Boom! Time-capsules are coming to Sui. TL;DR encrypt messages and NFTs into the future. Crazy interesting applications, see attached!
🍒 that tech was my PhD presented to NIST w/ @FBaldimtsi back in 2008 & we still have the fastest algorithm :), we were also the 1st to deploy it
So the overall point here, that E2E services leak a ton of metadata through key updates, is a good one. Same thing goes for Apple: you can more or less enumerate all devices if you reverse the Apple Directory Service APIs.
debunking TEE fud: a short argument reset to start the new year. collab with @0xQuintus
https://t.co/fu83KgFRGX
Myth 1: “SGX is being deprecated!" Trusted hardware is over.” Actually Confidential Compute is booming. Normies are going to use this whether or not web3 does too
I threw together a quick blog post explaining the recent attack on AirDrop privacy, and how Chinese law enforcement is exploiting it. https://t.co/TXlS53LxV2
🚨 Massive AI Security Release 🚨
@NIST just put out the best AI Security Publication that I've ever seen.
It is 106 pages of deep, technical content. It references real-world practical attacks. In this thread is the link and I'm going to cover a few highlights. 👇
Article on some new research that finds ways to balance privacy and stalker detection for AirTags and other location trackers. This is a collaboration with my students @gabrie_beck, Harry Eldridge and colleagues Abhishek Jain and Nadia Heninger. https://t.co/un3xU6ndup
Google is changing the way it stores and collects user location data, so that this data will remain on the phone and be encrypted in the cloud. The upshot is that Geofence warrants may become obsolete. EFF: https://t.co/g8Qm3P6v3U
💥New short paper with Yi Tang:
We 𝒄𝒐𝒎𝒑𝒍𝒆𝒕𝒆𝒍𝒚 𝒃𝒓𝒆𝒂𝒌 the assumption underlying the lattice-based "proof of sequential work" candidate from CRYPTO'23.
This solves a problem that was conjectured to require depth T... in depth poly(log T).
https://t.co/Q4aJVDJ1qE
They HACKED A TRAIN. For real. Train operators asked for this to see why their trains didn't run after servicing. Turns out that vendor/producer implemented a geofence lock for trains serviced somewhere else. Amazing story, one of the best hacks in 2023. https://t.co/1ZFpIVfLZr
I’m very happy to see that the EU parliament is making progress in beating back these mass-message scanning proposals. But I’m still pretty nervous that the EU Commission will find some way to bring these back. https://t.co/UQ8HQ8Y6lc
OpenSSL 3.2.0 has support for using Windows OS trust stores, raw public keys for TLS and third-party signature schemes enabling PQC signatures to be experimented with, certificate compression which is important for PQC certificates, and Hybrid Public Key Encryption (HPKE). All very exciting changes.
Everyone should have secure and modern messaging regardless of what phone they have. Excited to see Apple joining our ongoing work with the GSMA to evolve RCS. 💚+💙 https://t.co/MNsgNA0Qkg