<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: some_furry</title><link>https://news.ycombinator.com/user?id=some_furry</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 29 Jul 2026 05:13:10 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=some_furry" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by some_furry in "Discovering Cryptographic Weaknesses with Claude"]]></title><description><![CDATA[
<p>I wouldn't worry about too many mathematicians adopting the "even AI couldn't solve it" attitude.<p>Business folks riding the hype train? Maybe.</p>
]]></description><pubDate>Tue, 28 Jul 2026 20:56:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49089792</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=49089792</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49089792</guid></item><item><title><![CDATA[New comment by some_furry in "Discovering Cryptographic Weaknesses with Claude"]]></title><description><![CDATA[
<p>> One attack weakens HAWK, a post-quantum cryptography cipher candidate. I don't trust these PQC things one bit. I'll use them in combination with a strong clasically-resistant cipher (in so-called hybrid encryption modes), but not alone.<p>HAWK is a signature algorithm, not encryption.</p>
]]></description><pubDate>Tue, 28 Jul 2026 20:41:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49089654</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=49089654</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49089654</guid></item><item><title><![CDATA[New comment by some_furry in "Don't Take the Black Pill [video]"]]></title><description><![CDATA[
<p><a href="https://codeberg.org/awebo-chat/awebo" rel="nofollow">https://codeberg.org/awebo-chat/awebo</a></p>
]]></description><pubDate>Fri, 24 Jul 2026 19:44:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49040729</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=49040729</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49040729</guid></item><item><title><![CDATA[New comment by some_furry in "Nvidia, Microsoft, Meta warn against overregulating open-weight models"]]></title><description><![CDATA[
<p>To be clear: This isn't a technical discussion, it's a political one.<p>While your point is valid on its own merits, it isn't relevant here.</p>
]]></description><pubDate>Fri, 24 Jul 2026 17:11:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49038674</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=49038674</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49038674</guid></item><item><title><![CDATA[New comment by some_furry in "Nvidia, Microsoft, Meta warn against overregulating open-weight models"]]></title><description><![CDATA[
<p>It's a mix of grifts, gaffes, and <i>Project 2025</i>.</p>
]]></description><pubDate>Fri, 24 Jul 2026 16:06:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49037664</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=49037664</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49037664</guid></item><item><title><![CDATA[New comment by some_furry in "Nvidia, Microsoft, Meta warn against overregulating open-weight models"]]></title><description><![CDATA[
<p>I don't personally have a horse in this race, but if you want to accurately predict the next step:<p>Start with the outcome you believe will be the most in line with the spirit and traditions of the open source community. This is precisely what won't happen.<p>It won't necessarily be the inverse. It could be, of course, but it's also likely to be a compromise between the two.<p>For a topical example: The companies doing "AI" layoffs aren't doing so out of a sense of having failed their staff that helped carry them so far. Often, these announcements come on the heels of record-breaking profits. They're doing it <i>out of contempt for workers</i>.<p>See <a href="https://www.cnet.com/tech/services-and-software/cory-doctorow-reverse-centaurs-alt-view/" rel="nofollow">https://www.cnet.com/tech/services-and-software/cory-doctoro...</a> for Doctorow's take on centaurs vs. reverse centaurs. Broadly speaking: C-suite business leadership wants reverse centaurs. Workers want centaurs. Unless you have a union (or some other collective bargaining power structure that I'm not aware of), the C-suite calls the shots.<p>The same can be said of the current administration. They don't give a fuck what most of us want on any given issue. They're captured by an aggressive ideology. Their only incentive is to be able to spin their decision to make themselves look good; to posture as "strong" leadership.</p>
]]></description><pubDate>Fri, 24 Jul 2026 14:25:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=49036173</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=49036173</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49036173</guid></item><item><title><![CDATA[New comment by some_furry in "Do we just want slaves?"]]></title><description><![CDATA[
<p>It's not that silly of a blogpost. See: "permanent underclass", a term popular among people that believe that an Artificial General Intelligence (AGI) is imminent and <i>desirable</i>.</p>
]]></description><pubDate>Tue, 21 Jul 2026 05:38:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48988463</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48988463</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48988463</guid></item><item><title><![CDATA[We cannot wait for better post-quantum signature algorithms]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/ml-dsa-will-have-to-do/">https://blog.cloudflare.com/ml-dsa-will-have-to-do/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48846731">https://news.ycombinator.com/item?id=48846731</a></p>
<p>Points: 9</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 09 Jul 2026 14:43:23 +0000</pubDate><link>https://blog.cloudflare.com/ml-dsa-will-have-to-do/</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48846731</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48846731</guid></item><item><title><![CDATA[New comment by some_furry in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>You're all over the place except where the discussion was actually taking place.</p>
]]></description><pubDate>Tue, 07 Jul 2026 18:47:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48821895</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48821895</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48821895</guid></item><item><title><![CDATA[New comment by some_furry in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>What does a work of fiction have to do with whether two distinct government entities are the same thing or not?<p>That's beyond moving goalposts. Just take the L, dude.</p>
]]></description><pubDate>Tue, 07 Jul 2026 18:19:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48821506</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48821506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48821506</guid></item><item><title><![CDATA[New comment by some_furry in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>NIST does a lot of things that have nothing to do with computer security!<p>Would you indict NIST MEP <a href="https://www.nist.gov/mep/about-nist-mep" rel="nofollow">https://www.nist.gov/mep/about-nist-mep</a> as being an NSA project without evidence?</p>
]]></description><pubDate>Tue, 07 Jul 2026 17:41:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48821070</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48821070</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48821070</guid></item><item><title><![CDATA[New comment by some_furry in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>Didn't the FDA used to recommend pasteurizing milk?</p>
]]></description><pubDate>Tue, 07 Jul 2026 15:09:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48818920</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48818920</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48818920</guid></item><item><title><![CDATA[New comment by some_furry in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>> You're argument is that I shouldn't think of NIST as a patsy for the NSA,<p>Incorrect. My argument is that they aren't the same entity.<p>The thing you said is a whole different argument. "I like waffles" "So you hate pancakes" is happening.<p>> Incentives are basically all I consider when trying to establish true motive. But you're not required to consider motive when there's a history or pattern.<p>Yes you are. You need to consider both factors. Why render yourself willfully ignorant? That's not how you arrive at truth.</p>
]]></description><pubDate>Tue, 07 Jul 2026 15:06:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48818876</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48818876</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48818876</guid></item><item><title><![CDATA[New comment by some_furry in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>> In the past NSA has weakened encryption standards, for example NSA madified DES standard.<p>They made DES more secure against differential cryptanalysis (a method that was classified at the time DES was being designed). Sure, the whole "make the keys 56-bit instead of 64-bit" is a weakening, but differential cryptanalysis would have broken the entire fucking cipher if they didn't prevent it by selecting a secure S-box.<p>> The NSA pushed backdoored design of Dual_EC_DRBG was standardized in NIST SP 800-90A.<p>Correct, which another threat actor used in a backdoor by replacing the public key.<p>I'm not arguing that NIST isn't <i>vulnerable</i> to NSA influence. I'm arguing that they are not the same entity and do not have the same goals or incentives.<p>I'm not an NSA defender. <a href="https://furry.engineer/@soatok/116854899284071513" rel="nofollow">https://furry.engineer/@soatok/116854899284071513</a></p>
]]></description><pubDate>Tue, 07 Jul 2026 15:04:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48818849</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48818849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48818849</guid></item><item><title><![CDATA[New comment by some_furry in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>> But if I am honest, NIST recommending it at all is enough to suspect it of being compromised.<p>NIST isn't the NSA and doesn't have the NSA's goals in mind. They are briefed by NSA on some matters, sure, but they're not the same organization.<p>NSA has a dual mission: Both SIGINT and COMINT. While the SIGINT folks might rub their hands and laugh evilly at the prospect of backdooring the PQ KEM that the Internet wants to move towards, this plot makes no sense at several levels.<p>The NSA has, through CNSA 2.0, committed to moving the entire federal government onto ML-KEM for top secret communications. The COMINT guys would shit themselves in rage if it turned out to be backdoored, even if there was enough hubris that the backdoor was NOBUS.<p>If you can't trust the people, you should always seek to understand their incentives if you want to predict their behavior.<p>My interpretation of the CNSA 2.0 move was that the NSA believes 1) that ML-KEM is actually the good stuff, and 2) the Suite B transition failed so spectacularly that they want to signal confidence in ML-KEM by recommending it without hybridization. Since pretty much everything they do is top secret, they probably can't comment further.</p>
]]></description><pubDate>Tue, 07 Jul 2026 09:16:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48815370</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48815370</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48815370</guid></item><item><title><![CDATA[New comment by some_furry in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>Telecoms.<p>I wrote at length about this debate in my blog post about threat modeling: <a href="https://soatok.blog/2026/06/30/soatoks-informal-guide-to-threat-models/" rel="nofollow">https://soatok.blog/2026/06/30/soatoks-informal-guide-to-thr...</a></p>
]]></description><pubDate>Tue, 07 Jul 2026 09:04:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48815264</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48815264</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48815264</guid></item><item><title><![CDATA[New comment by some_furry in "Soatok's Informal Guide to Threat Models"]]></title><description><![CDATA[
<p>Let me distill this down to its most basic structure to make sure I'm understanding you.<p>Supoose we're trying to decide between two services for a long term group chat.<p>Service A, on the server-side, sees all messages, in plaintext, sent to/from all participants--including other servers. It can log it indefinitely. It sees the whole social graph. Some servers have no k-anonymity (self-hosted, single user), some have thousands of users. They're all over the world, including in jurisdictions the NSA's TAO can operate.<p>Service B can only see IP addresses and ciphertext. There's only one real 'server", but it has millions of users and the encryption is widely reputed by experts. Its servers happen to be hosted on American cloud providers.<p>By firmly disagreeing with the linked post, you are saying you prefer Service A on the matter of privacy, only because of the jurisdiction.<p>Is that really the hill you choose?</p>
]]></description><pubDate>Sun, 05 Jul 2026 21:38:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48798205</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48798205</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48798205</guid></item><item><title><![CDATA[New comment by some_furry in "Soatok's Informal Guide to Threat Models"]]></title><description><![CDATA[
<p>You mostly got it, yeah. Point 1, ECC is only also broken after Q-Day.<p>Hybrids obviously help if you believe Q-Day is far into the future, or never coming.<p>But if you take Q-Day happening as <i>possible in our lifetime</i>, the HNDL threat means data being encrypted today depends entirely on PQ security in the long run (since breaking EC with a Quantum Computer has an attack cost of like 2^30 or so instead of 2^120 or so).</p>
]]></description><pubDate>Sat, 04 Jul 2026 17:37:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48787204</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48787204</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48787204</guid></item><item><title><![CDATA[New comment by some_furry in "Soatok's Informal Guide to Threat Models"]]></title><description><![CDATA[
<p>It depends what I'm doing.<p>My dayjob involves a lot of code review and protocol cryptanalysis, so I agonize quite a bit there.<p>My blog would be less fun if I maintained the same level of rigor. If that makes any sense. ^^;</p>
]]></description><pubDate>Sat, 04 Jul 2026 17:26:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48787108</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48787108</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48787108</guid></item><item><title><![CDATA[New comment by some_furry in "Soatok's Informal Guide to Threat Models"]]></title><description><![CDATA[
<p>> Err, where did you wrote that? I can’t find it in your last two articles.<p>Just now. In an HN comment.<p>I write in conversational English. I'm not always going to meticulously write everything like a formal argument might.<p>If you didn't understand that what I wrote later in a blog post was predicated on an assumption established in the intro, but would have if I wrote an explicit transitional sentence, that's useful feedback. But if you're treating an informal blog post like a court filing, you might be setting yourself up for disappointment.</p>
]]></description><pubDate>Sat, 04 Jul 2026 16:24:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48786584</link><dc:creator>some_furry</dc:creator><comments>https://news.ycombinator.com/item?id=48786584</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48786584</guid></item></channel></rss>