Salta al contenuto principale



GE-Proton10-18 Released


Proton (upstream):

  • dxvk updated to latest git
  • vkd3d-proton/vkd3d updated to latest git
  • wine updated to latest bleeding-edge
  • dxvk-nvapi updated to latest git
  • proton script game fixes imported from upstream
  • vrclient fixes imported from upstream
  • wineopenxr fixes imported from upstream
  • makefile.in build fixes imported from upstream

Proton(em-10/wine-wayland)

  • imported fsr4 fixes/updates from em-10
  • imported wine-wayland (and additional) patches from em-10
  • imported imported ntsync ubisoft connect fix from em-10
  • imported x11 locale enablement patches/files
  • fixed issue with Wine-wayland driver causes the game screen to not fit the screen size when size chosen larger than screen size.

Proton(GE):

  • enabled wine writecopy option for ea/ubisoft/battlenet launchers

Protonfixes:

  • fixed issue with wine mono not getting removed fully (dotnet40+ should install now via winetricks)
  • fixed protonfix issue where it would quit instead of trying to create parent directory for config if it doesnt exist.
  • reverted a change that made vcrun2022 install instead of vcrun2019, which can lead to some games breaking
  • added fix for blue protocol star resonance videos to work
  • Fix Battle Engine Aquila overlapping sound
  • Company of Heroes 2 and Company of Heroes 3 Mp Desync fix
in reply to CannonGoBoom

I use the GE-Proton-Latest and I'm not sure if that's a good or bad thing. It feels like it's making everything else obsolete (unless of course you need an older version)

in reply to ☆ Yσɠƚԋσʂ ☆

I never understood this point. I can discover a crowded restaurant in downtown. Did other people know about it before me? Of cause, but no one I know
in reply to lugal

'discover' in the meme and in your comment don't have the same meaning. But if this was a competition of who can use a dictionary, you would have won for sure.
in reply to just_an_average_joe

I get what you mean, but I've seen the "how could they have discovered america if there was people there already" point used so many times that I'm actually starting to wonder if people are just so stupid that they can't figure out the same thing you just said
in reply to just_an_average_joe

I just don't think so. I mean, sure, it's a different context but I still feel like "there has no one been there before" just isn't part of the meaning. Sure, "for the first time" is but it doesn't include for whom. I just feel this is a weak point to make. "Marco Polo and the Discovery of the World" is a book by John Learner, who apparently thought the earth was uninhabited
Questa voce è stata modificata (1 settimana fa)


50% of German physicians joined the Nazi Party, twice the proportion of any other profession


and the current situation in the US drive.google.com/file/d/1CAk94…
Questa voce è stata modificata (1 settimana fa)


My social worker says I have to come out if I want them to use the correct name and pronouns.


Hi, so I'm a high school student and I happen to be trans FtM. I know I'm quite young, but I do believe in the importance of supporting trans people, even young people just in general.

I was born a girl (obviously) but now I'm a guy named Anthony. When I came out to my social worker "Mrs. A" (not her real name or initial), she said that she was proud of me for coming out, but that if I wanted teachers to refer to me as "male", "he/him", Anthony, etc. that I'd have to come out to my legal guardian.

The thing is my guardian isn't the most supportive of trans people. I came out to him a few years ago and he said I was just a confused girl and that "the left was just pushing their agenda onto me". He loves me, I'm sure he does, but he definitely wouldn't support me.

I told my therapist and a good friend of mine and both of them said that was breaking a rule of confidentiality. My sister told me that too. My therapist wonders if it's to get it changed on paperwork or something but says that if I want to be called Anthony at school, there should be no problem.

What do you all think?

in reply to Anthony

I'm not sure if they're the same thing, but back in my day we had a "School Counselor". I told her all about how my mom was abusing us, which backfired on me when she straight up told my mom everything I had said.

Hopefully it's changed on the last couple decades, but back then school counselors weren't required to have any accreditations and had no restriction on privacy.

That was when I learned the employees of the school are there to protect the school, not the students. You should be careful what you share until you've determined what sort of confidentiality you're guaranteed and what training this person has. Outing you or requiring you to out yourself are both pretty messed up to recommend.



POV: The highest paid engineer at your company gets fired





in reply to DeathByBigSad

I went roughly 2 weeks without food after I got out of the hospital from a severe head injury. I tried to eat, but I temporarily lost my sense of taste and my brain hallucinated this absolutely terrible taste in its place. Even my saliva and the inside of my mouth had this taste. In the hospital I mostly got my nutrients via IV.



American politics has devolved into shitposting and aura farming




‘Israel’s Reel Extremism’ - A Startling Documentary from Zeteo




Use hashtags for greater visibility on Mastodon


I’ve followed all the frequent posters on piefed.social using my mastodon.social account so we should be seeing a lot more PieFed content showing up there now. But unless you use hashtags, I’ll be the only one seeing it! When making your post, put a few

I've followed all the frequent posters on piefed.social using my mastodon.social account so we should be seeing a lot more PieFed content showing up there now. But unless you use hashtags, I'll be the only one seeing it!

When making your post, put a few words into the Tags field below the Body field, separated by a comma. No need to include the # character.



I think Mint is using my CPU for rendering instead of my GPU, how do I fix that?


I have a Nvidia GPU, which I understand is problematic with Linux. I've heard this is something can happen, so I assume it's why the "Cinnamon" process is using around 20-40% CPU resources at all times. So, how do I switch to using GPU for that? I've installed Nvidia drivers through the driver manager already

Edit: I figured it out, SecureBoot was turned on on the UEFI-level. I disabled it and reinstalled Mint, and it seems to work now.

Questa voce è stata modificata (2 settimane fa)
in reply to ssillyssadass

You can use it with secure boot enabled. See if Mint has documentation. Usually it's just setting it up with dkms, and installing your cert to the BIOS.
in reply to ssillyssadass

The Debian docs were really useful for me in setting up my 3090 on Debian proper.

Since Mint is downstream, maybe they will help you.

wiki.debian.org/NvidiaGraphics…



Arab states expanded cooperation with Israeli military during Gaza war, files show


Even as key Arab states condemned the war in the Gaza Strip, they quietly expanded security cooperation with the Israeli military, leaked U.S. documents reveal. Those military ties were thrown into crisis after Israel’s September airstrike in Qatar, but could now play a key role in overseeing the nascent ceasefire in Gaza.

Over the past three years, facilitated by the United States, senior military officials from Israel and six Arab countries came together for planning meetings in Bahrain, Egypt, Jordan and Qatar.

Qatar, whose capital was struck on Sept. 9 by Israeli missiles targeting Hamas leaders, was one of the countries that had quietly strengthened ties with the Israeli military. In May 2024. A planning document for the event, written two days before it was set to begin, shows that the Israeli delegation was scheduled to fly directly to the air base, circumventing Qatar’s civilian points of entry that could have risked public exposure.

in reply to IndustryStandard

Of course they did. The US bribes them on an on-going basis, and they fear being targetted next.


Israel-backed gangs kill Palestinian journalist in Gaza City


Saleh Aljafarawi, a well-known Palestinian journalist, was fatally shot in Gaza City on Saturday, just days after a Gaza ceasefire agreement was announced.

Various media reports suggest that Aljafarawi was killed when Hamas security forces had surrounded members of an armed militia.

Aljafarawi was cornered by armed men and killed with seven gunshots to his body.

The New Arab reported that Aljafrawi was targeted and killed by Israel-backed armed collaborator gangs while documenting the extensive destruction in the Sabra neighbourhood following the withdrawal of Israeli troops.




Why Signal over Jabber/XMPP?


Over the past few years I have gone through a bunch of different apps and protocols to find the best one for "securely" communicating with my family and friends.

I ended up with the amazing XMPP protocol and my family/friends frequently use its clients to contact me.

Monal for IOS and Cheogram/Conversations/Quicksy for Android. The android app I install depends on if I can get F-Droid on their phone or not.

It's been great with OMEMO encryption and the clients/apps available for XMPP. But sometimes I have issues introducing people to it.

Jabber (friendly name for xmpp) sounds silly to say. The clients all have weird names. And after trying the Signal mobile app it feels more focused than what anyone in the XMPP community has whipped up.

But the capabilities of XMPP makes it better.

Signal Cons (immediete)
- Centralized
- Single app
- Phone numbers

XMPP/Jabber Cons
- Picking server
- Apps are sort of less friendly

What really scares me about Signal is the centralization. Any nerd can easily host an XMPP server these days. But Signal from what I've heard really wants us to use their server.

If XMPP gets more attention I'm sure we can get people supporting projects and creating better apps.

I keep seeing people recommended Signal instead.

This is a bit of a tired ramble. What I wanna know is why anyone is preferring Signal over XMPP apps. I assume it might be not knowing about it. Tell me what you use to message people.

in reply to TurkeyDurkey

Most people don’t understand what is instance and do not want to do 3 step registration if they can do 2 step registration on Signal. Also, if I understand correctly, xmpp protocol and client didn’t support stickers and Signal added that feature and gifs? Not sure
in reply to cookie019

Protocol and client are different. I know Cheogram has some kind of sticker thing, but I don't think it's as robust as what Signal probably has. I can download Signal stickerpacks to use on Cheogram (the xmpp client), but using them was a tad difficult.


All Freedom Flotilla Coalition and Thousand Madleens volunteers freed after Israeli abduction


Dozens of testimonies from participants of the Freedom Flotilla and Madleens missions described degrading and often violent abuse by Israel


Archived version: archive.is/newest/thecanary.co…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.



Russia attacks Ukraine's power grid as Moscow worries over US Tomahawk missiles


Russia has attacked Ukraine’s power grid as part of an ongoing campaign to damage energy infrastructure before winter.


Archived version: archive.is/20251012130927/apne…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.



China says Taiwan president is 'prostituting' himself, after interview lauding Trump


Taiwan President Lai Ching-te is "prostituting" himself to foreigners to try and win their favour but his schemes are doomed to fail, China's government said on Wednesday after he gave an interview lauding U.S. President Donald Trump.


Archived version: archive.is/20251008085459/reut…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.

Questa voce è stata modificata (2 settimane fa)


Canada eyes putting nuclear reactors on the moon


'Canada is ... really good at nuclear' says CEO of space mining company


Archived version: archive.is/newest/cbc.ca/news/…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.

Questa voce è stata modificata (2 settimane fa)



UN force in Lebanon says peacekeeper wounded by Israeli grenade


The United Nations peacekeeping mission in Lebanon (Unifil) said Sunday that one of its members was wounded by an Israeli grenade dropped near a UN position in the country's south, the third incident of its kind in just over a month.


Archived version: archive.is/newest/middleeastey…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.

in reply to BrikoX

The lede is so insane. Did the "Israeli" grenade just walk into Lebanon and explode itself? There's never any actor or agent, just passive voice when Israel does illegal shit
in reply to lemmyseizethemeans

"Just before noon yesterday, an Israeli drone dropped a grenade that exploded near a Unifil position" in Kfar Kila, the force said in a statement published on Sunday.


Faneto accusato di violenze dalla ex: foto dei lividi e messaggi social. Le reazioni e cosa sappiamo finora


È diventato un caso nazionale quello che coinvolge Faneto, rapper emergente della scena urban italiana. La sua ex compagna, Alessandra, ha pubblicato sui social un racconto dettagliato di presunte violenze fisiche e psicologiche, accompagnandolo con foto di lividi, video e screenshot di messaggi. Il materiale, rilanciato da creator e pagine tematiche, ha alimentato in poche ore un’ondata di attenzione e solidarietà. L’artista, al momento, non ha diffuso dichiarazioni pubbliche.

COSA SAPPIAMO: Faneto accusato di violenze dalla ex: foto dei lividi e messaggi social. Le reazioni e cosa sappiamo finora



GOG Games


I downloaded from the website posted on fmhy but I don't know why my pc got really slow? Did I get a virus? From gog-games.to

I scanned the files with Malwarebytes and Windows Defender but I got nothing

Questa voce è stata modificata (2 settimane fa)
in reply to Panda1606

Almost certainly. For pirating games you're really playing with fire unless you're torrenting using a source that's well established and trusted directly from their official account, like FitGirl
[edit: can we take a moment to appreciate the downvoting here... whypastor.gif]
Questa voce è stata modificata (1 settimana fa)
in reply to Panda1606

i have 1TB worth of GOG games, and i got all of it from there. Never experienced any malware.
Questa voce è stata modificata (5 giorni fa)



Le Iene, nuovi audio sul caso Asia Vitale: anticipazioni e ospiti di stasera (12 ottobre)


Tornano stasera su Italia 1 le inchieste e i reportage de Le Iene, condotto da Veronica Gentili con Max Angioni. La puntata del 12 ottobre 2025 mette al centro due blocchi forti: i nuovi audio e le nuove dichiarazioni legate al caso Asia Vitale, vicenda che ha scosso l’opinione pubblica, e un viaggio ad alto rischio in Messico sul fentanyl, firmato da Matteo Viviani. In studio, tra gli ospiti, Neffa, Ernia e Beatrice Valli.

TUTTE LE ANTICIPAZIONI: Le Iene, nuovi audio sul caso Asia Vitale: anticipazioni e ospiti di stasera (12 ottobre)



AI image blocklist for uBlock Origin & Pi-hole


Found this AI art block list recently and thought I would share it with you guys. It definitely comes in handy!
Questa voce è stata modificata (2 settimane fa)
in reply to りん〜

This doesn't have anything to do with privacy.
Questa voce è stata modificata (1 settimana fa)
in reply to Pleat1752

Seeing this shit feels like an advertisement though, in a way.


Winded windows become a privacy nightmare?


So I just started messing around with the settings in my windows and account tied to it. And good Lord, this thing's just as bad as Android. 😒 ? The thing is literally saving all my inquiries and everything to my Microsoft account. I can't even turn off some of these features as far as trying to stop them. Many privacy settings are also buried all over the place. When did this happen?
Questa voce è stata modificata (2 settimane fa)
in reply to Toasted_Breakfast

It was the switch to Microsoft accounts. Everyone started using online accounts to login and when people complained apple said “okay, you don’t need to and here’s some ways to make it safer” after some high profile leaks, google said “we’ll anonymize your data so when we use it for tracking it’s not tied to you, also here’s some ways to make it safer” after everyone realized they weren’t not being evil and Microsoft said “are you fucking stupid? It says right there in the tos that we’re gonna take and use everything!”.

Go to massgrave.dev and start reading. Convert your Microsoft account to a local user account. You will still have a Microsoft account but you won’t use it to login. You will lose access to stuff you bought under your Microsoft account until you sign in. This may or may not be acceptable to you.

Use your knowledge from massgrave to convert your windows edition to enterprise iot ltsc if you’re on 21h2, otherwise either downgrade or flatten and reinstall that edition. You will now be able to receive security updates and stay on windows 10.







Video - Big Tech is FAKING revenue





Sunday, October 12, 2025


Fires reported in Russia's Belgorod Oblast amid suspected power plant attack -- NATO aircraft carry out 12-hour flight near Russian border amid rising tensions -- German airlines call to shoot down drones threatening airports -- Ukrainian air defenses ope

Share

The Kyiv Independent [unofficial]


Millions read the Kyiv Independent, but only one in 1,000 supports us financially

BECOME A MEMBER

Russia’s war against Ukraine


A view of a destroyed secondary school following a drone attack in the city of Kramatorsk on Oct. 11, 2025. (Jose Colon/Anadolu via Getty Images)

Zelensky discusses air defense with Trump after Russian strikes on Ukraine’s energy grid. “I informed President Trump about Russia’s attacks on our energy system — and I appreciate his willingness to support us,” Zelensky said.

