and it's remarkable how """low-level""" programmers think because you're responding to hardware error states that means your software MUST be the MOST half-assed unstructured bullshit at all times
the very first time i've ever once considered whether a backslash escape was adding too much complexity into a language was a badinage with @ska and @navi about parsing kernel command lines after i mentioned having to work around both the linux kernel and the node.js Console object to produce a backwards-compatible fix for coffeescript v2 shebang lines https://coffeescript.org/#breaking-changes-argument-parsing-and-shebang-lines and after an initial arrogance https://circumstances.run/@hipsterelectron/114994260313214101 recognized i was getting schooled by the aang and katara of shell command-line parsing and started taking notes
https://circumstances.run/@hipsterelectron/116209213401859882 i stand by this phrasing quietly iconoclastic -- describing how simple and significant it was to my entire mode of thinking around this problem space when @ska proposed to me for the first time that a backslash isn't just a tool it's necessarily a whole self-interacting dynamical system
wikipedia tries very hard to center the worship of icons https://en.wikipedia.org/wiki/Iconolatry and to pathologize responsess to it as a form of intolerance
conolatry was mainly manifested in popular worship, as freedom of worship while others viewed it as superstitious belief in the divine nature of icons or deities
that's an absolutely classic anti-intellectual line of argument and it's a favorite tactic of the tyrant microsoft e.g. in response to any reference to copyleft license protocols
Both extreme positions, iconolatry and iconoclasm, were rejected in 787 by the Second Council of Nicaea,
by this we can infer that modern-day liberal centrism is at least a thousand-year-old invention, although i believe tall tales about the followers of pythogoreas and their supposedly violent[citation needed] reaction to the concept of irrational numbers have sought to push it back another millennium into the historical record
@hipsterelectron this is an insanely based take by the way. this is the same reason why I am on a mission to kill the toolchain.
everyone is bamboozled by images! I know this because they genuinely see the toolchain stages as fixed objects, an actual firmament. they can't imagine any other configuration of flows or order of operations.
"you're actually the idiot for thinking that the dogma of the dragon book isn't the best possible way"
sure, I wrote 2 entire proprietary compilers and a bytecode interpreter for proprietary chips, one of which was designed by me, and I don't know anything. ok sure thing
"irrationals" do not even exist as a distinct concept without the thoroughly unnatural and much later imposition of "cartesian" "coordinate" "systems" as an approximation of topological and geometric measure theory, imho
this a fucking abombination imho
A Device Path is terminated by an End of Hardware Device Path node. This type of node has two sub-types ( Device Path End Structure):
End This Instance of a Device Path (sub-type 0x01). This type of node terminates one Device Path instance and denotes the start of another. This is only required when an environment variable represents multiple devices. An example of this would be the ConsoleOut environment variable that consists of both a VGA console and serial output console. This variable would describe a console output stream that is sent to both VGA and serial concurrently and thus has a Device Path that contains two complete Device Paths.
End Entire Device Path (sub-type 0xFF). This type of node terminates an entire Device Path. Software searches for this sub-type to find the end of a Device Path. All Device Paths must end with this sub-type.
bolded emphasis mine because this takes a description of a tree, one of the most well-characterized graph classes in human history, and makes it sound like a dark souls boss. it's really impressive stuff
and it still fails to describe the mechanisms or constraints or use cases of this hypothetical time-varying data flow process they just proposed. the structure they handwave over a pipelining output process seems only to inhibit system flexibility, not to capture its semantics at all (except perhaps inasmuch as it represents, in the form of code, which corporations have decided to do business with each other through the unregulated marketplace of software interfaces
first result on their fucking website when you try to find an actual goddamn specification https://uefi.org/sites/default/files/resources/UEFI_PQC_Update_Whitepaper_Final.pdf
UEFI Post-Quantum Cryptography: UEFI Specification Updates
if your fucking hardware specification is so brittle it has to know and care about the internecine political horse races between different groups of academic cryptographers who have made never ever solving the problem of their field into a performance art form, it's over. you're not doing a hardware specification at that point you're just selling cloud services for the BIOS
The advent of quantum computing poses a significant threat to the cryptographic algorithms
that underpin the security of modern computing platforms.
directly and provably false
Algorithm such as RSA2048, which is
widely used in UEFI Secure Boot and authenticated variable, is vulnerable to quantum attacks.
it's also vulnerable to rubber hose cryptanalysis (the modern iteration of this involves freezing RAM sticks). the security of any cryptosystem lies in the state-changing semantics it exposes to external and internal actors to control its behavior. the only perfectly secure system is one which contains no data and represents nothing of significance to any individual or group. /dev/null continues its reign over the title of Most Secure
of course it's microsoft
Over the last year, the UEFI Secure Sub Team (USST), a sub-team of the UEFI Specification
Working Group (USWG),
yeah
has met to define a path forward for several current and emerging
challenges:
and it's literally all just mathwashed jargon for monopolistic coercion processes to force users to "refresh" their perfectly working hardware due to a constructed maze of DRM schemes
- Adoption of post-quantum cryptography (PQC) for UEFI features and platforms
computers of course always have to be swapped out completely whenever you want to start doing different types of math with them
- Impacts of the 2011 UEFI Secure Boot key expiration on in-market PCs
literally just DRM to juice stock market timetables
- Review of the UEFI security features and common implementation/usage patterns, andthe depreciation of unused and unnecessary complexity
declaring any actual engineering and design colloration processes that unfuck the fucked system to be not only INCOMPATIBLE with the new spec, but in fact representative of an ILLEGAL state. just like TLS 1.3
https://www.cloudflare.com/learning/ssl/why-use-tls-1.3/#what-is-a-vulnerability
What is a vulnerability?
cloudflare teaches kindergarten students about 9/11
Cloudflare prioritizes supporting all the latest, most secure versions of networking protocols. Cloudflare immediately offered support for TLS 1.3; in fact, Cloudflare supported TLS 1.3 back in 2016, before the IETF finished fine-tuning it.
"all the latest, most secure versions" would make another great t-shirt to wear to a conference
MC Hammer, like SSL, was popular in the 90s.
the alt text on this image that takes up an entire screen of vertical space on this page about security protocols is literally just the text "MC Hammer". curious how they fetishize the black male body as a marker of unrestricted hedonism, like the first version of "SSL" that was never published by netscape because elgamal couldn't keep a straight face when telling investors it was totally going to secure their internet connections real fucking tight boss, just like you asked
MC Hammer has produced lasting art and beauty that connects people across time and space. TLS 1.3 has produced a version negotiation protocol that that induces a fugue state into any attempted implementor of its horrifyingly evil state machine
jesus fucking christ i can't believe the backdoor introduced into "post-quantum" linux module signing back in march by red hat/IBM employee david howells and waved through by linus himself over the weekend was literally just "goto fail" https://www.imperialviolet.org/2014/02/22/applebug.html
it would have been so fucking easy to explain it to a journalist that way
This sort of subtle bug deep in the code is a nightmare. I believe that it's just a mistake and I feel very bad for whoever might have slipped in an editor and created it.
actually, it's an incredibly fucking involved process:
- generating a checksum for a data stream,
- decrypting the given signature against someone's public key,
- verifying the decrypted payload matches your own computation of the same result,
and shoehorning all of that into the interface of a boolean predicate with early-return semantics would never pass any form of code review. that's not a fucking mistake
if you fuck up a checksum, then the signatures are different until you fix it, which would return the "oh shit someone is hacking your connection rn!!!!" response code. the system fails closed, like a nuclear reactor that successfully adheres to the incredibly deep construction of layered safety mechanisms that can't be silently overlooked
TLS was designed by engineers using tools from mathematicians.
false. TLS is a performance art piece developed by a collective of unnamed artisans working furiously over decades to develop a creole language derived from the orthographic forms of the prestige language of rennaisance-era european mathematical notation and the ASCII-annotated conventions of US english through the IETF's regular sponsorship of widely-read works of modern literature advancing the linguistic form through the RFC process
https://www.theawl.com/2015/08/literary-magazines-for-socialists-funded-by-the-cia-ranked/ fun fact: the paris review was created by two separate CIA agents during the era of bloody US colonialist violence across south america and eastern europe throughout the 70s and 80s, along with sponsoring a huge quantity of spanish and even arabic and russian literature, largely without any editorial involvement by the CIA at all. most of it was just money laundering on a massive scale, especially through the philanthropic foundations of extremely rich and famous US businessmen. only very rarely would they have to show their hand as censors if instead they can be hailed as supporters of underrepresented political and minority groups. joel whitney wrote a fantastic book called Finks on this process https://www.joelwhitney.net/ the term comes from their collegiate-level recruitment processes
TLS was 90s crypto: It meant well and seemed cool at the time, but the modern cryptographer’s design palette has moved on.
the 90s was literally the last time academic cryptography would ever produce a single original or useful idea
what was the showstopper surprise failure for TLS 3.0? https://en.wikipedia.org/wiki/POODLE#POODLE_attack_against_TLS
This attack exploits implementation flaws of CBC encryption mode in the TLS 1.0 - 1.2 protocols. Even though TLS specifications require servers to check the padding, some implementations fail to validate it properly, which makes some servers vulnerable to POODLE even if they disable SSL 3.0.[5]
whitfield diffie described a feasible attack against DES in fucking 1976!!!!!!!! https://en.wikipedia.org/wiki/Whitfield_Diffie
In 1975–76, Diffie and Hellman criticized the NBS proposed Data Encryption Standard, largely because its 56-bit key length was too short to prevent brute-force attack.
https://ee.stanford.edu/~hellman/resources/1976_sel_des_report.pdf
this man did not type out a 50-page report on a typewriter in 1976 to have google employees start naming The Same FUcking Vuln Again after a fucking poodle
DIFFIE'S DAD WAS A HISTORIAN OF THE BASQUE SEPARATIST MOVEMENT AND THAT'S HOW HE GOT HIS KID INTO CRYPTO???????? https://en.wikipedia.org/wiki/Whitfield_Diffie
they really play up his "poor grades in school" way too much though. sorry if you got into MIT as an undergrad your brain simply does not work the way mine does. i always failed the literal shape rotation examinations because people still act like being smart is about not making mistakes while performing an unambiguously measureable and preferably timed task. literally just video game logic
https://blog.cloudflare.com/rfc-8446-aka-tls-1-3/#~:~:text=TLS%201.2%20is%20slow
For a browser and web server to agree on a key, they need to exchange cryptographic data. The exchange, called the “handshake” in TLS, has remained largely unchanged since TLS was standardized in 1999. The handshake requires two additional round-trips between the browser and the server before encrypted data can be sent (or one when resuming a previous connection).
you can literally just send a chunk of data along with the cryptographic handshake both ways--that's literally how signal's x3dh protocol works to initiate a message chain http://codeberg.org/cosmicexplorer/grouplink
The additional cost of the TLS handshake for HTTPS results in a noticeable hit to latency compared to an HTTP alone. This additional delay can negatively impact performance-focused applications.
latency-focused applications are just lobbing packets into the ether over UDP anyway--the TCP stream abstraction was always a ridiculous fucking lark to enforce all the way down in the stack like that and anyone who took vint cerf's injection of TCP into UNIX/BSD seriously instead of writing their own RPC system in an OS they engineered from scratch like andrew tanenbaum's fucking incredible amoeba OS https://www.cs.vu.nl/pub/amoeba/Intro.pdf has simply never been exposed to any "performance-focused applications"
Hellman then hired Diffie as a grant-funded part-time research programmer for the 1975 spring term. Under his sponsorship, he also enrolled as a doctoral student in electrical engineering at Stanford in June 1975; however, Diffie was once again unable to acclimate to "homework assignments [and] the structure" and eventually dropped out after failing to complete a required physical examination: "I didn't feel like doing it, I didn't get around to it."[9] Although it is unclear when he dropped out, Diffie remained employed in Hellman's lab as a research assistant through June 1978.[12]
me when i keep putting off emailing potential grad school advisors cause i keep discovering new shit
"From the moment Diffie and Hellman published their findings..., the National Security Agency's crypto monopoly was effectively terminated. ... Every company, every citizen now had routine access to the sorts of cryptographic technology that not many years ago ranked alongside the atom bomb as a source of power."[8]
literally the polar opposite of an atom bomb and cannot be used to harm anyone but yes in fact this is one of the few clear-eyed and lucid evaluations of the significance of modular exponentiation and its incredible ability to propagate a sanctuary of absolute safety across an arbitrarily adversarial channel
As a general rule, public key crypto is slow and expensive (microseconds to milliseconds per operation) and symmetric key crypto is fast and cheap (nanoseconds per operation).
so wildly false and misleading it generates a rotating fractal kaleidoscope of falsehoods:
- asymmetric crypto using modular exponentiation in finite fields produces a form of "randomness" that cannot be guessed by the attacker without a corresponding exponentially-scaled computational and memory investment.
this is completely distinct from the task of symmetric encryption, in which highly structured data (typically totally-ordered bit strings) must be invertibly encoded
- literally every single symmetric encryption process relies upon modular exponentiation in finite fields to generate a secure stream of randomness to form the symmetric key stream. it's literally part of the problem definition!!!
so separating out that part from the rest of "symmetric" crypto is a really strange way to zoom in on an execution profile flamegraph
more generally:
- every single symmetric encryption process to date operates upon fixed-size blocks of message state, which imposes a fundamental limitation upon its ability to resist cryptanalysis. AES is still limited to blocks of literally fucking 128 bits!
modular exponentiation scales with the computational power of the attacker--there's nothing i've found whatsoever that works like this in the space of symmetric crypto.
@hipsterelectron
(The Graduate voice) I just wanna say one word to you son... FORTH