Security Cryptography Whatever

Security Cryptography Whatever

By Deirdre Connolly, Thomas Ptacek, David AdrianNewsScienceTechnologyTech NewsMathematics
Download on the App Store

Security Cryptography Whatever episodes

  • OMB Zero Trust Memo with Eric Mill

    The US government released a memo about moving to a zero-trust network architecture. What does this mean? We have one of the authors, Eric Mill, on to explain it to us.

    As always, your @SCWPod hosts are Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian).

    Transcript:
    https://securitycryptographywhatever.com/2022/06/10/omb-zero-trust-memo-with-eric-mill/

    Links:

    • OMB Memo
    • Executive order on cybersecurity 
    • PIV card 
      • Derived PIV
    • BeyondCorp
    • HSTS Preloading
      • .gov preloading 
    • Neither Rain, Nor Snow, Nor MITM
    • EDR memo
    • Technology Transformation Services (TTS)
    • Is it Christmas?


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 1 min
  • Tink with Sophie Schmieg

    We talk about Tink with Sophie Schmieg, cryptographer and algebraic geometer at Google.

    Transcript:
    https://securitycryptographywhatever.com/2022/05/28/tink-with-sophie-schmieg/

    Links:

    • Sophie: https://twitter.com/SchmiegSophie
    • Tink: https://github.com/google/tink
    • RWC talk: https://youtube.com/watch?t=1028&v=CiH6iqjWpt8
    • Where to store keys: https://twitter.com/SchmiegSophie/status/1413502566797778948
    • EAX mode: https://en.wikipedia.org/wiki/EAX_mode
    • AES-GCM-SIV: https://en.wikipedia.org/wiki/AES-GCM-SIV
    • Deterministic AEADs: https://github.com/google/tink/blob/master/docs/PRIMITIVES.md#deterministic-authenticated-encryption-with-associated-data
    • Thai Duong: https://twitter.com/XorNinja
    • AWS-SDK Vuln: https://twitter.com/XorNinja/status/1310587707605659649


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 8 min
  • Cancellable Crypto Takes and Real World Crypto

    Live from Amsterdam, it's cancellable crypto hot takes! A fun little meme, plus a preview of the Real World Crypto program!

    Transcript:
    https://securitycryptographywhatever.com/2022/04/12/cancellable-crypto-takes-and-real-world-crypto/

    Links:

    Tony's twete: https://twitter.com/bascule/status/1512539700220805124
    Real World Crypto 2022: https://rwc.iacr.org/2022
    Merch! https://merch.scwpodcast.com

    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 12 min
  • Lattices and Michigan Football with Chris Peikert

    We're back! With an episode on lattice-based cryptography, with Professor Chris Peikert of the University of Michigan, David's alma mater. When we recorded this, Michigan football had just beaten Ohio for the first time in a bajillion years, so you get a nerdy coda on college football this time!

    Transcript:
    https://securitycryptographywhatever.com/2022/03/12/lattices-and-michigan-football-with-chris-peikert/

    Slides: https://web.eecs.umich.edu/~cpeikert/pubs/slides-qcrypt.pdf

    Links:

    He Gives C-Sieves on the CSIDH: https://eprint.iacr.org/2019/725
    Lattice-based Cryptography: https://cims.nyu.edu/~regev/papers/pqc.pdf
    NIST PQC Competition: https://csrc.nist.gov/Projects/post-quantum-cryptography
    The 2nd Bar Ilan Winter School on Cryptography Lattice- Based Cryptography and Applications: https://www.youtube.com/playlist?list=PL8Vt-7cSFnw2OmpCmPLLwSx0-Yqb2ptqO
    A Decade of Lattice Cryptography: https://eprint.iacr.org/2015/939.pdf

    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 11 min
  • Biscuits with Geoffroy Couprie

    We've trashed JWTs, discussed PASETO, Macaroons, and now, Biscuits! Actually, multiple iterations of Biscuits! Pairings and gamma signatures and Datalog, oh my! 🍪

    Transcript:
    https://securitycryptographywhatever.com/2022/01/29/biscuits-with-geoffroy-couprie/

    Links:

    Biscuits V2: https://www.biscuitsec.org

    Experiments iterating on  Biscuits: https://github.com/biscuit-auth/biscuit/tree/master/experimentations

    Apache Pulsar:
    https://pulsar.apache.org

    Spec:
    https://github.com/biscuit-auth/biscuit/blob/master/SPECIFICATIONS.md


    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    59 min
  • Tailscale with Avery Pennarun and Brad Fitzpatrick

    “Can I Tailscale my Chromecast?”

    You love Tailscale, I love Tailscale, we loved talking to Avery Pennarun and Brad Fitzpatrick from Tailscale about, I dunno, Go generics. Oh, and TAILSCALE! And DNS. And WASM.

    Transcript:
    https://securitycryptographywhatever.com/2022/01/15/tailscale-with-avery-pennarun-brad-fitzpatrick/

    People:

    • Avery Pennarun (@apenwarr)
    • Brad Fitzpatrick (@bradfitz)
    • Deirdre Connolly (@durumcrustulum)
    • Thomas Ptacek (@tqbf)
    • David Adrian (@davidcadrian)
    • @SCWPod

    Links:

    • DERP server: https://github.com/tailscale/tailscale/tree/main/derp
    • https://xtermjs.org/
    • The Tail at Scale : https://research.google/pubs/pub40801/
    • Raft: https://raft.github.io/
    • Litestream: https://litestream.io/
    • MagicDNS: https://tailscale.com/kb/1081/magicdns/
    • Netstack: https://github.com/google/netstack



    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 19 min
  • The feeling's mutual: mTLS with Colm MacCárthaigh

    We recorded this months ago, and now it's finally up!
     
    Colm MacCárthaigh joined us to chat about all things TLS, S2N, MTLS, SSH, fuzzing, formal verification, implementing state machines, and of course, DNSSEC.

    Transcript:
    https://securitycryptographywhatever.com/2021/12/29/the-feeling-s-mutual-mtls-with-colm-maccarthaigh/

    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian



    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 11 min
  • Holiday Call-in Spectacular!

    Happy New Year! Feliz Navidad! Merry Yule! Happy Hannukah! Pour one out for the log4j incident responders!

    We did a call-in episode on Twitter Spaces and recorded it, so that's why the audio sounds different. We talked about BLOCKCHAIN/Web3 (blech), testing, post-quantum crypto, client certificates, ssh client certificates, threshold cryptography, U2F/WebAuthn, car fob attacks, geese, and more!

    Transcript:
    https://securitycryptographywhatever.com/2021/12/21/holiday-call-in-spectacular/

    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian

     


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 23 min
  • WireGuard with Jason Donenfeld

    Hey, a new episode! We had a fantastic conversation with Jason Donenfeld, creator of our favorite modern VPN protocol: WireGuard! We touched on kernel hacking, formal verification, post-quantum cryptography, developing with disassemblers, and more!

    Transcript:
    https://securitycryptographywhatever.com/2021/12/05/wireguard-with-jason-donenfeld/

    Links: 

    • WireGuard: https://www.wireguard.com
    • Tamarin: https://tamarin-prover.github.io
    • IDApro: https://hex-rays.com/ida-pro
    • NIST PQC: https://csrc.nist.gov/projects/post-quantum-cryptography/round-3-submissions
    • WireGuard Patreon: https://www.patreon.com/zx2c4


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 22 min
  • PAKEs, oPRFs, algebra with George Tankersley

    A conversation that started with PAKEs (password-authenticated key exchanges) and touched on some cool math things: PRFs, finite fields, elliptic curve groups, anonymity protocols, hashing to curve groups, prime order groups, and more.

    With special guest, George Tankersley!

    Transcript:
    https://securitycryptographywhatever.com/2021/10/26/pakes-oprfs-algebra-with-george-tankersley/

    Links: 

    • SRP deprecation: https://blog.cryptographyengineering.com/should-you-use-srp
    • OPAQUE: https://www.ietf.org/id/draft-irtf-cfrg-opaque-06.html
    • obfs: https://github.com/shadowsocks/simple-obfs
    • Elligator: https://elligator.cr.yp.to
    • Hash to Curve: https://www.ietf.org/archive/id/draft-irtf-cfrg-hash-to-curve-12.html
    • Magic Wormhole: https://github.com/magic-wormhole/magic-wormhole
    • Biscuits: https://github.com/CleverCloud/biscuit
    • Ristretto: https://ristretto.group
    • Monero signature bug: https://www.getmonero.org/ru/2017/05/17/disclosure-of-a-major-bug-in-cryptonote-based-currencies.html
    • SIDH smooth-order supersingular curves: https://link.springer.com/chapter/10.1007/978-3-662-53018-4_21


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 16 min

About Security Cryptography Whatever

From the publisher's feed

Some cryptography & security people talk about security, cryptography, and whatever else is happening.

More shows like Security Cryptography Whatever

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,053 Listeners

Planet Money by NPR

Planet Money

30,689 Listeners

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,639 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,087 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

623 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

The Quanta Podcast by Quanta Magazine

The Quanta Podcast

542 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

10,185 Listeners

Dwarkesh Podcast by Dwarkesh Patel

Dwarkesh Podcast

567 Listeners

Search Engine by PJ Vogt

Search Engine

4,592 Listeners

No Priors: Artificial Intelligence | Technology | Startups by Conviction

No Priors: Artificial Intelligence | Technology | Startups

140 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners