Apparently, it's a major pain to manipulate H.264 files and that's been slowing down research. At #reconmtl@elwrv introduced H26Forge which, when released in August, will undoubtedly act as a major catalyst. The whitepaper is currently available:
https://t.co/pYSZSzXl0X
#ResearchSaturday: Dave returns to video roots. Guest @elwrv of @UTAustin discusses "The Most Dangerous Codec in the World - Finding & Exploiting Vulnerabilities in H.264 Decoders." They found vulnerabilities & ultimately hidden security risks. Tune in: https://t.co/XCc7eOfCLo
#ResearchSaturday: Dave returns to video roots. Guest @elwrv of @UTAustin discusses "The Most Dangerous Codec in the World - Finding & Exploiting Vulnerabilities in H.264 Decoders." They found vulnerabilities & ultimately hidden security risks. Tune in: https://t.co/XCc7eOfCLo
Happy to finally share this paper, which has been 4 years in the making.
In a sentence, we construct general-purpose zero-knowledge proofs (leaking no information other than the correctness of the statement) in the setting of massive data streams.🧵
https://t.co/mFcVWCIZsr
NEW EPISODE!
@dadrian and @durumcrustulum gab about Tailscale's new Tailnet Lock, the Okta breach, what the fuck CISOs are for anyway, Rust in Android and Chrome, passkeys support, and of course, SBF.
https://t.co/KNV8izTuON
https://t.co/PeL4Ta5xIa Nice recent post on hardware acceleration and the sum-check protocol (or more generally any SNARK obtained by applying Fiat-Shamir to a logarithmic-round interactive protocol). Here is some additional context. (1/6)
A buddy who's interested in end-to-end encryption (E2EE) but hasn't done one of these projects in the very messy place which is the real world happened to ask me this morning about pitfalls which might not be obvious. So here's a partial list in the hopes that it's helpful. 🧵
let A be a PPT Turing Machine with access to a random tape.
output two ciphertexts to A
Hell, give it the plaintexts too
PPT algorithms can’t read
Laugh in IND-CCA2-illiteracy
Applying to grad school in EE/CS this fall? …need help?
Ask the MIT EECS Graduate Application Assistance Program! GAAP pairs applicants who need help with current PhD students for 1:1 mentoring. We match mentors weekly so it's never too late to sign up! https://t.co/EIKCHB1YeY
THREAD: The biggest story of my life is finally out.
Since 2019, I’ve been investigating a monitoring tool called Social Sentinel. They bill it as a way to help save students’ lives.
I found it had another purpose — surveilling campus protests. https://t.co/I0okAqeRen
Ok, so I got a chance to try out Safety Check. This is a new iOS 16 feature designed to quickly secure your phone against unwanted data sharing. It automates the old checklists I wrote (complained about) a while back.
Ever wanted to demonstrate your hacking prowess without revealing your special sauce? In our new paper (to appear at PETS23) we show how to prove, in zero-knowledge, that you can exploit a REAL system. Best of all, its efficient enough to use right now! A quick thread 1/6
After my last post, I had a request from some folks to discuss the security of SNARKs as they are currently deployed. I've done so in this new post here: https://t.co/PQ2BvDIGEe (1/9)
Overjoyed to announce The Secure Research Data Network Act #SRDN, the crowning achievement of my @AAAS_STPF! Huge thanks to Senator @RonWyden and team for entrusting me with the development and negotiation of this groundbreaking #bipartisan legislation 🧵 https://t.co/J7xqTD52Lx
Announcing the lattice-based cryptography club! Do you want to learn this type of cryptography? Find resources here: https://t.co/TEK2YB2ded Beautifully curated by @octaviopk and me. Thank you @Leptan@mfesgin@cryptocecy and more for allowing us to put your amazing thesis there!