Security Cryptography Whatever

Security Cryptography Whatever

By Deirdre Connolly, Thomas Ptacek, David AdrianNewsScienceTechnologyTech NewsMathematics
Download on the App Store

Security Cryptography Whatever episodes

  • "Patch, Damnit!"

    A lot of fixes got pushed in the past week! Please apply your updates!
    Apple, Chrome, Matrix, Azure, and more nonsense.

    Transcript:
    https://securitycryptographywhatever.com/2021/09/20/patch-damnit/

    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian

    Links!
    The accuvant story in MIT Technology Review
    All the Apple platforms patched FORCEDENTRY no-click 0-day
    Chrome patched some 0-days that were being exploited in the wild
    PASETO update





    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 15 min
  • How to be a Certificate Authority with Ryan Sleevi

    Not the hero the internet deserves, but the one we need: it's Ryan Sleevi!

    We get into the weeds on becoming a certificate authority, auditing said authorities, DNSSEC, DANE, taking over country code top level domains, Luxembourg, X.509, ASN.1, CBOR, more JSON (!), ACME, Let's Encrypt, and more, on this extra lorge episode with the web PKI's Batman.


    Transcript:
    https://securitycryptographywhatever.com/2021/09/06/how-to-be-a-certificate-authority-with-ryan-sleevi/

    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 35 min
  • Apple's CSAM Detection with Matthew Green

    We're talking about Apple's new proposed client-side CSAM detection system. We weren't sure if we were going to cover this, and then we realized that not all of us have been paying super close attention to what the hell this thing is, and have a lot of questions about it. So we're talking about it, with our special guest Professor Matthew Green.

    We cover how Apple's system works, what it does (and doesn't), where we have unanswered questions, and where some of the gaps are.

    Transcript:
    https://securitycryptographywhatever.com/2021/08/27/apple-s-csam-detection-with-matthew-green/

    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian

    Links:
    https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf

    https://www.apple.com/child-safety/pdf/Apple_PSI_System_Security_Protocol_and_Analysis.pdf

    https://www.law.cornell.edu/uscode/text/18/2258A

    https://www.missingkids.org/content/dam/missingkids/gethelp/2020-reports-by-esp.pdf

    https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT

    https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_what_it_does

    https://research.fb.com/blog/2021/02/understanding-the-intentions-of-child-sexual-abuse-material-csam-sharers/

    https://www.nytimes.com/interactive/2019/11/09/us/internet-child-sex-abuse.html

    https://www.apple.com/child-safety/pdf/Expanded_Protections_for_Children_Frequently_Asked_Questions.pdf



    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    53 min
  • Platform Security Part Deux with Justin Schuh

    We did not run out of things to talk about: Chrome vs. Safari vs. Firefox. Rust vs. C++. Bug bounties vs. exploit development. The Peace Corps vs. The Marine Corps.

    Transcript:
    https://securitycryptographywhatever.com/2021/08/21/platform-security-part-deux-with-justin-schuh/

    Find us at:
    https://twitter.com/scwpod
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 21 min
  • What do we do about JWT? with Jonathan Rudenberg

    🔥JWT🔥

    We talk about all sorts of tokens: JWT, PASETO, Protobuf Tokens, Macaroons, and Biscuits. With the great Jonathan Rudenberg!

    After we recorded this, Thomas went deep on tokens even beyond what we talked about here: https://fly.io/blog/api-tokens-a-tedious-survey/

    Transcript: https://securitycryptographywhatever.com/2021/08/12/what-do-we-do-about-jwt-with-jonathan-rudenberg/

    Find us at:
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian
    https://twitter.com/scwpod


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 15 min
  • The Great "Roll Your Own Crypto" Debate with Filippo Valsorda

    Special guest Filippo Valsorda joins us to debate with Thomas on whether one should or should not "roll your own crypto", and how to produce better cryptography in general.

    After we recorded this, David went even deeper  on 'rolling your own crypto' in a blog post here: https://dadrian.io/blog/posts/roll-your-own-crypto/

    Transcript:
    https://securitycryptographywhatever.com/2021/07/31/the-great-roll-your-own-crypto-debate-with-filippo-valsorda/

    Links:
    https://peter.website/meow-hash-cryptanalysis
    https://arxiv.org/pdf/2107.04940.pdf
    https://ristretto.group
    https://filippo.io/heartbleed

    Find us at:
    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr 1 min
  • NSO group, Pegasus, Zero-Days, i(OS|Message) security

    Deirdre, Thomas and David talk about NSO group, Pegasus,  whether iOS a burning trash fire, the zero-day market, and whether rewriting all of iOS in Swift is a viable strategy for reducing all these vulns.

    Transcript:
    https://securitycryptographywhatever.com/2021/07/26/nso-group-pegasus-zero-days-i-os-message-security/

    Find us at:

    https://twitter.com/durumcrustulum
    https://twitter.com/tqbf
    https://twitter.com/davidcadrian


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

    1 hr

About Security Cryptography Whatever

From the publisher's feed

Some cryptography & security people talk about security, cryptography, and whatever else is happening.

More shows like Security Cryptography Whatever

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,053 Listeners

Planet Money by NPR

Planet Money

30,689 Listeners

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,639 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,087 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

623 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

The Quanta Podcast by Quanta Magazine

The Quanta Podcast

542 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

10,185 Listeners

Dwarkesh Podcast by Dwarkesh Patel

Dwarkesh Podcast

567 Listeners

Search Engine by PJ Vogt

Search Engine

4,592 Listeners

No Priors: Artificial Intelligence | Technology | Startups by Conviction

No Priors: Artificial Intelligence | Technology | Startups

140 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners