Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Filippo Valsorda

@filippo@abyssdomain.expert
mastodon 4.7.3
  • Open on abyssdomain.expert

RC F'13, F2'17
Cryptogopher / Go cryptography maintainer
Geomys founder (https://geomys.org)

https://mkcert.dev / https://age-encryption.org / https://sunlight.dev

🕳️ “Gaze not into the abyss, lest you become recognized as an abyss domain expert, and they expect you keep gazing into the damn thing.” —@nickm@abyssdomain.expert

https://filippo.io/newsletter

13804 Followers
425 Following
50 Posts
Joined December 07, 2022
Location:
Rome 🇮🇹
Pronouns:
he/him
Website:
https://filippo.io
GitHub:
https://github.com/FiloSottile
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 3w ago
Oh damn I had not seen the details of the MicroTik RCE: the client can send a public RSA key with correct N and e = 1 and the server will use it. Two primitives/protocol things that would have prevented it: if RSA was defined with a fixed e, and if SSH clients sent a key hash instead. https://github.com/advisories/GHSA-j9wg-77fw-f22f
CVE-2026-67276 - GitHub Advisory Database
GitHub

CVE-2026-67276 - GitHub Advisory Database

RouterOS does not compare the complete RSA public key...

29
1
15
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 1mo ago

I used to be very good at playing the getting-hired and negotiation games, on behalf of myself and others.

Times have changed, and I've probably lost the pulse, but now, like back then, a big part is understanding what game the other side is playing.

This is a very good post to read for early- and mid-career folks: https://lobste.rs/s/mroowi/being_kicked_out_tech_industry#c_tvw4yk

Being kicked out of the tech industry
Lobsters

Being kicked out of the tech industry

215 comments

35
0
12
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 3mo ago
In 2020, OpenSSL had a vulnerability in handling the signature_algorithms_cert extension. https://openssl-library.org/news/secadv/20200421.txt Palo Alto apparently "solved" this in their IPS by blocking connections with "unknown" algs in signature_algorithms_cert. Six years later, we can't add ML-DSA to signature_algorithms_cert in Go. signature_algorithms_cert is dead. Sigh. Thanks to @cks@mastodon.social for diagnosing this. Sometimes it takes us months to figure out things like this. https://github.com/golang/go/issues/79626#issuecomment-4754225610
openssl-library.org
121
8
92
3
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 2mo ago
Passkeys can be stored just like password hashes! I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication. I'm looking for feedback before proposing this as crypto/passkey for Go 1.28! https://words.filippo.io/passkey-record/
Opaque, Interoperable Passkey Records (and a Go API)
words.filippo.io

Opaque, Interoperable Passkey Records (and a Go API)

Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.

49
8
30
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago

Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years.

That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.

https://words.filippo.io/crqc-timeline/

A Cryptography Engineer’s Perspective on Quantum Computing Timelines
words.filippo.io

A Cryptography Engineer’s Perspective on Quantum Computing Timelines

The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.

217
66
226
3
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 1mo ago

Ok, I think the ML-DSA performance side quest might be complete 🏎️

Very proud of how safe and clear the final incremental changes are, too.

13
0
5
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 1mo ago

ML-KEM and ML-DSA fill matrices/vectors with output from SHAKE, each element derived from slightly different inputs.

This is perfect for SIMD instructions, so now we have

func ReadMulti(s []*SHAKE, out [][]byte)

backed by AVX2 on amd64, and by the existing two-lane asm on arm64.

https://go.dev/cl/818720

go.dev
15
0
5
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 1mo ago

I am so happy we can now divinate precise diagrams in minutes to help reason through complicated code.

(This is the "butterfly" of the Number Theoretic Transform used in ML-DSA. You can make it a lot faster by not reducing non-overflowing intermediate states, but I had to convince myself that they do not, in fact, overflow.)

12
0
1
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago

Alright, it's official! 💰

@matthew_d_green@ioc.exchange and I bet on what will break first, ML-KEM-768 or X25519. The loser donates to a 501(c)(3) picked by the winner.

If you have an opinion on quantum computers or lattices, you can join with a side bet. Just submit a PR!

https://github.com/FiloSottile/ecc-vs-lattices-long-bet

ioc.exchange

Matthew Green (@matthew_d_green@ioc.exchange) - IOC.exchange

101
15
78
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 2mo ago
It's not my usual beat, but I wrote a pure-Python ML-DSA verifier. pip install mldsa It's 350 lines, CC0/0BSD, single-file, no dependencies, and thoroughly tested. Signature verification handles no secrets, so it doesn't need to be constant-time. https://words.filippo.io/mldsa-py/
Production ML-DSA Verification in 350 Lines of Python
words.filippo.io

Production ML-DSA Verification in 350 Lines of Python

I am publishing a production, pure-Python ML-DSA verifier. It's just 350 lines, and pretty readable and robust.

15
1
6
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago

Oh hey, with all the 🔥 I almost missed that today was the 12th anniversary of Heartbleed.

The online test I cobbled together that night gave me the opportunities to get started in this line of work!

Initially it was hilariously bad: a Flask server shelling out to a patched Go crypto/tls binary.

75
4
25
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago

There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers.

This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.

https://words.filippo.io/128-bits/?source=Mastodon

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
words.filippo.io

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys

There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.

57
6
41
2
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago

Looks like GitHub silently corrupted some index.

PR #237 definitely exists and is closed (https://github.com/C2SP/C2SP/pull/237) but is just... not in the list (https://github.com/C2SP/C2SP/pulls?q=is%3Apr+is%3Aclosed) regardless of filters.

I briefly doubted my own sanity. This is bad.

GitHub

tlog-cosignature: add ML-DSA-44 subtree cosignatures by FiloSottile · Pull Request #237 · C2SP/C2SP

The quantum computer timelines are getting more worrying, so we need a post-quantum signature algorithm for the tlog ecosystem. ML-DSA seems to be the algorithm all the implementation, analysis, an...

41
16
17
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago

How much storage / bandwidth / CPU / memory does it take to run a production Sunlight CT log? Surprisingly little!

There's now a public stats page, pulled every 5m from our Tuscolo prod metrics.

https://stats.sunlight.geomys.org/

Less than 2 cores, 300 MB of memory, ~250 Mbps of bandwidth, 260 GiB of SSD.

stats.sunlight.geomys.org
40
11
17
1
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Boosted by @ferrix@mastodon.online
I wrote up in the TLS mailing list why I think composite signatures (ML-DSA + ECDSA/RSA) are a net negative, will hurt the ecosystem, and should not be implemented. Hybrid key exchange was simple and self-contained. Hybrid signatures would be a mountain of complexity in code responsible for half of sev:crit in crypto libraries since 2020. https://mailarchive.ietf.org/arch/msg/tls/oh3jmmkHzHdp1hk4R4M9QjkmvBk/
mailarchive.ietf.org

[TLS] Re: Composite ML-DSA

Search IETF mail list archives

34
3
27
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago

Last year, my position was that we still had time to design PQ authentication mechanisms.

Now, based on the pace of progress and on statements like Google's, I believe:

1. we need to finish rolling out PQ key exchange yesterday
2. we need to start rolling out PQ auth now
3. it's too late to ship any new non-PQ design or system

https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/

Quantum frontiers may be closer than they appear
Google

Quantum frontiers may be closer than they appear

An overview of how Google is accelerating its timeline for post-quantum cryptography migration.

39
8
25
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 4mo ago

Can you see how to use a test vector that provides (seed, public key, message, µ, signature) to test a deterministic signing API that does (seed, message) → (signature) or a key generation API that does (seed) → (public key)?

Noted cryptographer D. J. Bernstein can't, certainly in good faith.

*sigh*

I jest, but refuting this FUD takes real resources we could spend so, so, so much better. It'd be sad if it wasn't so harmful.

https://mailarchive.ietf.org/arch/msg/tls/p5j6UCQGBAOblWPAjXb5ycMjxA4/

mailarchive.ietf.org

[TLS] Re: [Last-Call] Last Call: <draft-ietf-tls-mldsa-03.txt> (Use of ML-DSA in TLS 1.3) to Informational RFC

Search IETF mail list archives

18
4
7
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 4mo ago

There's been some confusion around some BRs non-compliant X.509 chains that OpenSSL accepts but Go rejects.

We're not going to introduce complexity in crypto/x509 to support them, but I realized you could always re-encode the issuer as an unsigned root to work around it.

So I made a little web tool to make it easy.

https://github.com/golang/go/issues/31440#issuecomment-4663196149

GitHub

crypto/x509: unexpected name mismatch error · Issue #31440 · golang/go

What version of Go are you using (go version)? Sorry, I'm not actually using Go itself, but I'm using etcd (https://github.com/etcd-io/etcd; apparently written in go) and got an error about subject...

13
1
5
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
If you'd like, you can buy a number of services from us, including rebrands and listed Operating Environments: https://geomys.org/fips140 However, you don't have to. Our certificate has one of the broadest list of tested environments (and algorithms) of the industry, and you can just use it with stock Go 1.24+ and GOFIPS140=v1.0.0, courtesy of Geomys. Because the point was removing this roadblock to Go adoption.
geomys.org

Geomys FIPS 140-3 Services

20
3
5
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago

There was no good way to see what CT logs are actually used by CAs, so I made a dashboard of Censys data on exe.dev.

There are some interesting patterns, but the main one is that Let's Encrypt is the only CA that evenly spreads load. Other CAs are mostly using older logs, or their own logs and Google's.

(Of course, LE is 50% of issuance, and GTS is 25%, so the rest don't matter much.)

https://groups.google.com/a/chromium.org/d/msgid/ct-policy/718571cb-a841-4102-bcfa-3fe3feab63ae%40app.fastmail.com

groups.google.com
22
3
11
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago

RE: @sophieschmieg@infosec.exchange

Yay test vectors!

I will write properly about this, but we are going pretty far to test ML-DSA *and make it easy to test,* so I am hopeful ML-DSA bugs will be rare compared to classical [EC|Ed]DSA bugs.

These test gaps were identified by writing multiple alternative ML-DSA implementations and mutation testing *those* to find missing vectors to then bring back to the Go implementation, and share on Wycheproof.

infosec.exchange

Sophie Schmieg: "Last time I had a 10+ hour flight, Opal nerd snip…" - Infosec Exchange

20
0
5
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago

I finally chased down test coverage for the last edge cases of ML-DSA's low-level, constant-time field operations like Decompose.

This is an accumulated (https://words.filippo.io/accumulated/) test that locks in the output for all possible inputs of all these tricky functions. https://go.dev/cl/762940

It's not even that slow (5.27s)!

Also available on CCTV, along with accumulated keygen/sign/verify tests worth 60M random tests: https://github.com/C2SP/CCTV/tree/main/ML-DSA/accumulated

Accumulated Test Vectors
words.filippo.io

Accumulated Test Vectors

Accumulated test vectors make it possible to run large sets of random known-answer tests without checking in large assets.

13
0
2
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago

NIST is updating SP 800-133, which details the "FIPS approved" ways to generate keys.

There's a lot of good news in it, it approves a lot of stuff we were doing, like X-Wing seed derivation and https://c2sp.org/det-keygen.

Here are my comments: https://leaflet.pub/f6fc0b3b-161d-4e35-99cd-e95ad62402a5

c2sp.org

Deterministic Key Generation | C2SP

Deterministic key pair generation from seed

10
0
6
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to

A brief timeline of the Go FIPS 140-3 validation:

  • February 2024: first prospectus
  • March 2024: started working with lab
  • July 2024: first contract
  • September 2024: opened issue
  • January 2025: froze module
  • May 2025: submitted validation
  • April 2026: certificate issued
9
2
2
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 4mo ago

I am live with Alex Gaynor to talk about the Geomys model of professional open source maintenance and how it helps projects face challenges, like the recent influx of LLM vulnerability findings!

Join us live on https://www.twitch.tv/filosottile right now or catch the recording soon!

twitch.tv
6
0
7
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 7mo ago

TIL about the git fast-import textual format!

Lets me write tests for the c2sp.org redirector against a synthetic git repository I can easily edit, and even gives me stable shorthands to refer to commits.

https://github.com/C2SP/C2SP/commit/99d43ad2adcddb85acf37028be45590cd78008c3

GitHub

.website: add tests based on repository imported from git fast-export · C2SP/C2SP@99d43ad

Community Cryptography Specification Project. Contribute to C2SP/C2SP development by creating an account on GitHub.

