Security Cryptography Whatever

Security Cryptography Whatever

By Deirdre Connolly, Thomas Ptacek, David AdrianNewsScienceTechnologyTech NewsMathematics
Download on the App Store

Security Cryptography Whatever episodes

  • Attacking Lattice-based Cryptography with Martin Albrecht

    Returning champion Martin Albrecht joins us to help explain how we measure the security of lattice-based cryptosystems like Kyber and Dilithium against attackers. QRAM, BKZ, LLL, oh my!

    Transcript: https://securitycryptographywhatever.com/2023/11/13/lattice-attacks/

    Links:

    - https://pq-crystals.org/kyber/index.shtml
    - https://pq-crystals.org/dilithium/index.shtml
    - https://eprint.iacr.org/2019/930.pdf
    - https://en.wikipedia.org/wiki/Short_integer_solution_problem
    - Frodo: https://eprint.iacr.org/2016/659
    - https://csrc.nist.gov/CSRC/media/Events/third-pqc-standardization-conference/documents/accepted-papers/ribeiro-saber-pq-key-pqc2021.pdf
    - https://en.wikipedia.org/wiki/Hermite_normal_form
    - https://en.wikipedia.org/wiki/Wagner%E2%80%93Fischer_algorithm
    - https://www.math.auckland.ac.nz/~sgal018/crypto-book/ch18.pdf
    - https://eprint.iacr.org/2019/1161
    - QRAM: https://arxiv.org/abs/2305.10310
    - https://en.wikipedia.org/wiki/Lenstra%E2%80%93Lenstra%E2%80%93Lov%C3%A1sz_lattice_basis_reduction_algorithm
    - MATZOV improved dual lattice attack: https://zenodo.org/records/6412487
    - https://eprint.iacr.org/2008/504.pdf
    - https://eprint.iacr.org/2023/302.pdf


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    58 min
  • Signal's Post-Quantum PQXDH, Same-Origin Policy, E2EE in the Browser Revisted

    We're back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.

    Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc

    Links:

    - https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/
    - https://github.com/superfly/macaroon
    - https://cryspen.com/post/pqxdh/
    - https://eprint.iacr.org/2023/1390.pdf


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 20 min
  • 'Jerry Solinas deserves a raise' with Steve Weis

    We explore how the NIST curve parameter seeds were generated, as best we can, with returning champion Steve Weis!

    “At the point where we find an intelligible English string that generates the
    NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore.”

    Transcript: https://securitycryptographywhatever.com/2023/10/12/the-nist-curves

    Links:

    - Steve’s post: https://saweis.net/posts/nist-curve-seed-origins.html
    - ANSI X9.62 ECDSA: https://safecurves.cr.yp.to/grouper.ieee.org/groups/1363/private/x9-62-09-20-98.pdf / FIPS 186-2 https://csrc.nist.gov/files/pubs/fips/186-2/final/docs/fips186-2.pdf
    - “A RIDDLE WRAPPED IN AN ENIGMA”: https://eprint.iacr.org/2015/1018.pdf
    - https://arstechnica.com/information-technology/2015/01/nsa-official-support-of-backdoored-dual_ec_drbg-was-regrettable/
    - https://www.muckrock.com/foi/united-states-of-america-10/origin-of-fips-186-4-elliptic-curves-over-prime-field-seed-parameters-national-institute-of-standards-and-technology-78756/
    - https://www.muckrock.com/foi/united-states-of-america-10/origin-of-fips-186-4-elliptic-curves-over-prime-field-seed-parameters-national-security-agency-78755/
    - Filippo’s bounty: https://words.filippo.io/dispatches/seeds-bounty/
    - Recommendations for Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters - NIST 800-186 with Curve25519 and friends
    - RFC 8422: Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS) Versions 1.2 and Earlier
    - https://www.rfc-editor.org/rfc/rfc4492#section-6
    - https://blog.cryptographyengineering.com/2017/12/19/the-strange-story-of-extended-random/
    - https://en.wikipedia.org/wiki/Bullrun_(decryption_program)
    - https://en.wikipedia.org/wiki/BSAFE
    - https://sockpuppet.org/blog/2015/08/04/is-extended-random-malicious/


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    58 min
  • Cruel Summer: hybrid signatures, Downfall, Zenbleed, 2G downgrades

    We're back from our summer vacation! We're covering a bunch of stuff we saw and did:

    Transcript: 
    https://securitycryptographywhatever.com/2023/09/13/cruel-summer/

    Links:
    - Zenbleed: https://lock.cmpxchg8b.com/zenbleed.html
    - Downfall: https://downfall.page
    - Post-quantum Yubikeys: https://security.googleblog.com/2023/08/toward-quantum-resilient-security-keys.html


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    59 min
  • Why do we think anything is secure, with Steve Weis

    What does P vs NP have to do with cryptography? Why do people love and laugh about the random oracle model? What's an oracle? What do you mean factoring and discrete log don't have proofs of hardness? How does any of this cryptography stuff work, anyway? We trapped Steve Weis into answering our many questions.

    Transcript: 
    https://securitycryptographywhatever.com/2023/06/29/why-do-we-think-anything-is-secure-with-steve-weis/

    Links:
    - The Random Oracle Methodology, Revisited: https://eprint.iacr.org/1998/011.pdf
    - Factoring integers with CADO-NFS: https://www.ens-lyon.fr/LIP/AriC/wp-content/uploads/2015/03/JDetrey-tutorial.pdf
    - On One-way Functions from NP-Complete Problems: https://eprint.iacr.org/2021/513.pdf
    - Seny Kamara's lecture notes on provable security: https://cs.brown.edu/~seny/2950-v/2-provablesecurity.pdf
    - How To Simulate It – A Tutorial on the Simulation Proof Technique: https://eprint.iacr.org/2016/046.pdf
    - A Survey of Leakage-Resilient Cryptography: https://eprint.iacr.org/2019/302
    - A Decade of Lattice Cryptography: https://eprint.iacr.org/2015/939.pdf


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    47 min
  • Elon's Encrypted DMs with Matthew Garrett

    Are Twitter’s new encrypted DMs unreadable even if you put a gun to Elon’s head? We invited Matthew Garrett on to do a deep decompiled dive into what kind of cryptography actually shipped.

    Transcript: 
    https://securitycryptographywhatever.com/2023/05/29/elons-encrypted-dms-with-matthew-garrett/

    Links:
    https://mjg59.dreamwidth.org/66791.html
    https://help.twitter.com/en/using-twitter/encrypted-direct-messages
    https://www.techdirt.com/2023/05/11/twitter-launches-not-actually-encrypted-encrypted-dms/
    BrokenKDF2BytesGenerator: https://github.com/bcgit/bc-java/blob/master/prov/src/main/java/org/bouncycastle/jce/provider/BrokenKDF2BytesGenerator.java#L70
    Analysis from sweis: https://twitter.com/sweis/status/1657082478727933954?s=20
    https://signal.org/docs/specifications/x3dh/
    https://signal.org/docs/specifications/doubleratchet/
    https://support.signal.org/hc/en-us/articles/360007059752-Backup-and-Restore-Messages
    Trail of Bits has not audited nor signed a contract yet, per Platformer: https://www.platformer.news/p/why-you-cant-trust-twitters-encrypted


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    53 min
  • WhatsApp Key Transparency with Jasleen Malvai and Kevin Lewi

    WhatsApp has announced they’re rolling out key transparency! Doing this at WhatsApp-scale (aka billions and biiillions of keys) is a significant task, so we talked to Jasleen Malvai and Kevin Lewi about how it works.

    Transcript: 
    https://securitycryptographywhatever.com/2023/05/06/whatsapp-key-transparency

    Links: 
    https://engineering.fb.com/2023/04/13/security/whatsapp-key-transparency/
    https://github.com/facebook/akd
    Parkeet: https://eprint.iacr.org/2023/081.pdf
    CONIKS: https://eprint.iacr.org/2014/1004.pdf
    SEEMless: https://eprint.iacr.org/2018/607.pdf
    WhatsApp Security Whitepaper: https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf
    Keybase key transparency: https://book.keybase.io/docs/server


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    56 min
  • Messaging Layer Security (MLS) with Raphael Robert

    Messaging Layer Security (MLS) 1.0 is (basically) here! We invited Raphael
    Robert, coauthor of the MLS specification to explain it to us and answer our annoying questions (read: why does this exist?)

    Transcript:
    https://securitycryptographywhatever.com/2023/04/22/mls/

    Links:
    - https://messaginglayersecurity.rocks/
    - https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html
    - https://messaginglayersecurity.rocks/mls-architecture/draft-ietf-mls-architecture.html
    - https://github.com/openmls/openmls
    - https://eprint.iacr.org/2022/1533.pdf
    - https://eprint.iacr.org/2020/1327.pdf
    - https://eprint.iacr.org/2022/559.pdf
    - https://signal.org/docs/
    - https://en.wikipedia.org/wiki/Key_encapsulation_mechanism
    - https://twitter.com/beurdouche/status/1220617962182389760
    - https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html#mls-ciphersuites
    - https://www.ietf.org/archive/id/draft-ietf-mls-federation-02.html
    - https://datatracker.ietf.org/wg/mimi/documents/
    - https://competition-policy.ec.europa.eu/dma/dma-workshops/interoperability-workshop_en
    - Yes in the protocol document this is 1.0: https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html#section-6


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    56 min
  • Real World: Crypto (2023)

    Real World Cryptography 2023 is happening any moment now in Tokyo. Also, some phone basebands are broken.

    Links

    • https://rwc.iacr.org/2023/
    • https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html


    Transcript: https://securitycryptographywhatever.com/2023/03/24/rwc-2023/


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    55 min
  • Threema with Kenny Paterson, Matteo Scarlata and Kien Tuong Truong

    Another day, another ostensibly secure messenger that quails under the gaze of some intrepid cryptographers. This time, it's Threema, and the gaze belongs to Kenny Paterson, Matteo Scarlata, and Kien Tuong Truong from ETH Zurich. Get ready for some stunt cryptography, like 2 Fast 2 Furious stunts.

    Transcript:
    https://securitycryptographywhatever.com/2023/01/27/threema/

    Links:
    https://breakingthe3ma.app/
    https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf
    https://threema.ch/en/blog/posts/ibex


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 4 min

About Security Cryptography Whatever

From the publisher's feed

Some cryptography & security people talk about security, cryptography, and whatever else is happening.

More shows like Security Cryptography Whatever

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,053 Listeners

Planet Money by NPR

Planet Money

30,689 Listeners

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,639 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,087 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

623 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

The Quanta Podcast by Quanta Magazine

The Quanta Podcast

542 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

10,185 Listeners

Dwarkesh Podcast by Dwarkesh Patel

Dwarkesh Podcast

567 Listeners

Search Engine by PJ Vogt

Search Engine

4,592 Listeners

No Priors: Artificial Intelligence | Technology | Startups by Conviction

No Priors: Artificial Intelligence | Technology | Startups

140 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners