Sign in

Joe Birr-Pixton

@jbp.io
184 followers 162 following 104 posts

computers, computer security, cryptography. rather dull really. locale: cambridge, uk github: github.com/ctz & github.com/rustls

PostsRepliesMedia
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 09/09/2026
rustls, our modern memory-safe TLS implementation is 10 years old! @jbp.io wrote a blog post reflecting on how we got here: rustls.dev/blog/2026-09...
rustls.dev
rustls: A Decade of Rustls
2548
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 13/08/2026
Happy to announce a new project: OxiSH, a modern, memory-safe SSH server. dirkjan.ochtman.nl/writing/2026... Prossimo has three criteria for suggesting memory-safe rewrites: (1) widely used, (2) on a security boundary and (3) performing a critical function. This is clearly true for SSH servers.
dirkjan.ochtman.nl
OxiSH: a modern, memory-safe SSH server – Dirkjan Ochtman
26714
Reposted by Joe Birr-Pixton
eliza🌻 @elizas.website · 07/08/2026
with times being what they are, it seems like you basically can't have a public open source repo without receiving LLM-written PRs. thus, after a great deal of thought, i have adopted the somewhat idiosyncratic Mycelium AI Policy in my personal projects: github.com/hawkw/myceli...
github.com
chore: introducing the Mycelium AI Policy (#566) · hawkw/mycelium@b77e854
2635546
Reposted by Joe Birr-Pixton
RustConf @rustconf.com · 26/07/2026
🎂 Ten years of Rustls. At #rustconf2026, Rustls project founder Joe Birr-Pixton and open source maintainer Daniel McCarney look back on a decade building a memory-safe TLS library trusted across the industry. View on schedule: sched.co/2KHyL Register: bit.ly/45kJb9Y
0112
Reposted by Joe Birr-Pixton
RustConf @rustconf.com · 22/07/2026
📢 Session: "A Decade of Rustls": update from maintainers @jbp.io & Daniel McCarney at #rustconf! 10 years in, what's next for one of Rust's most widely used TLS libs? 🎟️: rustconf.com/register?utm_source=rustconf_x&utm_medium=social&utm_campaign=week_july20 rustconf2026.sched.com/event/2KHyL/...
093
Joe Birr-Pixton @jbp.io · 02/07/2026
Pleased to announce a new network transport security protocol: "TSL" (Transport Security Layer). Suspiciously wire compatible with TLS, but obviously unrelated. Future standardisation efforts will happen outside the IETF, and contributions made with the aesthetic of american politics are banned
2120
Reposted by Joe Birr-Pixton
da share z0ne @dasharez0ne.bsky.social · 27/02/2026
TRANS RIGHT'S ARE HUMAN RIGHT'S - dashare.zone ADMIN
A SKLETON HOLDIN UP A FINGER TO POLITICANS AND THE PEACES OF SHIT WHO WANT TO WRECK EVERYONES LIFES, IF SOME OF US ARE NOT FREE THEN NONE OF US ARE FREE, THE POLITICANS AND BILLIONAIRES WHO RUN THE COUNTRY MEET ON A SECRET ISLAND TO BREED SEX SLAVES BUT THEY WANNA TELL US THAT WE SHOULD BE SCARED OF SOMEONE TAKEN A SHIT IN A PUBLIC BATHROOM, OR MAD AT SOMEONE FOR HAVIN A DRIVERS LICENSE, FASHISM AINT CREEPIN ANY MORE ITS JOGGING, THEY BETTER GET THERE BIG ASS BUNKERS BUILT QUICK CAUSE THERE FULL OF MEAT AND WE GROW HUNGRIER BY THE DAY - DASHARE.ZONE ADMIN
02542935
Joe Birr-Pixton @jbp.io · 25/06/2026
I released Graviola 0.4.1 yesterday, which improves ML-KEM-768 performance via the parallel SHAKE strategy -- compared to mlkem-native as included in aws-lc it is now 30% quicker on aarch64 and 8% quicker on x86-64 for combined keygen+encaps+decaps.
1120
Joe Birr-Pixton @jbp.io · 18/06/2026
I released Graviola 0.4.0 yesterday, with a new and quite quick ML-KEM-768 implementation. More perf work to do on this, but it is already quicker than libcrux-ml-kem, and competitive with mlkem-native on ARM64. And still builds mega fast! Consider supporting this work on github.com/sponsors/ctz
1235
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 10/06/2026
The recording of our talk at @canonicalltd.bsky.social's #UbuntuSummit is available now: www.youtube.com/watch?v=qKmR... Happy to answer questions here!
youtube.com
uPKI: improving certificate revocation on Linux | Ubuntu Summit 26.04
YouTube video by Canonical Ubuntu
062
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 27/05/2026
@jbp.io and I will be presenting on our upki project to make TLS certificate verification more secure for non-browser Linux apps.
0193
Joe Birr-Pixton @jbp.io · 18/05/2026
"No way to prevent this" says only cryptographic API where this regularly happens - barghest.asia/blog/cve-202... (previously jbp.io/2014/01/16/o... )
barghest.asia
CVE-2026-0073 Android adbd TLS client-authentication bypass
BARGHEST analysis of CVE-2026-0073, an Android adbd ADB-over-TCP authentication bypass enabling no-interaction RCE through cross-algorithm TLS certificate comparison.
030
Joe Birr-Pixton @jbp.io · 01/05/2026
At #rustweek I'll have new stickers celebrating a decade of rustls. First commit was ten years ago tomorrow
A stack of holographic stickers for the rustls TLS library
2322
Joe Birr-Pixton @jbp.io · 22/04/2026
youtu.be/rgZlzCd0DUU?... I guess this means I'm a tech influencer now? Thanks @frame.work
youtu.be
Framework [Next Gen] Event | 2026 Launch Event
YouTube video by Framework
131
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 10/04/2026
An update on rustls performance: it’s still pretty fast. www.memorysafety.org/blog/26q1-ru...
memorysafety.org
Q1 2026 Rustls Performance Update
Overview Offering top tier performance is a primary goal for the Rustls project. As such, the project has developed benchmarks representing some of the most performance critical functions and monitors them closely. The Rustls project periodically publishes test results that compare Rustls performance to other popular TLS libraries, OpenSSL and BoringSSL. The previously published test results are from July of 2025. The Rustls project is planning to start publishing performance reports more frequently going forward.
0236
Reposted by Joe Birr-Pixton
tef @tef.bsky.social · 30/03/2026
keep hearing "PULL UP" "PULL UP" and "TERRAIN, TERRAIN" but i'm pretty sure there's nothing to worry about
34910
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 13/03/2026
I wrote a blog post for the Alpha Omega Foundation on the work I did to surface RustSec advisories on crates.io: alpha-omega.dev/blog/surfaci...
crates.io
crates.io: Rust Package Registry
0122
Joe Birr-Pixton @jbp.io · 11/03/2026
github (2026, oil on canvas)
0170
Reposted by Joe Birr-Pixton
Deirdre Connolly¹ ² @durumcrustulum.com · 11/03/2026
Merkle Tree Certs! #realworldcrypto
141
Reposted by Joe Birr-Pixton
Thomas Ptacek @sockpuppet.org · 28/02/2026
None of you are giving me enough credit for not participating on the TLS working group mailing list. You're welcome. Everything I don't do, I don't do it for you.
2262
Joe Birr-Pixton @jbp.io · 24/02/2026
"If we publish this, suddenly people will start taking the cryptography opinions of the TLSWG very seriously. This would definitely happen thanks of the decades of demonstrated good decision making."
000
Reposted by Joe Birr-Pixton
tef @tef.bsky.social · 18/01/2026
if anything, i've found that the quality of his posts have gone down over time, i call this "doctorowification"
17410
Joe Birr-Pixton @jbp.io · 16/02/2026
One of the things I've been working on recently.
070
Joe Birr-Pixton @jbp.io · 08/02/2026
rust `use` statements are a conspiracy by big merge conflict to sell more conflicts
190
Joe Birr-Pixton @jbp.io · 06/02/2026
Life of a town councillor
Reporting a dead badger as a fly tipping incident
110
Reposted by Joe Birr-Pixton
Winnie the Pooh (Official) @indianawalsh.bsky.social · 19/01/2026
Gary Larson: In my cartoon I invented Cow Tools as a cautionary tale Cows: At long last, we have created the Cow Tools from classic newspaper comic Cow Tools
77140064011
Reposted by Joe Birr-Pixton
Filippo Valsorda @filippo.abyssdomain.expert · 09/01/2026
Here are some statistics (estimated via Poisson inference on the observed hit counts): Keys generated: 2^34.5 (95% CI: 2^33.6–2^35.0) Core-years: 56.7 (95% CI: 30.7–82.6) Average cores: ~5,200 (95% CI: 2,800–7,500) This is a lot, folks! Really grateful for this level of community support.
0202
Joe Birr-Pixton @jbp.io · 01/01/2026
Delighted to be recognised by @openuk.bsky.social for my recent open source work!
040
Reposted by Joe Birr-Pixton
Sean McArthur @seanmonstar.com · 30/12/2025
To end the year, a new major version of #rustlang reqwest, v0.13.0 is out! 🚀 - This brings rustls by default, replacing native-tls. 🦀 - Some feature and method cleanup. - But easy to upgrade for most everyone. seanmonstar.com/blog/reqwest...
seanmonstar.com
reqwest v0.13 - rustls by default
reqwest v0.13 brings rustls by default, feature cleanup, but otherwise easy to upgrade.
1395
Reposted by Joe Birr-Pixton
Josh Bressers @josh.bressers.name · 29/12/2025
This week on #OpenSourceSecurity I chat with Dirkjan Ochtman and Joe Birr-Pixton about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety
opensourcesecurity.io
Rustls with Dirkjan and Joe
Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many c...
053
Reposted by Joe Birr-Pixton
Sean McArthur @seanmonstar.com · 23/12/2025
Just published a new #rustlang reqwest release candidate: v0.13.0-rc.1. This has some breaking changes, the biggest was switching to rustls by default. I'd appreciate if you gave it a spin 🙏 github.com/seanmonstar/...
github.com
Release v0.13.0-rc.1 · seanmonstar/reqwest
👀 Discussion here if you give it try, thanks! Main breaking changes rustls is now default instead of native-tls rustls provider defaults to aws-lc instead of ring (rustls-no-provider exists if you...
