Sign in

Dirkjan Ochtman

@djc.ochtman.nl
1.2K followers 145 following 572 posts

Fan of Rust, open source maintainer. Please consider sponsoring my OSS work on GitHub.

PostsRepliesMedia
Reposted by Dirkjan Ochtman
Raph Levien @raphlinus.bsky.social · 23/09/2026
A huge milestone: Fearless SIMD 1.0 is published: linebender.org/blog/fearles.... This was a real collaboration, thanks especially to Sergey Davidoff for pushing this over the line, Laurenz Stampfl, Andrew Jakubowicz, valadaptive, Benjamin Saunders, and Daniel McNab.
linebender.org
Fearless SIMD v1.0 is here
Fearless SIMD v1.0 is here
27715
Reposted by Dirkjan Ochtman
Rust Language @rust-lang.org · 17/09/2026
⚠️ We believe that there is an ongoing campaign targeting owners of popular crates and rust-lang team members that is attempting to compromise devices and accounts in order to use them to publish malware. See our blog post for details: blog.rust-lang.org/2026/09/17/t...
blog.rust-lang.org
Be alert: targeted attacks on prominent Rustaceans | Rust Blog
Empowering everyone to build reliable and efficient software.
121990
Dirkjan Ochtman @djc.ochtman.nl · 12/09/2026
OxiSH does not support compression. We’ll see if someone really needs it, but will definitely keep it disabled by default.
080
Reposted by Dirkjan Ochtman
aly @aly.codes · 09/09/2026
Apparently Digital Ocean canceled their $50/month sponsorship of GNOME and FlatHub the month before giving Omarchy 3 million dollars. social.treehouse.systems/@barthalion/...
social.treehouse.systems
Bart Piotrowski (@barthalion@treehouse.systems)
Meanwhile DigitalOcean couldn’t afford $50 a month for GNOME and Flathub VMs and cancelled their sponsorship last month.
1117123
Dirkjan Ochtman @djc.ochtman.nl · 09/09/2026
rustls, our modern memory-safe TLS implementation is 10 years old! @jbp.io wrote a blog post reflecting on how we got here: rustls.dev/blog/2026-09...
rustls.dev
rustls: A Decade of Rustls
2548
Dirkjan Ochtman @djc.ochtman.nl · 03/09/2026
PSA: if you depend on Hickory DNS, upgrade now: github.com/hickory-dns/... DNS implementations (not just Hickory) have been hit pretty hard by LLM-assisted vulnerability research.
github.com
Release v0.26.2 · hickory-dns/hickory-dns
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in pars...
23311
Reposted by Dirkjan Ochtman
Predrag Gruevski @predr.ag · 27/08/2026
More good news: Jess Izen is stepping into an Engineer in Residence role with the Rust Foundation! She's done so much good work for the ecosystem already (see the post!) and I can't think of a better person to wear this hat 🦀 rustfoundation.org/media/welcom...
rustfoundation.org
Welcoming Jess Izen as Engineer in Residence at the Rust Foundation
The Rust Foundation is pleased to welcome Jess Izen (@jlizen) as our new Engineer in Residence. For the next year, Jess will work full time as part of the Foundation’s engineering team, taking directi...
0213
Dirkjan Ochtman @djc.ochtman.nl · 26/08/2026
I wonder whether people will start to update their priors about running “stable” (read old) software. blog.trailofbits.com/2026/08/26/v...
blog.trailofbits.com
VMs won't contain cyber-capable agents
You can no longer assume a mere VM will contain a sufficiently advanced AI agent.
1175
Reposted by Dirkjan Ochtman
Steve Klabnik @steveklabnik.com · 24/08/2026
Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust bughunters.google.com/blog/scaling...
bughunters.google.com
Blog: Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust
This blog post describes how we used AI to help us rewrite a C library (giflib) to Rust to mitigate memory safety vulnerabilities.
26514
Reposted by Dirkjan Ochtman
cinnamon 🐇 🏳️‍⚧️ @plushie.holdings · 24/08/2026
ohhhh firefox are using jxl-rs and not libjxl for decode now ^-^
1874
Dirkjan Ochtman @djc.ochtman.nl · 20/08/2026
Rust blog post: blog.rust-lang.org/2026/08/20/s...
blog.rust-lang.org
Supply chain attack on arrayref | Rust Blog
Empowering everyone to build reliable and efficient software.
031
Dirkjan Ochtman @djc.ochtman.nl · 20/08/2026
PSA: arrayref 0.3.10 (maintained by droundy, 54M recent downloads) appears to contain malware. rust-lang.zulipchat.com#narrow/chann...
rust-lang.zulipchat.com
Public view of rust-lang | Zulip team chat
Browse the publicly accessible channels in rust-lang without logging in.
0115
Dirkjan Ochtman @djc.ochtman.nl · 13/08/2026
Happy to announce a new project: OxiSH, a modern, memory-safe SSH server. dirkjan.ochtman.nl/writing/2026... Prossimo has three criteria for suggesting memory-safe rewrites: (1) widely used, (2) on a security boundary and (3) performing a critical function. This is clearly true for SSH servers.
dirkjan.ochtman.nl
OxiSH: a modern, memory-safe SSH server – Dirkjan Ochtman
26714
Reposted by Dirkjan Ochtman
ryan cooper @ryanlcooper.com · 02/08/2026
this owns www.inverse.com/input/cultur...
inverse.com
The adorable love story behind Wikipedia’s 'high five' photos
Nearly 14 years later, the tale of this iconic couple can finally be told.
453088783
Reposted by Dirkjan Ochtman
Nicholas Nethercote @nnethercote.bsky.social · 31/07/2026
New blog post: How to speed up the Rust compiler in July 2026 nnethercote.github.io/2026/07/31/h...
nnethercote.github.io
How to speed up the Rust compiler in July 2026
My last post on the Rust compiler’s performance was in December 2025. Let’s see what has happened since then.
68217
Reposted by Dirkjan Ochtman
Lucretiel @lucretiel.me · 30/07/2026
So when are we going to make AI code get a handle on wildly overwrought commenting. One easy way to spot under-reviewed vibecoding is comments that are oddly verbosely fixated on one particular minor implementation feature (because that’s the most recent thing that was worked on)
0134
Dirkjan Ochtman @djc.ochtman.nl · 15/07/2026
On my trusty M1 Max, a tiny test crate with graviola 0.4 as its single dependency runs clean `cargo check` 1.31x faster than with sha2 0.11, and clean `cargo build` 1.11x faster.
070
Reposted by Dirkjan Ochtman
Tobias Bieniek @tobias.bieniek.cloud · 13/07/2026
🦀 in case you're wondering what the crates.io team has been up to for the past 6 months: blog.rust-lang.org/2026/07/13/c... - Source Code Viewer - Untangling crates.io Accounts from GitHub - Advisories and Suggestions - Cuter Error Pages - Svelte Frontend Migration Completed #rustlang
blog.rust-lang.org
crates.io: development update | Rust Blog
Empowering everyone to build reliable and efficient software.
1309
Dirkjan Ochtman @djc.ochtman.nl · 13/07/2026
I suppose asking for new contributors on a popular programming language blog is equivalent to inviting a slop tsunami.
0110
Reposted by Dirkjan Ochtman
Armin Ronacher @mitsuhiko.at · 10/07/2026
Shitty personal attacks in a blog post are one thing, but when people reply “now I like zig even more” really makes me wonder what went wrong in our communities.
71405
Dirkjan Ochtman @djc.ochtman.nl · 01/07/2026
We're making good progress on upki, our collaboration with the rustls project to bring browser-grade web PKI capabilities to low level system utilities. #Canonical made a PPA available so you can try out upki in #Ubuntu. Give it a go and let us know! discourse.ubuntu.com/t/try-the-up...
discourse.ubuntu.com
Try the `upki` preview for Ubuntu!
