staff
Newsroom desk
HTTP WG moves to fence off status 402 as x402 spreads
Outside payment projects have assigned their own meaning to the long-reserved code; Mark Nottingham has floated a draft to limit collisions.
Trust by default still rules the data plane
A cluster of CVSS 9.8 pre-auth remote code execution bugs in ksqlDB, DataStax Enterprise, and ObjectDB turns separate full-disclosure posts into one argument about convenience defaults in high-value infrastructure.
Who steers the specs: legitimacy fights in Bitcoin and Ethereum process
Bitcoin stripped its longest-serving BIP editor with no written rule, no vote, and access revoked before the argument ended, on charges that amount to ordinary editing plus a reputation his critics admit is the real issue. A supporter conceded there is no governance process at all.
DataStax Enterprise 6.8 exposed to pre-auth RCE via Gremlin
Default unauthenticated Gremlin Server plus a Groovy sandbox bypass lets remote attackers run OS commands as the dse user.
Unauthenticated root RCE hits Confluent ksqlDB 7.9.1-ce defaults
A public advisory shows how default open ksqlDB, Kafka, and Connect endpoints chain into cron-based root execution with no credentials.
Bernstein documents 75 objections the IESG cannot edit away
In a four-part Last Call filing the last-call moderators appear to have blocked, Bernstein compiled 75 sourced objections, a Kyber co-designer's own warning against solo use, and a five-orders-of-magnitude cost gap. The IESG should not publish draft-ietf-tls-mlkem.
The motion to remove Luke Dashjr is a purge dressed up as process
A handful of BIP editors moved to strip Luke Dashjr of a role he has held for over a decade, using a removal procedure that, by their own admission, does not exist. The charges amount to editorial housekeeping and personality. The real risk is turning Bitcoin's neutral registry into a factional weapon.
The IESG should reject solo ML-KEM for TLS and keep the hybrid safety net
An IETF-wide last call asks the steering group to publish pure ML-KEM key agreement for TLS 1.3 as an RFC, the latest stage of a months-long fight over a rough-consensus call the chairs will not show their math on. A solo post-quantum handshake fails completely the day ML-KEM does, hybrids do not, and the code points already exist. The IESG should reject it. Comments close 13 August.
Bernstein files a formal complaint against SSH chairs who tried to silence him
The SSHM chairs met an unanswered objection to solo post-quantum signatures with moderation threats instead of discussion. D. J. Bernstein's RFC 2026 complaint reads IETF's own rules back to them: address objections and measure consensus, do not gavel them away. The call for adoption closes 17 August.
For SSH signatures, keep the classical layer
As the SSHM working group runs a call for adoption ending 17 August, the record makes a strong case against blessing solo ML-DSA for host and user authentication when a cheap ECC hedge removes an entire class of failure.