Intellectual (Non practicing, Lapsed) Mostly Harmless. Biological. NB Kaurna land. Autodidact, Polymath, Honoris Causa Ignoramus. #AI #Infosec #Consciousness Prefigurative Social & Technological Innovation enthusiast (#SocialInnovation, #TechForGood, #SystemicChange, #EthicalAI) #REGULATEAI ! "Humans are the larval form of AI" - me "Only thing that stops a bad guy with an AI... Is a good guy with an AI." - me "I fight for the user." - Tron Webby: https://dodgy.link/ is very dodgy. Header art: Luv, a replicant from the beautiful movie "Blade runner 2049", is having her nails done... ... simultaneously she rains death onto bandits with heavy ordinance from a drone through her augmented reality glasses. Avatar: Motif from a SA Amalgamated Metal Workers union banner. South Australian Museum. United, the workers, will never be defeated !
Wulfy—Speaker to the machines
@n_dimension@infosec.exchange
infosec.exchange
Replying to
@sjvn@mastodon.social
@sjvn@mastodon.social
RFC-1149
#RFC
Joe Ferguson
@joepferguson@phpc.social
DevOps Dev. PHP 8.6 Release Manager. Writer. Open Source, Linux, Python, PHP, Ansible, ❤️ DevOps. ⚽, 🏒, & 🏎 Fan. Trying to make a difference. Just happy to be here.
phpc.social
#PHP 8.6 Deprecations are open for voting. Lots of things to review; might want to pack a snack when you vote: https://wiki.php.net/rfc/deprecations_php_8_6
#opensource #rfc
RFC Editor
@rfceditor@mastodon.online
Announcements of official documents published by the RFC Editor at rfc-editor.org
mastodon.online
RFC 9954: Hybrid Key Exchange in TLS 1.3, D. Stebila, et al., https://www.rfc-editor.org/info/rfc9954 #RFC Hybrid key exchange refers to using multiple key exchange algorithms simultaneously and combining the result with the goal of providing security even if a way is found to defeat the encryption for all but one of the component algorithms. It is motivated by the transition to post-quantum 1/2
RFC Editor
@rfceditor@mastodon.online
Announcements of official documents published by the RFC Editor at rfc-editor.org
mastodon.online
RFC 9852: New Protocols Using TLS Must Require TLS 1.3, R. Salz, et al., https://www.rfc-editor.org/info/rfc9852 #RFC TLS 1.3 is widely used, has had comprehensive security proofs, and improves both security and privacy deficiencies in TLS 1.2. Therefore, new protocols that use TLS must require TLS 1.3. As DTLS 1.3 is not widely available or deployed, this prescription does not pertain to 1/2
julian
@julian@activitypub.space
Co-Founder (NodeBB) | Husband 🤷♂️ and Dad 🙉 to three | Rock Climber 🧗♂️ | Foodie 🥙 | Conductor 🎵 | Saxophonist 🎷 ✅ Small teams craft better code. 🇨🇦 Made in Canada 🗨️ Federating NodeBB with funding from NLNet ♥️🇪🇺
activitypub.space
NodeBB and RFC 9421
<p>I've been working (admittedly, with AI assistance) on HTTP signatures RFC 9421 support.</p> <p>The work will be done in stages. The first step is ensuring NodeBB can handle receipt of activities signed under the new standard (with adequate fallback to draft <code>cavage-12</code>).</p> <p>Afterwards NodeBB will begin sending out activities signed with both methods.</p> <p>Question re: double knock for AP devs who have implemented... is there a specific reason 9421-signed is sent first, and then cavage-12? [...]</p>
Hover or focus to reveal
Sensitive
I've been working (admittedly, with AI assistance) on HTTP signatures RFC 9421 support.
The work will be done in stages. The first step is ensuring NodeBB can handle receipt of activities signed under the new standard (with adequate fallback to draft cavage-12).
Afterwards NodeBB will begin sending out activities signed with both methods.
Question re: double knock for AP devs who have implemented... is there a specific reason 9421-signed is sent first, and then cavage-12? My understanding is the headers are separate — Signature-Input vs Signature, though there are two of the latter.
It seems possible to send both signatures at once.
RFC Editor
@rfceditor@mastodon.online
Announcements of official documents published by the RFC Editor at rfc-editor.org
mastodon.online
RFC 9851: TLS 1.2 is in Feature Freeze, R. Salz, et al., https://www.rfc-editor.org/info/rfc9851 #RFC Use of TLS 1.3, which fixes some known deficiencies in TLS 1.2, is growing. This document specifies that no changes will be approved for TLS 1.2 outside of urgent security fixes (as determined by TLS Working Group consensus), new TLS Exporter Labels, and new Application-Layer Protocol 1/2
You've seen all posts