@npub12tsc...x422 Hey why are fascists and antivaxxers being platformed at DEFCON this year? Are you afraid to tell them no? I'm happy to do it if you guys aren't.
If I make a post complaining about an annoying behavior, and we aren't close friends, doing that exact behavior isn't going to endear you to me. I just block.
Age Verification Doesn’t Need to Be a Privacy Footgun
"Won't someone think of the poor children?" they say, clutching their pearls as they enact another stupid law that will harm the privacy of every adult on Earth and create Prior Restraint that inhibits the freedom of speech in liberal democracies. Art: CMYKat If you're totally ignorant of how things work, the proposal of "verifying you're an adult" before you access adult content sounds, superficially, like a…
Against the Censorship of Adult Content By Payment Processors
This is a furry blog, where I write about whatever interests me and sign it with my fursona's name. I sometimes talk about furry fandom topics, but I sometimes also talk about applied cryptography. If you got a mild bit of emotional whiplash from that sentence, the best list of posts to start reading to get a feel for my usual fare is…
The Hacker News thread about Go 1.24's crypto/fips140 module being validated by FIPS 140-3 is full of misconceptions and it's too exhausting to reply to them all.
https://news.ycombinator.com/item?id=44575607
Before I begin, don't call it "FIPS certified". You have "validated modules", not certifications. This isn't CompTIA.
Broadly speaking, FIPS module validation has very little to do with actual cybersecurity. FIPS doesn't make you more secure.
FIPS is the minimum bar you must clear in order to sell to US government customers. Some non-US entities also care about it, but mostly you only give a shit if you want to sell to the US gov.
If you don't care about that, you don't care about FIPS. You're free!
Most developers shouldn't care about FIPS.
The handful of developers that *need* to care about FIPS will be well-served by Go's crypto module being validated, as it provides a memory-safe implementation of these algorithms that isn't Java.
In short, FIPS ain't what many HN users think it is.