Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Christian Huitema

@huitema@social.secret-wg.org
mastodon 4.7.2
  • Open on social.secret-wg.org

Working on that Internet thing...

https://www.privateoctopus.com/about.html

505 Followers
224 Following
50 Posts
Joined April 27, 2022
Web:
https://www.privateoctopus.com/about.html
Github:
https://github.com/huitema
Open post
Christian Huitema @huitema@social.secret-wg.org
· 1w ago
Replying to
@jssfr@zombofant.net @danlew@androiddev.social I had the same kind of conversation after telling an installer that I did not want my thermostats to be connected to WI-Fi. "I get it, none of you guys in tech want that."
40
5
1
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 1w ago
Replying to
@bruce@darkmoon.social @jpaskaruk@growers.social @jssfr@zombofant.net @danlew@androiddev.social I don't know when they will actually ship, but the Slate truck has no Internet connectivity.
7
1
1
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2w ago
Replying to
@wcbdata@vis.social @sarahtaber@mastodon.online @RealGene@hachyderm.io When I was little we were eating veggies from the garden, and using manure to fertilize the garden beds. But we were first working the manure in the ground before planting the vegetables. Everyone was doing that. Never heard of any problem. On the other hand, we were definitely not pooping in the garden!
6
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2w ago
Replying to
@wcbdata@vis.social @sarahtaber@mastodon.online @RealGene@hachyderm.io Correction: in fact I did hear of a problem. The local growers had convinced the management of the US base in St-Nazaire to buy their lettuces and carrots, that would be cheaper than flying them from the US. The soldiers got sick. There were germs in the veggies that did not bother the locals, but the US soldiers were not accustomed to them.
4
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 3mo ago
Replying to
I was expecting popcorn. I was not expecting Jacob Applebaum to post a precise description of how a change made by NIST in the final stages of ML-KEM publication is exactly what you need to establish a secret backdoor. That's not popcorn, that's dynamite. I don't see how the IETF could publish the draft as is after this publication. https://mailarchive.ietf.org/arch/msg/tls/BfV8R0Dr15PUOGfDi9d7_INJQzo/
mailarchive.ietf.org

[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Search IETF mail list archives

48
8
41
1
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2mo ago
Replying to
@timbray@cosocial.ca the main question is whether when the market crash it will be like 2001 or like 1929...
2
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 4mo ago

The "careful resume" RFC is finally published! I have been working on that issue for several years. The initial motivation came from the CNES in France and the ESA in Europe, who wanted a way to start QUIC connections faster on geo satellite links, instead of waiting multiple RTT for the congestion window to grow. And now we have it, all shiny and well polished by the IETF.

https://www.rfc-editor.org/info/rfc9959

rfc-editor.org
6
0
6
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange I don't know for 2012, but from 2013 on a large number of IETF participants were absolutely convinced of being under attack. It was fairly obvious that some IETF participants were either willing enablers of these attacks, or "useful idiots". But we don't know which ones, and we quickly realized that launching a witch-hunt would be very destructive, and that the safest path was to keep discussions strictly technical.
6
40
2
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 3mo ago
Replying to
@SteveBellovin@infosec.exchange @mattblaze@federate.social @indivisibleteam@mastodon.social The way I understand it, the issue is collateral fishing. Similar to fishing tuna, which is OK, but also catching dolphins, wich is not. In that case, spying on foreign agents, catching foreign data, but also catching foreign data about US citizen, which is dubious.
1
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@corbden@defcon.social @paul_ipv6@infosec.exchange In France, the academic networks moved to TCP-IP starting in 1988 with connections between INRIA and NSFNET and with the move of EUNET (european Unix Net) to adopt TCP-IP. There were a few commercial providers of modem connections in the early 90's, operating in a gray area of regulation, but big scale public networks only happened in the late 90's. Encryption regulation was eased in the late 90's, driven by commercial pressure.
2
0
1
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@paul_ipv6@infosec.exchange @corbden@defcon.social @mattblaze@federate.social The Minitel was indeed entirely owned by the French PTT (which was not yet France-Telecom). It only ran on their X.25 network (Transpac) and the billing of services was integrated with the phone bill.
2
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@cR0w@infosec.exchange I see the analogy with road networks, and the cycle of building freeways to ease traffic followed by building far away developments causing more traffic. There is always a pressure to develop more software faster, tempered by the need to fix bugs and avoid catastrophic issues. If it becomes easier to root out bugs, more software gets done faster, for an increased supply of bug. Quasi-equilibrium.
2
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@paul_ipv6@infosec.exchange @corbden@defcon.social @mattblaze@federate.social You could say that the Minitel was predecessor of the Web pages. There were even porn services, using 40*24 ASCII graphics! But there was none of the freedom of innovation of the Internet, which made it a dead end.
2
2
1
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@paul_ipv6@infosec.exchange @corbden@defcon.social @mattblaze@federate.social In France, the Internet itself was, hum, "only tolerated within academia" for quite some time. We had to find loopholes to bypass the official Telecom Monopoly...
2
6
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange The political problem is complex. First, there is a wide consensus in the IETF for not standing in the way of deployments, and in particular not using IETF processes to block IANA registration except in some very specific registers -- because blockades generate various kinds of smuggling that end up very counter-productive in general.
2
2
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange The IETF has a strong bent towards "publishing rather than censoring", unless the technical flaws are obvious. That bent drives strongly towards "publishing with some proper warning in the text", while not publishing at all would be pretty extraordinary, especially in presence of a constituency that really want to sell products to the US government. So at that stage of the debate, the issue is really about how strong the warning should be.
2
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@SystemsAppr@discuss.systems That's the general issue with security. Security is about making sure that stuff that should not be working doesn't. It generally does not guarantee that stuff that should be working will. And it sometimes over protects so stuff that maybe should be working doesn't anymore.
1
2
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@julf @mattblaze for reference: https://en.wikipedia.org/wiki/Andr%C3%A9_Tulard
en.wikipedia.org
1
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago

@randulo@mastodon.social @book@beige.party Most words using "th" in French come from the Greek, e.g., théatre, thèse, sympathie, etc. The standard pronunciation for these words was set by Renaissance scholars who had no idea what ancient Greek actually sounded like, and assumed that Theta just sounded like T. French people learning English understand that the English TH is a foreign sound, not present in native French. They will try moving their tongue as the teacher explained, but it will often come out as Z. Or F. Or D.

1
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@rsalz@ioc.exchange @pedromj@mastodon.social At that point, I am commenting on the IETF process, much as I would be commenting on the weather. If Pedro wants to influence the result, he should definitely work in the WG -- waiting on the sideline and publishing a "considered harmful" draft will be much less effective.
1
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@pedromj@mastodon.social @djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange Actually, working groups can pressure for changes in a draft. Once a draft is accepted by a working group, the status of the authors change. They are not the only one in charge of the text anymore. What they write must reflect the consensus of the WG, and if that consensus includes adding a warning, they have to do that.
1
20
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@pedromj@mastodon.social @djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange I am really not sure that publishing more words would help counter propaganda by the bad faith actors that Dan fears. If the WG does decide to publish the ML-KEM TLS draft, strong warnig would help somewhat. Changing the registration option of the hybrid key exchange algorithms to recommended=Y would also help. But propaganda is countered by public speech, not so much by standard actions.
1
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange By promoting, I meant "publication as an RFC would help the marketing (or promotion) of the PQ-only approach by actors linked to the US government." As in, "of course you can do that, the IETF published it as an RFC, do not look at the fine print."
1
3
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2mo ago
This announcement of OpenAI chatbot escaping the sandbox an hacking an external database smells strange. It smells like some kind of demo rigged up for marketing purposes. Convince enterprises to pay a fortune for the AI service that is oh so powerful. On par with Anthropic advertising loudly that their new model should be reserved to a select few, and then proposing it to customers as an expensive option!
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2mo ago
Replying to
@rpaulo@infosec.exchange Two points, so probably born 2 years ago.
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@djb @pedromj @paulehoffman @rsalz Easier to sell is pretty much the same as "Endorsement by the IETF". At that point, the technical arguments boil down to the risk that ML-KEM is found broken. Dan, you argue that that risk is very high because the promotion efforts are orchestrated by the government. But if people were to discard your argument, we are left with a generic discussion of risk. That discussion could result in having a recommendation=Y for hybrids versus no for naked. Maybe.
0
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange I don't understand what you mean by "removing". The hybrid key exchanges are defined in https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/ which went through IETF last call and is in the final stage of approval by the IESG. I don't know that anybody is proposing to remove that.
datatracker.ietf.org
0
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 1mo ago
Replying to
@stshank@mstdn.social From the article, passive cooling prevents the roof from getting too hot, and insures that the air inside the house is not hotter than the ambient outside temperature. That's cool. But I think this fails if the air outside is hotter than 37C. If I remember thermodynamics correctly, you can only cool the inside lower than the outside with some kind of heat pump, and that requires spending energy. Maybe solar panels on that roof?
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 1mo ago
Replying to
@SRDas@mastodon.online @carlmalamud@official.resource.org @paco@infosec.exchange @blogdiva@mastodon.social Seriously: buy a proper adapter. Or two. In theory, the US chargers are converging to the NACS standard. This is work in progress, lots of car come with the old CCS charger instead. But it is the future. When I swapped my Tesla for a Lucid Air, I kept the Tesla charger in my garage and bought an adapter. I have been using it for a year, no problem. This is what I bought: https://www.amazon.com/Lectron-Charging-Compatible-Connectors-Destination/dp/B09M6KFV9T/ref=pd_bxgy_d_sccl_1/141-7379390-4742037?pd_rd_w=MjBeD&content-id=amzn1.sym.9bef5913-5870-4504-8883-3ba89d7f8e39&pf_rd_p=9bef5913-5870-4504-8883-3ba89d7f8e39&pf_rd_r=EAF481AGP76ZP3CQP5A1&pd_rd_wg=G9ckN&pd_rd_r=7128906b-40cc-4394-b1b7-8c84e01e934e&pd_rd_i=B09DCTJCTV&th=1
amazon.com
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 1w ago
Replying to
@letoams@defcon.social from what I read, the protocol uses cleartext http for exchanges between nodes. In these days and age, that's a bit silly, especially if you expect the exchanged content to be private...
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2mo ago
Damn. Lindsay Graham was younger than me. Never would have guessed.
