βI lost 25 pounds in 20 daysβ: what itβs like to be on the frontline of a global cyber-attack
The security chief of SolarWinds reflects on the Russian hack that exposed US government agencies β and the heart attack he suffered in the aftermath
The 2020 SolarWind accident was one of the big cases where a compromised build environment lead to a far-spreading (and hard-to-detect) cyber incident. The Guardian just published a great article with the SolarWind CISO revisiting the events five years later: www.theguardian.com/technology/2...
24.10.2025 08:10 β π 0 π 0 π¬ 0 π 0
The extended paper is available here as open-access: www.cl.cam.ac.uk/techreports/...
24.10.2025 08:10 β π 0 π 0 π¬ 1 π 0
The picture shows Mario and Daniel presenting the last slide of their presentation at ACM CCS 2025 in Taipei. The text on the slide reads: A-Bs provide source-to-binary provenance using TEEs and sandboxing; complements Reproducible Builds and both can be combined in an any-trust model; practical evaluation (see our GitHub) and formal verification using Tamarin.
How to trust that the binaries that we deploy are truthfully built from the correct source code? π€
Just back from ACM CCS '25 π where we presented Attestable Builds as a solution to this challenge. It complements Reproducible Builds and uses TEEs as a trust anchor. With @coderlime.bsky.social
24.10.2025 08:10 β π 5 π 1 π¬ 1 π 0
The picture shows a smartphone and the imprint of a newspaper. The smartphone displays a screen from the SecureMessaging feature showing a key digest. The newspaper imprint shows the same digest. The digest consists of a number of randomly-looking letters and digits.
One of my favourite CoverDrop details: out-of-band verification of the trusted organization key which signs the entire key hierarchy. Its digest is included in the imprint of every printed Guardian newspaper, removing the need to trust CAs πποΈ more details: www.coverdrop.org
29.07.2025 10:45 β π 62 π 29 π¬ 1 π 5
Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments
Audits of AI/ML systems while protecting model IP and keeping the audit data confidential π€«
@inxoy.bsky.social is at the ICML TAIG workshop today, presenting our work on Attestable Audits: arxiv.org/html/2506.23... with Bill Marino and @arberesford.bsky.social
19.07.2025 13:57 β π 3 π 3 π¬ 0 π 0
Super excited that Jenny is presenting our new paper on "Web Authentication and Recovery in the Age of E2EE" at PETS today! ππ
Tons of interesting insights for a world in which we are moving away from passwords, and E2EE data becomes more long-term and critical. petsymposium.org/popets/2025/...
17.07.2025 11:37 β π 3 π 1 π¬ 1 π 0
β©οΈ Back-link to the launch post: bsky.app/profile/lamb...
27.06.2025 14:01 β π 0 π 0 π¬ 0 π 0
There are a lot of insights in both the original PETS paper (petsymposium.org/2022/files/p...) and Diana's PhD thesis (www.repository.cam.ac.uk/items/ec87dd...).
27.06.2025 13:58 β π 1 π 0 π¬ 1 π 0
CoverDrop involved users from the very beginningβavoiding the βsolution looking for problemβ trap. Big shout out to @mansoor.bsky.social , Diana, and @arberesford.bsky.social for getting this right from the very beginning by running two very insightful workshops with journalists and engineers.
27.06.2025 13:58 β π 4 π 0 π¬ 1 π 0
CoverDrop: Blowing the Whistle Through A News App
And if you like to learn more about the CoverDrop research behind SecureMessaging: www.coverdrop.org
20.06.2025 09:50 β π 0 π 0 π¬ 0 π 0
This announcement really should have our lead Rustaceans @itsibitzi.dev and @zekehg.bsky.social on top π¦! CoverDrop's implementation journey has been demonstrating the immense strengths that lie in Rust's type system and the mature tool chain. Looking forward to all the talk in September!
20.06.2025 09:50 β π 3 π 0 π¬ 1 π 0
The Guardianβs new whistleblower tool buries leaks to journalists within its own readersβ everyday traffic
Think "I am Spartacus!" βΒ but for leakers.
The Guardian appβs own data flows make leaks indistinguishable from regular traffic β cutting off one of the easiest ways for a repressive government or a corporate boss to identify a leaker. www.niemanlab.org/2025/06/the-...
09.06.2025 21:58 β π 46 π 23 π¬ 1 π 0
Thank you so much @martin.kleppmann.com for all your help, guidance, and feedback during this project! Especially with the tricky bits around key rotation and concurrency. And glad that we were able to distill some insights from the production world already into our P79 course.
09.06.2025 13:05 β π 13 π 0 π¬ 0 π 0
Thereβs a lot more to say, and Iβll highlight some aspects that Iβm particularly excited about over the next few weeks.
