#iacr — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iacr, aggregated by home.social.
-
Thanks to the #CAW #caw2026 organizers at #iacr #eurocrypt #eurocrypt2026 in #rome #italy for hosting my #shufflecake talk, great engagement, questions and audience feedback!
#crypto #cryptography #security #privacy #cypherpunk #foss #libre #opensource
-
Thanks to the #CAW #caw2026 organizers at #iacr #eurocrypt #eurocrypt2026 in #rome #italy for hosting my #shufflecake talk, great engagement, questions and audience feedback!
#crypto #cryptography #security #privacy #cypherpunk #foss #libre #opensource
-
FYI, I'll be schmoozing around at EUROCRYPT 2026, May 10-14 in Rome. My employer Horizen Labs is a sponsor of this amazing cryptography conference. I'll be giving a talk at the affiliated event CAW (Cryptography Applications Workshop) on the latest updates of Shufflecake, including juicy news on hidden OS. Pass by to say hi!
#cryptography #crypto #security #privacy #eurocrypt #iacr #horizenlabs #shufflecake #caw2026
-
FYI, I'll be schmoozing around at EUROCRYPT 2026, May 10-14 in Rome. My employer Horizen Labs is a sponsor of this amazing cryptography conference. I'll be giving a talk at the affiliated event CAW (Cryptography Applications Workshop) on the latest updates of Shufflecake, including juicy news on hidden OS. Pass by to say hi!
#cryptography #crypto #security #privacy #eurocrypt #iacr #horizenlabs #shufflecake #caw2026
-
Shufflecake will be presented at the Crypto Applications Workshop (CAW) in Rome, Italy (co-located with EUROCRYPT 2026 and many other crypto events), on May 10th, 2026. This talk is going to be an update of the latest news and status of the project in 2026, including juicy news on the Hidden OS!
https://shufflecake.net/#20260422-caw2026
#cryptography #crypto #security #privacy #eurocrypt #iacr #shufflecake #caw2026
-
Shufflecake will be presented at the Crypto Applications Workshop (CAW) in Rome, Italy (co-located with EUROCRYPT 2026 and many other crypto events), on May 10th, 2026. This talk is going to be an update of the latest news and status of the project in 2026, including juicy news on the Hidden OS!
https://shufflecake.net/#20260422-caw2026
#cryptography #crypto #security #privacy #eurocrypt #iacr #shufflecake #caw2026
-
i wonder if the #iacr #levchin #prize at #realworldcrypto this year goes to trump?
-
i wonder if the #iacr #levchin #prize at #realworldcrypto this year goes to trump?
-
It's public!
Fast Lightweight Online Encryption is a new secure way to do online (think "streaming") authenticated encryption with support for random access.
It comes with a public specification, reference code, test vectors, and a paper proving security.
- https://github.com/Snowflake-Labs/floe-specification
- https://eprint.iacr.org/2025/2275 -
It's public!
Fast Lightweight Online Encryption is a new secure way to do online (think "streaming") authenticated encryption with support for random access.
It comes with a public specification, reference code, test vectors, and a paper proving security.
- https://github.com/Snowflake-Labs/floe-specification
- https://eprint.iacr.org/2025/2275 -
Well, that’s embarrassing.
On the plus side, I guess it works.
-
Well, that’s embarrassing.
On the plus side, I guess it works.
-
International Cryptology Association Loses Crypto Keys, Voids Leadership Election
#Cybersecurity #Encryption #Security #IACR #Cryptography #ElectionSecurity #HumanError #Voting #Governance #KeyManagement #HeliosVoting #Privacy
-
International Cryptology Association Loses Crypto Keys, Voids Leadership Election
#Cybersecurity #Encryption #Security #IACR #Cryptography #ElectionSecurity #HumanError #Voting #Governance #KeyManagement #HeliosVoting #Privacy
-
密碼研究學會「遺失密碼」 無法解密選舉內容 導致整個投票要重來一次
國際密碼學研究協會(IACR)早前舉行年度管理層選舉,協會採用 Helios 開源電子投票系統,透過先進加密技 […]
#資訊保安 #Helios #IACR #密碼學
https://unwire.hk/2025/11/25/iacr-election-cancelled-key-lost-2025/tech-secure/?utm_source=rss&utm_medium=rss&utm_campaign=iacr-election-cancelled-key-lost-2025 -
Kryptograficzna wpadka roku: eksperci od szyfrowania zgubili klucz do własnych wyborów
To brzmi jak scenariusz kiepskiej komedii o działach IT, ale wydarzyło się naprawdę w jednej z najbardziej prestiżowych organizacji zajmujących się bezpieczeństwem na świecie.
International Association of Cryptologic Research (IACR) została zmuszona do anulowania wyników swoich corocznych wyborów do władz stowarzyszenia. Powód jest prozaiczny, a zarazem kuriozalny: jeden z urzędników zgubił klucz szyfrujący niezbędny do odczytania oddanych głosów. Organizacja przyznała, że odzyskanie wyników jest technicznie niemożliwe.
Głosowanie przeprowadzono przy użyciu systemu Helios, narzędzia open source, które wykorzystuje recenzowaną przez środowisko naukowe kryptografię do zapewnienia tajności i weryfikowalności wyborów.
Zgodnie z regulaminem stowarzyszenia, aby zapobiec manipulacjom, trzech niezależnych powierników otrzymało po jednej części materiału kryptograficznego. Aby odszyfrować ostateczne wyniki, system wymagał wprowadzenia wszystkich trzech części klucza prywatnego. Niestety, jeden z powierników „bezpowrotnie utracił” swoją część, co IACR określiło mianem „uczciwego, ale niefortunnego błędu ludzkiego”.
Konsekwencje tego zdarzenia są natychmiastowe. Moti Yung, powiernik, który nie był w stanie dostarczyć swojej części klucza, zrezygnował z pełnionej funkcji i został zastąpiony przez Michela Abdallę. Aby uniknąć powtórki z tej sytuacji w przyszłości, IACR zmienia procedury zarządzania kluczami prywatnymi. Zamiast wymagać kompletu trzech części, przyszłe wybory będą opierać się na mechanizmie progowym, wymagającym do odszyfrowania tylko dwóch z trzech fragmentów klucza. Nowe wybory rozpoczęły się w miniony piątek i potrwają do 20 grudnia.
#bezpieczenstwo #helios #iacr #kryptografia #news #szyfrowanie #wpadka #wybory
-
Cryptographers Held an Election. They Can’t Decrypt the Results.
Cryptographers Held an Election. They Can’t Decrypt the... #cryptography #iacr #election #encryption #helios #news #worldnews #nottheonion -
The results of the 2025 elections for the president and board members at the International Association for Cryptologic Research (IACR) have been botched because the results of the super-secure cryptographic e-voting system cannot be retrieved due to the "accidental loss" of a decryption key.
https://iacr.org/news/item/27138
While human mistakes happen, this incident comes under very troubling circumstances.
Why does an e-voting system of an association like IACR not support t-out-of-n threshold decryption?
Why is a system where a single party can collude to invalidate the vote considered acceptable?
Wouldn't be wiser to freeze to the date of November 20th the eligibility status for voting instead of "calling to arms" IACR members who had previously decided to opt out from Helios emails?
Does the identity of some of the candidates to Director represent a problem for IACR?
-
-
That said, I am glad that IACR is addressing this "human mistake" by making a "system design change" to a 2-of-3 quorum for the re-run.
https://www.iacr.org/news/item/27138
#IACR #Cryptography #KeyManagement #InfoSec #OPSEC #Elections
-
That said, I am glad that IACR is addressing this "human mistake" by making a "system design change" to a 2-of-3 quorum for the re-run.
https://www.iacr.org/news/item/27138
#IACR #Cryptography #KeyManagement #InfoSec #OPSEC #Elections
-
Possibly the funniest thing that could have happened in the board elections for the International Association
for Cryptologic Research -
Possibly the funniest thing that could have happened in the board elections for the International Association
for Cryptologic Research -
“Key Management” is the cryptographic community’s version of “…it’s always DNS”
International Association for Cryptologic Research runs secure vote and then loses the keys so nobody knows what the result is. As one commenter put it: “So a single member can collude to reset the vote?”
-
I will be at #IACR #Crypto2025 this year. I always enjoy meeting new people and catching up with old friends. If you're going, then please feel free to drop me a line.
-
"Towards Optimally Secure Deterministic Authenticated Encryption Schemes" was presented today at #IACR #Eurocrypt 2025 in Madrid.
https://link.springer.com/chapter/10.1007/978-3-031-91107-1_1 -
This morning our researcher Robin Geelen presented "Fully Homomorphic Encryption for Cyclotomic Prime Moduli" at #IACR #Eurocrypt 2025 in Madrid.
🔎Interested in this topic? Robin wrote a blog post to explain everything: https://www.esat.kuleuven.be/cosic/blog/eurocrypt-2025-a-new-fhe-scheme-for-high-precision-arithmetic/
#fhe #cryptography -
First Leg finished on the way to #iacr #eurocrypt . Rail construction between Göteborg and Hamburg so ferry it is
-
last year at #rwc2024 there was no streaming, intentionally. the reason they want people to come in person instead of sitting in front of a screen. sounds crazy? apparently companies argue if there is a stream they won't $$$ pay the travel for employees (what about people who are not employees? no idea). not this year though, i was told there will be #streaming. let's hope, for those unfortunate who cannot be there. #iacr
-
i want to go to #rwc2025 but am a bit bummed that the #iacr only accepts payment via credit cards. that is a serious gatekeeper. and when i ask for an alternative option i'm asked if would not reconsider and find a way to use a credit card. this makes me feel very sad, and i wonder where all the cryptographers disappeared that were into anonymous or payments from a less monopolized system. and no i'm not arguing for any #crapto like bitcoin, simple cash or sepa transfers are totally ok)
-
💥 ❤️ 📣 New updated revision of the #Shufflecake research paper 📣 ❤️ 💥 available on #IACR #Eprint https://eprint.iacr.org/2023/1529 and #arXiv https://arxiv.org/abs/2310.04589 (still not out, scheduled next Monday) which tracks changes up to software v0.4.5 and clarifies that the described scheme is the `Legacy' version of Shufflecake, and that future versions might deviate from the paper (*ah-ehm*... Lite *cough*). Also typo fixes and language improvements.
-
💥 ❤️ 📣 New updated revision of the #Shufflecake research paper 📣 ❤️ 💥 available on #IACR #Eprint https://eprint.iacr.org/2023/1529 and #arXiv https://arxiv.org/abs/2310.04589 (still not out, scheduled next Monday) which tracks changes up to software v0.4.5 and clarifies that the described scheme is the `Legacy' version of Shufflecake, and that future versions might deviate from the paper (*ah-ehm*... Lite *cough*). Also typo fixes and language improvements.
-
i was just told that it is deliberate that #realworldcrypto is not #streaming the event. apparently this is a controversial discussion every time. but they also decided next year will be streamed again... what i wonder though, why the secrecy? why not say it out on the webpage, sorry folks no streaming because of <reason>.
anyway, looking forward to the recordings, and next years streaming
-
seriously considering sponsoring live streaming (and archival) for the next #rwc when it is in europe... if anyone is interested, pls chip in, we have the hw and the personal we only need to cover travel and accommodation.
-
seriously considering sponsoring live streaming (and archival) for the next #rwc when it is in europe... if anyone is interested, pls chip in, we have the hw and the personal we only need to cover travel and accommodation.
-
can't believe it that there is no live stream for #realwordcrypto - #iacr please i beg you think of those that are not privileged to be there in person...
-
Looking for conferences on #Cryptography and #Security. #AfricaCrypt is in #Cameroon this year, a country that imprisons peolpe for *suspicions* of being gay. In 2021 to trans women were sent to prison for “wearing women’s clothing in a restaurant”.
In other words, we are talking about a complete shit-hole country and a non-negligible part of the cryptographic community cannot safely visit the conference because of that.
A conference that proudly associates itself with the #IACR. I think we should have a serious discussion about whether it is appropriate to place conferences in places that will imprison people for who they are and whether the IACR should associate with conferences that ignore these concerns.
For all the problems that conferences in the west have with accessibility (and that you may rightfully criticize), you can usually at least be confident that the government there won’t subject you to torture for who you are.
-
Die #IACR möchte eine Sammlung zu modernen Zero-Knowledge-Protokollen herausbringen und sucht dazu Veröffentlchungen:
-
💥 ❤️ 📣 New updated revision of the #Shufflecake research paper 📣 ❤️ 💥 available on #IACR #Eprint https://eprint.iacr.org/2023/1529 and #arXiv https://arxiv.org/abs/2310.04589 with improved pseudocode and explanation of the volume corruption mitigation strategy adopted in v0.4.3.
-
💥 ❤️ 📣 Full #Shufflecake paper 📣 ❤️ 💥 now available on #IACR #Eprint https://eprint.iacr.org/2023/1529
-
Superathlete? No.
Supersingular? Yes! -
CW: research review
The papers for this review:
* "Active TLS Stack Fingerprinting: Characterizing TLS Server Deployments at Scale"
* "HyPFuzz: Formal-Assisted Processor Fuzzing"
* "FPGA-Patch: Mitigating Remote Side-Channel Attacks on FPGAs using Dynamic Patch Generation"
* "30 Years of Synthetic Data"
* "On the Limits of Cross-Authentication Checks for GNSS Signals"
* "New Ways to Garble Arithmetic Circuits"
* "Exploration of Quantum Computer Power Side-Channels"
* "Side-Channel Analysis of Integrate-and-Fire Neurons within Spiking Neural Networks"
* "Those Aren't Your Memories, They're Somebody Else's: Seeding Misinformation in Chat Bot Memories"
* "Multi-step Jailbreaking Privacy Attacks on ChatGPT"
* "Measuring and Evading Turkmenistan's Internet Censorship: A Case Study in Large-Scale Measurements of a Low-Penetration Country"#IACR #arXiv #ResearchPapers #TLS #Fuzzing #FPGA #SideChannelAttacks #SyntheticData #GNSS #GPS #GarbledCircuits #QuantumComputers #PowerSideChannelAttacks #NeuralNetworks #SpikingNeuralNetworks #ChatBots #ChatGPT #CensorshipResistance
-
Hey is the #IACR already on the fediverse? And can we have #eprint as an #activitypub feeds? retoot if you agree please
-
CW: research review
S. Haskins and T. Stevado, "Unlocking doors from half a continent away: A relay attack against HID Seos"¹
HID Global is a major vendor of physical access control systems. In 2012, it introduced Seos, its newest and most secure contactless RFID credential technology, successfully remediating known flaws in predecessors iCLASS and Prox. Seos has been widely deployed to secure sensitive assets and facilities. To date, no published research has demonstrated a security flaw in Seos. We present a relay attack developed with inexpensive COTS hardware, including the Proxmark 3 RDV4. Our attack is capable of operating over extremely long ranges as it uses the Internet as a communications backbone. We have tested multiple real-world attack scenarios and are able to unlock a door in our lab with a card approximately 1960 km away. Our attack is covert and does not require long-term access to the card. Further, our attack is generic and is potentially applicable to other protocols that, like Seos, use ISO/IEC 14443A to communicate. We discuss several mitigations capable of thwarting our attack that could be introduced in future credential systems or as an update to Seos-compatible readers' firmware; these rely on rejecting cards that take too long to reply.
#IACR #ResearchPapers #HIDGlobal #RFID #RelayAttack #Cryptanalysis #PhysicalAccessControl #ISO14443
__
¹ https://eprint.iacr.org/2023/450 -
Public Service Announcement: I try to toot updates from both IACR and arXiv (plus a few other sites) which I find interesting, I underline the "I", but which might be of interest to others.
I always use the CW "research review" and the tags #ResearchPapers #arXiv #IACR plus other tags which are appropriate (either lifting them from the "keyword" section of the paper or what seems sensible to me).
-
CW: research review
D. Lammers et al., "Glitch-free is not Enough - Revisiting Glitch-Extended Probing Model"¹
Today, resistance to physical defaults is a necessary criterion for masking schemes. In this context, the focus has long been on designing masking schemes guaranteeing security in the presence of glitches. Sadly, immunity against glitches increases latency as registers must stop the glitch propagation. Previous works could reduce the latency by removing register stages but only by impractically increasing the circuit area. Nevertheless, some relatively new attempts avoid glitches by applying DRP logic styles. Promising works in this area include LMDPL, SESYM - both presented at CHES - and Self-Timed Masking - presented at CARDIS - enabling to mask arbitrary circuits with only one cycle latency. However, even if glitches no longer occur, there are other physical defaults that may violate the security of a masked circuit. Imbalanced delay of dual rails is a known problem for the security of DRP logic styles such as WDDL but not covered in formal security models.
In this work, we fill the gap by presenting the delay-extended probing security model, a generalization of the popular glitch-extended probing model, covering imbalanced delays. We emphasize the importance of such a model by a formal and practical security analysis of LMDPL, SESYM, and Self-Timed Masking. While we formally prove the delay-extended security of LMDPL and Self-Timed Masking, we show that SESYM fails to provide security under our defined security model what causes detectable leakage through experimental evaluations. Hence, as the message of this work, avoiding glitches in combination with d-probing security is not enough to guarantee physical security in practice.#IACR #ResearchPapers #SideChannelAnalysis #Masking #Glitching
__
¹ https://eprint.iacr.org/2023/035 -
CW: research review
J. Zeitschner et al., "PROLEAD_SW - Probing-Based Software Leakage Detection for ARM Binaries"¹
A decisive contribution to the all-embracing protection of cryptographic software, especially on embedded devices, is the protection against SCA attacks. Masking countermeasures can usually be integrated into the software during the design phase. In theory, this should provide reliable protection against such physical attacks. However, the correct application of masking is a non-trivial task which often causes even experts to make mistakes. In addition to human-caused errors, micro-architectural CPU effects can lead even a seemingly theoretically correct implementation to fail satisfying the desired level of security in practice. This originates from different components of the underlying CPU which complicates the tracing of leakage back to a particular source and hence avoids to make general and device-independent statements about its security.
In this work, we adapt PROLEAD for the evaluation of masked software, which has recently been presented at CHES 2022 and originally developed as a simulation-based tool to evaluate masked hardware designs.
We enable to transfer the already known benefits of PROLEAD into the software world. These include (1) evaluation of larger designs compared to the state of the art, e.g. a full AES masked implementation, and (2) formal verification under the well-established robust probing security model. In short, together with an abstraction model for the micro-architecture, the robust probing model allows us to efficiently detect micro-architectural leakages while being independent of a concrete CPU design. As a concrete result, using PROLEAD_SW we evaluated the security of several publicly available masked software implementations and revealed multiple vulnerabilities.Software: https://github.com/ChairImpSec/PROLEAD
#IACR #ResearchPapers #ARM #SoftwareLeakageDetection
__
¹ https://eprint.iacr.org/2023/034 -
CW: research review
H. Böck, "Fermat Factorization in the Wild"¹
We are applying Fermat’s factorization algorithm to sets of public RSA keys. Fermat’s factorization allows efficiently calculating the prime factors of a composite number if the difference between the two primes is small. Knowledge of the prime factors of an RSA public key allows efficiently calculating the private key. A flawed RSA key generation function that produces close primes can therefore be attacked with Fermat’s factorization.
We discovered a small number of vulnerable devices that generate such flawed RSA keys in the wild. These affect devices from two printer vendors - Canon and Fuji Xerox. Both use an underlying cryptographic module by Rambus.#IACR #ResearchPapers #FermatFactorisation #Canon #FujiXerox #RambusCryptographicModule
__
¹ https://eprint.iacr.org/2023/026 -
CW: scary science paper
This has definitely been an incredibly engaging paper. Here’s my most annotated page.
The padding solution described is certainly easy to use for schemes that support it, but the generic solution is creative and stimulating.
The paper is https://ia.cr/2020/1456 “How to Abuse and Fix Authenticated Encryption Without Key Commitment” #cryptography #science #iacr
-
The IACR election tally has been computed and partial decryption has started! Keep tuned for the results as soon as all trustees have partially decrypted the tally! :blobcataww: #iacr #cryptography #elections