4,974 karma · joined December 27, 2010
It might actually be wise [1] to create a new, slightly less permissioned license for open source wherein the open is defined as anything that isn’t in a kill or surveillance chain or, more broadly, for military use…
[1] for the community
The great Dr. Orr Dunkelman was admirably vocal in his opposition to the publishing of this draft.
The mere publishing of an RFC has customarily been treated by developers as a stamp of approval from the IETF.
The NSA, contractors and their fans argue that simply adding a "RECOMMENDED=N" in an obscure section of this draft will somehow prevent said implementations in deployments.
However, as an example, Canada's NSA equivalent specifically requested the draft to be published so that they can use it to support their poor choice in deployment of solo ML-KEM nation-wide.
While ML-KEM may be sound, significant bugs in implementations in the wild continue to be published.
To be clear, CRQCs do not exist today.
ECC is battle tested, proven, and is used today.
It makes no sense to delete working cryptography and replace it with potentially buggy, non-battle tested implementations of new cryptography for a threat that does not yet exist today.
Instead, you fight HNDL [1] with hybrid which preserves the safety of today, and hopefully also, tomorrow.
No serious security person should be recommending otherwise which is, perhaps, why some may question the motives of those that are pushing for solo ML-KEM.
[1] Harvest now decrypt later
Actually, based on the WGLC, or the three of them rather, it's pretty clear that Ph.D cryptographers significantly prefer hybrid over pure ML-KEM.
> he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.
The brigade by the NSA (6+ votes or more if you include NSA contractors), the AD being former NSA and the moderation of Dr. Bernstein for a footnote seems pretty fair and balanced </sic>.
Meanwhile, the lead of the EU PQC program, professors from several universities, Ph.Ds and, additionally, legendary cryptographers all expressed significant concern and even stronger opposition to the publishing of the draft.
Finally, the chairs refused to share their methodology in determining consensus when asked by several Professors and Ph.Ds.
Actually, Dr. Nadim Kobeissi formally proved that hybrid is secure, even if ML-KEM fails. [1]
I was happy to see the lead of Europe’s PQC team also voted with the cryptographers.
[1] Not AI codebases (and of course, AI code bases I guess)
This is going to be very useful for servers hosted in third party DCs.
We're working on a similar solution at UnixShells.com [1]. We built a VMM that forks, and boots, in < 20ms and is live, serving customers! We have a lot of great tools available, via MIT, on our github repo [2] as well!
We built this for use on UnixShells [1].
All remote connections are verified against the authorized_keys and are, of course, end to end encrypted.
This is MIT licensed. There is also a relay that lets you connect to your latch sessions that are behind NAT - this has a small cost to it for infrastructure. However, you can use tailscale/ngrok or your own external IP for free.
The will to fight for what one believes in - I think we can all agree that is an admirable human trait that would result, for those who do follow his views, in him being labeled as a hero and defender of people's rights.
Bravo, Garry.
Cool project!
[1] https://vp.net/l/en-US/blog/The-History-of-VPNs-and-Logging
Bad times for the internet.
I wonder how much longer the structure will be known by its current name, given the growing trend of letting slanderous/fringe uses of words dictate their dominant meanings [1].
[1] For example, the end of the master branch.
Happy Internet Archive Day! :-)
[1] servers gone, hosting sites gone, etc.
[1] https://www.reddit.com/r/ProtonVPN/comments/93pp40/comment/e...
Edit: Archived for posterity https://archive.is/xi92E