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@djb @pedromj @paulehoffman @rsalz In fact, there are many WG members arguing that we do not need an ML-KEM RFC since the NIST specification can just be deployed today. The counter to that argument is that publication as an RFC provides a stable reference, which helps interoperability, plus provides the IETF with a modicum of control. The counter to that counter argument is that RFC publication is mostly a marketing attempt, to make the algorithm easier to "sell".
0
6
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@pedromj@mastodon.social @djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange We are heading towards a situation where the ML-KEM key exchange draft will be published, probably in about a year. I would much prefer to see a warning in the text itself, and I think that can be achieved. After that, the IETF will have published 2 documents, hybrid ML-KEM and naked ML-KEM. If we follow Dan's reasoning, we can expect the US Gov to encourage "naked", which they might be able to break. We will be in the domain of opinions, not standards.
0
17
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
Of course, there are other bottlenecks beside scheduling. The big one is the socket API traversal, which is the limit for "batch" speed trials. But not all applications are sending lots of data. "Presence" style applications are just sending the occasional messages on a connection, and that's why the scheduling bottleneck was an issue.
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2w ago
Replying to
@the_wub@mastodon.social @rpaulo@infosec.exchange Of course, that suppose open source training models, and making them energy efficient. That's another question...
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2mo ago
Morning visitor. I think this deer was born in our yard. Obviously he likes it here. We like him too, but we also like our flowers!
0
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@rsalz@ioc.exchange Not that I specially want to, but yes I assume that after a couple more months of discussion the naked ML-KEM draft will be published. This is not certain, but that's the most likely outcome. This is not like the visibility draft, for which there was a plurality of "strongly oppose". This kind of debate typically ends with a compromise, such as OK to publish if the opponents get a strongly enough wording in the security section, or maybe in the intro.
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@jeroen@secluded.ch @SystemsAppr@discuss.systems Sure, having different error messages helps notice censorship. As long as the censors let you do that. But to beat censorship you have to smuggle the data through the borders. If censorship is the law of the land, established providers are unlikely to help you do the smuggling. Also, this is definitely not related to DNSSEC.
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@rsalz@ioc.exchange @pedromj@mastodon.social As for the security considerations, I think it will take some iterations before converging. And yes, the exact content is best discussed on the TLS mailing list.
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2w ago
Replying to on mastodon.social
@the_wub@mastodon.social @rpaulo@infosec.exchange Yes. In the end, energy is energy. I wanted to get a rough approximation of how much energy it takes to train a human intelligence, and use that to estimate whether a small organization could train its own models. The next question is, can we train open source models with about that amount of energy?
0
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2mo ago
The red halo of the red sun in the early morning. The ghosts of burnt forests, burnt houses. The new sight of summer in a world drying up.
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2mo ago
Replying to
@edavies@functional.cafe lol. I have seen strange riggings, but yes, this one is interesting.
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@SystemsAppr@discuss.systems Interesting that to show the value of DNS security you mention DNS censorship. DNSSEC does not fix censorship. It just tells you that the name resolution did not work...
0
1
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 5mo ago
Replying to
@pedromj@mastodon.social @djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange After publication of naked ML-KEM, we could try to sway opinion by publishing Internet drafts such a "naked ML-KEM considered harmful". We could lobby browser vendors to not implement that. We could publish in news papers, rally suppport from the EFF, etc. All that may help getting people to deploy hybryd ML-KEM instead. But it would help more if there is an warning in the naked ML-KEM draft itself.
0
13
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 4mo ago
Replying to
@briankrebs@infosec.exchange @paul_ipv6@infosec.exchange Look at what happened when Microsoft got seriously fixing bugs in Windows. The attacks mostly moved and targeted services running on the platform, while social engineering continued undisturbed...
0
0
0
0
Open post
Christian Huitema @huitema@social.secret-wg.org
· 2mo ago
Replying to
@edavies@functional.cafe Shit posting, are you? In any case, boat toilets are famous for causing shit. I remember an incident off a cape in Ireland fifty years ago -- at night, maybe 20 knots of wind, suddenly 5 inches of water in the cabin. It was the toilet. No need for gen AI!
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:11:11 UTC