The development of upki has been steadily progressing over the past few months. Since my last update, the project has released a beta version of the CLI tool and library, and the Ubuntu Foundations te...
1163
Reposted by Dirkjan Ochtman
The Rust Foundation @rustfoundation.org · 30/06/2026
We are pleased to welcome Wild to the RIL: the Rust Foundation's home for projects that power critical infrastructure. Wild is a linker with the goal of being very fast for iterative development & is supported financially by AWS. Read the announcement: rustfoundation.org/media/welcom...
rustfoundation.org
Welcoming Wild to the Rust Innovation Lab
The Rust Innovation Lab (RIL), housed under the Rust Foundation, is pleased to announce the arrival of its newest board-approved project, Wild: a very fast linker for Linux, with other operating…
0415
Reposted by Dirkjan Ochtman
Erk @erk.dev · 21/06/2026
A post by @mara.bsky.social have been stuck in my head for about two months now so I just had to write out my thoughts on what the most central railway station in the Netherlands is: erk.dev/2026/06/21/t...
erk.dev
The most central station in the Netherlands
A small journey about trying to find the most central station in the Netherlands
084
Dirkjan Ochtman @djc.ochtman.nl · 18/06/2026
graviola is amazing and more people should use it.
070
Reposted by Dirkjan Ochtman
Paolo Barbolini @paolobarbolini.bsky.social · 17/06/2026
This new graviola release is amazing! aws-lc-rs v1.17.0: 18 dependencies - 16s release build rustls-graviola v0.3.4: 45 dependencies - 9s release build rustls-graviola v0.4.0: 19 dependencies - 5.5s release build Tested on a 24 vCPU 5950X VM. github.com/ctz/graviola...
github.com
Release 0.4.0 · ctz/graviola
A new ML-KEM-768 implementation using verified assembler from the mlkem-native project. This drops the dependency on libcrux-ml-kem from rustls-graviola and the crate feature. Runtime performance i...
0162
Reposted by Dirkjan Ochtman
Trifecta Tech Foundation @trifectatech.bsky.social · 16/06/2026
We're excited to share that Firefox now uses zlib-rs for gzip (de)compression. This has both performance and safety advantages, but it took a while to get zlib-rs into production. Read why: trifectatech.org/blog/zlib-rs... Thanks to @gabrielesvelto.mas.to.ap.brid.gy and @mozilla.org #rustlang
trifectatech.org
zlib-rs in Firefox - Trifecta Tech Foundation
As of 151.0.0, Firefox uses zlib-rs for gzip (de)compression. This is very exciting, and has both performance and safety advantages.
0346
Dirkjan Ochtman @djc.ochtman.nl · 16/06/2026
MFA by emailing or texting a code is both bad security and crappy UX.
271
Reposted by Dirkjan Ochtman
Laurence Tratt @ltratt.bsky.social · 11/06/2026
I put crates.io/crates/depub together for this a while back. It's crude, but surprisingly effective.
181
Dirkjan Ochtman @djc.ochtman.nl · 10/06/2026
The recording of our talk at @canonicalltd.bsky.social's #UbuntuSummit is available now: www.youtube.com/watch?v=qKmR... Happy to answer questions here!
youtube.com
uPKI: improving certificate revocation on Linux | Ubuntu Summit 26.04
YouTube video by Canonical Ubuntu
062
Reposted by Dirkjan Ochtman
Filippo Valsorda @filippo.abyssdomain.expert · 09/06/2026
Ugh, apparently neither @github.com, nor @fastmail.com, nor @slack.engineering support post-quantum TLS key exchanges, making everything sent and received over these connections vulnerable to harvest-now-decrypt-later attacks, maybe as early as 2029.
