Filippo Valsorda

@filippo.abyssdomain.expert

RC F'13, F2'17 Cryptogopher / Go cryptography maintainer Professional open source maintainer https://filippo.io / https://github.com/FiloSottile https://mkcert.dev / https://age-encryption.org https://sunlight.dev / https://filippo.io/newsletter

Paging @masnick.com to the Streisand effect courtesy phone. An “engine problem“ is a complete non-issue and it was corrected in 24h! But Go2Sky sued @avherald.com! Now I’m reading about their 2016 incident they wanted to hide, and I’d never, ever fly an airline with this approach to transparency.

The Aviation Herald@avherald.com · 5d ago

REVOCATION: The post published by us on 04.07.2025: “Incident: Go2Sky B738 at Zakynthos on Jun 29th 2025, engine trouble #B738 #OM-GTK #OR-1238 avherald.com/h?article=529de372” is untrue. We hereby revoke this statement. For explanation see https://avherald.com/h?article=53c8958a

Also: HAWK’s entire foundation was very new—just 4-5 years old, an infant by cryptographic measures! Most brand-new cryptography gets broken or severely weakened before long. This is normal and good. Now AI will help speed up that process more systematically.

Filippo Valsorda@filippo.abyssdomain.expert · last wk.

I'm seeing folks draw the wrong conclusion (in good faith or not) from the HAWK attack. HAWK is a scheme that 1. cryptographers were suspicious of and 2. was still in the assessment process. A break is GOOD. It means the process is useful, and it INCREASES confidence in the selected algorithms.

I'm seeing folks draw the wrong conclusion (in good faith or not) from the HAWK attack. HAWK is a scheme that 1. cryptographers were suspicious of and 2. was still in the assessment process. A break is GOOD. It means the process is useful, and it INCREASES confidence in the selected algorithms.

I know it’s not most folks‘ primary concern, but LLMs or not, I’m unimpressed by how soft these infrastructure services are. What do you mean HF had a Jinja2 template injection. And I’m still not over GitHub’s unsandboxed RCE. Geomys might need to self-host code/CI to avoid a weak link.

JFrog Xray is defective, flagging unaffected binaries as vulnerable, and the cost is borne by maintainers who have to field requests to work around it. This is a real open source sustainability issue. (The problem here is JFrog, not the person who politely opened the issue.)

v1.3.1 release binaries embed Go toolchain vulnerable to CVE-2025-68121 (crypto/tls session resumption) · Issue #730 · FiloSottile/age

Summary The published v1.3.1 release binaries appear to be built with a Go toolchain that predates the fix for CVE-2025-68121 (Go issue golang/go#77217), a crypto/tls session-resumption vulnerabili...

github.com

The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised. blog.pypi.org/posts/2026-0... #python #security #supplychain #pypi

Releases now reject new files after 14 days - The Python Package Index Blog

PyPI no longer allows publishing new files to releases older than 14 days.

blog.pypi.org

Passkeys can be stored just like password hashes! I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication. I'm looking for feedback before proposing this as crypto/passkey for Go 1.28!

Opaque, Interoperable Passkey Records (and a Go API)

Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.

words.filippo.io

Getting kinda uncomfortable with the Zig dunking, which AFAICT is entirely based on the tone of one of Andrew's posts? For example, supporting Fil-C as a build target makes IMHO perfect sense for Zig, a language where embedding C code is a flagship feature.

Me: lots of urgent stuff to do, what should I pick? Brain: actually, here's a thought about passkeys, let's do some research, develop opinions, and then write a library, a spec, and a newsletter Me: ಠ_ಠ

Setting up Gerrit on @exe.dev with X-ExeDev-Email auth took 60s! However, that doesn't make git work. I hacked together a little proxy that does a tiny amount of OAuth2, exchanging exe.dev auth in the browser for a token that works with git-credential-oauth.

GitHub - filippo-claude/gerrit-exedev-auth-proxy: Authenticate Gerrit web and Git smart HTTP with exe.dev OAuth

Authenticate Gerrit web and Git smart HTTP with exe.dev OAuth - filippo-claude/gerrit-exedev-auth-proxy

github.com

excited to talk about the (mostly) boring vulns we have, with a slight digression about how LLMs have completely turned the way vulns are found upside down 🙃

GopherCon@gophercon.com · 4w ago

If Go is memory-safe, where do its vulnerabilities come from? 🔒 Go Security Team Lead @roland.zone shares how the Go team identifies, responds to, and learns from vulnerabilities across the Go ecosystem. Discover what those lessons mean for building more secure Go software. 🎟️ gophercon.com

I'm so jealous. Wikipedia banned THE CO-FOUNDER for off-wiki canvassing. Meanwhile the IETF is burning endless cycles on Bernstein's explicit WGLC external influence campaign and handing out one-month moderation periods over his silly sovereign citizen footers.

Wikipedia Banned Its Co-Founder Because Its Rules Mostly Work, Actually

In Larry Sanger’s recent failed attempt to start a “WikiProject Intellectual Diversity”, he tried to recruit his followers to help him change Wikipedia’s rules around representation of viewpo…

techdirt.com

A few people have asked me recently about how OpenSSH sshd implements privilege separation after the changes of the last couple of years, such as splitting sshd into multiple binaries. I finally got around to writing it up - please take a look if you're curious. github.com/openssh/open...

openssh-portable/README.privsep at master · openssh/openssh-portable

Portable OpenSSH. Contribute to openssh/openssh-portable development by creating an account on GitHub.

github.com

We're making good progress on upki, our collaboration with the rustls project to bring browser-grade web PKI capabilities to low level system utilities. #Canonical made a PPA available so you can try out upki in #Ubuntu. Give it a go and let us know! discourse.ubuntu.com/t/try-the-up...

Try the `upki` preview for Ubuntu!

The development of upki has been steadily progressing over the past few months. Since my last update, the project has released a beta version of the CLI tool and library, and the Ubuntu Foundations te...

discourse.ubuntu.com

We know vulnerability reports are not like ordinary issues. But why? It comes down to needing the scarce insight and temporary confidentiality to protect users. However, now that LLMs can find more or less the same bugs for everyone, none of that matters, and vuln reports are not special anymore.

Vulnerability Reports Are Not Special Anymore

We needed the insight and confidentiality to protect our users, but now that anyone can get the same results from LLM?

words.filippo.io

There we go. US Gov tightens post-quantum cryptography transition deadlines for high-value systems to 2030 for key exchange and 2031 for signatures. Also, speeding up the CMVP (FIPS 140 validation) processes. That’s how you know the rush is real. The quantum computers are (potentially) coming.

Securing the Nation Against Advanced Cryptographic Attacks

By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered: Section 1.  Background

whitehouse.gov