Ukraine strikes Russian oil refinery 1,400 kilometers from front, SBU source says. Security Service of Ukraine (SBU) drones struck a Russian oil refinery in Ufa on the morning of Oct. 11, resulting in explosions and a fire, a source in the agency told the Kyiv Independent.

Fires reported in Russia’s Belgorod oblast amid suspected power plant attack, local officials say. Falling debris from downed missiles sparked fires and caused damage in Belgorod, Russia, the regional governor reported Oct. 11 amid a suspected attack on a power plant in the city.

Your contribution helps keep the Kyiv Independent going. Become a member today.

UK, Ukraine sign LYRA defense cooperation agreement. Ukraine and the U.K. agreed to launch the LYRA defense cooperation program, focusing on battlefield tech and joint weapons development, Defense Minister Denys Shmyhal announced Oct. 11.

Ukrainian air defenses operating at 74% effectiveness, military chief says. “Over the past month, (Russia) has increased the number of air strikes 1.3 times,” Oleksandr Syrskyi said.

Zelensky approves new Russia sanctions in coordination with Japan. President Volodymyr Zelensky has signed new sanctions targeting Russian individuals and entities, aligning Ukraine’s latest measures with those previously imposed by Japan.

YOU MAY ALSO BE INTERESTED IN…

War Notes

Get the latest news from the front lines in your inbox every Friday

SUBSCRIBE

YOU MAY ALSO BE INTERESTED IN…

One story from Ukraine

Monday to Friday, get an email with our most important story of the day

SUBSCRIBE

Human cost of Russia’s war


Russian attacks kill 5, injure 17 in Ukraine over past day, hit energy grid. Ukrainian air defenses intercepted 54 out of the 78 Shahed-type attack drones and other drones launched by Russia overnight, the Air Force reported. Twenty-one drone strikes were recorded at six locations.

Millions read the Kyiv Independent, but only one in 1,000 supports us financially. One membership might not seem like much, but to us, it makes a real difference. If you value our reporting, consider becoming a member — your support makes us stronger.

BECOME A MEMBER

MAKE A DONATION

International response


Trump threatens China with additional 100% tariffs amid trade tensions. “The United States of America will impose a tariff of 100% on China, over and above any tariff that they are currently paying,” Donald Trump said.

UK, France, Germany to move forward with using Russian assets to aid Ukraine. “We agree to develop further bold and innovative mechanisms to increase the cost of Russia’s war and ramp up pressure,” the British government said in a statement.

Latvia orders over 800 Russian citizens to leave by mid-October. Latvia has ordered 841 Russian citizens to leave the country by Oct. 13, citing their failure to meet legal requirements, including proof of Latvian language proficiency and passing a national security screening, Politico reported.

Belarus launches military readiness check as security concerns grow. The Belarusian military is implementing a “set of measures” to bring select units to their “highest level of combat readiness” under Alexander Lukashenko’s direct orders.

North Korea displays new ICBM during parade with Russia’s Medvedev in attendance. The parade, attended by Chinese Premier Li Keqiang and United Russia party leader Dmitry Medvedev, featured a display of advanced weaponry.

Estonia closes border crossing with Russia over unusual military activity. Estonia has temporarily closed the Saatse border crossing following heightened Russian military activity near the area, the Estonian public broadcaster ERR reported on Oct. 10.

NATO aircraft carry out 12-hour flight near Russian border amid rising tensions. The joint U.K.-U.S. operation was conducted on Oct. 9, following recent airspace violations by Russia targeting several NATO countries.

German airlines call to shoot down drones threatening airports. Germany’s airlines are calling for drones that threaten airport operations to be shot down, Der Spiegel reported on Oct. 11. The call to action comes amid a recent surge of unidentified drone sightings that have disrupted airports in Germany, prompting efforts to address the threat.

