@joncallas@IceSolst Hmm. Is this sleep interruptible? Under what conditions? Is it a low-power sleep? Idle? Busy loop? Behave the same across architectures? If there is a suspend is it monotonic and finishes its interval, or skips? Love it.
Anthropic said no to the Pentagon.
Now Sam Altman is backing them:
"For all the differences I have with Anthropic, I mostly trust them as a company and I think they really do care about safety."
OpenAI and Anthropic both drawing the same line.
This is a big deal.
.@signalapp just rolled out quantum-resistant messaging to billions of people. This is a big deal.
Let me walk you through what's happening and why I think this matters.
For non-cryptography folks: the simple version:
You know how we worry about hackers? Well, future quantum computers will be like super-hackers that can break most of today's encryption.
Governments are already recording encrypted messages now, planning to decrypt them later when quantum computers exist. Signal just made your messages immune to this - and you didn't have to do anything. No app update to install, no settings to change. It just... works.
That's it. If you don't care about the technical details, you can stop reading here.
For everyone else: what's actually happening
Signal added a new layer called SPQR (Sparse Post-Quantum Ratchet) to their existing Double Ratchet. Instead of replacing the current protocol, they're running both in parallel and mixing the keys together - hence "Triple Ratchet."
The clever bit: an attacker now has to break BOTH elliptic curve crypto AND ML-KEM to read your messages. You get quantum resistance without giving up any of your current security.
The engineering problem they solved
Here's where it gets interesting. ML-KEM keys are massive - 1184 bytes versus 32 bytes for ECDH. That's a 37x increase. On mobile networks where every byte costs money, this could've been a disaster.
Their solution involves three things:
1. Erasure coding - They split keys into chunks and spread them across multiple messages. You only need any N chunks to reconstruct the key, not specific ones. This means an attacker can't just drop the "key message" - they'd have to drop ALL messages, causing obvious DoS.
2. ML-KEM Braid - They dug into the ML-KEM internals and realized they could send parts of it in parallel instead of sequentially. Turns out you can extract a 32-byte seed early and generate most of the ciphertext from that, allowing both sides to transmit simultaneously. Gets them to ~95% bandwidth utilization.
3. Slower is sometimes better - This one surprised me. They simulated a dozen different state machines and found that generating keys too aggressively actually makes things LESS secure during device compromise. If you're generating keys faster than your partner is confirming them, you're storing more decryption keys locally, giving an attacker more epochs to crack. They deliberately throttled it.
What I think about all this
I'm genuinely impressed. Here's why:
The gap between "we proved this in a paper" and "we deployed this to 2 billion people" is enormous. Most cryptographers never cross it. Signal did.
They didn't just bolt PQ crypto on top and call it a day. They actually optimized it, simulated it, found the edge cases, and made hard tradeoffs. The "slower is better" insight? That's the kind of thing you only learn by actually building and testing, not just theorizing.
The formal verification setup is how this SHOULD be done but almost never is. They used ProVerif during design (not after), and they're running hax/F* verification on every commit. Their codebase is provably panic-free. When's the last time you saw that in production crypto code?
The backward compatibility story is clean. SPQR data gets attached to messages but not mixed into keys initially. If the other side doesn't understand it, they ignore it and everything still works. After the first round-trip, SPQR locks in and can't be downgraded. Simple, elegant, secure.
Why this actually matters
Look, most "quantum-safe" announcements are vaporware. Companies slap "PQ-ready" on their marketing and call it a day. Signal shipped actual code that's protecting actual messages right now.
WhatsApp, iMessage, and everyone else using Signal Protocol variants now have to catch up. The competitive pressure is real.
And here's the thing that keeps me up at night: how many of your messages from the last 5 years are sitting in some government database waiting for quantum computers? If you were using Signal, you're good going forward. Anything else? Good luck.
The academic foundation
This came out of two papers - one at Eurocrypt '25 introducing the Triple Ratchet concept and proving it secure, another at USENIX '25 analyzing six different protocol designs to find the optimal one. Collaboration with PQShield, AIST, and NYU.
This is how it should work: academia and industry actually talking to each other, not just publishing papers that never get implemented.
What happens now
For users: absolutely nothing. You're already protected and you didn't have to think about it.
For other messaging apps: you're officially behind. Clock's ticking.
For protocol designers: study this implementation. The combination of erasure coding + ML-KEM optimization + hybrid construction is a template worth copying.
For the crypto community: this raises the bar. We can't keep publishing "quantum-safe" proposals that ignore real-world constraints like bandwidth, battery, and backward compatibility.
#DopeScope users, don't forget to upgrade your firmware! We've added some more detail to our upgrade instructions to make it even easier.
https://t.co/izo5qNup1k
This update provides multiple bug fixes and now allows you to detect and display #WiFi Probes from nearby devices.
Noblis' Scott James will present on #AI for operational efficiency and how #QuantumComputing paradigms can advise path planning algorithms for coordinated aircraft movement at and around airports, Jan. 8 at the TRB Annual Meeting. Learn more: https://t.co/4DD2y2czdA #TRBAM
“We are bathing in mystery and confusion… That will always be our destiny. The universe will always be much richer than our ability to understand it.”
Remembering Carl Sagan, who returned his borrowed stardust to the cosmos 28 years ago today https://t.co/slrZGEKxJO
In the wake of the 2024 election in the U.S., many people are concerned about their digital privacy. EFF has decades of experience in providing digital privacy and security resources, particularly for vulnerable people. We’ve written a lot of resources over the years and here are the top ten that we think are most useful right now 🧵(1/13)
"We are well advised to keep on nodding terms with the people we used to be, whether we find them attractive company or not."
Joan Didion on the value of keeping a notebook https://t.co/uR6a42FPv7
"A Wrinkle in Time" author Madeleine L’Engle, born on this day in 1918, on creativity, the meaning of hope, and how to get unstuck https://t.co/lINs1C9YoN
If you yearn for depth and delight without a feed of distraction, try the Marginalian newsletter, free and ad-free since 2006 — the week's most inspiring and soul-nourishing reads, in a single undistracted place: https://t.co/8ApDA5YPF6
“Books are not only the arbitrary sum of our dreams, and our memory. They also give us the model of self-transcendence…a way of being fully human.”
OTD in 1996, Susan Sontag composed her extraordinary letter to Borges about reading and self-transcendence https://t.co/s9aKKX4FhJ
Please join us in congratulating #TeamNoblis and all coauthors on publishing "Accuracy and Reproducibility of Forensic Tire Examination Decisions" in Forensic Science International. 50-day free access: https://t.co/Hb4cGWYO22 #TireForensics#ForensicScience#IgnitetheSpark