RSSAmplifier

Blog

gtank writes here

gtank writes here

blog.gtank.ccRSS feed ↗11 posts

Latest posts

Taxonomies

This is one of my favorite poems. There's no interesting story behind it: I picked up a book for its cover (at a time when I wasn't accustomed to buying books of poetry) and it's stayed with me ever since. Working with computers for

Notes on anonymous credentials

Best anonymous credentials that don't use pairings: Single show, no attributes, symmetric issuer: Privacy Pass; uses VOPRFs Multi show, attributes, symmetric issuer: CMZ14 (original, https://eprint.iacr.org/2013/516 )/CPZ19 (group element attribute variant, https://eprint.iacr.org/2019/1416 ); uses "algebraic MACs" and categorically

Notes on threshold signature schemes

A threshold signature allows a subset t of a group of n possible signers to collectively produce a signature for the entire group. The simplest ones tend to use some distributed key generation ("DKG") based on verifiable secret sharing ("VSS") to construct the keys and secret

Humanist social networking

Despite their name and ostensible purpose, social networks aren't very human. To companies, engineers, and advertisers, the emphasis has been on network , not social . We flatten users into profiles and communities into graphs. While it's certainly convenient for databases, it's an utter failure at

Adding privacy to legacy protocols with zero-knowledge proofs

Last January, Adam Langley did a really cool thing. He grafted zero-knowledge proofs onto an already-deployed, non-upgradable hardware system, thereby gaining privacy that the original design never allowed. I am VERY EXCITED ABOUT THIS. It's an existence proof for all kinds of amazing things. The

How to lock down your Google account

If someone has access to your Google account, they have immense power to track  or impersonate you. Whether they broke in, stole a computer, or you gave them access and now want them gone, here's what you can do to kick them out. First, get a computer

Advice for conference speakers

I've spent many hours working on tech conference talks over the past few years. I've spent even more time than that helping other people refine their talks, everything from startup pitches to lectures on cryptographic research, and after a recent week of conferencing I've

Efficient Private Contact Search

Recently, a friend and I indulged in the very normal spring weekend activity of discussing the Signal contact discovery problem in the park. The contact discovery problem is this: a service holds a list of all registered users, and an individual user has an address book. The user wants to

Modern Alternatives to PGP

Did your last Yubikey just break? Perhaps you forgot an offline backup password. Maybe you're just tired of living like a spy and never using smartphones. Whatever it is, you're here, and you're finally ready to give up on PGP . That's great!

A Macaroons Reading List

Macaroons are one of my favorite cryptographic constructions. They were almost the first one I really understood, and they heavily influence my designs for anything involving authorization. There's a lot to love about macaroons. They're elegant and fast. They're secure and easy to reason

Getting Started With Tor Development

Introduction Tor is an anonymity and censorship circumvention tool that uses a network of relays around the world to mask the origins and destinations of traffic. It's used by researchers, journalists, and activists all over the world, as well as by ordinary people who want to keep their