Sign in

Eric Rescorla

@rtfm.com
173 followers 4 following 39 posts

Newsletter: educatedguesswork.org

PostsRepliesMedia
Eric Rescorla @rtfm.com · 23/07/2026
This is actually a somewhat complicated technical issue. Apple designed a whole fancy cryptographic system for this but then ultimately opted not to deploy it. I'm having some trouble finding their writeup, but here's my summary: educatedguesswork.org/posts/apple-...
educatedguesswork.org
Overview of Apple's Client-side CSAM Scanning
100
Eric Rescorla @rtfm.com · 08/07/2026
I agree that there is an important difference between ST and Informational, but it's worth noting that all IETF Stream RFCs have IETF Consensus, whereas Independent Submissions do not need to (and likely do not).
100
Eric Rescorla @rtfm.com · 25/06/2026
Today on the newsletter: a look at the Amazon v. Perplexity case educatedguesswork.org/posts/notes-...
educatedguesswork.org
Notes on Amazon v. Perplexity
Agentic browsing and the Open Web
000
Eric Rescorla @rtfm.com · 09/06/2026
Now up on the newsletter: Why your asthma inhaler is so expensive (in the US). Hint: it starts with the ozone hole... educatedguesswork.org/posts/asthma...
educatedguesswork.org
Why your asthma inhaler is so expensive (in the US)
It starts with the ozone hole...
000
Eric Rescorla @rtfm.com · 23/05/2026
Now up on the newsletter: Understanding Age Assurance Accuracy educatedguesswork.org/posts/age-as...
educatedguesswork.org
Understanding age assurance accuracy
022
Eric Rescorla @rtfm.com · 11/05/2026
PSA. One benefit of having an electric car is it can make parking easier. It's not uncommon to come across a parking lot which is entirely full but has open EV charging spots. More expensive than charging at home but pretty cheap on the "cost of parking" scale.
000
Eric Rescorla @rtfm.com · 05/04/2026
Yeah I think you just end up having to run some kind of micro-server. I've had good luck with fly.io and Coudflare workers for this kind of thing,
fly.io
Build fast. Run any code fearlessly.
Build fast. Run any code fearlessly.
020
Eric Rescorla @rtfm.com · 28/03/2026
Of possible relevance to @matthewdgreen.bsky.social @alecmuffett.bsky.social
010
Eric Rescorla @rtfm.com · 28/03/2026
This week on the newsletter: "How not to mandate device-based age assurance" educatedguesswork.org/posts/device... In this post, we examine a number of enacted or proposed requirements for device-based age assurance and some of the ways they can go wrong.
educatedguesswork.org
How not to mandate device-based age assurance
Software design by legal mandate
154
Eric Rescorla @rtfm.com · 27/03/2026
Also, why not make a bomb that consists of a shield generator + a lasgun + fuse that activates the shield and lasgun at the same time. I guess it's unpredictable how big the explosion would be but still....
010
Eric Rescorla @rtfm.com · 07/03/2026
Correction: 2025.
000
Eric Rescorla @rtfm.com · 07/03/2026
Again, I wouldn't sign up for a marathon if I expected it to be that hot, but it's not like it's some exceptional situation that requires shortening the race.
000
Eric Rescorla @rtfm.com · 07/03/2026
For reference, the Badwater 135 takes place in Death Valley in July, so we're talking about running much more than a marathon in temperatures exceeding 100 F. That's exceptionally hot, but 86 F just isn't that hot.
100
Eric Rescorla @rtfm.com · 07/03/2026
I'm not saying I'd want to race in that, but running in those temperatures is well within the limits of human performance; mostly you need to slow down and hydrate a lot better. I've trained in hotter temps lots of times.
100
Eric Rescorla @rtfm.com · 07/03/2026
Moreover, the whole thing is just kind of odd because the forecast for LA is a high of 86 F (merrysky.net/forecast/los%2 0angeles/us ) and that's at 3 PM so it's cooler most of the race.
merrysky.net
100
Eric Rescorla @rtfm.com · 07/03/2026
None of this applies to marathons, which are a strictly defined distance. Nothing wrong with racing 18 miles (~30K); I've done it myself. But it's not a marathon and just giving someone a finisher medal doesn't make it one.
100
Eric Rescorla @rtfm.com · 07/03/2026
For example, I ran the 2026 Ultra Tour Monte Rosa, where they cut off the last 15 or so miles because of a rock fall. educatedguesswork.org/posts/utmr/ . And in fact it doesn't count as a finish for some purposes, like Hard Rock qualifying. hardrock100.com/hardrock-qua...
educatedguesswork.org
Ultra Tour Monte Rosa (UTMR) Race Report
200
Eric Rescorla @rtfm.com · 07/03/2026
The finished or not question can be a bit confusing in some events like mountain races where the course is always a bit fluid and organizers might need to change or shorten the race for reasons outside their control.
100
Eric Rescorla @rtfm.com · 07/03/2026
Some real map/territory confusion in this report by the LA Marathon to give people medals if they drop out after 18 miles (because it's hot). The finisher's medal commemorates that you finished, but it doesn't make you a finisher. www.nytimes.com/2026/03/07/u...
100
Eric Rescorla @rtfm.com · 06/03/2026
educatedguesswork.org
Let's build a tool-using agent
