Bijou64

Discover how bijou64 makes integer encoding safer and faster

Bijou64 takes a meaningful step beyond the familiar trade-offs in integer encoding.

4 min readInfoQ
Discover how bijou64 makes integer encoding safer and faster

There is a quiet satisfaction in watching a small, precise idea close a door that the industry had left open for years. Ink & Switch's bijou64 is exactly that kind of idea: a variable-length integer encoding where every number has exactly one byte representation. That single property, canonicality, eliminates an entire bug class that has quietly enabled attacks on PKCS#1, JWT libraries, and Bitcoin. We are not talking about a performance tweak or a nice-to-have optimization. We are talking about removing a category of failure that developers have learned to live with, often without knowing it. The fact that bijou64 also decodes two to ten times faster than LEB128 is almost a bonus. The real win is that a parser can now trust its input in a way that was previously impossible.

This is the kind of progress that does not need hype, because the engineering speaks for itself. The community response, with ports to Elixir, Go, Perl, and Java, suggests that developers recognize the value immediately. But we would offer a gentle caution: speed and correctness are not the same as simplicity in adoption. The Hacker News debate around SIMD performance and residual range checks is telling. It shows that even with a canonical design, the hard work is not in the encoding itself, but in how it integrates with existing systems and how thoroughly the edge cases are understood. We would tell a reader who is considering bijou64 to look beyond the benchmark tables and examine how the canonical property changes their own error handling. The encoding is a tool, not a silver bullet. It solves a specific problem with elegance, but it still lives inside a larger ecosystem of parsers, serializers, and protocols that each carry their own assumptions.

What makes this story feel different from the usual round of library announcements is the focus on a fundamental invariant rather than a feature list. In that way, it reminds us of other quiet infrastructure wins, like the recent Kubernetes 1.37 Released: Stable Metrics API and Rootless Kubelet in Beta where stability took precedence over new toys, or the practical tuning behind Cloudflare Measures Origin TLS Preferences, Cutting Handshake Retries from 52% to 3.7%. Those stories, like bijou64, are about reducing failure modes and improving trust in the system. They are not glamorous, but they are the foundation that more exciting work is built on. Even the Accelerate Local LLM Learning: A New Prototype for Faster Fact Correction shares a similar spirit: making complex systems more reliable and more understandable.

The takeaway we would leave you with is direct: adopt bijou64 not because it is new, but because it removes a class of bugs that you may not even know you have. The canonicality guarantee means that if you parse a bijou64 stream, you do not need to worry about duplicate representations of the same integer. That is not a luxury; it is a baseline for security. The open question is whether the broader ecosystem will adopt it as a standard, or whether it remains a niche tool for those who have been burned before. Watch how the ports mature and whether the encoding finds its way into critical libraries. That will tell you more than any benchmark ever could.

From InfoQ

Ink & Switch published bijou64, a variable-length integer encoding where every number has exactly one byte representation, closing the canonicality bug class behind attacks on PKCS#1, JWT libraries, and Bitcoin. The design also decodes two to ten times faster than LEB128. Community ports to Elixir, Go, Perl, and Java followed, while HN commenters debated SIMD performance and residual range checks.

Read the original at InfoQ