<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>advogato &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/advogato/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Mon, 20 Oct 2025 23:36:19 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Where are we on XChat security?</title>
		<link>https://noise.getoto.net/2025/10/21/where-are-we-on-xchat-security/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Mon, 20 Oct 2025 23:36:19 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/73625.html</guid>

					<description><![CDATA[AWS had an outage today and Signal was unavailable for some users for a while. This has confused some people, including Elon Musk, who are concerned that having a dependency on AWS means that Signal could somehow be compromised by anyone with sufficien...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Cordoomceps &#8211; replacing an Amiga&#8217;s brain with Doom</title>
		<link>https://noise.getoto.net/2025/08/05/cordoomceps-replacing-an-amigas-brain-with-doom/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Tue, 05 Aug 2025 00:30:19 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/73001.html</guid>

					<description><![CDATA[There's a lovely device called a pistorm, an adapter board that glues a Raspberry Pi GPIO bus to a Motorola 68000 bus. The intended use case is that you plug it into a 68000 device and then run an emulator that reads instructions from hardware (ROM or ...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Secure boot certificate rollover is real but probably won&#8217;t hurt you</title>
		<link>https://noise.getoto.net/2025/07/31/secure-boot-certificate-rollover-is-real-but-probably-wont-hurt-you/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Thu, 31 Jul 2025 16:12:59 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/72892.html</guid>

					<description><![CDATA[LWN wrote an article which opens with the assertion "Linux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a key from Microsoft that is set to expire in September". This is, depending on interpretation, either misle...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Why is there no consistent single signon API flow?</title>
		<link>https://noise.getoto.net/2025/06/24/why-is-there-no-consistent-single-signon-api-flow/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Tue, 24 Jun 2025 06:03:07 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/72688.html</guid>

					<description><![CDATA[Single signon is a pretty vital part of modern enterprise security. You have users who need access to a bewildering array of services, and you want to be able to avoid the fallout of one of those services being compromised and your users having to chan...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>My a11y journey</title>
		<link>https://noise.getoto.net/2025/06/20/my-a11y-journey/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Fri, 20 Jun 2025 08:48:38 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/72379.html</guid>

					<description><![CDATA[23 years ago I was in a bad place. I'd quit my first attempt at a PhD for various reasons that were, with hindsight, bad, and I was suddenly entirely aimless. I lucked into picking up a sysadmin role back at TCM where I'd spent a summer a year before, ...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Locally hosting an internet-connected server</title>
		<link>https://noise.getoto.net/2025/06/17/locally-hosting-an-internet-connected-server/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Tue, 17 Jun 2025 05:17:40 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/72095.html</guid>

					<description><![CDATA[I'm lucky enough to have a weird niche ISP available to me, so I'm paying $35 a month for around 600MBit symmetric data. Unfortunately they don't offer static IP addresses to residential customers, and nor do they allow multiple IP addresses per connec...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>How Twitter could (somewhat) fix their encrypted DMs</title>
		<link>https://noise.getoto.net/2025/06/05/how-twitter-could-somewhat-fix-their-encrypted-dms/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Thu, 05 Jun 2025 13:18:48 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/71933.html</guid>

					<description><![CDATA[As I wrote in my last post, Twitter's new encrypted DM infrastructure is pretty awful. But the amount of work required to make it somewhat better isn't large.When Juicebox is used with HSMs, it supports encrypting the communication between the client a...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Twitter&#8217;s new encrypted DMs aren&#8217;t better than the old ones</title>
		<link>https://noise.getoto.net/2025/06/05/twitters-new-encrypted-dms-arent-better-than-the-old-ones/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Thu, 05 Jun 2025 11:02:47 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/71646.html</guid>

					<description><![CDATA[When Twitter[1] launched encrypted DMs a couple of years ago, it was the worst kind of end-to-end encrypted - technically e2ee, but in a way that made it relatively easy for Twitter to inject new encryption keys and get everyone's messages anyway. It w...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Failing upwards: the Twitter encrypted DM failure</title>
		<link>https://noise.getoto.net/2025/03/19/failing-upwards-the-twitter-encrypted-dm-failure/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Tue, 18 Mar 2025 23:58:52 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/71188.html</guid>

					<description><![CDATA[Almost two years ago, Twitter launched encrypted direct messages. I wrote about their technical implementation at the time, and to the best of my knowledge nothing has changed. The short story is that the actual encryption primitives used are entirely ...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>The GPU, not the TPM, is the root of hardware DRM</title>
		<link>https://noise.getoto.net/2025/01/02/the-gpu-not-the-tpm-is-the-root-of-hardware-drm/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Thu, 02 Jan 2025 01:14:05 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/70954.html</guid>

					<description><![CDATA[As part of their "Defective by Design" anti-DRM campaign, the FSF recently made the following claim:Today, most of the major streaming media platforms utilize the TPM to decrypt media streams, forcefully placing the decryption out of the user's control...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>When should we require that firmware be free?</title>
		<link>https://noise.getoto.net/2024/12/12/when-should-we-require-that-firmware-be-free/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Thu, 12 Dec 2024 15:57:59 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/70895.html</guid>

					<description><![CDATA[The distinction between hardware and software has historically been relatively easy to understand - hardware is the physical object that software runs on. This is made more complicated by the existence of programmable logic like FPGAs, but by and large...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Android privacy improvements break key attestation</title>
		<link>https://noise.getoto.net/2024/12/12/android-privacy-improvements-break-key-attestation/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Thu, 12 Dec 2024 12:16:06 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/70630.html</guid>

					<description><![CDATA[Sometimes you want to restrict access to something to a specific set of devices - for instance, you might want your corporate VPN to only be reachable from devices owned by your company. You can't really trust a device that self attests to its identity...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>What the fuck is an SBAT and why does everyone suddenly care</title>
		<link>https://noise.getoto.net/2024/08/22/what-the-fuck-is-an-sbat-and-why-does-everyone-suddenly-care/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Thu, 22 Aug 2024 08:52:49 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/70348.html</guid>

					<description><![CDATA[Short version: Secure Boot Advanced Targeting and if that's enough for you you can skip the rest you're welcome.Long version: When UEFI Secure Boot was specified, everyone involved was, well, a touch naive. The basic security model of Secure Boot is th...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>SSH agent extensions as an arbitrary RPC mechanism</title>
		<link>https://noise.getoto.net/2024/06/12/ssh-agent-extensions-as-an-arbitrary-rpc-mechanism/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Wed, 12 Jun 2024 02:57:36 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/69646.html</guid>

					<description><![CDATA[A while back, I wrote about using the SSH agent protocol to satisfy WebAuthn requests. The main problem with this approach is that it required starting the SSH agent with a special argument and also involved being a little too friendly with the impleme...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Digital forgeries are hard</title>
		<link>https://noise.getoto.net/2024/03/14/digital-forgeries-are-hard/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Thu, 14 Mar 2024 09:11:32 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/69507.html</guid>

					<description><![CDATA[Closing arguments in the trial between various people and Craig Wright over whether he's Satoshi Nakamoto are wrapping up today, amongst a bewildering array of presented evidence. But one utterly astonishing aspect of this lawsuit is that expert witnes...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Debugging an odd inability to stream video</title>
		<link>https://noise.getoto.net/2024/02/20/debugging-an-odd-inability-to-stream-video/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Mon, 19 Feb 2024 22:30:15 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/69343.html</guid>

					<description><![CDATA[We have a cabin out in the forest, and when I say "out in the forest" I mean "in a national forest subject to regulation by the US Forest Service" which means there's an extremely thick book describing the things we're allowed to do and (somewhat longe...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Dealing with weird ELF libraries</title>
		<link>https://noise.getoto.net/2024/01/02/dealing-with-weird-elf-libraries/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Tue, 02 Jan 2024 19:04:32 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/69070.html</guid>

					<description><![CDATA[Libraries are collections of code that are intended to be usable by multiple consumers (if you're interested in the etymology, watch this video). In the old days we had what we now refer to as "static" libraries, collections of code that existed on dis...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Making SSH host certificates more usable</title>
		<link>https://noise.getoto.net/2023/12/19/making-ssh-host-certificates-more-usable/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Tue, 19 Dec 2023 19:48:14 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/68721.html</guid>

					<description><![CDATA[Earlier this year, after Github accidentally committed their private RSA SSH host key to a public repository, I wrote about how better support for SSH host certificates would allow this sort of situation to be handled in a user-transparent way without ...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Why does Gnome fingerprint unlock not unlock the keyring?</title>
		<link>https://noise.getoto.net/2023/12/05/why-does-gnome-fingerprint-unlock-not-unlock-the-keyring/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Tue, 05 Dec 2023 06:32:10 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/68537.html</guid>

					<description><![CDATA[There's a decent number of laptops with fingerprint readers that are supported by Linux, and Gnome has some nice integration to make use of that for authentication purposes. But if you log in with a fingerprint, the moment you start any app that wants ...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Why ACPI?</title>
		<link>https://noise.getoto.net/2023/11/01/why-acpi/</link>
		
		<dc:creator><![CDATA[Matthew Garrett]]></dc:creator>
		<pubDate>Wed, 01 Nov 2023 06:30:06 +0000</pubDate>
				<category><![CDATA[advogato]]></category>
		<category><![CDATA[fedora]]></category>
		<guid isPermaLink="false">https://mjg59.dreamwidth.org/68350.html</guid>

					<description><![CDATA["Why does ACPI exist" - - the greatest thread in the history of forums, locked by a moderator after 12,239 pages of heated debate, wait no let me start again.Why does ACPI exist? In the beforetimes power management on x86 was done by jumping to an opaq...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 127/139 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-05 23:52:53 by W3 Total Cache
-->