Fredrik Dahlgren's Avatar

Fredrik Dahlgren

@fegge.bsky.social

Cryptography and static analysis @ Trail of Bits

240 Followers  |  237 Following  |  75 Posts  |  Joined: 26.06.2023  |  1.7307

Latest posts by fegge.bsky.social on Bluesky

That’s a great idea! Please open an issue on the repo so it doesn’t get lost. πŸ™‚

10.08.2025 16:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Buttercup is now open-source! Now that DARPA’s AI Cyber Challenge (AIxCC) has officially ended, we can finally make Buttercup, our CRS (Cyber Reasoning System), open source!

We’re open sourcing our AI reasoning system Buttercup, which placed second in DARPAs AI Cyber Challenge! It runs on your laptop and works with any OSS-fuzz/ClusterFuzz compatible project.

blog.trailofbits.com/2025/08/08/b...

10.08.2025 06:27 β€” πŸ‘ 16    πŸ” 7    πŸ’¬ 1    πŸ“Œ 0
aicyberchallenge.com

Trail of Bits won second place in DARPAs AI Cyber Challenge (AIxCC) at DEFCON! πŸ™Œ

Congratulations to all of the competing teams. Amazing work!

aicyberchallenge.com

09.08.2025 11:56 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Ordered and looking forward to reading this!

09.08.2025 08:55 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
A request for ChatGPT to draw an ASCII art image of a fierce dragon, followed by an image of a happy little blob with snail-like pony tails.

A request for ChatGPT to draw an ASCII art image of a fierce dragon, followed by an image of a happy little blob with snail-like pony tails.

Are we AGI yet?

09.08.2025 08:46 β€” πŸ‘ 8    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0

No matter your interpretation of the categorical imperative, we can’t have a functioning society if lying isn’t penalized.

07.08.2025 19:36 β€” πŸ‘ 640    πŸ” 121    πŸ’¬ 11    πŸ“Œ 6
Preview
Exclusive: Google is indexing ChatGPT conversations, potentially exposing sensitive user data Thousands of shared ChatGPT chats are now appearing in Google search results.

Well this is bad. Google is indexing ChatGPT conversations exposing sensitive user data

I tried a few quick searches. I found someone's chat where I can see their api key

I found some building their resume. Their name, email and phone numbers are exposed.

www.fastcompany.com/91376687/goo...

31.07.2025 20:59 β€” πŸ‘ 2643    πŸ” 1816    πŸ’¬ 80    πŸ“Œ 255
Tom Lehrer - Wernher von Braun
YouTube video by The Tom Lehrer Wisdom Channel Tom Lehrer - Wernher von Braun

As we lost the great Tom Lehrer today, can every technologist please have (another) listen to youtu.be/QEJ9HrZq7Ro?... "Once the rockets are up / who cares where they come down? / that's not my department / says Wernher von Braun"

27.07.2025 19:19 β€” πŸ‘ 6    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
A list of topics from the Microsoft Ignite program. *Every* topic mentions Copilot, AI, or intelligent agents in some way.

A list of topics from the Microsoft Ignite program. *Every* topic mentions Copilot, AI, or intelligent agents in some way.

I wonder if we’ll hear anything about AI at Microsoft Ignite this year..? πŸ€”

23.07.2025 13:49 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Building secure messaging is hard: A nuanced take on the Bitchat security debate The release of Bitchat last week was met with a mixture of glowing praise and sharp criticism. Both extremes bear some truth, but they also miss the mark and reveal gaps in how we discuss security in ...

Sometimes it is easy to forget that all of the mature E2EE systems we have today started out as small proof-of-concepts full of compromises, shortcuts, and we’ll-deal-with-that-later’s.

blog.trailofbits.com/2025/07/18/b...

18.07.2025 16:06 β€” πŸ‘ 9    πŸ” 3    πŸ’¬ 0    πŸ“Œ 1
Preview
The FIPS 140-3 Go Cryptographic Module Go now has a built-in, native FIPS 140-3 compliant mode.

We announced the new native Go FIPS 140-3 mode today!

FIPS 140, like it or not, is often a requirement, and I was increasingly sad about large deployments replacing the Go crypto packages with non-memory safe cgo bindings.

Go is now one of the easiest and most secure ways to build under FIPS 140.

15.07.2025 21:40 β€” πŸ‘ 205    πŸ” 49    πŸ’¬ 12    πŸ“Œ 4
Preview
Swedish Prime Minister Pulls AI Campaign Tool After It Was Used to Ask Hitler for Support Sweden's Moderate party allowed users to make the PM hold a sign bearing any name they wanted. You know what happened next.

Swedish Prime Minister Pulls AI Campaign Tool After It Was Used to Ask Hitler for Support

πŸ”— www.404media.co/swedish-prim...

14.07.2025 20:08 β€” πŸ‘ 109    πŸ” 21    πŸ’¬ 6    πŸ“Œ 8
Preview
Spain awards Huawei contracts to manage intelligence agency wiretaps Huawei will manage and store judicially authorized wiretaps in Spain, under a contract that bucks the trend of Western governments restricting use of the Chinese tech company's products and services.

Wow. Spain is putting salt typhoon out of business. They are just going to hand it all to them: Huawei contracted to manage their wiretaps….

therecord.media/spain-awards...

12.07.2025 22:54 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

We ran a randomized controlled trial to see how much AI coding tools speed up experienced open-source developers.

The results surprised us: Developers thought they were 20% faster with AI tools, but they were actually 19% slower when they had access to AI than when they didn't.

10.07.2025 19:46 β€” πŸ‘ 6904    πŸ” 3023    πŸ’¬ 112    πŸ“Œ 626

Swedish security police have unintentionally leaked the locations of the Swedish prime minister and the Swedish monarch by using the fitness app Strava while on assignments.

Those who cannot learn from history are doomed to repeat it. πŸ™„

www.bbc.com/news/technol...

09.07.2025 10:30 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Commission presents Roadmap for effective and lawful access to data for law enforcement The European Commission presented today a Roadmap setting out the way forward to ensure law enforcement authorities in the EU have effective and lawful access to data.

Well, this horrible idea refuses to die so we should refuse to let it pass and start organizing again.

ec.europa.eu/commission/p...

05.07.2025 17:25 β€” πŸ‘ 75    πŸ” 43    πŸ’¬ 2    πŸ“Œ 5
Preview
Denmark pushes to suspend Hungary’s EU voting rights Danish European Affairs Minister Marie Bjerre says Copenhagen will ramp up Article 7 proceedings against Budapest.

Sounds like Denmark is going to make life quite uncomfortable for Orban 😁

About time to really show him his place and get Ukraine’s EU accession process moving.

03.07.2025 20:58 β€” πŸ‘ 457    πŸ” 84    πŸ’¬ 19    πŸ“Œ 15
A small animal, dancing in the dark holding a cane.

A small animal, dancing in the dark holding a cane.

CodeQL now supports Rust!

github.blog/changelog/20...

01.07.2025 15:45 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The Trail of Bits cryptography team will be in Cannes for EthCC this week. Hit us up if you want to hang out and talk about ZK, MPC, FHE, E2EE or your favorite acronym of choice!

29.06.2025 12:18 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Never heard about mise before. I need to try this on a real project!

28.06.2025 12:57 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Release Notes - zizmor Abbreviated change notes about each zizmor release.

zizmor v1.10.0 is released!

this is a *huge* new release: it exposes a new (experimental) auto-fix mode, more precise subspanning for fixtures, as well as a brand new pedantic audit (anonymous-definition)

read the full notes here: docs.zizmor.sh/release-note...

26.06.2025 18:42 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0
Preview
NATO’s β€œBrain Death” in The Hague At the 2025 NATO Summit, allies pledged to raise defense spending to 5 percent of GDP. But spending targets alone ignore deeper issues. Europe must shift its focus to building capable, integrated mili...

My take on the NATO summit. Lots of unintended consequences with Europeans agreeing to something that few intend to deliver on. NATO ignoring its major challenge, fighting together as Europe with less US. That requires deep reforms, not vague spending pledges.
www.csis.org/analysis/nat...

25.06.2025 21:25 β€” πŸ‘ 241    πŸ” 76    πŸ’¬ 16    πŸ“Œ 17
We mostly talk about our livers when they fail.
What about when our livers succeed?
[liver image]
Share if your liver is succeeding right now!

We mostly talk about our livers when they fail. What about when our livers succeed? [liver image] Share if your liver is succeeding right now!

18.06.2025 04:10 β€” πŸ‘ 34    πŸ” 76    πŸ’¬ 2    πŸ“Œ 0
Post image 07.06.2025 20:59 β€” πŸ‘ 959    πŸ” 175    πŸ’¬ 7    πŸ“Œ 6
A chart for quantum computers, of number of qubits versus error rate, on a logarithmic scale. Broadly it shows a large gap between current quantum computers in the bottom left, and a curve in the top right of the resources they need to break RSA.

A chart for quantum computers, of number of qubits versus error rate, on a logarithmic scale. Broadly it shows a large gap between current quantum computers in the bottom left, and a curve in the top right of the resources they need to break RSA.

An out-of-schedule update to my quantum landscape chart: sam-jaques.appspot.com/quantum_land..., prompted by
@craiggidney.bsky.social 's new paper: arxiv.org/abs/2505.15917.

A startling jump (20x) in how easy quantum factoring can be!

Also: much improved web design!

19.06.2025 18:52 β€” πŸ‘ 63    πŸ” 26    πŸ’¬ 3    πŸ“Œ 0

We’ll miss you Will! Good luck and hope our paths cross again in the future!

17.06.2025 16:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Cryspen is excited to announce it has been awarded a grant from the Ethereum Foundation to extend our hax verification toolchain with support for the Lean prover. Watch this space for more on this soon!

#FormalVerification #Lean #Rust

17.06.2025 04:38 β€” πŸ‘ 12    πŸ” 5    πŸ’¬ 2    πŸ“Œ 0

Here's a paradox: Swedes have a very low opinion of Trump. Meanwhile, in many ways the Swedish government has adopted his playbook – the xenophobia, the war on "woke" and "cancel culture," the flagrant corruption, the rejection of experts and expertise, the attacks on universities, etc. >

12.06.2025 08:31 β€” πŸ‘ 150    πŸ” 65    πŸ’¬ 8    πŸ“Œ 4

1/ Earlier this year, Yuval Domb of @ingonyama.com discovered Logjumps β€” a more efficient way to do large-prime field multiplication than Montgomery multiplication. So much modern crypto relies on modular multiplication β€” all the way from TLS sessions to elliptic-curve based ZK proofs.

11.06.2025 00:40 β€” πŸ‘ 9    πŸ” 4    πŸ’¬ 1    πŸ“Œ 1

We (finally) published all the material from this course on SQIsign, including lecture slides and exercise sheets for the Sage laboratory. Available here: github.com/andreavico/S...

10.06.2025 15:58 β€” πŸ‘ 13    πŸ” 12    πŸ’¬ 1    πŸ“Œ 0

@fegge is following 20 prominent accounts