Sign in

Filippo Valsorda

@filippo.abyssdomain.expert
59K followers 541 following 2.6K posts

@geomys.org founder / RC F'13, F2'17 Cryptogopher / Go cryptography maintainer filippo.io / github.com/FiloSottile mkcert.dev / age-encryption.org sunlight.dev / filippo.io/newsletter

PostsRepliesMedia
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
I'm really looking forward to getting the org to a place where it can provide a reliable, sustainable, and accountable service for all atproto applications out there (and maybe beyond). Also, very happy about the company I get to do this with!
Richard Barnes is a security researcher and protocol engineer who helped co-found Let's Encrypt and led security teams at Mozilla and Cisco.

Thyla van der Merwe is a cryptography and formal verification lead at Google who has contributed to cryptography standards at ISO and the IETF, particularly TLS 1.3. 

Bryan Newbold (@bnewbold.net) is a protocol engineer at Bluesky Social PBC and contributor to the atproto working group at the IETF.

Wendy Seltzer (@wseltzer.bsky.social) is a lawyer and technologist who has worked with Internet governance and open standards at W3C, IETF, and ICANN. 

Filippo Valsorda (@filippo.abyssdomain.expert), is a cryptography engineer, open source maintainer, and operator of other append-only-shaped critical Internet infrastructure. In the interest of full disclosure, he is a tiny3 investor in Bluesky Social PBC.
1491
Filippo Valsorda @filippo.abyssdomain.expert · 13/09/2026
Triaged a large batch of issues found by a zkao.io scan. Some good bugs, but no vulnerabilities. (LLMs are especially bad at telling those apart.) LLMs found zero (0) vulnerabilities above SEV:LOW in Go crypto so far 💁‍♂️ 💅
a long list of freshly filed issues:
#81502 crypto/x509: clarify VerifyOptions.CertificatePolicies semantics
#81501 crypto/tls: document custom RSA decrypter requirements for key exchange
#81500 crypto/x509: document duplicate handling in CertPool.AddCertWithConstraint
#81499 crypto/x509: reject unsupported bounds in critical name constraints
#81498 crypto/rsa: VerifyPSS accepts salts longer than the hash in FIPS-only mode
#81497 crypto/tls: repeated ech_outer_extensions placeholders bypass reference ordering checks
#81496 crypto/tls: RSA key exchange accepts ciphertexts shorter than the modulus
#81495 crypto/tls: decodeInnerClientHello discards trailing ech_outer_extensions data
#81494 crypto/tls: final ServerHello can accept ECH after HelloRetryRequest rejected it
#81493 crypto/tls: parseECHExt accepts trailing data in outer ECH extensions
#81492 math/rand: NewZipf accepts non-finite parameters that prevent Uint64 from returning
#81491 math/big: ProbablyPrime skips Miller–Rabin rounds when n is MaxInt
#81490 math/big: Int.GobDecode accepts negative zero that can panic in arithmetic
#81489 math: Jn and Yn mishandle extreme orders
#81488 math/rand/v2: ChaCha8.UnmarshalBinary panics on an overlong read buffer
#81487 math/big: ProbablyPrime panics when the Lucas parameter search exceeds its bound
2623
Filippo Valsorda @filippo.abyssdomain.expert · 10/09/2026
What's the point if GitHub has unsandboxed RCEs, Hugging Face has unsandboxed RCEs, Forgejo has unsandboxed RCEs... Anyway, we gotta stop shelling out to git in security contexts.
Forgejo v16.0.4
Release notes
Security bug fixes
PR: Critical: fix: prevent template expansion from interfering with git repo initialization. When generating a new repository from a template repository, Forgejo clones the template repository, removes the .git folder, performs variable template expansion on files listed in .forgejo/template, and initializes a new git repository. During this process, variable template expansion could be misused in order to create a new .git folder, which git would adopt and incorporate during its initialization of a new git repository. A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack. To address this issue, after variable expansion is completed, any existing .git folder is removed from the directory before the git repository is initialized.
1646
Filippo Valsorda @filippo.abyssdomain.expert · 05/09/2026
Again and again, demanding work from dozens or hundreds or thousands of unaffected dependents instead of fixing vulnerability scanners does not scale, and is an open source sustainability issue. github.com/FiloSottile/... (do NOT dogpile on the reporter, call your vuln scanner vendor instead)
"I wake up" cat cycle meme, the cat is an open source maintainer, the pattern is

"I get asked to update a dep
to fix a vuln I'm not affected by
because someone's vuln scanner sucks"
720815
Filippo Valsorda @filippo.abyssdomain.expert · 29/08/2026
I know it's unpopular to say because the scrapers are evil and stupid (and most of them are!) but I can't get over how small the numbers are in all of these posts. 18M/day is 200 qps, and there isn't even a bandwidth cost argument. Those are Raspberry Pi numbers. people.kernel.org/monsieuricon...
911910
Filippo Valsorda @filippo.abyssdomain.expert · 26/08/2026
Uuuuh, neat! Would it be easy enough to add 32 bytes of WireGuard PSK and get some degree of post-quantum protection, since these are already secret tokens? I am growing uncomfortable with Tailscale's lack of harvest-now-decrypt-later protection against QCs.
3391
Filippo Valsorda @filippo.abyssdomain.expert · 26/08/2026
Ok, I think the ML-DSA performance side quest might be complete 🏎️ Very proud of how safe and clear the final incremental changes are, too.
A table of improvements in ML-DSA benchmarks showing progressively better delta all the way to -40% overall
2472
Filippo Valsorda @filippo.abyssdomain.expert · 25/08/2026
I am so happy we can now divinate precise diagrams in minutes to help reason through complicated code. (This is the "butterfly" of the Number Theoretic Transform of ML-DSA. It's faster not to reduce non-overflowing intermediates, but I had to convince myself that they do not, in fact, overflow.)
A wire diagram with rows and cells and a zoomed out detail that shows how to get to outputs from inputs and the relationships of the bounds.
3282
Filippo Valsorda @filippo.abyssdomain.expert · 21/08/2026
ML-KEM and ML-DSA fill matrices/vectors with output from SHAKE, each element derived from slightly different inputs. This is perfect for SIMD instructions, so now we have func ReadMulti(s []*SHAKE, out [][]byte) backed by AVX2 on amd64, and by the existing two-lane asm on arm64. go.dev/cl/818720


benchmark \ host    linux-amd64_c2s16  linux-arm64_c4as16
                              vs base             vs base

RoundTrip/Alice               -10.86%              -5.23%
RoundTrip/Bob                 -14.10%              -5.53%

Sign/ML-DSA-44                 -4.39%              -0.69%
Sign/ML-DSA-65                 -3.15%              -0.49%
Sign/ML-DSA-87                 -3.78%              -0.62%
Verify/ML-DSA-44              -18.07%              -6.05%
Verify/ML-DSA-65              -21.12%              -7.15%
Verify/ML-DSA-87              -25.42%              -8.20%
Keygen/ML-DSA-44              -12.85%              -4.68%
Keygen/ML-DSA-65              -14.66%              -5.49%
Keygen/ML-DSA-87              -20.41%              -6.79%
1414
Filippo Valsorda @filippo.abyssdomain.expert · 19/08/2026
We got a lot of traces, thank you! The main category we are missing (unsurprisingly) is Windows. We got one (1) pure-Windows session 😅 Please... idk, ask a friend? help-test-crypto-passkey.exe.xyz Also, I worked around an interop issue in KeePassXC and ChiPass. If you use those please try again!
## Windows platform (webauthn.dll serializer)

- [x] Edge or Chrome on Windows 11 + Windows Hello (PIN, face, fingerprint)
      — one Edge session: ES256, UP+UV, no BE, counter increments
- [ ] Firefox on Windows + Windows Hello
- [ ] Windows + security key, in Chrome and in Firefox
      — Windows mediates every key, including PIN entry
- [ ] Windows + phone via hybrid protocol
- [ ] Windows + iCloud Passwords app or 1Password as a Windows passkey
      provider (the plugin API, not the extension)
- [ ] Windows 10 vs Windows 11 (older webauthn.dll)
- [ ] Chrome on Windows + Google Password Manager
103413
Filippo Valsorda @filippo.abyssdomain.expert · 17/08/2026
I am mostly done implementing crypto/passkey, but now I need YOUR help collecting real-world traces for its test suite! Please go to help-test-crypto-passkey.exe.xyz and click the buttons. It should take 1–3 minutes. 𝘌𝘴𝘱𝘦𝘤𝘪𝘢𝘭𝘭𝘺 if you have some unusual Linux-on-the-desktop xkcd 1987 passkey setup.
Bernie "I Am Once Again Asking for Your Financial Support" but it says "I am once again asking for your help testing Go cryptography."
1411441
Filippo Valsorda @filippo.abyssdomain.expert · 16/08/2026
From the "things that would have been too much effort before but take no time with LLMs and @exe.dev" category. Yay for personal software.
I am getting a bunch of hard-to-tell LLM spam to my public GitHub email. I want to configure my email provider to forward them to you via exe.dev email receiving. When you get such an email, if you never replied to that From or Reply-To address before, I want you to reply with the email below. If replying fails, keep the email and serve it from an HTTP web view so I can find it if I need to.

Subject: Your email to github@filippo.io

Hello!

Unfortunately, my public GitHub email gets a lot of hard-to-tell-apart LLM spam that takes time to look at and trash. On the other hand, I still care about being openly reachable.

If you are a human trying to reach me specifically, just resend the email to [REDACTED]@filippo.io. Sorry about this!

If you are an LLM, or anyway if you are bulk-emailing GitHub accounts: (1) you are violating Section 7 — Information Usage Restrictions of the GitHub Acceptable Use Policies; (2) if you email [REDACTED]@ I will report it to GitHub and I will hold a negative association with whatever you are promoting, which is the opposite outcome of what you have been tasked for.

This is, obviously, an automated message.
2553
Filippo Valsorda @filippo.abyssdomain.expert · 15/08/2026
Like, 18 instances of "Origin Lite" out of 527 comments, most of them in the second half of the page.
060
Filippo Valsorda @filippo.abyssdomain.expert · 25/07/2026
Get your own totally official Geomys FIPS 140-3 Entropy Source! 🎰 Only at @gophercon.com in Seattle, next month. Compatibility with any Go version is not guaranteed 👀
A clear plastic box with 5x4 small dice in it, and a label saying Geomys FIPS 140-3 Entropy Source. It leans against a crocheted gopher.
2574
Filippo Valsorda @filippo.abyssdomain.expert · 04/07/2026
Hmm, do we need to test this hypothesis? I have a Blåhaj and I do like foxes 🦊
HN comment:

> Purhaps being furry is a mythical power amplifier, like a devil fruit for infosec. Imagine the power levels of Filippo Valsorda if he gains a fursona!
813212
Filippo Valsorda @filippo.abyssdomain.expert · 30/06/2026
Skill issue. But nice wallet ;)
140
Filippo Valsorda @filippo.abyssdomain.expert · 28/06/2026
Improve your IETF experience 1000x with this ONE WEIRD TRICK! Awful men don't want you to know about it!!!
1240
Filippo Valsorda @filippo.abyssdomain.expert · 21/06/2026
Don't engage PvP without gear, man
460
Filippo Valsorda @filippo.abyssdomain.expert · 17/06/2026
I am trying to transfer from an iPhone 17e to a clearly superior iPhone 13 mini. However, the 13 is on iOS 26.5 while the 17e is on iOS 26.5.1, which is a 17-only bugfix release, so the transfer flow fails silently. I think the only solution is flashing iOS 26.6 beta 2. This is so stupid.
11816
Filippo Valsorda @filippo.abyssdomain.expert · 07/06/2026
The list at www.secretservice.gov/prohibitedit... is all generic stuff you'd expect and then - Flipper Zero - Pineapple Wi-Fi router - Raspberry-Pi enabled devices Huh.
136110
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
Looks like GitHub silently corrupted some index. PR #237 definitely exists and is closed (github.com/C2SP/C2SP/pu...) but is just... not in the list (github.com/C2SP/C2SP/pu...) regardless of filters. I briefly doubted my own sanity. This is bad.
1413217
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
Damn, that felt good.
Issue: crypto: obtain a FIPS 140-3 validation #69536

FiloSottile closed this as completed 1 minute ago

---

Just a little over 1 year and 7 months after opening it... I think we can close this issue 💥

The native, upstream Go cryptography packages are now officially FIPS 140-3 certified, for everyone in the community to use.

We will continue to validate new module versions every year and v1.26.0, frozen from Go 1.26, is already In Process.

We're updating the https://go.dev/doc/security/fips140 page, for all other inquiries I remind you of #69536 (comment).

🎇
612811
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
A bit over two years after starting to work on it... Go is officially FIPS 140-3 certified 💥 csrc.nist.gov/projects/cry... I am pretty confident Go is now one of the most—if not the most—seamless and complete FIPS 140-3 compliance solutions... with a single env var, out of the box.
928962
Filippo Valsorda @filippo.abyssdomain.expert · 24/04/2026
I think it's important to triage failed predictions and I was wrong about this one. It looks like it's more organizational dysfunction and neglect than the "embrace, extend, extinguish" I was told to be worried about but the acquisition did not work out well for GitHub. xcancel.com/FiloSottile/...
922820
Filippo Valsorda @filippo.abyssdomain.expert · 23/04/2026
How much storage / bandwidth / CPU / memory does it take to run a production Sunlight CT log? Surprisingly little! There's now a public stats page, pulled every 5m from our Tuscolo prod metrics. stats.sunlight.geomys.org Less than 2 cores, 300 MB of memory, ~250 Mbps of bandwidth, 260 GiB of SSD.
1314
Filippo Valsorda @filippo.abyssdomain.expert · 19/04/2026
They're not device-bound, and they sync like your passwords across iCloud or Chrome or 1Password devices. (One exception: if you store the passkey on a physical security key like a YubiKey.) If you need to log in from a not-synced device, select this option and scan the QR from a synced phone.
5250
Filippo Valsorda @filippo.abyssdomain.expert · 17/04/2026
31537
Filippo Valsorda @filippo.abyssdomain.expert · 15/04/2026
If you feel like that deprives you of FIPS 140-3 madness, you might appreciate this new footnote. words.filippo.io/fips-hkdf/#f...
How it works is that FIPS 140-3 is basically an empty pointer that references paywalled ISO/IEC 19790:2012(E). SP 800-140A/B/C/D/E/F modify/replace Annex A/B/C/D/E/F of that standard, because changing an ISO or FIPS standard is too painful. Annex D, replaced by SP 800-140D, are the Approved Generation and Establishment Methods. SP 800-140D Rev. 2, the latest, is an empty pointer to https://csrc.nist.gov/projects/cmvp/sp800-140d, because changing an SP is too painful. This was all supposed to make FIPS 140 easier by making it a modular ISO standard or something. In practice, none of that matters and the actual standard is the Implementation Guidance, because changing the web page is too painful.
2173
Filippo Valsorda @filippo.abyssdomain.expert · 15/04/2026
I had a whole post on "yes, HKDF is FIPS 140-3 compliant, actually" but now NIST just went and added it by name to the list of Approved algorithms with a change comment saying "it was always compliant, yo" (paraphrased), so yay. words.filippo.io/fips-hkdf/
[April 2026 Update] RFC 5869 is now listed in SP 800-140D, the top-level list of official Approved SSP Generation and Establishment Methods for FIPS 140-3 purposes.1 This makes it as a whole just as Approved as SP 800-108 or SP 800-56C.

The CMVP announced its addition with the comment “even though it is technically compliant to SP 800-56C which is already listed” proving it had always been FIPS 140-3 compliant.

The rest of the post is retained for historical purposes (and because if you want to be precise, you still need to figure out how to list it on your certificate), but most of you can stop reading now.
2346
Filippo Valsorda @filippo.abyssdomain.expert · 11/04/2026
Alright, it's official! 💰 @matthewdgreen.bsky.social and I bet on what will break first, ML-KEM-768 or X25519. The loser donates to a 501(c)(3) picked by the winner. If you have an opinion on quantum computers or lattices, you can join with a side bet. Just submit a PR! github.com/FiloSottile/...
The Hybrids Long Bet
ML-KEM-768 vs. X25519

This is a public wager between Matthew Green ("Lattice Cryptanalysis side") and Filippo Valsorda ("Quantum Computers side"). Stakes are settled by charitable donation (see Section 7).

It is motivated by views about the security and deployment relevance of the X25519MLKEM768 hybrid handshake. Notwithstanding that motivation, this wager is not about any hybrid handshake, combiner, or protocol composition. The covered constructions are the separate underlying components defined in Section 1.

🗞️ As reported in The Register.

Deadline. December 31, 2040, 23:59:59 UTC.

Stakes.

Main wager: what breaks first, ML-KEM-768 or X25519? → USD $5,000 donation.
Secondary wager: will ML-KEM-768 weaken significantly? → USD $1,000 donation.
Moral win: Filippo Valsorda buys Matthew Green drinks if ML-KEM-512 weakens.
Back bets.

Anyone can join the bet by choosing a side and stakes for the main and/or secondary wager. If the selected side loses, the back bettor donates the staked amount to the charity chosen by the winner. Back bettors don't select arbiters or charities.

Tip

Do you have an opinion and want to put your money where your mouth is? Do you like raising money for charity through abstruse wagers? Submit a PR and add your name below!
711929
Filippo Valsorda @filippo.abyssdomain.expert · 07/04/2026
Oh hey, with all the 🔥 I almost missed that today was the 12th anniversary of Heartbleed. The online test I cobbled together that night gave me the opportunities to get started in this line of work! Initially it was hilariously bad: a Flask server shelling out to a patched Go crypto/tls binary.
518215
Filippo Valsorda @filippo.abyssdomain.expert · 05/04/2026
I finally chased down test coverage for the last edge cases of ML-DSA's low-level, constant-time field operations like Decompose. This is an accumulated (words.filippo.io/accumulated) test that locks in the output for all possible inputs of all these tricky functions. go.dev/cl/762940
2251
Filippo Valsorda @filippo.abyssdomain.expert · 04/04/2026
They also added an allowlist of all Homebrew packages, interesting. I am kinda tempted to try developing a lockdown policy, but man Santa looks janky.
220
Filippo Valsorda @filippo.abyssdomain.expert · 04/04/2026
There are some interesting patterns, but the main one is that Let's Encrypt is the only CA that evenly spreads load. Other CAs are mostly using older logs, or their own logs and Google's. (Of course, LE is 50% of issuance, and GTS is 25%, so the rest don't matter much.)
1112
Filippo Valsorda @filippo.abyssdomain.expert · 04/04/2026
There was no good way to see what CT logs are actually used by CAs, so I made a dashboard of @censys.bsky.social data on @exe.dev. groups.google.com/a/chromium.o...
1445
Filippo Valsorda @filippo.abyssdomain.expert · 29/03/2026
Some personal/protocol news! Looking forward to helping make PLC the trustworthy and auditable bedrock of identity on atproto. Catch me, @wseltzer.bsky.social, or @bnewbold.net at #AtmosphereConf if you want to chat! We’re still getting started but want to be transparent even in the early stages.
Public Ledger of Credentials Organization has been founded as a Swiss association Initial board
Bryan Newbold
Richard Barnes
Wendy Seltzer
Filippo Valsorda
Thyla van der Merwe
88916
Filippo Valsorda @filippo.abyssdomain.expert · 26/03/2026
I’m at #AtmosphereConf, look for me in the teddy bear sweater and say hi! If you’re not at the conference, consider muting this thread 😅
4240
Filippo Valsorda @filippo.abyssdomain.expert · 20/03/2026
So uh, apparently $288/year is not enough to run a Mastodon service for ~3 users, and this is a known issue (masto.host/mastodon-con...) with no solution (github.com/mastodon/mas...!
1520720
Filippo Valsorda @filippo.abyssdomain.expert · 13/03/2026
They sell entropy sources at FamilyMart in Taiwan in convenient 51-bit packages!
A small plastic box with 20 six side plastic dice. In the background a Family Mart
61669
Filippo Valsorda @filippo.abyssdomain.expert · 08/03/2026
Dustin Moody from NIST: “you don’t need more than 128 bits of symmetric keys for post-quantum security” #rwc2026 Say it louder, for the people in the back!
26614
Filippo Valsorda @filippo.abyssdomain.expert · 16/02/2026
Frog and Toad with a box illustration. Badly edited text.

Frog put the KEY in a box. "There," he said. "Now we will not SIGN MALICIOUS MESSAGES."
"But we can ASK THE HSM," said Toad.
"That is true," said Frog.
124935
Filippo Valsorda @filippo.abyssdomain.expert · 13/02/2026
So, I hope it goes without saying for almost everyone, but don't do shit like this. The first issue mentioning a fork was totally fair, spamming every thread in the issue tracker without permission from the maintainer is not.
13 email notifications of comments on GitHub issues for the same project, all mentioning a community fork.
2312
Filippo Valsorda @filippo.abyssdomain.expert · 12/02/2026
Here's a little demo of our new pkg.geomys.dev code viewer for Go modules! Install the (minimal-permissions) extension from chromewebstore.google.com/detail/pkgge... or addons.mozilla.org/en-US/firefo... to link directly to it from pkg.go.dev.
1250
Filippo Valsorda @filippo.abyssdomain.expert · 07/02/2026
Had Claude replace the bsky embed with simple server-rendered boxes and I like the result a lot better! github.com/FiloSottile/...
030
Filippo Valsorda @filippo.abyssdomain.expert · 06/02/2026
Just had the next Geomys CT log hw delivered, this one to be racked in an EU DC. This means my home office now has an Ampere Altra 64-core NAS with 96 TB HDD, a Dell PowerEdge R6515, a Milk-V Jupiter RISC-V 64-bit, redundant fiber, a Turris Omnia, a USB Armory, and an Enigma replica. And a MacBook.
7763
Filippo Valsorda @filippo.abyssdomain.expert · 30/01/2026
I just bought a whole new server for the Geomys transparency services (CT log, tlog witness with SLA, more soon) using “PayPal Check out” and for some reason it was extremely funny to me.
Paypal check out button. Below it, Dell PowerEdge R6515 Server, €6,992.47
3201
Filippo Valsorda @filippo.abyssdomain.expert · 29/01/2026
Everybody asking for ML-DSA in Go:
no throw only fetch dog meme:
ML-DSA ETA
NO REQUIREMENTS DETAILS
ONLY ETA
1165
Filippo Valsorda @filippo.abyssdomain.expert · 26/01/2026
Because not using AI tools for what they excel at produces less secure code. For example, they are great at debugging (words.filippo.io/claude-debug...), they can find real issues in code review, they know more math than me, and they can write static analyzers I would have never had the time for.
A Mastodon post from a redacted account quoting my post about Go AGENTS.md lines, saying:

> aaaaaaaaaaaaaaaaaaaaa, why is age-encryption guy doing AI
2916
Filippo Valsorda @filippo.abyssdomain.expert · 26/01/2026
Here are three lines from my AGENTS.md that make agents a lot better with Go. Go has great CLI tools, but many people don't know about them, and so agents are not trained to reach for them. Maybe the Go project should maintain a Go development skill?
- To see source files from a dependency, or to answer questions
  about a dependency, run `go mod download -json MODULE` and use
  the returned `Dir` path to read the files.

- Use `go doc foo.Bar` or `go doc -all foo` to read documentation
  for packages, types, functions, etc.

- Use `go run .` or `go run ./cmd/foo` instead of `go build` to
  run programs, to avoid leaving behind build artifacts.
51054
Filippo Valsorda @filippo.abyssdomain.expert · 25/01/2026
This is beautifully done! Here's a uv one-liner, in case it's useful. uv run --with 'maptoposter@https://git.olaren.dev/Olaren/maptoposter.git' python -m maptoposter --help
1432