#cryptography — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cryptography, aggregated by home.social.
-
CVE-2026-74889 - Critical crypto weakness in openssl_encrypt <1.4.0. HKDF with no salt/static info weakens key derivation, enabling multi-target attacks. CVSS 9.8. Update immediately. #CVE #cryptography #infosec
-
CVE-2026-74889 - Critical crypto weakness in openssl_encrypt <1.4.0. HKDF with no salt/static info weakens key derivation, enabling multi-target attacks. CVSS 9.8. Update immediately. #CVE #cryptography #infosec
-
Se viene intensa la segunda mitad del año!
A fines de setiembre voy a estar dando una conferencia online sobre Criptografía post-cuántica en #Ubuntu en la #UbuConLa... si andan por allá dense una vuelta! :ubuntu: :gnu: :linux:
Creo que se va a transmitir en vivo el evento, les comparto por acá cualquier novedad, link de acceso y demás.
Por mi parte, a leer y jugar con comandos 🤓 🖥️
#juncotic #ubuntu #ubuconla2026 #ubucon #canonical #gnu #linux #cybersecurity #infosec #pqcrypto #cryptography
-
Se viene intensa la segunda mitad del año!
A fines de setiembre voy a estar dando una conferencia online sobre Criptografía post-cuántica en #Ubuntu en la #UbuConLa... si andan por allá dense una vuelta! :ubuntu: :gnu: :linux:
Creo que se va a transmitir en vivo el evento, les comparto por acá cualquier novedad, link de acceso y demás.
Por mi parte, a leer y jugar con comandos 🤓 🖥️
#juncotic #ubuntu #ubuconla2026 #ubucon #canonical #gnu #linux #cybersecurity #infosec #pqcrypto #cryptography
-
None can be a #cybersecurity warrior without knowing the basics of secret speech and writing. #cryptography" ?> https://cromwell-intl.com/cybersecurity/crypto/?s=mc
-
None can be a #cybersecurity warrior without knowing the basics of secret speech and writing. #cryptography" ?> https://cromwell-intl.com/cybersecurity/crypto/?s=mc
-
Use steganography to hide messages in an image in Python
-
Use steganography to hide messages in an image in Python
-
Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.
At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.
An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.
Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.
Four claims and the evidence, including the one regulator that did say something:
https://postquantum.com/post-quantum/protecting-the-cbom/
#PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity
-
CVE-2026-74876 - Critical crypto flaw in openssl_encrypt <1.4.0. Unverified key bundles allow secret leakage via attacker-controlled keys. CVSS 9.8. Unpatched - update immediately. #CVE #infosec #cryptography
-
CVE-2026-74876 - Critical crypto flaw in openssl_encrypt <1.4.0. Unverified key bundles allow secret leakage via attacker-controlled keys. CVSS 9.8. Unpatched - update immediately. #CVE #infosec #cryptography
-
Looks like lattice based cryptography gets to survive another day:
https://eprint.iacr.org/2026/1693
The authors credit ChatGPT with generalizing their main theorem and with producing a lean formalization, which is also pretty neat.
-
FYI: Cryptographic publisher IDs reach Japan as fake news clones multiply: Cryptographic publisher IDs reach Japan's two largest newspapers as OP-CIP targets 50 organizations by 2027, Brazil suspends Discord video and DOOH climbs. https://ppc.land/cryptographic-publisher-ids-reach-japan-as-fake-news-clones-multiply/ #Cryptography #FakeNews #DigitalPublishing #MediaIntegrity #JapanNews
-
A quick look at zero-knowledge proofs
https://bernsteinbear.com/blog/zkp/
Comments: https://news.ycombinator.com/item?id=49303776
#HackerNews #zero-knowledge-proofs #cryptography #privacy #security #technology
-
A quick look at zero-knowledge proofs
https://bernsteinbear.com/blog/zkp/
Comments: https://news.ycombinator.com/item?id=49303776
#HackerNews #zero-knowledge-proofs #cryptography #privacy #security #technology
-
Meet KEMchatka: an experimental, serverless P2P terminal chat over Tor hidden services.
No accounts, no port forwarding, zero disk logging.
Features hybrid post-quantum encryption: X25519 + ML-KEM-1024 (FIPS 203) combined via HKDF-SHA512 to defeat "harvest now, decrypt later" attacks. Simple out-of-band setup.
When privacy is under threat, build tools that protect it.
https://github.com/bashcore/kemchatka
#PostQuantum #Tor #Python #CyberSecurity #Privacy #OpenSource #Cryptography
-
Meet KEMchatka: an experimental, serverless P2P terminal chat over Tor hidden services.
No accounts, no port forwarding, zero disk logging.
Features hybrid post-quantum encryption: X25519 + ML-KEM-1024 (FIPS 203) combined via HKDF-SHA512 to defeat "harvest now, decrypt later" attacks. Simple out-of-band setup.
When privacy is under threat, build tools that protect it.
https://github.com/bashcore/kemchatka
#PostQuantum #Tor #Python #CyberSecurity #Privacy #OpenSource #Cryptography
-
@malb thanks for reporting, I feel I'm aging faster whenever results like this appear.
Now, how about https://eprint.iacr.org/2026/1630 ? Sigh...
-
@malb thanks for reporting, I feel I'm aging faster whenever results like this appear.
Now, how about https://eprint.iacr.org/2026/1630 ? Sigh...
-
f/1.8 and be there!
#cryptography #shitpost -
f/1.8 and be there!
#cryptography #shitpost -
The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. Justin Drake called it the end of an eight year, eight figure rabbit hole. I tried to understand what actually happened, and the short version is that nobody broke anything.
The Foundation paused its $992,000 Poseidon1 collision prize on August 1, twelve days before the announcement. Two years of funded cryptanalysis, roughly $1.36M in announced ceilings, produced exactly what such programs should. Reduced-round results, a partial collision tier claimed in April, and no break on any parameter set that matters.
What changed was the proving side. Binius at EUROCRYPT 2025 and then Flock this June made bit-oriented hashes cheap inside binary-field SNARKs. Flock proves 660k+ BLAKE3 compressions per second on ten M4 Max cores at under 250x native cost. Poseidon existed to make hashing affordable in prime-field circuits, and that problem dissolved.
Two details the coverage missed. Buterin publicly refused a Poseidon precompile in February. The program had found Poseidon2 issues needing extra rounds or a reversion to Poseidon1, and enshrining one version meant a dangling precompile forever. And Anthropic's July release, the one that broke HAWK, also pointed Mythos at Poseidon and got under 10x, a mildly reassuring data point almost nobody registered.
For this audience the RC4 parallel will make sense. AES-NI shipped in 2010, RC4 hung on through BEAST era workarounds, and RFC 7465 only killed it in 2015. Same shape here, except Ethereum's dependency was still in a research roadmap instead of a billion endpoints. The rest of us have the harder version.
Full analysis, including the four things the announcement doesn't say and the caveat that the binary-field provers doing this are young software. Full analysis:
https://postquantum.com/security-pqc/ethereum-roadmap-drops-poseidon/
-
Cryptanalysts are using AI models now, openly and on live claims. So what does "independently confirmed" mean? Less than it meant two years ago, and two events this summer show why.
April 2024 is the baseline. Yilei Chen posted a claimed polynomial-time quantum algorithm for LWE on the first day of the NIST PQC Standardization Conference. Eight days later he withdrew it, with an acknowledgment thanking Hongxun Wu and, independently, Thomas Vidick for finding the bug in Step 9. That parenthetical is the whole quality control mechanism of the field. Two experts, reasoning separately, converged on the same defect. Neither had seen the other's reading.
July 23, 2026. Ananth and Sahai at UCSB and UCLA posted a proof of efficient unclonable encryption at 10:35 Pacific. Seyoon Ragavan at MIT posted the same result three hours and eighteen minutes later. Both credited GPT-5.6 Sol Ultra with the core ideas. Both traced to the same Simons Institute talk. Neither knew the other was working on it. Ragavan drove the model in supervised two-hour stretches; Ananth and Sahai used a self-critiquing UCLA harness. Two workflows about as different as two workflows get, one construction, one working day.
August 2026. Daniel Simon's claimed polynomial-time algorithm for the Dihedral Coset Problem is being adjudicated right now on ePrint and Discord, in days rather than months, with Bernstein and Kirshanova among the people reading it. Several of the substantive responses were produced by humans working with models. One lists two language models on its byline. Disclosure across the documents is uneven: some name the model and version, some say only "AI assistance."
The mechanism cryptanalysis depends on is not expertise. It is decorrelated failure. Two humans with similar training still make different mistakes, at different points, for different reasons, and their errors decorrelate even when their education does not. The risk with shared tooling is not sampling correlation. It is common-cause error, where shared weights, training data, post-training and retrieval reproduce the same blind spot across operators who have no way of noticing they share it.
I am not claiming three model-assisted reviews reduce to one. I am claiming we currently lack the provenance to know how much independent weight they deserve.
The fix is cheap. Every cryptanalysis note that circulates before peer review should end with two sections: who found what, and what was checked by whom, with what, and how hard. Ragavan's paper already does most of it, and ships a Lean 4 formalization that states which claims it does not cover. A kernel shares no weights with anything.
IACR has barred models from bylines since May 2025. That rule governs formal submission. It does not reach the circulating notes where Simon is actually being adjudicated.
(This post was edited by AI, but the points are mine. If anyone else wrote the same thing around the same time, blame it on ChatGPT)
https://postquantum.com/post-quantum/independence-problem-ai-cryptanalysis/
#infosec #cryptography #cryptanalysis #PQC #postquantum #formalmethods
-
Cryptanalysts are using AI models now, openly and on live claims. So what does "independently confirmed" mean? Less than it meant two years ago, and two events this summer show why.
April 2024 is the baseline. Yilei Chen posted a claimed polynomial-time quantum algorithm for LWE on the first day of the NIST PQC Standardization Conference. Eight days later he withdrew it, with an acknowledgment thanking Hongxun Wu and, independently, Thomas Vidick for finding the bug in Step 9. That parenthetical is the whole quality control mechanism of the field. Two experts, reasoning separately, converged on the same defect. Neither had seen the other's reading.
July 23, 2026. Ananth and Sahai at UCSB and UCLA posted a proof of efficient unclonable encryption at 10:35 Pacific. Seyoon Ragavan at MIT posted the same result three hours and eighteen minutes later. Both credited GPT-5.6 Sol Ultra with the core ideas. Both traced to the same Simons Institute talk. Neither knew the other was working on it. Ragavan drove the model in supervised two-hour stretches; Ananth and Sahai used a self-critiquing UCLA harness. Two workflows about as different as two workflows get, one construction, one working day.
August 2026. Daniel Simon's claimed polynomial-time algorithm for the Dihedral Coset Problem is being adjudicated right now on ePrint and Discord, in days rather than months, with Bernstein and Kirshanova among the people reading it. Several of the substantive responses were produced by humans working with models. One lists two language models on its byline. Disclosure across the documents is uneven: some name the model and version, some say only "AI assistance."
The mechanism cryptanalysis depends on is not expertise. It is decorrelated failure. Two humans with similar training still make different mistakes, at different points, for different reasons, and their errors decorrelate even when their education does not. The risk with shared tooling is not sampling correlation. It is common-cause error, where shared weights, training data, post-training and retrieval reproduce the same blind spot across operators who have no way of noticing they share it.
I am not claiming three model-assisted reviews reduce to one. I am claiming we currently lack the provenance to know how much independent weight they deserve.
The fix is cheap. Every cryptanalysis note that circulates before peer review should end with two sections: who found what, and what was checked by whom, with what, and how hard. Ragavan's paper already does most of it, and ships a Lean 4 formalization that states which claims it does not cover. A kernel shares no weights with anything.
IACR has barred models from bylines since May 2025. That rule governs formal submission. It does not reach the circulating notes where Simon is actually being adjudicated.
(This post was edited by AI, but the points are mine. If anyone else wrote the same thing around the same time, blame it on ChatGPT)
https://postquantum.com/post-quantum/independence-problem-ai-cryptanalysis/
#infosec #cryptography #cryptanalysis #PQC #postquantum #formalmethods
-
ICYMI: Cryptographic publisher IDs reach Japan as fake news clones multiply: Cryptographic publisher IDs reach Japan's two largest newspapers as OP-CIP targets 50 organizations by 2027, Brazil suspends Discord video and DOOH climbs. https://ppc.land/cryptographic-publisher-ids-reach-japan-as-fake-news-clones-multiply/ #Cryptography #FakeNews #JapanNews #MediaIntegrity #DigitalIdentity
-
🚨 Breaking News! 🚨 The #NSA and #IETF continue their epic saga of cryptographic ping-pong. 🏓 If you thought the last eight parts were thrilling, part 9 is here to remind you that you can, in fact, fall asleep with your eyes open. 😴🔍
https://blog.cr.yp.to/20260814-update.html #BreakingNews #Cryptography #TechSaga #Cybersecurity #HackerNews #ngated -
🚨 Breaking News! 🚨 The #NSA and #IETF continue their epic saga of cryptographic ping-pong. 🏓 If you thought the last eight parts were thrilling, part 9 is here to remind you that you can, in fact, fall asleep with your eyes open. 😴🔍
https://blog.cr.yp.to/20260814-update.html #BreakingNews #Cryptography #TechSaga #Cybersecurity #HackerNews #ngated -
#TutaMail and #ProtonMail are by far the world's two best #email providers/services for #Anonymity, #Privacy and #Security (#APS).
I have recently (12th August 2026) carried out a thorough #research into this as I am planning to migrate to whichever is the best email provider/service for APS and move away from and ditch #USA #BigTech.
Between the two, the one that comes on top depends on what you value most on aggregate. In individual edge terms, here is how they compare:
Tuta Mail: cheaper; more custom domains; more email addresses; more established/robust Post- #Quantum (PQ) Security today; most integrated encrypted ecosystem; better custom-domain #migration; purest cryptographic #architecture; slightly stronger #FOSS #philosophy.
ProtonMail: better PQ #cryptography evolution and #interoperability; much better for open standards; much better #Thunderbird #compatibility; better (long-term) export / #portability; much easier/better to change client and/or provider later; (far) richer #feature set.
-
Everything is about to "go dark"
https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/
Comments: https://news.ycombinator.com/item?id=49304447
#HackerNews #go #dark #cryptography #technology #security #news #blog
-
Everything is about to "go dark"
https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/
Comments: https://news.ycombinator.com/item?id=49304447
#HackerNews #go #dark #cryptography #technology #security #news #blog
-
In today's thrilling episode of "Security Theater 101," Z.ai bombards us with an eye-watering jumble of numbers and acronyms that would confuse even the most seasoned conspiracy theorist. 🤯 Amongst the chaos, we're told something about Apple's Safari and FreeBSD's #vulnerabilities, but you'll need a decoder ring and a PhD in #cryptography to figure out the rest. 🔍💾
https://cvd.z.ai #SecurityTheater #Zai #AppleSafari #FreeBSD #HackerNews #ngated -
In today's thrilling episode of "Security Theater 101," Z.ai bombards us with an eye-watering jumble of numbers and acronyms that would confuse even the most seasoned conspiracy theorist. 🤯 Amongst the chaos, we're told something about Apple's Safari and FreeBSD's #vulnerabilities, but you'll need a decoder ring and a PhD in #cryptography to figure out the rest. 🔍💾
https://cvd.z.ai #SecurityTheater #Zai #AppleSafari #FreeBSD #HackerNews #ngated -
Cryptographic publisher IDs reach Japan as fake news clones multiply: Cryptographic publisher IDs reach Japan's two largest newspapers as OP-CIP targets 50 organizations by 2027, Brazil suspends Discord video and DOOH climbs. https://ppc.land/cryptographic-publisher-ids-reach-japan-as-fake-news-clones-multiply/ #Cryptography #FakeNews #DigitalPublishing #JapanNews #MediaIntegrity
-
CW: llm producing genuinely impressive cryptographic result
I was looking at the NIST-competition for further signatures at work today and noticed that HAWK has been withdrawn...
(Context: NIST wasn't exactly enthusiastic about any signature scheme in the previous pqc competition and started a new one that is now in round three with only a few schemes left. HAWK was the only remaining lattice based scheme with the claim to fame being that it is basically FALCON (in standardization by NIST as FN-DSA) without the need for floating point arithmetic.)
Now it turns out that Anthropic has an LLM that managed to find a severe enough attack to require enough of an adjustment to the parameters, that HAWK would become noncompetitive.
This was genuinely new, clearly found by AI, on a very high profile target that lots of humans actively tried to break unsuccessfully, and clearly important that it was found...
They also managed to improve the cryptanalysis on a round reduced version of AES, another VERY impressive feat!
