maniel,

Isn’t elliptic curves cryptography sensitive to quantum computers attack? Shor’s algorithm etc

Pantherina,

Nice no ChatGPT anymore to remember how that damn Algorithm is spelled.

Why not just call it RSB ? People, really!

CarbonScored,
@CarbonScored@hexbear.net avatar

TL;DR: It’ll use a new, more secure key type.

const_void,

YouTube thumbnails are cancer

duncesplayed,

YouTube titles, too :(

Blackmist,
ky56,

DeArrow by the same developer as SponsorBlock seems to be actively developed and community contributions are fast.

lntl,

i don’t think I’ve created an RSA key since 2017

018118055,

I had to create one this year after discovering that connectbot (ssh client on Android) didn’t support agent forwarding otherwise.

lntl,

considered harmful

lemann,

Probably a good idea to look for a different client, call me tinfoil but I wouldn’t want to touch a very old mechanism that is supported/pushed by a very recognisable 3 letter agency

018118055,

Probably. It’s in f-droid but increasingly looking not quite unmaintained, but not developed actively enough.

LiveLM,

I’ve just started using SSH inside of Termux, got tired of all the weird pitfalls SSH Clients for Android usually have

lemann,

I delete them from the ssh config folder after installation, along with the DSA and ECDSA keys. No ed25519? No auth.

Also prevents a handful of bots from attempting SSH login into your cloud infra, a lot of them don’t support ed25519 kex

aard,
@aard@kyu.de avatar

A surprising amount of services (including Azure last I tried) can only handle RSA keys, so after trying ecdsa only for a while I ended up adding a RSA key again.

With that said - it’s 2023, in almost all cases you should have your keys in a hardware module nowadays, in which case you’d use a different command for keygeneration.

fossisfun, (edited )
@fossisfun@lemmy.ml avatar

Actually it is the same story with TLS 1.3 and TLS 1.2. A bunch of sites still doesn’t support TLS 1.3 (e. g. arstechnica.com, startpage.com) and some of them only support TLS 1.2 with RSA (e. g. startpage.com).

You can try this yourself in Firefox by disabling ciphers (search for security.ssl3 in about:config) or by setting the minimum TLS version to 1.3 (security.tls.version.min = 4 in about:config).

deepdive,

Strange enough TLS 1.3 still doesn’t support signed ed25519 certificates :| P‐256, NIST P‐384 or NIST P‐521 curves are known to be “backdoored” or having deliberately chosen mathematical weakness. I’m not an expert and just a noob security/selfhoster enthusiast but I don’t want to depend on curves made by NSA or other spy agencies !

I also wondering if the EU isn’t going to implement something similar with all their new spying laws currently discussed…

LaggyKar,
@LaggyKar@programming.dev avatar

AFAIK, they’re not known to be backdoored, only suspected

deepdive,

Yeah wrong wording, but the fact that we have to depend mostly on NSA’s cryptographic schemes makes it very suspicious !

lolcatnip,

Do you have a link for storing keys in hardware? I have no idea how you’d do that.

RegalPotoo,
@RegalPotoo@lemmy.world avatar

tl;dw - ed25519 keys are now the default

MigratingtoLemmy,

Finally damnit

ultra,

Nice!

Grass,

From the thumbnail I was wondering if it was this. Thanks for saving me the watch.

Synthead, (edited )

Thanks for reducing the click bait.

WalrusByte,
@WalrusByte@lemmy.world avatar

Oh nice! That’s the key type I use anyway, so nice to know I don’t have to pass as many options in now

kool_newt,

In 2005, Curve25519 was first released by Daniel J. Bernstein.[5] (en.wikipedia.org/wiki/Curve25519)

DJB? Nice! Always been a fan.

rammer,
@rammer@sopuli.xyz avatar

Yeah, look at the curves on that guy.

NoSpotOfGround,

It says that

Starting in 2014, OpenSSH defaults to Curve25519-based ECDH.

So what changed recently? (I didn’t watch the video, in fairness).

domi,
@domi@lemmy.secnd.me avatar

ssh-keygen now defaults to ed25519 so you don’t have to do ssh-keygen -t ed25519 anymore. The default since 2014 is for key exchange when connecting.

NoSpotOfGround,

Got it, thank you!

SteveTech,

Woah peertube federating with lemmy is actually really cool!

ademir,
@ademir@lemmy.eco.br avatar

right!? the fediverse is so cool!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • linux@lemmy.ml
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #