Sign in

cpu

@cpu.xkeyscore.club
157 followers 248 following 27 posts

Recluse open source programmer. Ⓥ. he/him. github.com/cpu hachyderm.io/@cpu

PostsRepliesMedia
Reposted by cpu
The Rust Foundation @rustfoundation.org · 11/09/2026
This past Weds at #rustconf, Joe Birr-Pixton and Daniel McCarney shared an update on the Rustls project 10 years in! Don't miss this write-up from Joe that captures some of what they covered onstage. Congrats on such a long run of this important project, Rustls! rustfoundation.org/media/guest-...
041
Reposted by cpu
RustConf @rustconf.com · 22/07/2026
📢 Session: "A Decade of Rustls": update from maintainers @jbp.io & Daniel McCarney at #rustconf! 10 years in, what's next for one of Rust's most widely used TLS libs? 🎟️: rustconf.com/register?utm_source=rustconf_x&utm_medium=social&utm_campaign=week_july20 rustconf2026.sched.com/event/2KHyL/...
093
Reposted by cpu
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 08/07/2026
I don't get why anybody is listening to Jacob Applebaum. My cat has about the same expertise in cryptography, and has never been credibly accused of sexual abuse. She's also a lot cuter.
Photo of a donut with an opening showing the pitch black interior. The void has eyes
32814
Reposted by cpu
Dirkjan Ochtman @djc.ochtman.nl · 01/07/2026
We're making good progress on upki, our collaboration with the rustls project to bring browser-grade web PKI capabilities to low level system utilities. #Canonical made a PPA available so you can try out upki in #Ubuntu. Give it a go and let us know! discourse.ubuntu.com/t/try-the-up...
discourse.ubuntu.com
Try the `upki` preview for Ubuntu!
The development of upki has been steadily progressing over the past few months. Since my last update, the project has released a beta version of the CLI tool and library, and the Ubuntu Foundations te...
1163
Reposted by cpu
Dirkjan Ochtman @djc.ochtman.nl · 27/05/2026
@jbp.io and I will be presenting on our upki project to make TLS certificate verification more secure for non-browser Linux apps.
0193
Reposted by cpu
Joe Birr-Pixton @jbp.io · 01/05/2026
At #rustweek I'll have new stickers celebrating a decade of rustls. First commit was ten years ago tomorrow
A stack of holographic stickers for the rustls TLS library
2322
Reposted by cpu
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
If you'd like, you can buy rebrands and listed OEs from us. However, you don't have to! Our cert has one of the broadest list of tested OEs of the industry, and you can just use it with stock Go 1.24+ and GOFIPS140=v1.0.0, courtesy of Geomys. The point was removing this roadblock to Go adoption.
geomys.org
Geomys FIPS 140-3 Services
Geomys handles the CMVP validation of the FIPS 140-3 Go Cryptographic Module, and contributes the module to the upstream Go project, for the benefit of the Go community.
2244
Reposted by cpu
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
A bit over two years after starting to work on it... Go is officially FIPS 140-3 certified 💥 csrc.nist.gov/projects/cry... I am pretty confident Go is now one of the most—if not the most—seamless and complete FIPS 140-3 compliance solutions... with a single env var, out of the box.
928962
Reposted by cpu
Freddy @freddyb.bsky.social · 24/04/2026
New Blog post: "Multiple things can be true at the same time" - frederikbraun.de/feels-and-ll... Dear reader, I am sure you have read a lot of blog posts about AI in the past weeks or months. This is my post.…
frederikbraun.de
Multiple things can be true at the same time
Multiple things can be true at the same time
052
Reposted by cpu
Dirkjan Ochtman @djc.ochtman.nl · 13/03/2026
I wrote a blog post for the Alpha Omega Foundation on the work I did to surface RustSec advisories on crates.io: alpha-omega.dev/blog/surfaci...
crates.io
crates.io: Rust Package Registry
0122
Reposted by cpu
Deirdre Connolly¹ ² @durumcrustulum.com · 11/03/2026
@filippo.abyssdomain.expert plugs Wycheproof test vectors github.com/C2SP/wychepr... #realworldcrypto
github.com
GitHub - C2SP/wycheproof: Project Wycheproof tests crypto libraries against known attacks.
Project Wycheproof tests crypto libraries against known attacks. - C2SP/wycheproof
141
Reposted by cpu
roland.zone @roland.zone · 03/03/2026
did something very silly, may have some at gophercon this year if you ever sent us a vulnerability report or contributed to Go crypto (or are just nice to me) thanks to @ljamesart.bsky.social who did the great art!
5816
Reposted by cpu
The Rust Foundation @rustfoundation.org · 02/12/2025
With the @openuk.bsky.social Awards coming up, we’re excited that Rustls — a memory-safe TLS library — is shortlisted in two categories, and Creator Joe Birr-Pixton is also recognized individually. The Rust Foundation is proud to support Rustls through the Rust Innovation Lab 🧡
rustfoundation.org
Rustls Shortlisted for Two 2025 OpenUK Awards - The Rust Foundation
The Rust Foundation is delighted to congratulate Rustls for being shortlisted in the Open Source Software and Security categories of the OpenUK Awards 2025 — and Joe Birr-Pixton, Rustls Creator, for…
