Sign in

Richard Barnes

@ipv.sx
907 followers 823 following 528 posts

Trying to do right by the world, in part by using computers and cryptography. (🦋 DMs disabled, please use Germ 🦠)

PostsRepliesMedia
Richard Barnes @ipv.sx · 12/08/2026
Also lol "stimulated"
000
Richard Barnes @ipv.sx · 12/08/2026
The good news from a countermeasures perspective is that these things can't shock you through your clothes or hair, only bare skin. Once again, the inflatable frog costume proves effective at neutralizing police weapons. www.complianttechnologies.net/faqs
185
Richard Barnes @ipv.sx · 11/07/2026
I'm not going to resurrect my X account to argue with djb, but in case anyone here cares... Does he not understand that people are using naked ECDH all over the Internet? Why no similar freak out about that? If ECDH+ML-KEM is great, shouldn't we go further? RSA+ECDH+ML-KEM+McEliece here we come!
080
Richard Barnes @ipv.sx · 24/06/2026
Just to pick one starting point, conflating these use cases seems like a terrible idea. Storing my own data is very different (and much simpler!) than any of the others. The middle two are single-owner, which is again quite different from the full complexity of private communities.
130
Richard Barnes @ipv.sx · 18/04/2026
I enjoy Indian food, but I think this new restaurant might not be my top priority to visit.
A mostly built out new restaurant with a sign that says DELHI BELLY
020
Richard Barnes @ipv.sx · 09/02/2026
CBP international arrival stats show international arrivals in Minneapolis (gray line) down 15-20% during the period where ICE has been in town. Worst declines in an already bad year for international visitors. bifurcation.github.io/cbp-awt/
A chart of international arrivals, year on year change in 30-day moving average.  A thick black line shows a national decline of 5-10% over the year.  A thinner gray line shows Minneapolis generally tracking the national trend, until ICE shows up and it drops to 15-20% down (vs. 0-5% nationally).
010
Richard Barnes @ipv.sx · 29/01/2026
Looking at the crosstabs here, it's largely the usual "old rich white men suck" story. More surprising is the 42% Strong Oppose in the Northeast region. I initially thought YouGov was including OH or something, but the Census Bureau defines the region as CT, ME, MA, NH, NJ, NY, PA, RI, VT.
The same YouGov survey results as in the quoted post, but with Strong Oppose results circled in blue from the Male (37%), 65+ (45%), White (39%) and $100K+ (35%).  The Strong Oppose result from the Northeast region (42%) is circled in pink.
000
Richard Barnes @ipv.sx · 19/11/2025
There are several colors not used by the official rubric. Blues, pinks, purples all pretty available.
The official SCOTUS guide to what color binding your brief has to have.
100
Richard Barnes @ipv.sx · 19/11/2025
I feel like if you bound something like this in the format of a Supreme Court brief and left some stacks at coffee shops around DC, they would get around.
Various printed SCOTUS briefs bound in colors that indicate their purpose. White for a certain petition, red for appellee’s merits brief, green for amici, yellow for a merits reply brief, and tan for a motions reply brief.
100
Richard Barnes @ipv.sx · 18/11/2025
Is it just me or are the new Office icons on macOS terrible?
The new PowerPoint "drippy orb" iconThe new Word "why is it swirly" iconThe new Outlook "envelopes don't swirl that way" icon
110
Richard Barnes @ipv.sx · 14/11/2025
There is some interesting variation in here. HNL and EWR seem to buck the trend, while IAD and BWI are doing appreciably worse.
A chart of international arrivals in the US (year on year, 3 month moving average), with separate, lighter lines for EWR and HNL.  While the overall trend is about a 5% decline, EWR and HNL in positive territory.A chart of international arrivals in the US (year on year, 3 month moving average), with separate, lighter lines for IAD and BWI.  While the overall trend is about a 5% decline, IAD and BWI are even more negative.
120
Richard Barnes @ipv.sx · 14/11/2025
6mo update! There are some interesting transients in here, but the overall story seems to be that international arrivals are down about 5% from last year, and trending worse. bifurcation.github.io/cbp-awt/
A chart of international arrivals in the US (year on year, 3 month moving average).  There appears to be a drop and bump in March/April, and a bump in Sept/Oct.  But overall, things are down about 5% and trending downward.
100
Richard Barnes @ipv.sx · 12/11/2025
Unironically yes!
A NeXTcube, a black cube of computing prowess last sold in 1993.
080
Richard Barnes @ipv.sx · 12/11/2025
There is nothing that captures the user-hostility of enterprise software quite so neatly as this prompt. As far as I can tell, it does absolutely nothing. Clicking Yes does not reduce the number of times one has to sign in. I tick the "Never again" box every time, yet it always appears again.
An Office 365 dialogue box: Stay signed in?  With No and Yes buttons, and a "Don't show this again" tick box.  The "Don't show this again" tick box is ticked.
053
Richard Barnes @ipv.sx · 02/11/2025
Principal Skinner: Am I out of touch?  No, it’s the children who are wrong.
010
Richard Barnes @ipv.sx · 28/08/2025
This assertion is a massive red flag. Not rekeying when someone leaves means that the person hasn't really been removed, since the untrusted provider can just forward them messages that they can still decrypt. This should not be an acceptable property for an allegedly E2E-secure system.
Signal’s approach for groups up to 1000 members is pragmatic and effective: all members agree pairwise states for the Double Ratchet algorithm. This way the cost of agreeing keys is “front-loaded” — each new member must agree on a key with each other member before being able to send messages. When a member leaves, no special action is needed, other than notifying all members about it.
141
Richard Barnes @ipv.sx · 28/08/2025
Are large groups a problem? Yes. People love to be performatively cynical about this. But there’s a big difference between “1000 employees and my compliance bot can see this meeting” and “The vendor can hand this to the feds”.
Is End-to-End Encryption in Large Groups a Real Problem?

It depends on the definition of “large”, but we are assuming that “large” is any group where simple member broadcast to update keys is inefficient, so we are talking about many thousands of members.
130
Richard Barnes @ipv.sx · 28/08/2025
The post also seems to assume that the AS is provided by the app provider. If that were true, he would have a point, but it’s not. For example, in Webex, an MLS client can use a certificate from any Web PKI CA. Same approach as in HTTPS, same strong protection from the transport provider.
But without the separation of services on the business level, this separation in design is purely academic rather than practical. Promoting MLS as an effective solution for E2E encryption, without disclosing the requirement for provider trust, is at best misleading, at worst — fraudulent.
110
Richard Barnes @ipv.sx · 28/08/2025
The crux of Evgeny’s argument is that MLS doesn’t solve authentication. Instead, it allows app designers to plug in an “AS” that provides this function. Evgeny says this reduces MLS to the “trust me bro” model of security.
Let’s apply the same reasoning to MLS. Does MLS protect message content from the untrusted provider? One of the components of MLS is the “authentication service” — a component that is supplied by a communication provider. The MLS specification states in part 16.10:

    A compromised Authentication Service (AS) can assert a binding for a signature key and identity pair of its choice, thus allowing impersonation of a given user. This ability is sufficient to allow the AS to join new groups as if it were that user. Depending on the application architecture, it may also be sufficient to allow the compromised AS to join the group as an existing user, for instance, as if it were a new device associated with the same user.

The MLS specification explicitly requires trust in the communication provider as a condition for MLS securing the message content from the untrusted provider, which is self-contradictory — we are required to trust an untrusted party, which contradicts the purpose of E2E encryption.
130
Richard Barnes @ipv.sx · 19/08/2025
Always a good question to ask. I can attest that the founders are great and Germ is a public benefit corp like Bluesky. They’re using the MLS standard instead of rolling their own, and they’ve published a lot of detail about their architecture. And IIUC they’re working on open-sourcing more.
There have been a lot of companies that overpromised on their encryption and security properties. What makes Germ trustworthy?
242
Richard Barnes @ipv.sx · 19/08/2025
TBH I’m not a huge conf guy. I tend to go to more participatory things like IETF. My general advice would be to go where the hallway track is good, and meet good people. I go to Real World Crypto for the good academic/industry overlap, met a bunch of collaborators there.
What are your favorite security conferences?
121
Richard Barnes @ipv.sx · 19/08/2025
It’s new, and I think it’s the wave of the future. “First-wave” secure messengers like Signal and WhatsApp are all strongly tied to single identities with global reachability. There are a couple of other apps trying similar things (I forget the names) but Germ has made it most accessible.
Has Germs multi-identity idea been tried with secure messaging before? What lessons do you seem them learning well from the secure messaging space?
141
Richard Barnes @ipv.sx · 19/08/2025
I’ll go for one of the classics here, the need for products to help users understand what’s going on. As a friend put it, we’ve had thousands of years to understand privacy in real life, where it’s obvious why. We need to build up the “why” and the skills in digital spaces.
Hi Richard, what do you see is the biggest threat we have to digital privacy today?
141
Richard Barnes @ipv.sx · 19/08/2025
Whew, full answer longer than skeet-length. But “proactive” is definitely the answer — Build things that show how encryption keeps people safe (like Germ!). Get involved with activism (EFF, Global Encryption Coalition, etc.). Let your representatives know you care.
How do you envision government policy shaping the future of digital privacy? Is it better to be proactive or reactive?
151
Richard Barnes @ipv.sx · 19/08/2025
Hi! I would say that I work at the intersection of applications, protocols, and cryptography — using cryptography to enable security properties that matter for applications, with protocols as the glue that hold things together.
I have a question! How would you describe your specialty? Protocol engineer? Cryptographic engineer? Something else?
141
Richard Barnes @ipv.sx · 24/07/2025
Apparently @abr.bsky.social is back at the IETF!
Title slide from an IETF presentation, showing the title "ABR in MoQ"
130
Richard Barnes @ipv.sx · 10/07/2025
ORD-DCA in the summer.
Darth Vader telling Boba Fett and Lando, “I have delayed the flight.  Pray I don’t delay it further.”
031
Richard Barnes @ipv.sx · 12/06/2025
Indeed, appears to be down for everyone, not just me. status.anthropic.com
A screenshot from the Anthropic status page, showing a Major Outage for their API server.
100
Richard Barnes @ipv.sx · 12/06/2025
"Claude is down" is the new "my code is compiling"
An error message from Claude Code indicating repeated attempts to connect to the Claude API, all failing with 503 No Healthy Upstream.  The 503 error indicates that the problem is on the server side.
120
Richard Barnes @ipv.sx · 06/06/2025
Strong Bad’s cousin from Brussels
A logo on a shower wall in Norway that says “Euro Bad”
020
Richard Barnes @ipv.sx · 29/05/2025
I feel seen.
A poster at McDonald’s with the tagline “Flaky & Hot” and a picture of an apple pie
030
Richard Barnes @ipv.sx · 22/05/2025
Robot lawn mowers gliding across the lawn outside the office, actually kind of soothing, like watching herd animals graze.
020
Richard Barnes @ipv.sx · 04/05/2025
For Derby night tonight, made Detroit-style pizza from the Serious Eats recipe. So good! Made me think of you @josephhall.org, as the person who introduced me to the style. Also unexpectedly great pairing with Starr Hill Roxanne raspberry sour.
Two thirds of a Detroit-style pizza (the other third having been devoured) on a wooden cutting board.  Showing off its golden rim of crispy cheese and alternating rows of pepperoni and sauce.A twelve-ounce can of Roxanne Raspberry American Sour from Starr Hill brewing in Charlottesville, VA.  A small celadon porcelain elephant sculpture is peeking around the side.
281
Richard Barnes @ipv.sx · 01/05/2025
I saw someone passing around a version of the WaPo charts here, and updated with the latest data. Now 6 weeks after @pbump.com's initial reporting, things are back to normal for the mainland. Data can tell a different story depending on where the series ends!
A chart of non-US passenger arrivals at Miami, Chicago, and Honolulu airports, shown as year-on-year change in 30-day moving average. There is a general downward trend over time. Miami and Chicago show a sharp drop in March, which partly rebounds in early April, then fully by the end of April. Honolulu doesn't seem to drop significantly.
161
Richard Barnes @ipv.sx · 20/04/2025
This argument is also directly out of the Nazi playbook. “This disabled person costs the community 60,000 RM over their lifetime. Fellow citizens, this is your money!” encyclopedia.ushmm.org/images/large...
A poster advertising the NSDAP publication Neues Volk, showing a disabled person with the slogan in the post.
1217
Richard Barnes @ipv.sx · 19/04/2025
And in our era of “Christian” Nationalism, the last of the Solemn Collects hits extra hard.
A passage from the Book of Common Prayer:

Let us pray for all who have not received the Gospel of Christ;

For those who have never heard the word of salvation
For those who have lost their faith
For those hardened by sin or indifference
For the contemptuous and the scornful
For those who are enemies of the cross of Christ and persecutors of his disciples
For those who in the name of Christ have persecuted others

That God will open their hearts to the truth, and lead them to faith and obedience.
000
Richard Barnes @ipv.sx · 16/04/2025
@pbump.com When you published this, I replicated the analysis because I was curious about HNL. Included MIA and ORD as mainland control points. I just updated the chart with the last ~2 weeks of data, and it appears things have actually bounced back by about a third.
A chart of non-US passenger arrivals at Miami, Chicago, and Honolulu airports, shown as year-on-year change in 30-day moving average.  There is a general downward trend over time.  Miami and Chicago show a sharp drop in March, which partly rebounds in early April.  Honolulu doesn't seem to drop significantly.
130
Richard Barnes @ipv.sx · 26/03/2025
I had to look at some code today 😭
That scene from The Matrix where Cypher points to the green code and tells Neo "All I see is blonde, brunette, redhead..." except the code is C and C++ and Cypher says "All I see is UAF, shell injection, buffer overflow..."
060
Richard Barnes @ipv.sx · 24/03/2025
That’s a wrap on #ATmosphereConf! Thanks to @knowtheory.net and @bmann.ca and everyone for a great weekend!
A hand-written name tag for Richard Barnes @ipv.sx
1130
Richard Barnes @ipv.sx · 13/02/2025
See also Dulles International Airport, which seems to have replaced its long-standing rainbow light display with the flag of revolutionary France ca. 1790.
A glass wall that is usually lit with rainbow colors, but which now has three vertical stripes of red, white, and blue.  This was probably intended to be a sign of US patriotism, but turns out to represent a flag used by the French Revolution.
030
Richard Barnes @ipv.sx · 13/02/2025
Might be something to do with this? Which of course is not intended to signify anything to do Gender Ideology or the LGBTQ Agenda, but all rainbows seem to attract hostile attention these days.
The Kennedy Center lit up in rainbow colors, as it is every year around the Kennedy Center Honors, symbolizing "a spectrum of many skills within the performing arts"
130
Richard Barnes @ipv.sx · 26/09/2024
I support notions of sociability that include punching people until they do what you want. www.nbcnews.com/science/scie...
A screenshot of text from the article, reading as follows:

Octopuses would also punch fish to keep the group moving.

“If the group is very still and everyone is around the octopus, it starts punching, but if the group is moving along the habitat, this means they’re looking for prey, so the octopus is happy. It doesn’t punch anyone,” Sampson said.
030
Richard Barnes @ipv.sx · 18/09/2024
Doing so well as a humble engineer, I do kinda wonder what the statistics are across the Bluesky population.
The results of an online quiz showing that I know 30,399 English words, putting me in the top 0.01%
010
Richard Barnes @ipv.sx · 17/09/2024
𐎨 𐎣𐎮𐎭'𐏂 𐎪𐎭𐎮𐎼 𐎼𐎧𐎠𐏂 𐎨 𐎤𐏍𐎯𐎤𐎢𐏂𐎤𐎣
A screenshot from Arrested Development of Michael Bluth saying "I don't know what I expected", which is transliterated into cuneiform in the post.
131
Richard Barnes @ipv.sx · 17/09/2024
I’m such a Certified Elder that I needed help finding the right thing to click on to get this. Thanks @abr.bsky.social
Richard Barnes was the 35,774th user on Bluesky — a Certified Elder!
240
Richard Barnes @ipv.sx · 01/09/2024
A screenshot of Google Maps showing the Arlington Cemetery metro stop and a road with the cemetery labeled “Arlington Cemetery”
010
Richard Barnes @ipv.sx · 17/08/2024
Amen, me too! Great job!
A selfie showing Richard at the end of his long run, with Independence Ave and the very top of the Capitol dome in the backgroundA Strava map showing a running route from Rosslyn, across the National Mall, along the Wharf and Anacostia Park, then up Pennsylvania Ave to finish.  9.3 miles overall, at a pace of 9:46 per mile.
111
Richard Barnes @ipv.sx · 07/06/2024
@riana.bsky.social with the raw 🔥 truth on Microsoft Recall. Everything about this feature reeks of bad incentives and irresponsible decisions. duo.com/decipher/aft...
A screenshot from the Decipher column quoting Riana:

Will the company use dark patterns to get people to opt-in without fully understanding that they’re doing so? Will employers who want to surveil their employees’ every move - because let’s be honest, that’s the only real use case for this idea - get to turn this on for their employees? What about domestic abusers who could force their victims (such as a spouse or child) to turn this feature on? There is simply no good reason for this feature; nobody was asking for it, and the non-creepy use cases (such as finding a recipe you think you looked at once) are too minor to justify the creepy ones. It should be killed entirely.
085
Richard Barnes @ipv.sx · 28/05/2024
90s kids remember.
A screenshot of the Wikipedia entry for the Pentium FDIV bug.  The text "1 in 9 billion" is highlighted, reflecting the extraordinarily low error rate that was considered unacceptable in 1994.
000
Richard Barnes @ipv.sx · 28/05/2024
AGI has arrived!
The title and abstract of a paper from the arXiv.  The title is "Transformers Can Do Arithmetic with the Right Embeddings".  In the abstract, the following text is highlighted "we can reach state-of-the-art performance, achieving up to 99% accuracy on 100 digit addition problems"
100