12
3
3
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@neverpanic oh Debian oldstable is not gonna make it. stable might not make it! I have a secret, over-optimistic wish that this will kill the "constantly run software 3-5 years out of date" model of distribution, and free us upstreams from having to deal with its fallout, but I know it won't.
7
2
1
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
@scottley @dangoodin that is precisely the misconception the article is trying to rectify.
6
0
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
@ck@chaos.social Yeah the NSA contacted me a few years ago and told me "we would like for all US military and national security to be protected with crypto that Chinese mathematicians can break, can you help us?" It's how I got my Green Card.
6
1
1
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@jornfranke I am a cryptography engineer so I can tell you from experience: no, ML-KEM and ML-DSA are easier to implement and easier to test than all their classical alternatives.
4
3
1
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@sophieschmieg heh, @matthew_d_green would not take my correctly-leveraged bet :P
3
2
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 7mo ago
Replying to
@benjojo@benjojo.co.uk @sa@chaos.social I mean, “left/right 360” is a standard ATC direction to get you into a brief hold or add space in front of you. I wouldn’t be surprised to learn jetliners have an autopilot 360-at-level button.
4
0
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
@neverpanic@chaos.social oh yeah I agree CNSA 2.0 is a whole waste of time, but at least it’s a waste of time with a name and a rationale.
2
0
1
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 7mo ago
Replying to
@jamesog That post makes almost no sense to me. If they are talking about module deps, since Go 1.17 go.mod has all the dependencies, there is nothing dynamic about it. If they are talking about package deps, it's not working.
3
1
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@arianvp I do think they should get moving. But also, a passkey with a broken signature algorithm is still more secure than a password: the attacker needs the public key to fake a signature, and that's only in the website's database. I think it should still be phishing-resistant, too.
2
1
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
@curt now I want to run one on a laptop. Or a Steam Deck!
1
0
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
@dangoodin I have half an hour if you want to text me on Signal about it :)
1
1
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@S1m it's coming! https://github.com/str4d/age-plugin-yubikey/pull/215
GitHub

Add support for `mlkem768p256tag` recipient type by str4d · Pull Request #215 · str4d/age-plugin-yubikey

Based on #213.

1
0
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@timezone I'm afraid so, yes. (With the asterisk that the attacker also needs the public key to use a QC.)
1
0
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@ohir @mikaeleiman nope, the distance between now and Ed25519 is way larger than between Ed25519 and Ed448.
1
0
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@mikaeleiman @ohir yup, it's not great, but it is what it is. (RAM is kinda fine if you optimize for it, and CPU is actually faster than classical. But yes, size sucks.)
1
6
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@jornfranke I encourage you to reread the article because it addresses all your objections, especially the "why did they not break a small key". I will add that the cryptography experts are actually very confident in the security of lattices. https://keymaterial.net/2025/12/13/a-very-unscientific-guide-to-the-security-of-various-pqc-algorithms/
keymaterial.net
1
6
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@S1m it's as safe as it always was, and as safe as if QCs were impossible. (Which is to say very safe, no one really thinks AES will get surprise broken.) \PSKs are fine if you can keep them from being compromised. The scheme you excerpted should be fine if auth_secret is not known to the attacker.
0
3
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
@djc yep! CT is redundant at the ecosystem level already.
0
1
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@timbray yeah, if ML-KEM is broken classically before the CRQCs arrive (after which hybrid doesn't help you anymore). Which part are you responding to?
0
0
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
@freddy can Geomys just sponsor 3x 700GB SSDs (RAID1 with spare) for you to run a prod Sunlight? I am deadly serious!
0
1
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 2mo ago
Replying to
@shaoyu@mastodon.social passkeys can't be phished.
0
2
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 5mo ago
Replying to
@djc 9.41T of available RAID 1 zpool, plenty of bandwidth, 128GB memory, 48 cores. Waaaay overprovisioned.
0
3
0
0
Open post
Filippo Valsorda @filippo@abyssdomain.expert
· 6mo ago
Replying to
@certkit They don't matter in terms of CA write load, monitors definitely need to consume all logs.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:22:01 UTC