0115
Reposted by cpu
Filippo Valsorda @filippo.abyssdomain.expert · 20/11/2025
In August I delivered my traditional Go Cryptography State of the Union talk at @gophercon.com in New York. It goes into everything at the intersection of Go and cryptography from the last year. (Also, bragging t-shirts!) Watch the video or read the transcript of my performance review!
words.filippo.io
The 2025 Go Cryptography State of the Union
I delivered my traditional Go Cryptography State of the Union talk at GopherCon US 2025 in New York. It goes into everything that happened at the intersection of Go and cryptography over the last…
14210
Reposted by cpu
Plabayo BV @plabayo.bsky.social · 30/09/2025
Maintaining #Rustls isn’t just code — it’s choices. Dirkjan shared how OSS maintainers balance safety vs. niche flexibility and why API instability or incompatibility can ripple across the ecosystem. Full story at netstack.fm/#episode-7
netstack.fm
Netstack.FM — A Podcast About Networking and Rust
Interviews, monologues, and deep dives into Rust and modern networking systems.
055
Reposted by cpu
Joe Birr-Pixton @jbp.io · 03/09/2025
We have a little blog post about this rustls.dev/blog/2025-09...
rustls.dev
rustls: Rustls and the Rust Foundation's Rust Innovation Lab
023
Reposted by cpu
roland.zone @roland.zone · 29/08/2025
we lived
0301
cpu @cpu.xkeyscore.club · 28/08/2025
PowerDNS Recursor 5.3.0 has a nice note in the changelog: > The embedded webserver used to display the status page and process REST API calls has been rewritten in Rust and now supports multiple listen addresses and TLS. The new code is powered by Hyper+Rustls+Ring 🦀 🔒 (h/t Stefan Schmidt)
071
cpu @cpu.xkeyscore.club · 21/08/2025
TIL the B root servers have deployed experimental DoT support for TLS on the recursor -> auth. server leg: b.root-servers.org/research/tls...
b.root-servers.org
Experimental DNS over TLS support
B.root-servers.net DNS operated by the University of Southern California
030
Reposted by cpu
Joseph Lorenzo Hall, PhD @josephhall.org · 30/07/2025
TIL that the ITU has an annual "X.509 Day", wheeee www.itu.int/md/T25-TSB-C...
A document announcing the "Fourth ITU-T X.509 Day (2025) event" on September 5, 2025, from 13:00 to 16:00 (Geneva time). It details ITU-T X.509 as a foundational standard for public key infrastructure and digital certificates, outlining its history and applications. The event's objectives include reviewing X.509 progress, assessing post-quantum cryptography readiness, exploring decentralized PKI, discussing cross-border digital identity, strengthening AI trust, showcasing real-world adoption, and identifying future directions.
132
Reposted by cpu
Filippo Valsorda @filippo.abyssdomain.expert · 15/07/2025
We announced the new native Go FIPS 140-3 mode today! FIPS 140, like it or not, is often a requirement, and I was increasingly sad about large deployments replacing the Go crypto packages with non-memory safe cgo bindings. Go is now one of the easiest and most secure ways to build under FIPS 140.
go.dev
The FIPS 140-3 Go Cryptographic Module
Go now has a built-in, native FIPS 140-3 compliant mode.
1119949
Reposted by cpu
Joe Birr-Pixton @jbp.io · 10/07/2025
Today we released rustls 0.23.29 crates.io/crates/rustl... -- highlights are better error reporting for unsupported signature algorithms in certificates, and quite a few performance improvements (via a set of changes that started almost 2 years ago!)
crates.io
crates.io: Rust Package Registry
1113
Reposted by cpu
Dirkjan Ochtman @djc.ochtman.nl · 09/07/2025
Pretty excited about the release of instant-acme 0.8, with lots of work from @cpu.xkeyscore.club (who joined as a maintainer) on ARI, profiles, integration testing and a much improved API. github.com/djc/instant-...
github.com
Release 0.8.0 · djc/instant-acme
The 0.8 release contains substantial changes to make the API more modular. It integrates full support for ACME Renewal Information (ARI, recently standardized as RFC 9773). Since the 0.7.2 release,...
071
cpu @cpu.xkeyscore.club · 07/07/2025
Nerd-sniped by bagder into looking at how rustls-ffi stacks up against OpenSSL on memory allocations/peak heap usage when plugged in as a curl vTLS backend. Headlines: * with rustls-ffi 0.15.0: 2,176 allocations. peak heap of 394kB. * with openssl 3.4.1: 308,132 allocations (!). peak heap of 2.1MB
1184
cpu @cpu.xkeyscore.club · 01/07/2025
You love to see it.
github.com
Track two new CVE's of ogsudo by squell · Pull Request #1173 · trifectatechfoundation/sudo-rs
Two new CVE's were disclosed yesterday in ogsudo which do not apply to sudo-rs since they pertain to functionality we chose not to support.
040
Reposted by cpu
roland.zone @roland.zone · 30/06/2025
I don't think they post here, but excited to be talking about what the Go Security team does, and why (hopefully) you don't hear much about us, at GopherCon UK in August.
🔥Keynote Speaker Announcement

