Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Paul Wouters 🇪🇺🇨🇦

@letoams@defcon.social
mastodon 4.7.3
  • Open on defcon.social

Aiven Security Architect
Former two term IETF Security Area Director, IESG
Opensource dev: libreswan, Fedora, etc (see github)
NIST SP800-77 Rev.1 author
RDRonline player

383 Followers
262 Following
50 Posts
Joined February 03, 2023
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 1w ago
RE: https://toot.radicle.dev/@radicle/117325296857732162 Calling this a “security vulnerability” is a bit of a stretch ?
Open quoted post
Quoting
Radicle
@radicle@toot.radicle.dev
Unfortunately, we have to inform you about security vulnerabilities in the network protocol that Radicle nodes use to communicate amongst each other. https://radicle.dev/2026/09/23/disclosure-of-vulnerability-in-network-protocol
Open quoted post
toot.radicle.dev

Radicle: "Unfortunately, we have to inform you about securi…" - Radicle Mastodon

2
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

Based on the great work of Antony Green over at redhat for https://github.com/atgreen/block-copyfail which can block copy.fail on a running kernel without reboot, I pacakged up the bpf into a oneshot systemd service you can install and start on many machines https://nohats.ca/ftp/block-copyfail/

github.com
29
0
29
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 4mo ago

RE: @campuscodi@mastodon.social

This is why code that takes untrusted input - like daemons - don’t have permissions to write their own config files

mastodon.social
16
1
9
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago

RE: @GossiTheDog@cyberplace.social

1) Burn more gas

2) ???

3) Blame Canada !

cyberplace.social
3
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

Ohh, I got a cute plaque in RFC format! Thanks #ietf

defcon.social
12
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago

Here we go again, it's goin' through our heads
Here we go again, we're all wondering when
Here we go again, it's never gonna end
Here we go again, we're going 'til we're dead
Here we go again

2
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago

People who dislike NIST KEM because of a Kyber hash() removed from hash(prng(x): use wireguard !

Wireguard: session_id = RDRAND(x)

(Bypassing Linux random pool, twice known to crash kernel because failed hwrng on AMD CPUs) multiple session id’s were all zeroes, putting raw random state onto the wire)

2
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 4mo ago
Replying to
@Strandjunker@mstdn.social @briankrebs@infosec.exchange when the system fails, you shutdown the country. General strike. Everyone everywhere. You can’t wait two years.
6
1
4
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

RE: @GnuPG@mstdn.social

“Well known” to be its own incompatible standard and also squatting on the OpenPGP v4 code point. There is no OpenPGP v4, and technically this is a trademark violation of the OpenPGP trademark owned by #ietf

mstdn.social
5
4
4
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
mailarchive.ietf.org
5
3
2
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago

I found Arthur Morgan’s grave! No eagle though so I guess I’m a bad guy

1
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago

PQ or not PQ, there is no try

1
0
1
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago

RE: @lwn@fedi.lwn.net

Dan Williams was always kind, especially when people became negative which is too common in opensource. He made the opensource world a better place. Helping his family is the least we can do now.

fedi.lwn.net
1
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

RE: @newsguyusa@flipboard.social

AI has truly taken over the hype lead from blockchain/bitcoin

flipboard.social
3
0
1
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 4mo ago

RE: @internet_nl@mastodon.nl

As I have said before, relying on badly maintained websites for contact information about badly maintained websites is not really secure or useful. Hacked machines will just change it to not alert the real sysadmins.
I’ve already seen so many outdated or 4x errors in these.
There is value in reaching out through alternative channels (social media, LinkedIn, optrust, dns-oarc, mawk, etc)

mastodon.nl
2
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 3mo ago
Replying to
@mikalai@privacysafe.social @pluralistic@mamot.fr @eff@mastodon.social Please see https://www.ietf.org/process/process/ There is no voting, no re-voting and there is a difference between adoption calls and working group last call, and it’s normal to have revisions that address concerns and a new follow-up working group last call to confirm consensus. But instead of reading up on how the IETF works, sure you can also just make up a conspiracy theory. It is much easier and doesn’t require any time or effort on your part.
Guide to the IETF standards process
IETF

Guide to the IETF standards process

The IETF follows open and well-documented processes for its work, including setting Internet standards. This guide synthesizes various sources to describe the IETF standards process at a high level.

1
4
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 3mo ago
Replying to
@djb@mastodon.cr.yp.to @rsalz@ioc.exchange with a broken premise, where you end up hardly matters. There is a safe most researched algorithm and a saver slightly more complicated hybrid. We get RFCs and the people or the market or the international governments decide if and what they want to accept. The IETF just facilitates both. It makes the slightly saver one recommended. This is where the story should end but Dan Quichotte is on a mission and can’t take he is in the rough of rough consensus that the IETF doesn’t want to forbid the safe option that some other orgs such as USG and 3GPP want to use.
1
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 3mo ago
Replying to
@djb@mastodon.cr.yp.to sure like last round where people copy pasted your template and then later apologized and confirmed they didn’t know what they were talking about and had been mislead by your social media postings to act. *slow clap*
1
9
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 3mo ago
Replying to
@djb@mastodon.cr.yp.to note this exact strategy was attempted by the vendors who didn’t want TLS 1.3 to happen because ephemeral key exchanges were made mandatory in TLS 1.3 ruining their network monitoring capabilities. They sent lots of people to try and block TLS 1.3, but the attempts didn’t work. The IETF has experience with people sending sockpuppets. It is sad to see you attempt a similar strategy.
1
1
1
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@rene_mobile@infosec.exchange https://github.com/atgreen/rhel-block-copyfail is a runtime block for all three - without needing a reboot. Install and start service. Then have weekend and patch when you can finally reboot the machines in a few days
github.com
2
0
2
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

RE: @olaf@social.secret-wg.org

Cute even I don’t agree with all of it, the essence of the article stands.

social.secret-wg.org
2
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

RE: @gtbarry@mastodon.social

No one with the @eff@mastodon.social tool installed in downtown toronto I guess ?

mastodon.social
2
2
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

RE: @rfceditor@mastodon.online

This took waaaaay too long for a simple real life needed fix.

mastodon.online
2
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@GnuPG @bwh that statement is of course wrong, speaking as co-author of RFC 9580 and as former Security Area Director I am well aware of the actual history. The problem now with the Individual (non-consensus) draft of gnupg/Werner is that it pretends to be a draft that will register IANA OpenPGP values, while it doesn’t, and conflicts with the real RFC 9580 that already allocated values. So anything different from RFC 9589 will just cause confusions for real OpenPGP implementations. If it wants to register its own values, it should do so as “reserved” values for IANA OpenPGP so there are no conflicting values. And it should stay away from already allocated values to introduce incompatible behaviour.
2
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

“Toronto's Billy Bishop airport could not currently handle the Challenger 650 jet at full capacity, with its 3,988-foot runway. Recently, Ford said his government plans to take over the City of Toronto's stake in the island airport to expand the runway and allow jets to fly in and out.”

I called it! Ford wanted to change the airport only so his own personal government paid jet could take off from downtown.

The same reason why bike lanes had to be removed - because it slows down Your Highness Fnord II

https://www.cbc.ca/news/canada/toronto/doug-ford-jet-airport-runways-9.7172500

#topoli

cbc.ca
2
3
4
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@carlwgeorge@fosstodon.org will pick it up tomorrow and do your review , thanks !!
1
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

RE: @sash@hachyderm.io

Interesting story about accidental trust

hachyderm.io
1
0
1
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

Did anyone write a copy.fail exploit yet that does the equivalent of initcall_blacklist=algif_aead_init so that it disabled itself on the running kernel? For those of us with large scale amount of running kernels that take time to replace :)

1
2
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

#fedora Anyone up for a quick re-review of a package that accidentally got orphaned that I'm taking back? Been stalled for a week now :/

Willing to counter-review something too :)
https://bugzilla.redhat.com/show_bug.cgi?id=2460762

defcon.social
1
2
1
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@wdormann it seemed my VM was on 6.18.7–100 and hadn’t pulled in the updates yet
1
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@wdormann @CliffsEsport fedora was vulnerable to me (maybe not if a kernel got released in the last few hours but otherwise yes it’s vulnerable )
1
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

RE: @torrentfreak@defcon.social

This was always going to happen. This is why DNS needs to re-decentralize

defcon.social
1
0
1
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@dvzrv @freepg @hko gnupg is dead
1
3
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@andrewg @dvzrv @freepg @hko I meant dead as in Hari Seldon 😀
1
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

RE: @bbcnews@flipboard.com

Wow - th Gravy Plane ride is over ? I think Trump corruption got so bad, Canadians are finally seeing our own version of utterly corrupt (fake thermen, hotels as casinos, science centre rebuild kickbacks, GreenBelt scam)

flipboard.com
1
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago

#topoli I wondered why Ford was mucking with the island airport rules. Since there is basically no construction there, there isn’t any money to hand out to his friends. But then he made Ontario buy himself a private jet and it all made sense

defcon.social
0
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago
Replying to
@atoponce@fosstodon.org the person with a real fix, design, implementation, benchmark and science report, for FIPS and non-FIPS, was Stephen Mueler. Sadly, the Linux cabal picked the wrong successor - abandoning strong science
0
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 3mo ago
Replying to
@mikalai@privacysafe.social if they blindly do what we say, they will use the RECOMMENDED=Y entry for the hybrid. But also, browsers and web servers won’t offer it with a higher preference than hybrid, so no your bank connection will use the hybrid.
0
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 4mo ago

RE: @Daojoan@mastodon.social

I am looking at you, “Best Buy Marketplace” et all.

mastodon.social

JA Westenberg: "The Costco theory of the internet: People are ti…" - Mastodon

0
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@wdormann weird because I had a successful test on up to date f42 yesterday …
0
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago
Replying to
@atoponce@fosstodon.org didn’t Jason add a SHA1 there somewhere to “fix it” after he took over from Theo Tso ?
0
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@adamshostack “assume, I am about to fail, how will AI that’s over my head to use, save me?”
0
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@adamshostack its a bit of a leading question. 🤣
0
3
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 1w ago
I don’t wish an agonizing slow deathbed on anyone, but apparently I need to make an exception for Pope Leo XIV
0
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 2mo ago
Replying to
@durumcrustulum.com TLS day
0
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@neverpanic@chaos.social been playing with this and it’s exactly what I wanted ! Thanks !
0
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@owen yes I reached the point where I want to run curve448 instead of curve25519 so I can run things without any djb algo
0
0
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@adamshostack@infosec.exchange @jpmens@mastodon.social not if you use them as forwarder - only when you use them as trust endpoint. It’s the users choice on how to configure their dns
0
0
1
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 1w ago
Replying to
@durumcrustulum@ioc.exchange “Pope Leo XIV called for an end to medically assisted suicide during a visit to medical facilities in Lourdes, France, on Sunday”
0
1
0
0
Open post
Paul Wouters 🇪🇺🇨🇦 @letoams@defcon.social
· 5mo ago
Replying to
@jap@mastodon.nl seconds to minutes - just delete the DS for the domain
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:51:04 UTC