brian Smith @briansmith.bsky.social · 27/01/2026
I will go to the Rust Los Angeles meetup event in Santa Monica tomorrow (Wed) evening: www.meetup.com/rust-los-ang...
meetup.com
Rust Los Angeles: Building Git-LFS Replacements in Rust, Wed, Jan 28, 2026, 6:00 PM | Meetup
The Rust ecosystem is exploding right now! New tools, use cases, and companies adopting it at scale. With so many interested in staying up-to-date on these trends, we figur
000
Reposted by Brian Smith
Marc-André Moreau @awakecoding.com · 29/07/2025
New blog post! 📰 I tried "vibe coding" in VSCode using GitHub Copilot (Claude Sonnet) to build an MCP proxy tool in Rust — I didn't touch a line of code, just pure agent mode magic 🧙‍♂️ 🚀👇 awakecoding.com/posts/vibe-c...
awakecoding.com
Vibe coding a Rust MCP proxy in VSCode with GitHub Copilot
A hands-off experiment building a Rust-based Model Context Protocol (MCP) proxy tool using only GitHub Copilot agent mode. Covers setup, multi-transport support, and lessons learned from letting Copil...
012
Reposted by Brian Smith
Jonathan Protzenko @protz.bsky.social · 10/06/2025
This is what I've been driving for the past year! It's an exciting time, with Rust making its way into one of the most critical pieces of software: the core crypto library used in Azure and Windows. With Rust, formal verification becomes easier, and so far, no blockers to Rust adoption.
66514
Brian Smith @briansmith.bsky.social · 10/06/2025
Tried macOS 26 beta in a VM. I like the glass effect. The default icons in dark mode are like the ones on iPhone, but the clear icons look good. It seems like a stepping stone toward touchscreen Macs. Lots of big UI elements & more of an emphasis on interactivity. Needs refinement of the layering.
130
Reposted by Brian Smith
ePrint Updates @eprint.ing.bot · 02/06/2025
Formal Security and Functional Verification of Cryptographic Protocol Implementations in Rust (Karthikeyan Bhargavan, Lasse Letager Hansen, Franziskus Kiefer, Jonas Schneider-Bensch, Bas Spitters) ia.cr/2025/980
Abstract. We present an effective methodology for the formal verification of practical cryptographic protocol implementations written in Rust. Within a single proof framework, we show how to develop machine-checked proofs of diverse properties like runtime safety, parsing correctness, and cryptographic protocol security. All analysis tasks are driven by the software developer who writes annotations in the Rust source code and chooses a backend prover for each task, ranging from a generic proof assistant like F⋆ to dedicated crypto-oriented provers like ProVerif and SSProve Our main contribution is a demonstration of this methodology on Bert13, a portable, post-quantum implementation of TLS 1.3 written in Rust and verified both for security and functional correctness. To our knowledge, this is the first security verification result for a protocol implementation written in Rust, and the first verified post-quantum TLS 1.3 library.
1106
Brian Smith @briansmith.bsky.social · 10/05/2025
@watchmarquee.bsky.social @mlb.com Would love to get the Cubs games in 5.1 audio through MLB.TV.
000
Brian Smith @briansmith.bsky.social · 06/03/2025
It’s the time of year where we re-read ComodoHacker’s pastebin. Props to pastebin.com for keeping this up for all these years. pastebin.com/u/ComodoHacker
pastebin.com
ComodoHacker's Pastebin - Pastebin.com
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
011
Brian Smith @briansmith.bsky.social · 14/02/2025
Released *ring* 0.17.9. X25519 is about 20% faster for GCC users (clang got it in 0.17.8). AES-GCM is slightly faster. Auditing the code for memory safety and panic-freeness should be easier now. Expect 100% compat with 0.17.8, but MSRV was raised from 1.61 to 1.63; still Debian-Stable-friendly.
1101
Reposted by Brian Smith
Casper Kessels @casperkessels.com · 11/02/2025
New study on the effect of driver aids on crash risk: - Lane keep assist: -19% - Driver monitoring systems: -14% - Automatic emergency braking: -10.7% - Adaptive Cruise Control: +8% - Cruise Control: +12% No data on speed limit alerts though. www.sciencedirect.com/science/arti...
sciencedirect.com
Rethinking Advanced Driver Assistance System taxonomies: A framework and inventory of real-world safety performance
In this review, we assess the real-world effectiveness of ADAS! (ADAS!) in preventing vehicle crashes. We propose a new, data-driven framework of safe…
2193
Brian Smith @briansmith.bsky.social · 07/02/2025
I wish I wasn’t the kind of person to question whether a language’s mutex implementation guarantees acquire/release semantics.
031
Reposted by Brian Smith
Clive "Max" Maxfield @magnificent-max.bsky.social · 30/01/2025
Rust Rules! (Programming Language-Wise) www.eejournal.com/article/rust... Ferrous Systems has carved out a leadership role with respect to Rust solutions for safety-critical systems. Its flagship tool chain, Ferrocene, has achieved IEC 62304 Class C qualification for medical device software.
Metal sheet covered in rust with blue, green cyan, yellow, orange, and red hues
14110
Reposted by Brian Smith
Ben Adida @benadida.com · 28/01/2025
It's a big week for voting technology. We're launching VotingWorks, the voting system we've been hard at work on for six years. Transparent, secure, and easy to use. So every American can trust their ballots are counted correctly. voting.works/machines
voting.works
Voting Machines
The only open-source voting machines used in United States elections. Designed to VVSG 2.0.
1195
Reposted by Brian Smith
Johnathan Nightingale @johnathan.bsky.social · 18/01/2025
Step N+1: the person with the keys will tell you that having the option to disable specific integration points is an enterprise-only feature, but that they can add it to your account if you confirm that's what you want. A few minutes later, it's active. Ours now looks like this.
Updated screenshot of google admin panel for "Gemini for Google Workspace" -- the panel now has a panel labelled "Feature Access" with the ability to toggle gemini in Drive and Docs, Gmail, Chat, and Meet. They are all toggled to Off.
141
Reposted by Brian Smith
Litbowl @litbowl.bsky.social · 17/01/2025
I want to share my experience today with Google support, trying to get Gemini (their AI/plagiarism machine) turned off in my Google workspace account. That account is where I personally do all my work communication—I am an editor, and most of my work contracts explicitly ban any use of Generative AI
7728431415
Brian Smith @briansmith.bsky.social · 16/01/2025
Time to deprecate & remove wasm32-unknown-unknown. It is basically the same as a WASI 0.2 environment that exposes no components. It’s easy to create a minimal WASI 0.2 environment that implements wasi-random—or whatever—by delegating to the host (browser, etc.). This would simplify many libraries.
011
Brian Smith @briansmith.bsky.social · 15/01/2025
Thinking about switching to RedNote Actions for CI. I heard it has native loongarch64 support.
020
Reposted by Brian Smith
Dustin Volz @dustinvolz.bsky.social · 05/01/2025
NEWS: The massive Chinese hack of U.S. telecoms breached firms Charter, Consolidated and Windstream as part of a historic espionage campaign. Security vendor Fortinet was a key intrusion point. Investigators are still grappling with the damage. That and much much more: www.wsj.com/tech/cyberse...
wsj.com
How Chinese Hackers Graduated From Clumsy Corporate Thieves to Military Weapons
Massive ‘Typhoon’ cyberattacks on U.S. infrastructure and telecoms sought to lay the groundwork for potential conflict with Beijing, as intruders gathered data and got in position to impede response a...
817082
Brian Smith @briansmith.bsky.social · 02/01/2025
If magic links work well for signing into your website then passkeys are probably a poor alternative for improving sign-in convenience, as they are overkill and the costs associated with them are high, especially end user support costs. Why not OpenID Connect w/ Discovery using the email address?
110
Brian Smith @briansmith.bsky.social · 27/12/2024
Saw Wicked, the stage production, in L.A. last night. It was truly a masterpiece of art. I usually avoid musicals of all sorts, and I seem to annoy people with my Hamilton review (“absolutely not worth the ticket price”). Especially if you have no interest in it, consider giving it a go.
000
Brian Smith @briansmith.bsky.social · 13/12/2024
When I order something from overseas on eBay I reliably (100% of the time) get a phishing text related to my package being stuck in customs. Receiving this message is the primary & only mechanism by which I learn my package has arrived in the US before it shows up at my door a few days later.
110
Brian Smith @briansmith.bsky.social · 06/12/2024
If you have chopped down a tree, drug it into your home, placed it in a pot of water, and decorated it with lights, then it is highly likely that you plugged it into whatever outlet that room has. If it isn’t a GFCI outlet, you can get an “inline” GFCI cord/wall-wart for this.
021
Brian Smith @briansmith.bsky.social · 06/12/2024
AFAICT, the best defense against disasters (e.g. fire) caused by water (rain/sleet/snow/hose overspray) in electric decorations (e.g. Christmas lights) is the exclusive use of GFCI power outlets. If you don’t have conveniently-placed GFCI outlets, inexpensive “inline” GFCI adapters are available.
010
Reposted by Brian Smith
Filippo Valsorda @filippo.abyssdomain.expert · 06/12/2024
Supply chain attack via a shell injection in a PR branch name (!) due to unsafe use of GitHub Actions' pull_request_target. Inserted a crypto miner in the PyPI package. Paging @yossarian.net to the courtesy phone. Would github.com/woodruffw/zi... have caught it?
15619
Brian Smith @briansmith.bsky.social · 06/12/2024
This was stabilized in Rust 1.81 as std::hint::assert_unchecked (doc.rust-lang.org/std/hint/fn....), while the functionally equivalent `if !cond { std::hint::unreachable_unchecked() }` has been stable since Rust 1.27, released in 2018.
doc.rust-lang.org
assert_unchecked in std::hint - Rust
Makes a soundness promise to the compiler that `cond` holds.
170
Brian Smith @briansmith.bsky.social · 19/11/2024
Many Californians seem to feel too overwhelmed by the daily grind to do anything to make this world more beautiful. But there is something you can do, no matter how busy you are: You can remove the compliance stickers from your cars’ driver side window. Please! Encourage others do the same.
131
Reposted by Brian Smith
Erant @erant.bsky.social · 18/11/2024
I worked at Apple in the Red Team at the time. As has been speculated publicly, this ended up being the result of a merge failure. The merge was submitted as a single ~10,000 line diff and (understandably) none of the reviewers caught it. Procedures were changed after this one…
1546
Brian Smith @briansmith.bsky.social · 22/09/2023
Let's Build a FIPS-validated Rust Crypto Library: briansmith.org/lets-build-a...
briansmith.org
Let's Build a FIPS-validated Rust Crypto Library
010
Brian Smith @briansmith.bsky.social · 22/08/2023
As a matter of principle I keep my car’s top down unless it is raining. I usually park it top down windows up. I found some auto insurers cover a car that is parked with the top down only if it is locked. Most seem to require the windows to be up too. The worst further require the top be up.
050