13310
Joe Birr-Pixton @jbp.io · 23/12/2025
DSE assessment in shambles
Attempt to use a laptop with assistance of two colleagues
010
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 08/12/2025
Earlier this year, LWN.net featured an excellent article named "Linux's missing CRL infrastructure", and today Canonical announced it will be working with me and @jbp.io over the coming weeks to start bridging the PKI infrastructure gap. discourse.ubuntu.com/t/addressing...
discourse.ubuntu.com
Addressing Linux's Missing PKI Infrastructure
Earlier this year, LWN featured an excellent article titled “Linux’s missing CRL infrastructure”. The article highlighted a number of key issues surrounding traditional Public Key Infrastructure (PKI)...
3255
Reposted by Joe Birr-Pixton
The Rust Foundation @rustfoundation.org · 02/12/2025
With the @openuk.bsky.social Awards coming up, we’re excited that Rustls — a memory-safe TLS library — is shortlisted in two categories, and Creator Joe Birr-Pixton is also recognized individually. The Rust Foundation is proud to support Rustls through the Rust Innovation Lab 🧡
rustfoundation.org
Rustls Shortlisted for Two 2025 OpenUK Awards - The Rust Foundation
The Rust Foundation is delighted to congratulate Rustls for being shortlisted in the Open Source Software and Security categories of the OpenUK Awards 2025 — and Joe Birr-Pixton, Rustls Creator, for…
0115
Reposted by Joe Birr-Pixton
eliza🌻 @elizas.website · 25/11/2025
my “we are not enron” T-shirt has people asking a lot of questions already answered by my shirt
0497
Reposted by Joe Birr-Pixton
J. L. Westover @mrlovenstein.bsky.social · 20/11/2025
heheheheh
62578529
Joe Birr-Pixton @jbp.io · 19/11/2025
lots of posts about unwrap(). not too many posts about simply not having your code and configuration meet for the very first time in production.
081
Joe Birr-Pixton @jbp.io · 17/11/2025
sounds like something the bad bacteria would put on their packaging
Trusted friendly bacteria
010
Reposted by Joe Birr-Pixton
OpenUK @openuk.bsky.social · 04/11/2025
Congratulations to the shortlisted nominees in the 6th annual OpenUK Awards 2026, 🏆🍾🥂 Andy Piper, @bboreham.bsky.social, Daniel Gale, @davidtw.co, Dermoscopea, @flox.dev, Godfrey Inyama, Jan Faracik, @jbp.io, LVFS (fwupd.org), lowRISC CIC, Dr Margaret Hartnett, @manyfold.3dp.chat.ap.brid.gy,...
152
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 27/10/2025
New Rust RFC: adding a crates.io Security tab github.com/rust-lang/rf...
crates.io
crates.io: Rust Package Registry
0145
Joe Birr-Pixton @jbp.io · 26/10/2025
"I appreciate that you're frustrated, but I should clarify: I'm an AI assistant, so I don't have a mother or family relationships."
110
Joe Birr-Pixton @jbp.io · 25/10/2025
It's time to send GCC to live on a farm.
010
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 01/10/2025
I wrote another blog post for the Prossimo blog about how we improve the unhappy path for rustls users: www.memorysafety.org/blog/rustls-...
memorysafety.org
Improving Error Handling in Rustls
Dirkjan Ochtman is a maintainer of the Rustls TLS library that we've invested in since 2021. While he and the other maintainers have made many improvements and landed important features, we've asked D...
0134
Joe Birr-Pixton @jbp.io · 29/09/2025
Microsoft has a product called Copilot Pro, and Github has a product called Copilot Pro. They are different prices, different and unrelated products, shipped by teams that have no awareness of each other. Incredible product management and business acumen.
1130
Joe Birr-Pixton @jbp.io · 03/09/2025
We have a little blog post about this rustls.dev/blog/2025-09...
rustls.dev
rustls: Rustls and the Rust Foundation's Rust Innovation Lab
023
Reposted by Joe Birr-Pixton
cpu @cpu.xkeyscore.club · 28/08/2025
PowerDNS Recursor 5.3.0 has a nice note in the changelog: > The embedded webserver used to display the status page and process REST API calls has been rewritten in Rust and now supports multiple listen addresses and TLS. The new code is powered by Hyper+Rustls+Ring 🦀 🔒 (h/t Stefan Schmidt)
071
Reposted by Joe Birr-Pixton
Conrad Ludgate @conrad.cafe · 27/08/2025
When working with async, you often need to call a function that would block the runtime. Turns out not all blocking functions are the same Tokio defines two kinds of blocking functions: IO bound and CPU bound. A close read of the tokio docs tells you to avoid CPU bound tasks in spawn_blocking
1143
Joe Birr-Pixton @jbp.io · 26/08/2025
i've been trying to use LLMs a lot today, to convert around 1000 pages of dense legal agreement PDFs into markdown.
100