Much broken crypto, one common thread: bespoke, ill-designed cryptographic protocols.
Matrix, Mega, Threema, Telegram: secure primitives are not enough in complex applications. The new mantra shall be "don't roll your own protocol".
We (@winterdeaf@kientuong114 and I) took a deep dive on Threema, a Swiss-made secure messaging app. We found 6 new cryptographic vulnerabilities. Full paper at https://t.co/XMu8SZBCc3; mini-thread follows. #threema
The 2nd Cryptographic Applications Workshop (#CAW) will be at Eurocrypt 2025!
#CAW focuses on the construction and analysis of cryptography built for practice, bridging the gap between research and real-world applications.
Our call of talks is open: https://t.co/OalSPDafSJ
Much broken crypto, one common thread: bespoke, ill-designed cryptographic protocols.
Matrix, Mega, Threema, Telegram: secure primitives are not enough in complex applications. The new mantra shall be "don't roll your own protocol".
We (@winterdeaf@kientuong114 and I) took a deep dive on Threema, a Swiss-made secure messaging app. We found 6 new cryptographic vulnerabilities. Full paper at https://t.co/XMu8SZBCc3; mini-thread follows. #threema
New from the TLS meeting at IETF 117: Encrypted Client Hello (ECH) is enabled for 1% of Chrome stable users. A big step for privacy online!
https://t.co/hUyJp5qwm6
#WAC6 talks:
Matteo Scarlata @winterdeaf will present "why Threema failed in practice" lessons learned from 7 cryptographic attacks against a secure messenger.
The paper with @kientuong114@kennyog will be presented at USENIX '23.
Full workshop program: https://t.co/3cJT5Ypgi9
I would like to thank the chairs for letting us use heart emojis in the paper title. I think this is a very important step forward for academia and research.
Can't wait to use "👀" for related work and "🤨" for limitations on the next one
No one sees ChatGPT for the first time and thinks "just some n-gram correlations" or "no real knowledge inside".
Those unintuitive beliefs trickle down from some experts, who should know better than to teach their controversial theories as established fact: 🧵 (1/12)
NEW EPISODE! THREEEEEMAAAAAAAA
We recorded this almost two weeks ago, yay it's out!
With special guests @kennyog@kientuong114@winterdeaf
https://t.co/HYrvlHtjPo
In early 2022 I started working with Kenny and Matteo on analyzing Threema, the messenger used by 🇨🇭govt, army and 🇩🇪 chancellor. Happy to say that the disclosure period is over and results are out! Fun vulnerabilities included :)
Check out our website: https://t.co/i0DwIkyLaj
@cronokirby You are of course right -- it is not a matter of credentials. But when I get out of my academic bubble, I'm always surprised by how scarcely diffused provable security and formal methods are!
ETH cryptographers @kennyog, @winterdeaf and @kientuong114 have conducted a security analysis and discovered various vulnerabilities in the secure messaging app Threema. Read their full paper here: https://t.co/2RMABs2Eun
#threema#Security#messenger
https://t.co/ShSFmffXUv