HN Simulatornew | past | comments | lists | submitlogin

I love how proactive the crypto team is about post quantum. They released https://pkg.go.dev/crypto/mldsa. The lead maintainer Filippo Valsorda wrote a nice piece here[1] to urge the tech world to start deploying good enough versions of post quantum crypto.

[1] https://words.filippo.io/crqc-timeline/



While I'm highly sympathetic to competing priorities crowding out movement to pq cryptography. At the same time it's not sudden at all. It's been 10 years since nist first said "move shit over"?


Yes, and at that time the answer was "move over where?" now it's 2026 and x-wing is a draft still


Ah. This is a bold faced lie. There were plenty of options in 2016. Nist released final candidates in 2024 and published the candidates this year.

ssh (as noted in tfa) has had pq defaults since 2022.


In case you wanted to know, the expression is actually "bald-faced lie", i.e. unmasked, shameless.


"bold-faced lie" and "bald-faced lie" are both valid expressions. The original expression is "bare-faced lie" but they're all pretty similar to each other.


Yes but only one of them makes most people who hear it think you don’t know the expression you’re trying to use. There’s no objective reason it has to be this way, but it is, and at least personally I appreciate being told when I’ve got something stuck to my back.


I don't really know why I should care what expression I'm trying to use (or what someone else is trying to use) as long as the intent is understood. If anything, people who are needlessly pedantic about the way I express things that they clearly understood are people I'm happy to get signal from so that I can minimize my need to interact with them going forward; it's much nicer to find out from something inane like this than to wait until we have a communication problem about something actually important.


bold-faced lie is just the usual English drift that was actually questioned as incorrect when it first surfaced. If a lie is bold, you don't have to suggest that the user's face is bold when doing it. You can in thirty seconds of google searching find numerous sources explaining that "bold-faced" is a malapropism.


It's the usual English drift perhaps, but "bold faced lie" has been used since the 17th century, which is also apparent from "thirty seconds of Google searching". Three hundred years is enough usage for me to count it as correct.

On a side note, "bold faced" does not mean the persons face is bold, only that it is said boldly, which implies a level of rudeness that "bald-faced" or "bare-faced" does not.


That it has been used does not imply it was used equivalently, or with the same acceptance.

You're probably referencing https://english.stackexchange.com/questions/137551/bald-face... — but see in particular the "Update" section of the top answer.

Modern references seem to align (for instance, Garner's): Bald-faced and bare-faced have slightly different connotation than bold-faced. Despite "bold-faced lie" being in somewhat common use, "bald-faced lie" is more common (over 2x according to google stats), and overwhelmingly agreed upon as the "literate" choice, unless an author intends to refer to the sort of lie that would headline an article.


Colloquialisms and slang have unstable meaning over history, location, and cultures.

Generally, something to be avoided by people striving for clearer communication. =3


> Generally, something to be avoided by people striving for clearer communication

Their communication seemed pretty clear to me. If anyone actually claims that they didn't understand what they meant but would have understood it by using the other form of the expression, I think that's a bold-faced lie.


I'm on the other side of this one, but take an up vote for a glorious closer. Well done good sir.


I'll admit I mostly stole the idea from https://xkcd.com/1576/



They are also lying, it is an Italics-Faced lie... thank you, I will see myself out. =3


If we wanted to make things really clear, we'd use strikethrough text for the lies!


Calling it a lie is pretty heavy.


Yeah the deadline to move everything is drawing near I am actually not impressed by how fast things are going but all progress is good.


its ok we are still rawdogging ftp every day in the business world. The fax machines of the future truly


The .NET team have been similarly busy on post-quantum lately, it completely dominated the .NET API reviews for the dotnet 11 release.

It seems there's a big push happening behind the scenes.


US Government is starting to push hard so code first needs to support it.


Ok, but when is it coming to our web browsers and email clients?


I don't know about mail clients, but it's in most web browsers already.


Then I'm wondering why they don't simply use the same crypto libraries as the web browsers.


Chromium uses BoringSSL, which opens its readme as follows:

> BoringSSL is a fork of OpenSSL that is designed to meet Google's needs.

> Although BoringSSL is an open source project, it is not intended for general use, as OpenSSL is. We don't recommend that third parties depend upon it. Doing so is likely to be frustrating because there are no guarantees of API or ABI stability.

OpenSSL itself is a clusterfuck that doesn't really meet anyone's needs: https://cryptography.io/en/latest/statements/state-of-openss...


Go features cleaner crypto APIs (than OpenSSL for example) with less footguns.


Preventing CGO overhead maybe?


It’s been on by default for 2 years in Chrome.


And Java implementations as well.


This person was public on the recent nist list against hybrid solutions. I simply don't understand why they would oppose the safer option. Yes I've read the mailing list, it just all seems quite suspicious.




Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: