I m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaining to colleagues why Baltimore isn t actually like The Wire. And second, trying not to talk about AI. Here I m going to Continue reading Everything is about to go dark
Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAWK, while the second is an improved attack against reduced-round AES. Anthropic also released a blog post describing the research process that produced these results. A few people Continue reading Some…
Yesterday Apple announced a big step towards deploying real AI in their Siri ecosystem. In most ways this is good and inevitable: Siri is one of the world s most widely-used voice agents, and it would be good if it didn t suck. The idea that Apple would boost its capabilities with frontier models wasn t so much Continue reading The future of Siri, or: why private inference isn’t private enough
Update August 11, 2026: A group of researchers from all over Europe were inspired by this post, and actually turned it into a real working attack! Check out their writeup and paper here. This is a quick post I wanted to write about a hobby project I spent a weekend on. It has little to Continue reading Let s talk about encrypted reasoning
This is the second in a series of posts about anonymous credentials. You can find the first part here. In the previous post, we introduced the notion of anonymous credentials as a technique that allows users to authenticate to a website without sacrificing their privacy. As a quick reminder, an anonymous credential system consists of Continue reading Anonymous credentials: an illustrated primer…
This post has been on my back burner for well over a year. This has bothered me, since with every month that goes by, I become more convinced that anonymous authentication the most important topic we could be talking about as cryptographers. This isn t just because I love neat cryptography: it s that I don t trust Continue reading Anonymous credentials: an illustrated primer
It s not every day that we see mainstream media get excited about encryption apps! For that reason, the past several days have been fascinating, since we ve been given not one but several unusual stories about the encryption used in WhatsApp. Or more accurately, if you read the story, a pretty wild allegation that the widely-used Continue reading WhatsApp Encryption, a Lawsuit, and a Lot of Noise
I learn about cryptographic vulnerabilities all the time, and they generally fill me with some combination of jealousy ( oh, why didn t I think of that ) or else they impress me with the brilliance of their inventors. But there s also another class of vulnerabilities: these are the ones that can t possibly exist in important production software, Continue reading Kerberoasting
Update 6/10: Based on a short conversation with an engineering lead at X, some of the devices used at X are claimed to be using HSMs. See more further below. Matthew Garrett has a nice post about Twitter (uh, X) s new end-to-end encryption messaging protocol, which is now called XChat. The TL;DR of Matthew s post Continue reading A bit more on Twitter/X s new encrypted messaging
This is a cryptography blog and I always feel the need to apologize for any post that isn t straight cryptography. I m actually getting a little tired of apologizing for it (though if you want some hard-core cryptography content, there s plenty here and here.) Sometimes I have to remind my colleagues that out in the real Continue reading Dear Apple: add Disappearing Messages to iMessage right now