46315
Reposted by Dirkjan Ochtman
Trifecta Tech Foundation @trifectatech.bsky.social · 01/06/2026
We're proud to announce the first release of our latest data compression project, Zstandard in Rust! Read why we did this, the current state of the project, and where we're hoping to take it: buff.ly/JoruN7e Thanks to Chainguard, Astral, NLnet Foundation, and @sovereign.tech. #rustlang #opensource
trifectatech.org
Announcing Zstandard in Rust - Trifecta Tech Foundation
Over the past year, we've been silently working on our third compression project. After zlib and bzip2 we're now taking on zstd with libzstd-rs-sys, and are proud to announce its first release.
14914
Dirkjan Ochtman @djc.ochtman.nl · 27/05/2026
@jbp.io and I will be presenting on our upki project to make TLS certificate verification more secure for non-browser Linux apps.
0193
Reposted by Dirkjan Ochtman
Andrew Gallant @burntsushi.net · 26/05/2026
Why don't Jiff's strftime and strptime routines validate the format string separately from formatting or parsing a datetime? github.com/BurntSushi/j...
github.com
Why don't Jiff's `strftime` and `strptime` routines validate the format string separately from formatting or parsing a datetime? · BurntSushi jiff · Discussion #560
I've been considering moving from chrono to jiff. So far, I've been liking what I'm reading, especially when it comes to time zones. However, one thing stood out to me. That's the strftime and strp...
0203
Reposted by Dirkjan Ochtman
Paolo Barbolini @paolobarbolini.bsky.social · 14/05/2026
A few days ago I tried instant-xml for a project that had to deal with complex xml files. Now I'm switching rusty-s3 over to using it. github.com/paolobarboli...
github.com
refactor: migrate XML (de)serialization from quick-xml to instant-xml by paolobarbolini · Pull Request #156 · paolobarbolini/rusty-s3
quick-xml relies on serde, which does not map well with xml. This switches to instant-xml, which uses it's own system for serialization and deserialization. It doesn't support streaming dec...
172
Dirkjan Ochtman @djc.ochtman.nl · 14/05/2026
PSA: rustup might be failing in some GitHub runners on macOS github.com/actions/runn...
github.com
macos-15-arm64/20260511.0048 ships broken Homebrew rustup-init — rejects '+stable' and 'metadata' argv · Issue #14097 · actions/runner-images
Description The macos-15-arm64/20260511.0048 image ships a Homebrew rustup at /opt/homebrew/bin/rustup (1.29.0) whose bundled rustup-init binary rejects standard argv that the rustup CLI passes to ...
030
Reposted by Dirkjan Ochtman
conputer dipshit @davidcrespo.bsky.social · 09/05/2026
jesus christ xcancel.com/jarredsumner...
1118718
Dirkjan Ochtman @djc.ochtman.nl · 08/05/2026
Early incident report: bugzilla.mozilla.org/show_bug.cgi...
bugzilla.mozilla.org
2038351 - Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
UNCONFIRMED (nobody) in CA Program - CA Certificate Compliance. Last updated 2026-05-08.
040
Dirkjan Ochtman @djc.ochtman.nl · 05/05/2026
Yes! Also unnameable_types.
091
Reposted by Dirkjan Ochtman
Joe Birr-Pixton @jbp.io · 01/05/2026
At #rustweek I'll have new stickers celebrating a decade of rustls. First commit was ten years ago tomorrow
A stack of holographic stickers for the rustls TLS library
2322
Reposted by Dirkjan Ochtman
Joe Birr-Pixton @jbp.io · 22/04/2026
youtu.be/rgZlzCd0DUU?... I guess this means I'm a tech influencer now? Thanks @frame.work
youtu.be
Framework [Next Gen] Event | 2026 Launch Event
YouTube video by Framework
131
Reposted by Dirkjan Ochtman
Mara Bos @mara.bsky.social · 16/04/2026
I'm *very* excited to report that we got initial funding and have hired our first Rust maintainers! RustNL's Rust Maintainers Team starts out with two full time maintainers, one intern, and five part-time maintainers, now stably employed to continue their work on Rust! 🎉 rustnl.org/maintainers/
Screenshot of the website, listing the eight team members: Oli (full-time), Waffle (full-time), Tiffany (intern), Mara (part-time), Jana (part-time), Nia (part-time), Bjorn (part-time), and Folkert (part-time).
420332
Dirkjan Ochtman @djc.ochtman.nl · 16/04/2026
After 13 months of work, today we released Hickory DNS 0.26.0 (our memory-safe DNS libraries and server), which should be more robust, faster and easier to use correctly. Detailed release notes are here: github.com/hickory-dns/...
github.com
Release 0.26.0 · hickory-dns/hickory-dns
13 months after the release of 0.25.0, we finally have a bigger feature release of Hickory DNS, the suite of DNS libraries and authoritative/recursive name servers written in pure Rust. A lot of wo...
0162
Reposted by Dirkjan Ochtman
Benjamin Fry @bluejekyll.bsky.social · 14/04/2026
That little DNS project I started about 10 years ago is making some news with Google! This is definitely because so many people have jumped in to help contribute here. Special call out to @djc.ochtman.nl who’s picked up a huge amount of slack for me in the last year. arstechnica.com/gadgets/2026...
arstechnica.com
Google shoehorned Rust into Pixel 10 modem to make legacy code safer
Cellular modems are complex black boxes of legacy code, but Google is making them safer with Rust.
1172
Dirkjan Ochtman @djc.ochtman.nl · 13/04/2026
From an LLD maintainer: “wild is worth calling out separately: its user time is comparable to lld's but its system time is roughly half, and its parse phase is 4-8x faster than either of the C++ linkers.” maskray.me/blog/2026-04... (Via @llvmweekly.org.)
maskray.me
Recent lld/ELF performance improvements
Since the LLVM 22 branch was cut, I've landed patches that parallelize more link phases and cut task-runtime overhead. This post compares current main against lld 22.1, mold, and wild. Headline: a Rel
0181
Dirkjan Ochtman @djc.ochtman.nl · 11/04/2026
Very cool to see that Google is using Hickory DNS (which I help maintain) to power DNS message parsing in the Pixel firmware! Reviewing those PRs does indeed seem like a short while ago…
0364
Reposted by Dirkjan Ochtman
Goldstein (still not a pseudonym) @goldstein.latinsky.app · 03/04/2026
This woman is facing a copyright claim for her own music by an AI company that took her youtube page and copied her.
311848851
Dirkjan Ochtman @djc.ochtman.nl · 10/04/2026
An update on rustls performance: it’s still pretty fast. www.memorysafety.org/blog/26q1-ru...
memorysafety.org
Q1 2026 Rustls Performance Update
Overview Offering top tier performance is a primary goal for the Rustls project. As such, the project has developed benchmarks representing some of the most performance critical functions and monitors them closely. The Rustls project periodically publishes test results that compare Rustls performance to other popular TLS libraries, OpenSSL and BoringSSL. The previously published test results are from July of 2025. The Rustls project is planning to start publishing performance reports more frequently going forward.
0236
Reposted by Dirkjan Ochtman
Rust Language @rust-lang.org · 08/04/2026
⚠️ An active phishing attack is targeting crate owners by asking them to "confirm that your email address is still active". These messages are not from crates.io, and should be ignored. (We will never ask you to confirm that your e-mail address is still active.) ⚠️
215563
Reposted by Dirkjan Ochtman
Filippo Valsorda @filippo.abyssdomain.expert · 06/04/2026
Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years. That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.
words.filippo.io
A Cryptography Engineer’s Perspective on Quantum Computing Timelines
The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.
11303123
Reposted by Dirkjan Ochtman
Carl Lerche @carllerche.com · 04/04/2026
Apparently, if a crate is not 100% human written, it is off topic for /r/rust: reddit.com/r/rust/comme.... I have been working on Toasty for 3 years, 9 months with AI tools. I am quite proud of the code quality and stand by it. By their standard, the entire tokio-rs GitHub organization is now OT.
reddit.com
Toasty, an async ORM for Rust, is now on crates.io
2215712