frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

ML-KEM Mythbusting

https://keymaterial.net/2025/11/27/ml-kem-mythbusting/
20•durumcrustulum•6h ago

Comments

contact9879•6h ago
thanks sophie. now if only this would get as many eyeballs as the inciting one

sigh

westurner•6h ago
From https://news.ycombinator.com/item?id=45743372 re: the Cloudflare Merkle Tree draft:

> Problem is PQ signatures are large. If certificate chain is small that could be acceptable, but if the chain is large, then it can be expensive in terms of bandwidth and computation during TLS handshake. That is the exchange sends many certificates which embed a signature and a large (PQ) public key.

> Merkle Tree Certificates ensures that an up to date client only needs 1 signature, 1 public key, 1 merkle tree witness.

> Looking at an MTC generated certificate they've replaced the traditional signing algorithm and signature with a witness.

> That means all a client needs is a signed merkle root which comes from an expanding Merkle Tree signed by the MTCA (Merkle Tree CA), which is delivered somehow out of band.

From "Keeping the Internet fast and secure: introducing Merkle Tree Certificates" (2025-10) https://blog.cloudflare.com/bootstrap-mtc/ :

> The central problem is the sheer size of these new algorithms: signatures for ML-DSA-44, one of the most performant PQ algorithms standardized by NIST, are 2,420 bytes long, compared to just 64 bytes for ECDSA-P256, the most popular non-PQ signature in use today; and its public keys are 1,312 bytes long, compared to just 64 bytes for ECDSA. That's a roughly 20-fold increase in size. Worse yet, the average TLS handshake includes a number of public keys and signatures, adding up to 10s of kilobytes of overhead per handshake. This is enough to have a noticeable impact on the performance of TLS.

Are ML-KEM certs impractically large too?

durumcrustulum•2h ago
ML-KEM is a key establishment scheme, not a signature scheme.

Pocketbase – open-source realtime back end in 1 file

https://pocketbase.io/
82•modinfo•2h ago•28 comments

TigerStyle: Coding philosophy focused on safety, performance, dev experience

https://tigerstyle.dev/
22•nateb2022•1h ago•10 comments

How Charles M Schulz created Charlie Brown and Snoopy (2024)

https://www.bbc.com/culture/article/20241205-how-charles-m-schulz-created-charlie-brown-and-snoopy
112•1659447091•6h ago•41 comments

Same-day upstream Linux support for Snapdragon 8 Elite Gen 5

https://www.qualcomm.com/developer/blog/2025/10/same-day-snapdragon-8-elite-gen-5-upstream-linux-...
380•mfilion•14h ago•184 comments

Vsora Jotunn-8 5nm European inference chip

https://vsora.com/products/jotunn-8/
63•rdg42•7h ago•13 comments

250MWh 'Sand Battery' to start construction in Finland

https://www.energy-storage.news/250mwh-sand-battery-to-start-construction-in-finland-for-both-hea...
212•doener•7h ago•102 comments

China's BEV Trucks and the End of Diesel's Dominance

https://cleantechnica.com/2025/11/26/chinas-bev-trucks-and-the-end-of-diesels-dominance/
72•xbmcuser•2h ago•39 comments

Physicists drive antihydrogen breakthrough at CERN

https://phys.org/news/2025-11-physicists-antihydrogen-breakthrough-cern-technique.html
165•naves•5d ago•45 comments

A programmer-friendly I/O abstraction over io_uring and kqueue (2022)

https://tigerbeetle.com/blog/2022-11-23-a-friendly-abstraction-over-iouring-and-kqueue/
60•enz•7h ago•19 comments

Migrating to Positron, a next-generation data science IDE for Python and R

https://posit.co/blog/positron-migration-guides
12•ionychal•2h ago•4 comments

Quake Engine Indicators

https://fabiensanglard.net/quake_indicators/index.html
227•liquid_x•3d ago•48 comments

Maxduino Review: Tape Cassette Emulator for Multiple Retro Computers

https://retrogamecoders.com/maxduino-review/
29•ibobev•3d ago•0 comments

Feedback doesn't scale

https://another.rodeo/feedback/
145•ohjeez•1d ago•53 comments

Memories of .us

https://computer.rip/2025-11-11-dot-us.html
144•sabas_ge•1d ago•48 comments

Installing Java in 2025, and Version Managers

https://blog.hakanserce.com/post/version_managers/
9•hakanserce•3d ago•2 comments

GitLab discovers widespread NPM supply chain attack

https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/
98•OuterVale•14h ago•37 comments

Indie, alone, and figuring it out

https://danijelavrzan.com/posts/2025/11/indie-dev/
59•wallflower•4d ago•9 comments

Tell HN: Happy Thanksgiving

651•prodigycorp•1d ago•163 comments

Experimenting with Robin Hood Hashing

https://twdev.blog/2025/11/robin_hood/
8•signa11•4d ago•2 comments

Bird flu viruses are resistant to fever, making them a major threat to humans

https://medicalxpress.com/news/2025-11-bird-flu-viruses-resistant-fever.html
100•bikenaga•6h ago•81 comments

Giving the Jakks Atari Paddle a Spin

https://nicole.express/2025/paddle-me-atari.html
25•ingve•4d ago•0 comments

Underrated reasons to be thankful V

https://dynomight.net/thanks-5/
171•numeri•9h ago•76 comments

Implementing Bluetooth LE Audio and Auracast on Linux Systems

https://www.collabora.com/news-and-blog/blog/2025/11/24/implementing-bluetooth-le-audio-and-aurac...
11•losgehts•3d ago•0 comments

DeepSeekMath-V2: Towards Self-Verifiable Mathematical Reasoning [pdf]

https://github.com/deepseek-ai/DeepSeek-Math-V2/blob/main/DeepSeekMath_V2.pdf
173•fspeech•10h ago•36 comments

DIY NAS: 2026 Edition

https://blog.briancmoses.com/2025/11/diy-nas-2026-edition.html
417•sashk•1d ago•267 comments

TPUs vs. GPUs and why Google is positioned to win AI race in the long term

https://www.uncoveralpha.com/p/the-chip-made-for-the-ai-inference
331•vegasbrianc•17h ago•244 comments

ML-KEM Mythbusting

https://keymaterial.net/2025/11/27/ml-kem-mythbusting/
20•durumcrustulum•6h ago•3 comments

Mixpanel Security Breach

https://mixpanel.com/blog/sms-security-incident/
227•jaredwiener•23h ago•109 comments

Coq: The World's Best Macro Assembler? (2013) [pdf]

https://nickbenton.name/coqasm.pdf
153•addaon•1d ago•67 comments

GitLab scan finds 17,000 secrets in public repos, leading to $9000+ in bounties

https://trufflesecurity.com/blog/scanning-5-6-million-public-gitlab-repositories-for-secrets
13•adrianwaj•2h ago•4 comments