Reposted by Simone RagusaSoatok, the Furbidden One @soatok.bsky.social · 22/07/2026I feel like if you get the title of Distinguished Engineer as a cryptographer, something has gone horribly wrong. #INDCCA 1213
Reposted by Simone RagusaRuss Cox @swtch.com · 30/05/2026“But it happened” is definitely worth more attention. youtu.be/tlQ7EoJDTQY?...youtu.be"But it happened."YouTube video by Molly Rocket 310136
Reposted by Simone RagusaFilippo Valsorda @filippo.abyssdomain.expert · 28/04/2026A bit over two years after starting to work on it... Go is officially FIPS 140-3 certified 💥 csrc.nist.gov/projects/cry... I am pretty confident Go is now one of the most—if not the most—seamless and complete FIPS 140-3 compliance solutions... with a single env var, out of the box. 928962
Reposted by Simone RagusaFilippo Valsorda @filippo.abyssdomain.expert · 06/04/2026Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years. That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.words.filippo.ioA Cryptography Engineer’s Perspective on Quantum Computing TimelinesThe risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately. 11303123
Reposted by Simone RagusaFilippo Valsorda @filippo.abyssdomain.expert · 27/12/2025💥💥💥💥💥 age v1.3.0 💥💥💥💥💥 Post-quantum keys, seeking DecryptReaderAt API, age-inspect CLI tool, built-in recipients compatible with hardware plugins, non-interactive passphrase input, Go framework for implementing plugins, and sooooo many improved errors. Six years to the day after the first beta!github.comage v1.3.0: post-quantum (and more)!Exactly six years after the first age beta release, v1.3.0 brings post-quantum resistance to age, along with a couple long-requested features, built-in support for recipients compatible with hardwa... 415329
Reposted by Simone RagusaFilippo Valsorda @filippo.abyssdomain.expert · 19/12/2025Using an age keyserver as a demo, this article demonstrates how to add a transparency log to a centralized service step-by-step. We use Tessera for the tlog, VRFs for privacy, and the Witness Network. It all takes just 500 lines to integrate! The result of years of work making tlogs accessible.words.filippo.ioBuilding a Transparent KeyserverWe apply a transparency log to a centralized keyserver step-by-step, in less than 500 lines, with privacy protections, anti-poisoning, and witness cosigning. 26117
Simone Ragusa @interrato.dev · 17/10/2025One month ago, I earned my master's degree in cybersecurity. Working on my thesis was deeply rewarding, and I received a final grade that exceeded any expectations I had when I began this journey two years ago. Thank you to all the great people who make cryptography open and welcoming to anyone. 250