- The future of Siri, or: why private inference isn’t private enough
- Let’s talk about encrypted reasoning
- Anonymous credentials: an illustrated primer (Part 2)
- Anonymous credentials: an illustrated primer
- WhatsApp Encryption, a Lawsuit, and a Lot of Noise
- Kerberoasting
- A bit more on Twitter/X’s new encrypted messaging
- Dear Apple: add “Disappearing Messages” to iMessage right now
- Three questions about Apple, encryption, and the U.K.
- How to prove false statements? (Part 3)
- U.K. asks to backdoor iCloud Backup encryption
- How to prove false statements? (Part 2)
- How to prove false statements? (Part 1)
- Let’s talk about AI and end-to-end encryption
- Is Telegram really an encrypted messaging app?
- A quick post on Chen’s algorithm
- Attack of the week: Airdrop tracing
- To Schnorr and beyond (part 2)
- To Schnorr and beyond (Part 1)
- Some rough impressions of Worldcoin
- On Ashton Kutcher and Secure Multi-Party Computation
- PRFs, PRPs and other fantastic things
- Book Review: Red Team Blues
- Remarks on “Chat Control”
- Why encrypted backup is so important
- One-Time Programs
- In defense of crypto(currency)
- An extremely casual code review of MetaMask’s crypto
- Thinking about “traceability”
- A case against security nihilism
- Why the FBI can’t get your browsing history from Apple iCloud (and other scary stories)
- Ok Google: please publish your DKIM secret keys
- Attack of the week: Voice calls in LTE
- Why is Signal asking users to set a PIN, or “A few thoughts on Secure Value Recovery”
- Does Zoom use end-to-end encryption?
- EARN IT is a direct attack on end-to-end encryption
- What is the random oracle model and why should you care? (Part 5)
- Can end-to-end encrypted systems detect child sexual abuse imagery?
- How safe is Apple’s Safe Browsing?
- Looking back at the Snowden revelations
- How does Apple (privately) find your offline devices?
- Attack of the week: searchable encryption and the ever-expanding leakage function
- On Ghost Users and Messaging Backdoors
- Let’s talk about PAKE
- Why I’m done with Chrome
- Friday Dachshund Blogging
- Wonk post: chosen ciphertext security in public-key encryption (Part 2)
- Was the Efail disclosure horribly screwed up?
- A few thoughts on Ray Ozzie’s “Clear” Proposal
- Wonk post: chosen ciphertext security in public-key encryption (Part 1)
- Hash-based Signatures: An illustrated Primer
- A few notes on Medsec and St. Jude Medical
- Apple in China: who holds the keys?
- Attack of the Week: Group Messaging in WhatsApp and Signal
- The strange story of “Extended Random”
- A few thoughts on CSRankings.org
- Attack of the week: DUHK
- Falling through the KRACKs
- Patching is hard; so what?
- Beyond public key encryption
- Secure computing for journalists
- The future of Ransomware
- Zero Knowledge Proofs: An illustrated primer, Part 2
- The limitations of Android N Encryption
- Attack of the week: 64-bit ciphers in TLS
- Is Apple’s Cloud Key Vault a crypto backdoor?
- Statement on DMCA lawsuit
- What is Differential Privacy?
- Attack of the Week: Apple iMessage
- Attack of the week: DROWN
- On the Juniper backdoor
- Why the Tor attack matters
- A riddle wrapped in a curve
- Let’s talk about iMessage (again)
- The network is hostile
- A history of backdoors
- Attack of the week: Logjam
- How do we build encryption backdoors?
- Truecrypt report
- Attack of the week: FREAK (or ‘factoring the NSA for fun and profit’)
- How to paint yourself into a corner (Lenovo edition)
- Another update on the Truecrypt audit
- How do we pay for privacy?
- Hopefully the last post I’ll ever write on Dual EC DRBG
- On the new Snowden documents
- Zero Knowledge Proofs: An illustrated primer
- Attack of the Week: Unpicking PLAID
- Attack of the week: POODLE
- Why can’t Apple decrypt your iPhone?
- Slate piece
- What’s the matter with PGP?
- Noodling about IM protocols
- Attack of the Week: Triple Handshakes (3Shake)
- Attack of the week: OpenSSL Heartbleed
- How do you know if an RNG is working?
- Cryptographic obfuscation and ‘unhackable’ software
- A letter from US security researchers
- A few more notes on NSA random number generators
- Can hackers decrypt Target’s PIN data?
- An update on Truecrypt