Sign in

Filippo Valsorda

@filippo.abyssdomain.expert
2 followers 0 following 149 posts

@geomys.org founder / RC F'13, F2'17 Cryptogopher / Go cryptography maintainer filippo.io / github.com/FiloSottile mkcert.dev / age-encryption.org sunlight.dev / filippo.io/newsletter

PostsRepliesMedia
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
↪ Replying to @quillmatiq.com
Registered directly on @eurosky.social, to use the @standard.site lexicon via @leaflet.pub! ✨ atproto ✨
200
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
It's the former, and yes I read it as PLC red all the time 😅
000
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
🏍️🦋
@iame.li@iame.li
Deep @filippo.abyssdomain.expert x Bluesky lore in the PLC announcement Excited for the scene in the atproto movie where Filippo buys @pfrazee.com a nice motorcycle for some reason
000
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
I'm really looking forward to getting the org to a place where it can provide a reliable, sustainable, and accountable service for all atproto applications out there (and maybe beyond). Also, very happy about the company I get to do this with!
Richard Barnes is a security researcher and protocol engineer who helped co-found Let's Encrypt and led security teams at Mozilla and Cisco.

Thyla van der Merwe is a cryptography and formal verification lead at Google who has contributed to cryptography standards at ISO and the IETF, particularly TLS 1.3. 

Bryan Newbold (@bnewbold.net) is a protocol engineer at Bluesky Social PBC and contributor to the atproto working group at the IETF.

Wendy Seltzer (@wseltzer.bsky.social) is a lawyer and technologist who has worked with Internet governance and open standards at W3C, IETF, and ICANN. 

