frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

DJB's Cryptographic Odyssey: From Code Hero to Standards Gadfly

https://cryptography.watch/articles/djb-cryptographic-odyssey/
11•crypto_watchdog•4h ago

Comments

darfo•2h ago
"the ranting on mailing lists, meanwhile, will fade into the archives..."

Only if time proves DJB wrong.

vessenes•2h ago
To me this is the worst sort of journalism - couched in neutral language, it's an editorial piece disguised as a 'facts' piece.

Facts - DJB, largely right, at times a decade+ early, is fighting with standards boards. He does not believe the NSA has come off their long-standing approach to keep industry cryptography protocols weaker than five eyes cryptanalysis tools. The NSA's former employees, in the chain of command at the standards board, disagree with this characterization, and offer no proof to the contrary (if such a thing were possible).

Put another way, just because DJB is paranoid and coming across as strident right now does not mean he's wrong.

We really benefitted globally in the late 1990s from the cypherpunk movement getting legal coverage; the anti-government hacker mentality and culture that formed when writing about cryptography was mostly illegal, when allowed to publish and deliver to industry, brought real safety to billions of humans through better cryptographic protocols. Unfortunately, I'm not aware of an area where that same ethos is alive right now - in this way DJB's a dinosaur - and people a generation younger than him don't understand where he came from, and in this case, I think, don't understand how to use his viewpoint as a way to assess the world. It's not the only viewpoint, but it's an extremely useful one.

Not only that, it's a viewpoint that has asymmetric benefit - if he's wrong, well then, we just added a little useful safety. If he's right, then, thank God someone did something about it.

dsr_•1h ago
Many clever people would benefit the world more if they had other people doing the advocacy work for them.
WaryByDesign•2h ago
> the way he went about it — the accusatory tone, the refusal to compromise or even acknowledge that others might simply have honest differing opinions

...is entirely familiar and not a recent phenomena. He dismissed me as a "BIND company shill" during an IETF meeting in... 2008(?) for pointing out some (minor) implementation issues I saw with DNSCurve.

tptacek•1h ago
This reads very LLM-y, misses huge chunks of the story (multiple paragraphs on "clamping" and static ECDH, a single line on Ristretto and nothing on signature schemes, which is where that matters), has a breathless tone about Chapoly and Nacl that is totally unwarranted, misses almost all the NIST PQC drama, most of which was not in fact about hybrid cryptography, and in the end doesn't offer any analysis, just this bad re-telling.

My guess is someone had this generated as part of some dumb pressure campaign. It's weird.

(It's funny that people are chiming in to call this a "hit piece"; if anything, it's twisting itself into pretzels to be charitable to Bernstein's IETF involvement. I assume whoever generated it supports him.)

zdw•1h ago
Going a bit meta - this blog seems strange as its only other story is criticizing a member of the go community. The OP has posted this story, done so twice (first time was flagged) and has no other comments on HN.

There may also be a downvote brigade in this comment section.

tptacek•1h ago
I think this must be a bit. On the one hand you have this story about Bernstein, someone who has made a pastime out of weaponizing process in consensus organizations to drag progress to a halt when he's failed to coerce his preferred outcome; on the other hand you have a story villainizing Filippo Valsorda for not doing that, and avoiding standards organizations altogether.
octoberfranklin•1h ago
Anonymous hit piece.

DJB, like RMS, has proven over decades that he is swayed only by principles. When these people sound the alarm, you should listen. Even if they are nerdy folks.

dadrian•32m ago
RMS has, at minimum, showed that he swayed by parrots, spider plants, and free plane tickets and guest lodgings.
zdw•1h ago
I first encountered djb's work back in the 90's with qmail and djbdns, where he took a very different and compartmentalized approach to the more common monolithic tooling for running email and DNS. I'd even opine that the structure of these programs are direct ancestors to modern microservice architectures, except using unix stdio and other unix isolation mechanisms.

He's definitely opinionated, and I can understand people being annoyed with someone who is vociferous in their disagreement and questioning the motives of others, but given the occasional bad faith and subversion we see by large organizations in the cryptography space, it's nice to have someone hypervigilant in that area.

I generally think that if djb thinks something is OK in terms of cryptograpy, it's passed a very high analytical bar.

wqweto•1h ago
The article is complete drivel and most probably sponsored by an US agency.

I trust DJB even more after reading this and so should you.

dingaling•12m ago
Oh, probably fortuitous that I was blocked by Cloudflare.

What Not to Write on Your Security Clearance Form

https://milk.com/wall-o-shame/security_clearance.html
142•wizardforhire•1h ago•31 comments

I Verified My LinkedIn Identity. Here's What I Handed Over

https://thelocalstack.eu/posts/linkedin-identity-verification-privacy/
771•ColinWright•11h ago•284 comments

How far back in time can you understand English?

https://www.deadlanguagesociety.com/p/how-far-back-in-time-understand-english
106•spzb•3d ago•52 comments

Keep Android Open

https://f-droid.org/2026/02/20/twif.html
1875•LorenDB•1d ago•643 comments

Show HN: Iron-Wolf – Wolfenstein 3D source port in Rust

https://github.com/Ragnaroek/iron-wolf
8•ragnaroekX•2h ago•4 comments

macOS's Little-Known Command-Line Sandboxing Tool (2025)

https://igorstechnoclub.com/sandbox-exec/
139•Igor_Wiwi•3h ago•50 comments

The Nekonomicon – Nekochan.net Archive, Updated

http://nekonomicon.irixnet.org/
18•ThatGuyRaion•1h ago•7 comments

I found a Vulnerability. They found a Lawyer

https://dixken.de/blog/i-found-a-vulnerability-they-found-a-lawyer
798•toomuchtodo•22h ago•367 comments

AI uBlock Blacklist

https://github.com/alvi-se/ai-ublock-blacklist
137•rdmuser•10h ago•61 comments

Turn Dependabot off

https://words.filippo.io/dependabot/
587•todsacerdoti•20h ago•170 comments

Facebook is cooked

https://pilk.website/3/facebook-is-absolutely-cooked
1367•npilk•23h ago•743 comments

Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI

https://github.com/ggml-org/llama.cpp/discussions/19759
792•lairv•1d ago•209 comments

Wikipedia deprecates Archive.today, starts removing archive links

https://arstechnica.com/tech-policy/2026/02/wikipedia-bans-archive-today-after-site-executed-ddos...
547•nobody9999•23h ago•332 comments

Andrej Karpathy talks about "Claws"

https://simonwillison.net/2026/Feb/21/claws/
260•helloplanets•8h ago•418 comments

CXMT has been offering DDR4 chips at about half the prevailing market rate

https://www.koreaherald.com/article/10679206
69•phront•3h ago•38 comments

Lean 4: How the theorem prover works and why it's the new competitive edge in AI

https://venturebeat.com/ai/lean4-how-the-theorem-prover-works-and-why-its-the-new-competitive-edg...
114•tesserato•4d ago•45 comments

Padlet (YC W13) Is Hiring in San Francisco and Singapore

https://padlet.jobs
1•coffeebite•6h ago

Coccinelle: The Linux kernel's source-to-source transformation tool

https://github.com/coccinelle/coccinelle
63•anon111332142•9h ago•17 comments

CERN rebuilt the original browser from 1989 (2019)

https://worldwideweb.cern.ch
231•tylerdane•18h ago•83 comments

Permacomputing

https://wiki.xxiivv.com/site/permacomputing.html
4•tosh•4d ago•0 comments

The bare minimum for syncing Git repos

https://alexwlchan.net/2026/bare-git/
42•speckx•4d ago•25 comments

Every company building your AI assistant is now an ad company

https://juno-labs.com/blogs/every-company-building-your-ai-assistant-is-an-ad-company
271•ajuhasz•23h ago•145 comments

What Is OAuth?

https://leaflet.pub/p/did:plc:3vdrgzr2zybocs45yfhcr6ur/3mfd2oxx5v22b
182•cratermoon•16h ago•68 comments

Approaches to writing two-sentence journal entries

https://alexanderbjoy.com/two-sentence-journal-approaches/
64•fi-le•3d ago•6 comments

Gitas – A tool for Git account switching

https://github.com/letmutex/gitas
50•letmutex•4d ago•39 comments

Index, Count, Offset, Size

https://tigerbeetle.com/blog/2026-02-16-index-count-offset-size/
140•ingve•3d ago•64 comments

Blue light filters don't work – controlling total luminance is a better bet

https://www.neuroai.science/p/blue-light-filters-dont-work
214•pminimax•1d ago•208 comments

Understanding Std:Shared_mutex from C++17

https://www.cppstories.com/2026/shared_mutex/
36•ibobev•4d ago•20 comments

The path to ubiquitous AI (17k tokens/sec)

https://taalas.com/the-path-to-ubiquitous-ai/
796•sidnarsipur•1d ago•431 comments

JWasm: Masm Compatible Assembler

https://github.com/Baron-von-Riedesel/JWasm
18•doener•4d ago•1 comments