Hungary launches petition against EU’s Ukraine war funding, Orban says. Hungarian Prime Minister Viktor Orban said on Oct. 11 that Budapest has launched a nationwide petition drive to collect signatures in opposition to the European Union’s “war plan” to finance Ukraine’s war effort.

In other news


Bomb threats force Ukrainian Railways to halt 3 trains, including international line. The affected trains included routes between Dnipro and Kyiv, Ternopil and Kyiv, and the international Kyiv–Warsaw route.

YOU MAY ALSO BE INTERESTED IN…

WTF is wrong with Russia?

A weekly newsletter about Russian politics, history, and culture

SUBSCRIBE

This newsletter is open for sponsorship. Boost your brand’s visibility by reaching thousands of engaged subscribers. Click here for more details.

Today’s Ukraine Daily was brought to you by Martin Fornusek, Kateryna Hodunova, Lucy Pakhnyuk, and Dmytro Basmat.

If you’re enjoying this newsletter, consider joining our membership program. Start supporting independent journalism today.

Share

#russia #france #belarus #china #germany #uk #hungary #security #japan #NATO #eu #Trump #chinese #oil #EuropeanUnion #genocide #war #trains #fascist #ukrainian #british #schools #Ukraine #Trade #homes #International #orban #PETITION #warcrimes #weapons #Apartments #Lukashenko #threats #украина #Budapest #Kyiv #путин #NorthKorea #zelensky #Destroyed #Dnipro #airspace #Ternopil #Estonia #Russiasanctions #русский #PutinWarCrimes #airforce #CrimesAgainstHumanity #RussianWarCrimes #russianwar #Kramatorsk #Belgorod #terrorists #houses #sbu #latvia #ICBM #latvian #Lyra #Shahed #fires #Киев #геноцид #Airports #tariffs #russianterrorists #airdefense #russianterrorism #expelled #RussianAggression #bordercrossing #powerplants #bombthreats #KyivIndependent #EnergyGrid #OilRefineries #internationallawviolations #DefenseCooperation #AirportOperations #Effectiveness #shotdown #explosions #killingcivilians #residentialbuildings #DroneAttacks #wareffort #militaryreadiness #russianstrikes #russianattacks #combatreadiness #shootdowndrones #UFA #frozenrussianassets #CiviliansTargeted #aidukraine #ComradeKrasnov #Russiancitizens #attackdrones #ukrainiancities #russianborder #civiliansAttacked #civiliansTortured #Военныепреступления #residentialAreas #BelgorodOblast #Гражданские #нападавшиенапытку #Преступленияпротивчеловечности #Русскиесмерти #убитые #цивилийцы #airspaceViolations #RussianInvasions #RussianOilRefinery #closedAirports #closesBorder #disruptedAirports #downedMissiles #GermanAirlines #jointWeapons #KyivWarsaw #nationalSecurityScreening #NATOAircraft #nearRussianBorder #NorthKoreanICBM #RussianIndividuals #Saatse #threateningAirports #UkrainianAirDefenses #UkrainianRailways #unidentifiedDroneSightings #unusualMilitaryActivity #WTFIsWrongWithRussia
Questa voce è stata modificata (2 settimane fa)


Israel raids homes of West Bank prisoners set to be released in deal


The Israeli army has raided the homes of several Palestinian prisoners in the occupied West Bank whose names were included in the list of prisoners to be released in an exchange deal following the Gaza ceasefire.


For the third day running, Israel violates Gaza ‘ceasefire’ to maim and murder Palestinians


cross-posted from: ibbit.at/post/80105

Israel has violated the ‘ceasefire’ it agreed with Palestinian militia to bomb, murder and maim Palestinians for the third consecutive day – the first three days of the supposed ceasefire period.

Israel: horrific violations of the ceasefire


On Saturday 11 October, an occupation drone targeted a group of civilians in the Jabalia refugee camp, killing one civilian and seriously injuring several others, including one man left with both lower legs shredded or gone:

thecanary.co/wp-content/upload…

Israel thinks – correctly, because of the collaboration of the UK and other western governments – that it can get away with mass the mass slaughter of civilians and daily breaches of its supposed commitments.

It is a rogue and terror state.

Featured image via the Canary

By Skwawkbox


From Canary via this RSS feed



Cryptologist DJB Alleges NSA is Pushing an End to Backup Algorithms for Post-Quantum Cryptography


"The problem in a nutshell. Surveillance agency NSA and its [UK counterpart] GCHQ are trying to have standards-development organizations endorse weakening [pre-quantum] ECC+PQ down to just PQ."

Part of this is that NSA and GCHQ have been endlessly repeating arguments that this weakening is a good thing... I'm instead looking at how easy it is for NSA to simply spend money to corrupt the standardization process.... The massive U.S. military budget now publicly requires cryptographic "components" to have NSA approval... In June 2024, NSA's William Layton wrote that "we do not anticipate supporting hybrid in national security systems"...

[Later a Cisco employee wrote of selling non-hybrid cryptography to a significant customer, "that's what they're willing to buy. Hence, Cisco will implement it".]

What do you do with your control over the U.S. military budget? That's another opportunity to "shape the worldwide commercial cryptography marketplace". You can tell people that you won't authorize purchasing double encryption. You can even follow through on having the military publicly purchase single encryption. Meanwhile you quietly spend a negligible amount of money on an independent encryption layer to protect the data that you care about, so you're actually using double encryption.

in reply to technocrit

Nobody gives a shit about NIST if they lose the 1 thing that make them useful : their credibility.

If some credible doubt is shed on them ... then NIST is just an acronym with no power.

That being said IMHO a pragmatic heuristic is spotting "Do what I say, not what I do" and thus if NSA relies on PQ, or hybrid, or something well you can deduce from that they assume whatever solution they do NOT use if then not safe in a useful lifespan (which might be totally different from your threat model).

Edit : did tinker with openquantumsafe.org/about/ in particular github.com/open-quantum-safe so if you have an opinion on that I'd be curious.

Questa voce è stata modificata (2 settimane fa)
in reply to utopiah

If some credible doubt is shed on them ... then NIST is just an acronym with no power.


Doubt it, given tha NIST has no credibility among researches, only in the general public that ignore their shenanigans:

NIST doesn't need credibility, it simply needs to pass along NSA's aproval stamp for $next_algorithm, so $next_algorithm becomes a widely used standar.

Questa voce è stata modificata (2 settimane fa)
in reply to Danitos

Pushing for insecure post-quantum algorithms, that may be secure against quantum computers


Eh, I doubt that is how it works. We do not have quantum computers yet, so how we prove security in quantum settings is by specifying the adversary to have specified quantum capabilities, in addition to classical capabilities. Hence, broken under traditional attack means broken under quantum attack.

You can say that new post-quantum schemes are less verified compared to established classical schemes, but that does not mean classical is necessarily more secure.

in reply to someacnt

I think we both agree on the same thing, I comunicated it badly. The better approach is to apply a post-quantun algorithm on top of a classical one, so you are safe against both types of computers. The advantage of this approach is that you need to crack both algorithms at the same time.

NIST seems to prefers a hybrid approach, where a single algorithm is supposedly safe against both classical and quantum computers, leaving you with a single point of failure.

in reply to Danitos

You can always encrypt the payload twice if you want. But really what are you arguing? That every time you encrypt something, you should encrypt it serially with all known encryption algorithms "just in case?" Hell why not do it again just to make sure?

A key component of encryption is efficiency. Most cryptographic processes are going to be occurring billions of times across billions of transactions and involving billions of systems. It's worthwhile for robust encryption algorithms to be efficient and avoid unnecessary calculations unless those calculations demonstrate some advantage. For example PBKDF2, where the multiple rounds of identical encryption convey a demonstrable increase in time to decrypt via brute-force mechanisms. If the standard is 4096 which it was in 2005, you coming along and saying, but why isn't it 4097? The CIA is using >4096, therefore that means that 4096 is insecure! Isn't really understanding why 4096 was chosen to begin with. Additionally no one is stopping you from using one million iterations with key1 and then doing another million rounds with key2.

in reply to PowerCrazy

That's not what I'm trying to say. I'm not saying apply 1000 classical algos on top of 1000 quantum algos. I'm saying that post-quantum needs to be an extra layer, not a replacement.

This is explained further in the first few sentences of the third link I posted: blog.cr.yp.to/20251004-weakene… Note the author is an expert in the topic: en.wikipedia.org/wiki/Daniel_J…

Questa voce è stata modificata (1 settimana fa)
in reply to Danitos

Well I haven't see the arguement for why Quantum resistent encryption would somehow be weaker to traditional cryptographic techniques. I understand that early "quantum encryption" alogrithms were flawed, and it'll probably be a long time before we get the DES of Quantum Encryption. But all that means is that we don't have vetted "strong" quantum encryption techniques yet, and should stick with traditional encryption since quantum encryption isn't worth it yet. If Quantum encryption becomes worthwhile, we shouldn't have "traditional encryption", because it will be obsolete.

If the first cylinder lock was easily bypassed compared to my old reliable wafer lock, then why should I use the cylinder lock at all? Now that cylinder locks are better then wafer locks why should I use a tumbler lock at all? There is no added security by using a wafer lock.

Questa voce è stata modificata (1 settimana fa)
in reply to PowerCrazy

Quantum computers represent a complete paradigmatic. Modern quantum computers beat classical ones on some problems, while still not being able to factor some 2 digit numbers.

A single algorithm would be probable arrive some day, but why risk it right now? The Signal protocol adopted Post-Quantum some years ago. They going for a hybrid, not well tested over several years against classical computers, algorithm, would have been a security disaster.

in reply to technocrit

I was wondering what djb was up to lately. Glad to see he is still poking bears.


Cryptologist DJB Alleges NSA is Pushing an End to Backup Algorithms for Post-Quantum Cryptography


"The problem in a nutshell. Surveillance agency NSA and its [UK counterpart] GCHQ are trying to have standards-development organizations endorse weakening [pre-quantum] ECC+PQ down to just PQ."

Part of this is that NSA and GCHQ have been endlessly repeating arguments that this weakening is a good thing... I'm instead looking at how easy it is for NSA to simply spend money to corrupt the standardization process.... The massive U.S. military budget now publicly requires cryptographic "components" to have NSA approval... In June 2024, NSA's William Layton wrote that "we do not anticipate supporting hybrid in national security systems"...

[Later a Cisco employee wrote of selling non-hybrid cryptography to a significant customer, "that's what they're willing to buy. Hence, Cisco will implement it".]

What do you do with your control over the U.S. military budget? That's another opportunity to "shape the worldwide commercial cryptography marketplace". You can tell people that you won't authorize purchasing double encryption. You can even follow through on having the military publicly purchase single encryption. Meanwhile you quietly spend a negligible amount of money on an independent encryption layer to protect the data that you care about, so you're actually using double encryption.


Technology reshared this.

in reply to technocrit

Excuse me for being denser than a neutron star here… but that mean we won’t be able to “home brew” some sort of our own equipment and our own double encryption system (crowd sourcing like where Linux is right now from where it started) is that feasible? Or am I way off the mark here?
in reply to RangerAndTheCat

Of course we do and that's what Signal did. But if your platform doesn't care (like most), then the NSA can see everything
in reply to technocrit

We fight wars to live in peace, we grow sheep to eat lamb chops, and we keep trust to gain reputation to then spend it. That quote about stones.

Still very good to see someone as famous as Bernstein say this.

But yes, it's weird, TLS allows whatever the software on two sides of the negotiation allow and support. GOST, something Chinese, something you've made yourself. Anything.

Except if there's somehow a vulnerability in TLS hidden in the open, but, eh, that's a bit too conspiracy-minded for a post not discussing TLS itself.