giving hands to the brain in a vat
000
Eric Rescorla @rtfm.com · 06/03/2026
Now up on the newsletter: Let's build a tool-using agent In this post, I walk through in some detail how AI agent tool calling works, including digging into the inputs and outputs of the LLM before they get translated into a coherent-looking JS API. educatedguesswork.org/posts/tool-c...
100
Reposted by Eric Rescorla
Knight-Georgetown Institute (KGI) @knightgtown.bsky.social · 29/01/2026
📣 New from KGI: Age Assurance Online explores how age assurance systems work and their tradeoffs in accuracy, circumvention, availability, and privacy. A must-read for policymakers, service providers + users to understand the consequences of these systems: kgi.georgetown.edu/research-and...
kgi.georgetown.edu
Age Assurance Online: A Technical Assessment of Current Systems and their Limitations – Knight-Georgetown Institute
043
Eric Rescorla @rtfm.com · 01/01/2024
The standard way to avoid cross-protocol attacks is now to use ALPN In the TLS handshake.
010
Eric Rescorla @rtfm.com · 25/12/2023
Now up, part II in my series about transparency systems: Certificate Transparency in Reality educatedguesswork.org/posts/transp...
000
Reposted by Eric Rescorla
Richard Barnes @ipv.sx · 15/12/2023
Welcome to Bluesky @rtfm.com ! Folks might recognize EKR from such hits as TLS 1.3, Let's Encrypt, and being Firefox CTO. He also writes a really good blog. Y'all should all follow him.
022
Eric Rescorla @rtfm.com · 15/12/2023
Of course, actually deploying this in practice turns out to be a lot harder than it sounds, which I'll get to in the next post. educatedguesswork.org/posts/transp...
001
Eric Rescorla @rtfm.com · 15/12/2023
3. Site operators can then download all certificates, make sure they match the consensus, and then check for bogus certificates in their name. Mission accomplished.
100
Eric Rescorla @rtfm.com · 15/12/2023
If all goes well, this gives you a closed loop that makes it impossible to surreptitiously issue a certificate. 1. The consensus system requires the CA to commit to all its certificates. 2. Clients verify that certificates have been committed to.
100
Eric Rescorla @rtfm.com · 15/12/2023
The post has more detail, but the idea behind the proof is to show that there is a path from your certificate back to the root of the true, thus demonstrating that the tree was computed over your certificate.
100
Eric Rescorla @rtfm.com · 15/12/2023
Finally, when you go to the Web server, it proves that it's certificate matches the summary. What this means technically is that it gives you a Merkle inclusion proof that goes back to the root.
110
Eric Rescorla @rtfm.com · 15/12/2023
Next, you need some mechanism whereby each element in the system can assure itself that it has the same summary as everyone else (this is actually the hard part).
110
Eric Rescorla @rtfm.com · 15/12/2023
The standard solution here is what's called a consensus system. Effectively, you compute a summary of all the published certificates (typically by assembling them into a Merkle hash tree).
100
Eric Rescorla @rtfm.com · 15/12/2023
For instance, if the CA has it on their web site and sends it to clients but not to sites when they check, then the system breaks down.
100
Eric Rescorla @rtfm.com · 15/12/2023
The first step is to have the client (i.e., the browser) check that the certificate was published, thus hopefully forcing the CA to publish it. But now we have to confront the definition of "publish". How do we know the CA published to everyone?
100
Eric Rescorla @rtfm.com · 15/12/2023
The challenge here is ensuring that CAs are actually publishing every certificate. If your concern is that the CA was intentionally misissuing, it might just choose not to publish the bogus certificate.
100
Eric Rescorla @rtfm.com · 15/12/2023
A misissued certificate can be revoked, and, if investigation reveals improper practices, browsers might choose to distrust the CA, thus rendering all of its certificates invalid.
100
Eric Rescorla @rtfm.com · 15/12/2023
The basic idea is to require every certificate has to be published, thus allowing sites -- or services on their behalf -- to detect (at least in principle) when a certificate has been misissued
100
Eric Rescorla @rtfm.com · 15/12/2023
The solution that the ecosystem has converged on is something called a "transparency system", and in the case of the WebPKI "certificate transparency". Instead of trying to prevent misbehavior by CAs, a transparency system tries to make it detectable.
100
Eric Rescorla @rtfm.com · 15/12/2023
When paired with some fairly public failures by WebPKI certificate authorities, this creates an obvious problem.
100
Eric Rescorla @rtfm.com · 15/12/2023
Most real-world authentication protocols rely on some kind of trusted authentication service to attest to endpoint identities. The obvious problem here is the word "trusted"; if the authentication service misbehaves, then the whole system breaks down.
101
Eric Rescorla @rtfm.com · 15/12/2023
Hello Blue Sky! Check out first post in my series on transparency systems. educatedguesswork.org/posts/transp...
141