Security Cryptography Whatever

Security Cryptography Whatever

By Deirdre Connolly, Thomas Ptacek, David AdrianNewsScienceTechnologyTech NewsMathematics
Download on the App Store

Security Cryptography Whatever episodes

  • Has RSA been destroyed by a quantum computer???

    There's a paper that claims one can factor a RSA-2048 modulus with the help of a 372-qubit quantum computer. Are we all gonna die?

    Also some musings about Bruce Schneier.

    Errata:
    Schneier's honorary PhD is from the University of Westminster, not UW.


    Transcript:
    https://securitycryptographywhatever.com/2023/01/06/has-rsa-been-destroyed-by-a-quantum-computer/

    Links:

    https://arxiv.org/pdf/2212.12372.pdf
    https://eprint.iacr.org/2021/232.pdf
    https://github.com/lducas/SchnorrGate
    https://sweis.medium.com/did-schnorr-destroy-rsa-show-me-the-factors-dcb1bb980ab0
    https://www.schneier.com/blog/archives/2023/01/breaking-rsa-with-a-quantum-computer.html
    https://scottaaronson.blog/?p=6957



    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    42 min
  • End of Year Wrap Up

    David and Deirdre gab about some stuff we didn't get to or just recently happened, like Tailscale's new Tailnet Lock, the Okta breach, what the fuck CISOs are for anyway, Rust in Android and Chrome, passkeys support, and of course, SBF.

    Transcript:
    https://securitycryptographywhatever.com/2023/01/04/end-of-year-wrap-up/

    Links:
    https://tailscale.com/blog/tailnet-lock/
    https://security.googleblog.com/2022/12/memory-safe-languages-in-android-13.html
    https://groups.google.com/a/chromium.org/g/chromium-dev/c/0z-6VJ9ZpVU


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr
  • Software Safety and Twitter with Kevin Riggle

    We talk to Kevin Riggle (@kevinriggle) about complexity and safety. We also talk about the Twitter acquisition. While recording, we discovered a new failure mode where Kevin couldn't hear Thomas, but David and Deirdre could, so there's not much Thomas this episode. If you ever need to get Thomas to voluntarily stop talking, simply mute him to half the audience!

    https://twitter.com/kevinriggle

    Transcript:
    https://securitycryptographywhatever.com/2022/11/24/software-safety-and-twitter-with-kevin-riggle/

    Errata

    • It was the Mars Climate Orbiter that crashed due to a units mismatch
    • David confused the Dreamliner with the 737 Max

    Links

    • https://free-dissociation.com/blog/posts/2018/08/why-is-it-so-hard-to-build-safe-software/
    • https://complexsystems.group/
    • https://how.complexsystems.fail/
    • https://noncombatant.org/2016/06/20/get-into-security-engineering/
    • https://blog.nelhage.com/2010/03/security-doesnt-respect-abstraction/
    • http://sunnyday.mit.edu/safer-world.pdf
    • https://www.adaptivecapacitylabs.com/john-allspaw/
    • https://www.etsy.com/codeascraft/blameless-postmortems
    • https://increment.com/security/approachable-threat-modeling/
    • https://www.nytimes.com/2022/11/17/arts/music/taylor-swift-tickets-ticketmaster.html
    • https://www.hillelwayne.com/post/are-we-really-engineers/
    • https://www.hillelwayne.com/post/we-are-not-special/
    • https://www.hillelwayne.com/post/what-we-can-learn/
    • https://lotr.fandom.com/wiki/Denethor_II
    • https://twitter.com/sarahjeong/status/1587597972136546304


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    59 min
  • Matrix with Martin Albrecht and Dan Jones

    No not the movie: the secure group messaging protocol! Or rather all the bugs and vulns that a team of researchers found when trying to formalize said protocol. Martin Albrecht and Dan Jones joined us to walk us through "Practically-exploitable Cryptographic
    Vulnerabilities in Matrix".

    Transcript:
    https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/

    Links: 

    • https://nebuchadnezzar-megolm.github.io/static/paper.pdf
    • https://nebuchadnezzar-megolm.github.io
    • Signal Private Group system: https://eprint.iacr.org/2019/1416.pdf
    • https://signal.org/blog/signal-private-group-system/
    • https://spec.matrix.org/latest/
    • WhatsApp Security Whitepaper: https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf
    • https://www.usenix.org/conference/usenixsecurity21/presentation/albrecht FS, PCS etc
    • Other clients: https://nvd.nist.gov/vuln/detail/CVE-2022-39252 https://nvd.nist.gov/vuln/detail/CVE-2022-39254 https://nvd.nist.gov/vuln/detail/CVE-2022-39264 
    • https://dadrian.io/blog/posts/roll-your-own-crypto/
    • https://podcasts.apple.com/us/podcast/the-great-roll-your-own-crypto-debate-feat-filippo-valsorda/id1578405214?i=1000530617719 
    • WhatsApp End-to-End Encrypted Backups: https://blog.whatsapp.com/end-to-end-encrypted-backups-on-whatsapp
    • Roll your own and Telegram: https://mtpsym.github.io/ 




    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 7 min
  • SOC2 with Sarah Harvey

    We have Sarah Harvey (@worldwise001 on Twitter) to talk about SOC2, what it means, how to get it, and if it's important or not. The discussion centers around two blog posts written by Thomas:

    • SOC2 Starting Seven: https://latacora.micro.blog/2020/03/12/the-soc-starting.html
    • SOC2 at Fly: https://fly.io/blog/soc2-the-screenshots-will-continue-until-security-improves/

    Transcript:
    https://securitycryptographywhatever.com/2022/10/16/SOC2-with-Sarah-Harvey/

    Links:

    • Tailscale recent post on getting SOC2’d: https://tailscale.com/blog/soc2-type2/
    • SSO Tax: https://sso.tax
    • David’s previous job: https://getnametag.com
    • David's other startup: https://censys.io
    • Thomas works at https://fly.io



    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 2 min
  • Nate Lawson II

    This episode got delayed because David got COVID. Anyway, here's Nate Lawson: The Two Towers.

    • Steven Chu: https://en.wikipedia.org/wiki/Steven_Chu
    • CFB: https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_feedback_(CFB)
    • CCFB: https://link.springer.com/chapter/10.1007/11502760_19
    • XXTEA: https://en.wikipedia.org/wiki/XXTEA
    • CHERI: https://cseweb.ucsd.edu/~dstefan/cse227-spring20/papers/watson:cheri.pdf


    Transcript:
    https://securitycryptographywhatever.com/2022/09/29/nate-lawson-ii/

    Errata:

    • Pedram Amini did in fact do Pai Mei


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 24 min
  • Nate Lawson: Part 1

    We bring on Nate Lawson of Root Labs to talk about a little bit of everything, starting with cryptography in the 1990s.

    Transcript:
    https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/

    References

    • IBM S/390: https://ieeexplore.ieee.org/document/5389176
    • SSLv2 Spec: https://www-archive.mozilla.org/projects/security/pki/nss/ssl/draft02.html
    • Xbox 360 HMAC: https://beta.ivc.no/wiki/index.php/Xbox_360_Timing_Attack
    • Google Keyczar HMAC bug (reported by Nate): https://rdist.root.org/2009/05/28/timing-attack-in-google-keyczar-library/

    Errata

    • HMAC actually published in 1996, not 1997
    • "That was one of the first, I think hardware applications of DPA was, was, um, satellite TV cards." Not true, they first were able to break Mondex, a MasterCard smart card



    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 21 min
  • Hot Cryptanalytic Summer with Steven Galbraith

    Are the isogenies kaput?! There's a new attack that breaks all the known parameter sets for SIDH/SIKE, so Steven Galbraith helps explain where the hell this came from, and where isogeny crypto goes from here.

    Transcript:
    https://securitycryptographywhatever.com/2022/08/11/hot-cryptanalytic-summer-with-steven-galbraith/

    Merch: https://merch.scwpodcast.com

    Links:

    • https://eprint.iacr.org/2022/975.pdf
    • https://eprint.iacr.org/2022/1026.pdf
    • https://ellipticnews.wordpress.com/2022/07/31/breaking-supersingular-isogeny-diffie-hellman-sidh/
    • GPST active adaptive attack against SIDH: https://eprint.iacr.org/2016/859.pdf
    • Failing to hash into supersingular isogeny graphs: https://eprint.iacr.org/2022/518.pdf
    • https://research.nccgroup.com/2022/08/08/implementing-the-castryck-decru-sidh-key-recovery-attack-in-sagemath/
    • Kuperberg attack via Peikert: https://eprint.iacr.org/2019/725.pdf
    • SQISign: https://eprint.iacr.org/2020/1240.pdf
    • (Post recording)  Breaking SIDH in polynomial time:
      https://eprint.iacr.org/2022/1038.pdf


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    53 min
  • Passkeys with Adam Langley

    Adam Langley (Google) comes on the podcast to talk about the evolution of WebAuthN and Passkeys!

    David's audio was a little finicky in this one. Believe us, it sounded worse before we edited it. Also, we occasionally accidentally refer to U2F as UTF. That's because we just really love strings.

    Transcript:
    https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/

    Links:

    • GoogleIO Presentation
    • WWDC Presentation
    • W3C WebAuthN
    • Adam's blog on passkeys and CABLE
    • Cable / Hybrid PR
    • CTAP spec from FIDO
    • Noise NKPSK
    • DERP


    Don't forget about merch! https://merch.securitycryptographywhatever.com/


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 4 min
  • Hertzbleed

    Side channels! Frequency scaling! Key encapsulation, oh my! We're talking about the new Hertzbleed paper, but also cryptography conferences, 'passkeys', and end-to-end encrypting yer twitter.com DMs.

    Transcript:
    https://securitycryptographywhatever.com/2022/06/17/hertzbleed/

     Links:

    • Hertzbleed Attack | ellipticnews (wordpress.com)
    • https://www.hertzbleed.com/hertzbleed.pdf
    • https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3920031

    Merch: https://merch.scwpodcast.com


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    59 min

About Security Cryptography Whatever

From the publisher's feed

Some cryptography & security people talk about security, cryptography, and whatever else is happening.

More shows like Security Cryptography Whatever

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,053 Listeners

Planet Money by NPR

Planet Money

30,689 Listeners

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,639 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,087 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

623 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

The Quanta Podcast by Quanta Magazine

The Quanta Podcast

542 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

10,185 Listeners

Dwarkesh Podcast by Dwarkesh Patel

Dwarkesh Podcast

567 Listeners

Search Engine by PJ Vogt

Search Engine

4,592 Listeners

No Priors: Artificial Intelligence | Technology | Startups by Conviction

No Priors: Artificial Intelligence | Technology | Startups

140 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners