!lymvtcwDJ7ZA9Npq:lix.systems

Lix Development

345 Members
(Technical) development of Lix, the package manager, a Nix implementation. Please be mindful of ongoing technical conversations in this channel.124 Servers

Load older messages


SenderMessageTime
23 Apr 2025
@irenes:matrix.orgIrenesoh I see, mTLS is TLS with mutual authentication20:40:06
@irenes:matrix.orgIrenesexcellent20:40:09
@irenes:matrix.orgIrenesI'm highly supportive of that20:40:12
@irenes:matrix.orgIrenesI had to look it up :) I had it in my head that it was a UDP-based TLS-like, which I know a lot less about20:40:26
@irenes:matrix.orgIrenesalso, for programmatically initiating client connections with TLS you have several robust libraries you can use - openssl, libressl, boringssl, ...20:41:17
@irenes:matrix.orgIreneswith SSH you have one choice and it's libssh20:41:29
@irenes:matrix.orgIrenesit's not a bad library, but, it can be nice to know that there are alternatives if you ever find yourself going in a different direction than upstream20:42:04
@irenes:matrix.orgIrenesthe SSH protocol kind of stopped getting new features a while ago, like, it's nominally still maintained but most of the love has gone towards TLS20:43:12
@irenes:matrix.orgIrenesnot that new and shiny is always good, but, these are security and production features, you know?20:43:22
@irenes:matrix.orgIrenesssh itself gets new stuff all the time, just, the protocol is kinda ... well, I said it already20:43:52
@irenes:matrix.orgIrenesokay20:44:02
@irenes:matrix.orgIrenessorry for the lecture!20:44:05
@irenes:matrix.orgIrenesI offer this only to inform, because it's an area I've dug into, I am happy to go along with whatever people want20:44:21
@irenes:matrix.orgIrenesand of course it's not decided this is happening at all20:44:27
@irenes:matrix.orgIrenesbut yeah20:44:30
@charles:computer.surgeryCharlesoh huh so did i23:57:30
@hexa:lossy.networkhexadTLS is that23:59:56
24 Apr 2025
@irenes:matrix.orgIrenesahh00:00:06
@hexa:lossy.networkhexa* DTLS is that00:00:10
@irenes:matrix.orgIrenesit's almost as if the convenient acronyms aren't so much :)00:00:16
@irenes:matrix.orgIrenesthank you00:00:20
@hexa:lossy.networkhexaI swear there was a security issue around DTLS that had a name00:00:58
@hexa:lossy.networkhexawas it heartbleed?00:01:34
@hexa:lossy.networkhexaoh, but that also affected TLS00:02:13
@irenes:matrix.orgIreneswas it the one based on the weird three-way handshake00:05:47
@irenes:matrix.orgIrenesI remember about ten years ago cloudflare announced something fancy about their handshakes, and a few months later someone announced a vulnerability suspiciously similar to the thing cloudflare bragged about00:06:27
@irenes:matrix.orgIrenes(though cloudflare's thing was clearly "okay")00:06:37
@irenes:matrix.orgIrenesbut this is a very hazy memory00:06:40
@irenes:matrix.orgIrenesI think it was probably closer to 15 years ago00:06:47
@irenes:matrix.orgIrenesI didn't think it was UDP-related though00:07:17

Show newer messages


Back to Room ListRoom Version: 10