asciilifeform: 'what, you idiot niggers really thought that pygmies can run a country ? only yale graduates can run a country, shut up get back on yer knees'
asciilifeform: and in the end, 'We acknowledge that the issue exists and will work towards fixing it. ... I will say this very clearly once again: there is an avoidable security flaw in the Tox handshake. This is not something someone made up. The effect is that if your secret key is stolen, an attacker can impersonate anyone to you. We will fix this issue, most likely by adopting Noise for handshakes.'
asciilifeform: 'You might benefit from a bit of humility before comparing your protocol to OTR and SIGMA, both of which were groundbreaking works created by experts, as opposed to a slapdash protocol...'
asciilifeform: instead he reincarnates as 10,001 cryptoderps
asciilifeform: 'Perhaps Tox doesn't care about this, or about many of the threat models that modern AKEs are designed to protect against, in which case, probably it's fine to continue using your homebrewed crypto. But if you actually desire some kind of high assurance security, I strongly recommend not building your own protocols and instead use something designed by an educated expert, such as Noise.' << lol , schneier never dies.
asciilifeform: the cost of using an item that does not fit in head, is essentially the cognitive equivalent of curl liquishit | bash .☟︎
asciilifeform: http://btcbase.org/log/2017-04-28#1649464 << gotta understand the principle : if martians landed tonight, and fixed, somehow, all of the bugs in openssl, and god signed off that there are no more -- openssl will STILL be a turd, because does not fit in head !☝︎