Filippo Valsorda (@filippo.abyssdomain.expert), is a cryptography engineer, open source maintainer, and operator of other append-only-shaped critical Internet infrastructure. In the interest of full disclosure, he is a tiny3 investor in Bluesky Social PBC.
000
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
I'm excited to announce that the PLC Organization now has a statute! And a bank account! And a @standard.site publication! All the important stuff. The PLC Org is an independent Swiss Association meant to operate the PLC directory, which collects and distributes signed updates to atproto accounts.
blog.plcred.org
First steps of the PLC organization - Public Ledger of Credentials Organization
One year ago, Bluesky Social PBC announced their intention to facilitate the creation of an independent organization to operate the Public Ledger of Credenti…
200
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
“Tech is inherently political” is not just about ideology, but about power, too. Yielding technological improvements to the adversary will have predictable outcomes. I’m really worried it will lock in power centralization in a way that will be impossibly hard to reverse. It’s already happening.
000
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
The thing that worries me most lately is that many people who know that “fascism is bad, actually” have also convinced themselves that AI tools must be eschewed as fake or impure. In a self-reinforcing loop, there is relatively little AI tooling and infra by “fascism is bad” folks.
200
Filippo Valsorda @filippo.abyssdomain.expert · 24/09/2026
filippo.io/mldsa@v1.0.0 is now updated to the Go 1.27 implementation and API. It's also now a transparent wrapper on Go 1.27+ using type aliases, so the same program can use it alongside crypto/mldsa without issues. Essentially, it's a drop-in compatibility replacement for crypto/mldsa.
000
Filippo Valsorda @filippo.abyssdomain.expert · 17/09/2026
We got paged the other night, so now I know a lot more about ZFS internals than I ever thought I would. groups.google.com/a/chromium.o...
groups.google.com
Tuscolo2026h2 write-path degradation on August 9th
000
Filippo Valsorda @filippo.abyssdomain.expert · 13/09/2026
One or two of the math/big ones would have been vulns, but we finished moving math/big out of crypto a couple years ago! 🏁
000
Filippo Valsorda @filippo.abyssdomain.expert · 13/09/2026
Triaged a large batch of issues found by a zkao.io scan. Some good bugs, but no vulnerabilities. (LLMs are especially bad at telling those apart.) LLMs found zero (0) vulnerabilities above SEV:LOW in Go crypto so far 💁‍♂️ 💅
a long list of freshly filed issues:
#81502 crypto/x509: clarify VerifyOptions.CertificatePolicies semantics
#81501 crypto/tls: document custom RSA decrypter requirements for key exchange
#81500 crypto/x509: document duplicate handling in CertPool.AddCertWithConstraint
#81499 crypto/x509: reject unsupported bounds in critical name constraints
#81498 crypto/rsa: VerifyPSS accepts salts longer than the hash in FIPS-only mode
#81497 crypto/tls: repeated ech_outer_extensions placeholders bypass reference ordering checks
#81496 crypto/tls: RSA key exchange accepts ciphertexts shorter than the modulus
#81495 crypto/tls: decodeInnerClientHello discards trailing ech_outer_extensions data
#81494 crypto/tls: final ServerHello can accept ECH after HelloRetryRequest rejected it
#81493 crypto/tls: parseECHExt accepts trailing data in outer ECH extensions
#81492 math/rand: NewZipf accepts non-finite parameters that prevent Uint64 from returning
#81491 math/big: ProbablyPrime skips Miller–Rabin rounds when n is MaxInt
#81490 math/big: Int.GobDecode accepts negative zero that can panic in arithmetic
#81489 math: Jn and Yn mishandle extreme orders
#81488 math/rand/v2: ChaCha8.UnmarshalBinary panics on an overlong read buffer
#81487 math/big: ProbablyPrime panics when the Lucas parameter search exceeds its bound
200
Filippo Valsorda @filippo.abyssdomain.expert · 11/09/2026
Oh damn I had not seen the details of the MicroTik RCE: the client can send a public RSA key with correct N and e = 1 and the server will use it. Two primitives/protocol things that would have prevented it: if RSA was defined with a fixed e, and if SSH clients sent a key hash instead.
github.com
CVE-2026-67276 - GitHub Advisory Database
RouterOS does not compare the complete RSA public key...
000
Filippo Valsorda @filippo.abyssdomain.expert · 10/09/2026
What's the point if GitHub has unsandboxed RCEs, Hugging Face has unsandboxed RCEs, Forgejo has unsandboxed RCEs... Anyway, we gotta stop shelling out to git in security contexts.
Forgejo v16.0.4
Release notes
Security bug fixes
PR: Critical: fix: prevent template expansion from interfering with git repo initialization. When generating a new repository from a template repository, Forgejo clones the template repository, removes the .git folder, performs variable template expansion on files listed in .forgejo/template, and initializes a new git repository. During this process, variable template expansion could be misused in order to create a new .git folder, which git would adopt and incorporate during its initialization of a new git repository. A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack. To address this issue, after variable expansion is completed, any existing .git folder is removed from the directory before the git repository is initialized.
000
Filippo Valsorda @filippo.abyssdomain.expert · 09/09/2026
19% of all WebPKI certificates issued yesterday included an SCT from the Geomys Tuscolo Certificate Transparency log 🤯
sctdata.geomys.org
CT Log Usage Dashboard
Measured by counting embedded SCTs in trusted leaf certificates, using Censys data.
000
Filippo Valsorda @filippo.abyssdomain.expert · 06/09/2026
Oh hey, actually, before I log off, real quick: do you have an artist you like to recommend for a logo of a project? Ideally someone in the atproto community. Self-recommendations welcome!
400
Filippo Valsorda @filippo.abyssdomain.expert · 06/09/2026
I am going write-only on social media for a bit. I'm ok! It's just not doing me or the world much good to scroll right now, and I have a mountain of really cool stuff to do. Anyway, if you see my posts with interactions restricted, this is why. You can reach me via email, Slack, or Signal.
leaflet.pub
A social media hiatus
I am taking a hiatus from consuming social media. Not sure for how long. Maybe a month (so until early October 2026)? We'll see how it goes. I will keep pos…
11261
Filippo Valsorda @filippo.abyssdomain.expert · 05/09/2026
It doesn’t open the door to anything if it’s statically unreachable. If some contexts decide to self-inflict technicality unjustified requirements, sounds like their problem.
000
Filippo Valsorda @filippo.abyssdomain.expert · 05/09/2026
I prefer issues over PRs, and this is not an AI issue.
000
Filippo Valsorda @filippo.abyssdomain.expert · 05/09/2026
The issue tracker is open, so it’s not unreasonable to open an issue per se.
000
Filippo Valsorda @filippo.abyssdomain.expert · 05/09/2026
Again and again, demanding work from dozens or hundreds or thousands of unaffected dependents instead of fixing vulnerability scanners does not scale, and is an open source sustainability issue. github.com/FiloSottile/... (do NOT dogpile on the reporter, call your vuln scanner vendor instead)
"I wake up" cat cycle meme, the cat is an open source maintainer, the pattern is

"I get asked to update a dep
to fix a vuln I'm not affected by
because someone's vuln scanner sucks"
000
Filippo Valsorda @filippo.abyssdomain.expert · 03/09/2026
Preach.
000
Filippo Valsorda @filippo.abyssdomain.expert · 31/08/2026
I am getting a lot of "why should we improve something, it's the scrapers who should stop!" I mean, sure? But the scrapers will not listen to me, or you. Like any kind of abuse, we can only talk about how to handle it, and my point is that "just serve the traffic" can be doable at these volumes.
000
Filippo Valsorda @filippo.abyssdomain.expert · 31/08/2026
I love absolutely everything about vulnbrocards.com by @yossarian.net. I actually hope these become widely recognized references. blog.yossarian.net/2026/04/11/B...
blog.yossarian.net
Brocards for vulnerability triage
000
Filippo Valsorda @filippo.abyssdomain.expert · 30/08/2026
hi, yes
000
Filippo Valsorda @filippo.abyssdomain.expert · 30/08/2026
Alright, filippo.io/mlockexe now exists. mlockexe.OnFault() will prevent thrashing of the executable's pages under memory pressure.
filippo.io
mlockexe package - filippo.io/mlockexe - Go Packages
Filippo Valsorda@filippo.abyssdomain.expert
Tempted to make a package that mlock(MLOCK_ONFAULT)s the executable pages, so they can't be paged out, which is almost never what you want. Unfortunately systemd's default LimitMEMLOCK is 8MB.
000
Filippo Valsorda @filippo.abyssdomain.expert · 30/08/2026
Tempted to make a package that mlock(MLOCK_ONFAULT)s the executable pages, so they can't be paged out, which is almost never what you want. Unfortunately systemd's default LimitMEMLOCK is 8MB.
000
Filippo Valsorda @filippo.abyssdomain.expert · 30/08/2026
TIL that under memory pressure Linux will evict .text, and then thrash for a couple minutes or more, reading it back thousands of times, before hitting the OOM killer. For 60MB of executable out of 8GB of memory (0.75%). That's objectively silly.
400
Filippo Valsorda @filippo.abyssdomain.expert · 29/08/2026
Since apparently scrapers are crawling years-old repositories, making a one-time index sounds very doable. Totally understood it's work, but it used to be 1-4 weeks and it's now 1-2 days, plus convincing people to deploy an maintenance, which I know is not zero. Still feels worth it.
000
Filippo Valsorda @filippo.abyssdomain.expert · 29/08/2026
Someone should definitely make an anonymous cgit renderer that's up to 2010s qps standards, though, agreed. It's actually a very LLM friendly job, because you can even target HTML byte-equivalence on—ironically—a large example dataset.
000
Filippo Valsorda @filippo.abyssdomain.expert · 29/08/2026
> the scrapers are evil and stupid (and most of them are!) I get where you're coming from, but I think it makes sense for me to keep sending patches where I'm sending them (e.g. avoiding 10x cost jumps on PQ handshakes), but that doesn't make my observation wrong.
200
Filippo Valsorda @filippo.abyssdomain.expert · 29/08/2026
I am only 20% shitposting when I say: thankfully we have LLMs that are very good at performance optimizations.
000
Filippo Valsorda @filippo.abyssdomain.expert · 29/08/2026
I know it's unpopular to say because the scrapers are evil and stupid (and most of them are!) but I can't get over how small the numbers are in all of these posts. 18M/day is 200 qps, and there isn't even a bandwidth cost argument. Those are Raspberry Pi numbers. people.kernel.org/monsieuricon...
200
Filippo Valsorda @filippo.abyssdomain.expert · 29/08/2026
I used to be very good at playing the negotiation game, on behalf of myself and others. Times have changed, and I've probably lost the pulse, but a big part is understanding what game the other side is playing. This is a good post to read for early- and mid-career folks: lobste.rs/s/mroowi/bei...
000
Filippo Valsorda @filippo.abyssdomain.expert · 28/08/2026
Sure! It's not a comprehensive battery of tests, though, just a specific profile. I think you can get access to the FIDO2 compliance test suite if you ask.
000
Filippo Valsorda @filippo.abyssdomain.expert · 28/08/2026
Define bench test?
000
Filippo Valsorda @filippo.abyssdomain.expert · 28/08/2026
If it’s through the OS instead of intercepting the JS API through the browser extension (ugh), then yeah!
000
Filippo Valsorda @filippo.abyssdomain.expert · 28/08/2026
Thank you both! Looks like I have almost all the boxes ticked, except a 3rd party authenticator that uses the platform API. @vcsjones.dev you have one session that says Windows Hello with Apple Passwords but it's only a registration and it has a Windows Hello AAGUID.
000
Filippo Valsorda @filippo.abyssdomain.expert · 27/08/2026
What are the equivalents of the cigarette smoke and hijackings?
000
Filippo Valsorda @filippo.abyssdomain.expert · 27/08/2026
Yup. I have a giant note of parser alignment issues across many protocols to one day write this post.
000
Filippo Valsorda @filippo.abyssdomain.expert · 26/08/2026
Uuuuh, neat! Would it be easy enough to add 32 bytes of WireGuard PSK and get some degree of post-quantum protection, since these are already secret tokens? I am growing uncomfortable with Tailscale's lack of harvest-now-decrypt-later protection against QCs.
000
Filippo Valsorda @filippo.abyssdomain.expert · 26/08/2026
Yep!
000
Filippo Valsorda @filippo.abyssdomain.expert · 26/08/2026
Ok, I think the ML-DSA performance side quest might be complete 🏎️ Very proud of how safe and clear the final incremental changes are, too.
A table of improvements in ML-DSA benchmarks showing progressively better delta all the way to -40% overall
000
Filippo Valsorda @filippo.abyssdomain.expert · 25/08/2026
I am so happy we can now divinate precise diagrams in minutes to help reason through complicated code. (This is the "butterfly" of the Number Theoretic Transform of ML-DSA. It's faster not to reduce non-overflowing intermediates, but I had to convince myself that they do not, in fact, overflow.)
A wire diagram with rows and cells and a zoomed out detail that shows how to get to outputs from inputs and the relationships of the bounds.
000
Filippo Valsorda @filippo.abyssdomain.expert · 24/08/2026
No, AFAICT Linux could fix this, although I suspect it would require coordination with the file systems, which might end up looking like O_DIRECT support.
000
Filippo Valsorda @filippo.abyssdomain.expert · 24/08/2026
I remember trying to go down that path, too, and finding it not as simple as I hoped.
000
Filippo Valsorda @filippo.abyssdomain.expert · 24/08/2026
Pretty much! Use ZFS.
000
Filippo Valsorda @filippo.abyssdomain.expert · 24/08/2026
I remember considering O_DIRECT for Sunlight recovery and concluding it was a massive pain and not really an interface that wanted to be used. ZFS just makes the dataset read only, the one sane answer.
000
Filippo Valsorda @filippo.abyssdomain.expert · 24/08/2026
I’m not sure that’s defined behavior without O_DIRECT, no! It could noop against the matching clean cached page.
000
Filippo Valsorda @filippo.abyssdomain.expert · 23/08/2026
The two valid answers for fsync() errors are hard rebooting the machine or just using ZFS.
000
Filippo Valsorda @filippo.abyssdomain.expert · 21/08/2026
ML-KEM and ML-DSA fill matrices/vectors with output from SHAKE, each element derived from slightly different inputs. This is perfect for SIMD instructions, so now we have func ReadMulti(s []*SHAKE, out [][]byte) backed by AVX2 on amd64, and by the existing two-lane asm on arm64. go.dev/cl/818720


benchmark \ host    linux-amd64_c2s16  linux-arm64_c4as16
                              vs base             vs base

RoundTrip/Alice               -10.86%              -5.23%
RoundTrip/Bob                 -14.10%              -5.53%

Sign/ML-DSA-44                 -4.39%              -0.69%
Sign/ML-DSA-65                 -3.15%              -0.49%
Sign/ML-DSA-87                 -3.78%              -0.62%
Verify/ML-DSA-44              -18.07%              -6.05%
Verify/ML-DSA-65              -21.12%              -7.15%
Verify/ML-DSA-87              -25.42%              -8.20%
Keygen/ML-DSA-44              -12.85%              -4.68%
Keygen/ML-DSA-65              -14.66%              -5.49%
Keygen/ML-DSA-87              -20.41%              -6.79%
000