There is a genuine argument now that AI is competitive with the best human cryptanalysts and I am not yet sure what to make of that... 😐
#crypto #cryptography #pqc -
CW: llm producing genuinely impressive cryptographic result
I was looking at the NIST-competition for further signatures at work today and noticed that HAWK has been withdrawn...
(Context: NIST wasn't exactly enthusiastic about any signature scheme in the previous pqc competition and started a new one that is now in round three with only a few schemes left. HAWK was the only remaining lattice based scheme with the claim to fame being that it is basically FALCON (in standardization by NIST as FN-DSA) without the need for floating point arithmetic.)
Now it turns out that Anthropic has an LLM that managed to find a severe enough attack to require enough of an adjustment to the parameters, that HAWK would become noncompetitive.
This was genuinely new, clearly found by AI, on a very high profile target that lots of humans actively tried to break unsuccessfully, and clearly important that it was found...
They also managed to improve the cryptanalysis on a round reduced version of AES, another VERY impressive feat!
There is a genuine argument now that AI is competitive with the best human cryptanalysts and I am not yet sure what to make of that... 😐
#crypto #cryptography #pqc -
Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.
Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.
Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.
So I try to explain the change.
https://postquantum.com/security-pqc/google-cloud-pqc-roadmap/
#PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity
-
Yomiuri and Asahi gain cryptographic IDs as fake clones of their sites spread: Dentsu is signing its own Japanese ad buys with the same credential, and OP-CIP wants 50 organizations running it by early 2027. Will browser makers follow? https://ppc.land/yomiuri-and-asahi-gain-cryptographic-ids-as-fake-clones-of-their-sites-spread/ #Cryptography #DigitalSecurity #AdTech #BrowserSafety #WebAuthenticity
-
Introducing Automatic Key Verification https://lobste.rs/s/b3y5qs #cryptography #privacy
https://signal.org/blog/automatic-key-verification/ -
Introducing Automatic Key Verification https://lobste.rs/s/b3y5qs #cryptography #privacy
https://signal.org/blog/automatic-key-verification/ -
I can't believe they chose "Mallory" as the attacker's name in the man-in-the-middle attack when "Malcolm" was right there
-
I can't believe they chose "Mallory" as the attacker's name in the man-in-the-middle attack when "Malcolm" was right there
-
Unpatched #HP #ThinPro flaw allows bypass of disk #encryption protections
https://cyberinsider.com/unpatched-hp-thinpro-flaw-allows-bypass-of-disk-encryption-protections/
-
Unpatched #HP #ThinPro flaw allows bypass of disk #encryption protections
https://cyberinsider.com/unpatched-hp-thinpro-flaw-allows-bypass-of-disk-encryption-protections/
-
https://specifications.freedesktop.org/secret-service/latest/
Is this the state-of-the-art design? 🤔
-
https://specifications.freedesktop.org/secret-service/latest/
Is this the state-of-the-art design? 🤔
-
This is the part of 2FA/TOTP that many people don’t realize:
Your phone isn’t receiving the 6-digit code from the server.
Instead, your authenticator app acts like a specialized cryptographic calculator. 🧮🔐
It takes a shared secret key, combines it with the current time, and applies the TOTP algorithm to generate a temporary 6-digit code.
At the same time, the server independently performs the same calculation using its copy of the secret key and the same time counter.
Same secret + same time counter + same algorithm = same result.
That’s why your authenticator app can generate the correct code without receiving it from the server.
It’s a simple idea, but a brilliant application of cryptography.
You can even test this yourself: add the same TOTP secret to both Google Authenticator and Microsoft Authenticator. Even if you set them up at different times, both apps can independently generate the same 6-digit code at the same time.
And here’s another important point:
The algorithm doesn’t need to be secret.
TOTP is based on publicly known, standardized cryptographic algorithms such as HMAC. What needs to remain secret is the shared secret key.
So:
🧮 Algorithm/math: Can be publicly known.
🔑 Secret key: Must remain private. Never share it.
⏱️ Time: Isn’t secret.
🔐 Security: Comes from protecting the secret key, not from hiding the algorithm.That’s a core principle of modern cryptography: A cryptographic system should remain secure even when the algorithm is publicly known. The secret is the key.
#2FA #TwoFactor #Security #Cybersecurity #SecretKey #Authentication #Cryptography #Math #TOTP #OTP #AuthenticatorApp #Internet #SecurityResearch