We are delighted to announce that Roland Shoemaker will be a key note speaker at this year's #gopherconuk.

Roland leads the Go Security team at Google, working on cryptography, transport security, vulnerability triage, and generally keeping Go secure. Before working on the Go team, he worked on the Let's Encrypt project building the certificate authority software which now issues millions of certificates each day.

Despite its 15 year history, Go has had a rather uneventful security history. In his keynote, Roland will talk about why that is, some of the mistakes made, and what they learnt. Along with what he's working on now, and what’s on the horizon to make Go an even better, safer language for the next 15 years.

Buy your tickets over on our website & join Roland as he opens Day 1 of our conference on 13th August 2025.

🎟️ https://buff.ly/Azghzwp
2357
cpu @cpu.xkeyscore.club · 25/06/2025
IP address certificate subjects are coming to Let's Encrypt SOON™: community.letsencrypt.org/t/getting-re... The groundwork for this was started ~2020 so it's extremely cool to see it coming to fruition !
060
cpu @cpu.xkeyscore.club · 23/06/2025
Harsh but fair
A screenshot of a GitHub warning banner with the text: "Your blame took too long to compute."
050
Reposted by cpu
xan || roguesys @hackd.net · 19/06/2025
Wrote some notes on self-hosting an Atuin sync server and getting to it via Tailscale hackd.net/posts/atuin-...
031
Reposted by cpu
eliza🌻 @elizas.website · 19/06/2025
‪*slaps roof of libcrypto* this bad boy can fit so much global mutable state inside it!‬
1601
Reposted by cpu
James Munns @jamesmunns.com · 17/06/2025
Had a gig wrap up a little earlier than expected, I should have availability starting July or so. As always: if you need help with Embedded, Rust, or similar things, shoot me a message! If you're a user of postcard, p-rpc, or are interested in the more experimental new ergot: shoot me a message!
23621
Reposted by cpu
Filippo Valsorda @filippo.abyssdomain.expert · 17/06/2025
I implore folks to apply a better theory of the mind than "they dumb or evil" to experienced Chrome engineers entrusted with the security of 3.5B people. You can still disagree! But if you can't articulate their technical motivations, please pause for a second and consider you might be missing it.
1493
cpu @cpu.xkeyscore.club · 12/06/2025
Today I thought I would try the Spotify Linux desktop client instead of the web UI. It's only _slightly_ disconcerting to find after an hour of listening that it's been spewing stack smashing errors 😬
A nix-shell terminal instance showing many instances of the line:

"**** stack smashing detected ***: terminated"
121
Reposted by cpu
Go @golang.org · 11/06/2025
🎉 Go 1.25 Release Candidate 1 is released! 🏃‍♀️ Run it in dev! Run it in prod! File bugs! go.dev/issue/new 📢 Announcement: groups.google.com/g/golang-ann... 📦 Download: go.dev/dl/#go1.25rc1
Go 1.25RC1
38528
Reposted by cpu
Joe Birr-Pixton @jbp.io · 10/06/2025
Here's my talk on Graviola -- youtu.be/n6gA93iSj68
youtu.be
Graviola: fast, high-assurance cryptography for Rust - Joe Birr Pixton
YouTube video by RustNL
081
Reposted by cpu
Sovereign Tech Agency @sovereign.tech · 04/06/2025
In case you missed it, here’s the second in-depth interview with open source maintainer Stefan Eissing @icing.bsky.social from the first cohort of the Sovereign Tech Fellowship. Stefan has been building connections since the days of dial-up modems. (1/2)
121
Reposted by cpu
James Munns @jamesmunns.com · 01/06/2025
Whenever I get self conscious about naming libraries silly things, I remind myself that Arm (the acorn risc machine) released the ARM (architecture reference manual) for their A/R/M (application/realtime/microcontroller) processors, making the document the Arm A/R/M ARM.
215923
cpu @cpu.xkeyscore.club · 30/05/2025
Woodfrogs are great. i) they can survive -6°C temps and having 60% of the water in their bodies freeze ii) they have kvlt face paint I rest my case
Close-up view of a woodfrog on a speckled rock. The wood frog is light brown except for its dark face marks.
010
cpu @cpu.xkeyscore.club · 30/05/2025
This week I've been working on adding Pebble integration tests to Go's /x/crypto/acme package: github.com/cpu/crypto/b... Not as complete yet, but fun to contrast the resulting code with the version I cooked up in Rust in collaboration w/ @djc.ochtman.nl for instant-acme: github.com/djc/instant-...
140
cpu @cpu.xkeyscore.club · 26/05/2025
It's been a minute 🫠
020
cpu @cpu.xkeyscore.club · 24/05/2025
The "L" key on my keyboard has been dropping keystrokes ately and you can probably te from the mess of typos ike this I'm eaving everywhere in my wake
100
cpu @cpu.xkeyscore.club · 24/05/2025
Fiddling with x509-limbo this morning for rustls-webpki (github.com/C2SP/x509-li...). Between Wycheproof, BoGo, BetterTLS and x509-limbo there's no shortage of excellent cryptography/TLS test frameworks these days.
github.com
Add CRL verification support to rustls-webpki, fixup CRL test case by cpu · Pull Request #441 · C2SP/x509-limbo
👋 Hi folks, One of the features that distinguishes the Rusts fork of webpki from its predecessor is support for revocation checking with CRLs. This branch updates the x509-limbo harness to take adv...
091
cpu @cpu.xkeyscore.club · 23/05/2025
Hello! I'm Daniel/@cpu I <3 open source and split my time between working for @geomys.org on Go cryptography, and hacking on various other bits of applied cryptography (notably github.com/rustls/rustls & friends). I'm new to Bluesky. Let's see how it goes?
1241