09.06.2025 13:02 β π 3 π 0 π¬ 0 π 0
Our CoverDrop white paper has a lot more technical details and we are immensely grateful to everyone who have provided us with valuable feedback throughout this project: www.cl.cam.ac.uk/techreports/...
09.06.2025 13:02 β π 3 π 0 π¬ 2 π 0
CoverDrop: Blowing the Whistle Through A News App
We launched CoverDrop π providing sources with a secure and anonymous way to talk to journalists. Having started five years ago as a PhD research project, this now ships within the Guardian app to millions of usersβall of which provide cover traffic. Paper, code, and more info: www.coverdrop.org
09.06.2025 13:00 β π 59 π 20 π¬ 1 π 1
GitHub repo here: github.com/lambdapionee...
28.04.2025 16:14 β π 1 π 0 π¬ 0 π 0
PETS paper here: petsymposium.org/popets/2024/...
28.04.2025 16:14 β π 0 π 0 π¬ 1 π 0
Panorama of Linz
Greatly enjoyed talking at JKU Linz about our Sloth π¦₯ library which uses Secure Enclaves (SEs) for key stretching and deniable encryption. Importantly, it works around Android/iOS API limitations and, therefore, Sloth is available to regular apps on most smartphones without modifications.
28.04.2025 16:13 β π 0 π 0 π¬ 1 π 0
The final slides are online now: bsky.app/profile/lamb...
07.04.2025 15:17 β π 3 π 1 π¬ 2 π 0
Department of Computer Science and Technology β Course pages 2024β25: Cryptography and Protocol Engineering β Course materials
It's done! The final lecture slides and notes for "P79 Cryptography and Protocol Engineering" are now online: www.cl.cam.ac.uk/teaching/242... π. This is the first time that @martin.kleppmann.com and I have done this courseβwe very much welcome feedback, corrections, and suggestions for next time
07.04.2025 15:15 β π 28 π 5 π¬ 2 π 1
The slides are updated as-we-go on the course website: www.cl.cam.ac.uk/teaching/242... Currently, the highlight are the great X25519/Ed25519 slides by Martin. Content should be complete by begin of March :)
17.02.2025 09:53 β π 1 π 0 π¬ 0 π 0
The lectures are not recorded, but we will upload the slides and lecture notes online. There will be another post when the full set becomes available.
29.01.2025 16:03 β π 4 π 0 π¬ 1 π 0
We believe that simply preaching "Don't roll your own crypto" does not cut it anymoreβthe next generation of engineers and researchers needs to be able to critically evaluate available implementations and competently navigate risks and trade-offs.
29.01.2025 13:24 β π 6 π 0 π¬ 0 π 0
Making quantum compilers @ Quantinuum and rusty open source libs.
Engineers interested in Rust, getting together to socialise and discuss projects.
Making network egress filtering effective, reliable and usable. Founder & Chief Engineer at @chasersystems.bsky.social
Blog: https://www.new23d.com/
Professor of Planetary Computing at the University of Cambridge @cst.cam.ac.uk, where I co-lead the @eeg.cl.cam.ac.uk and work on computing for global biodiversity and climate change with @conservation.cam.ac.uk.
Homepage at https://anil.recoil.org
postdoc @princeton
computational cognitive science βͺ machine learning
https://smn.one
Security Researcher (https://coderlime.at), co-founder of Light Squares Ltd (https://lightsquares.dev) and CEO of Lins Security GmbH (https://linssecurity.com).
PhD Student at ETH Zurich, Cryptography and more
The official Real World Cryptography Bluesky feed. Follow us for news of upcoming events.
Journalist at the Financial Times. Not the chancellor. Email me on rachel.rees@ft.com
todepond.com
β΅ London ΰ·΄ @tldraw.com
Editor of Weekend FT β’ sinkhole tracker β’ Do not buy crypto from me or anyone who appears to be me
Professor of Emergent Harms, Department of Computer Science & Technology, University of Cambridge
Director, Cambridge Cybercrime Centre
Fellow and Director of Studies, King's College
she/her
Cryptographer who likes to implement multi-party computation and works for CSIRO's Data61. Views my own. π³οΈβππ¨ππ¦πΊ (he/him)
Chief Communications Officer at Guardian Media Group
privacy prof at KIT and CeTI/TU Dresden
Mass produced during the Machine Era but redesigned for the Psychic Era
RC F'13, F2'17
Cryptogopher / Go cryptography maintainer
Professional open source maintainer
https://filippo.io / https://github.com/FiloSottile
https://mkcert.dev / https://age-encryption.org
https://sunlight.dev / https://filippo.io/newsletter
Investigations Correspondent, The Guardian | Tips: henry.dyer@theguardian.com/henrydyer.01 (Signal) | Interested in Politics/Media/π/CofE
https://www.theguardian.com/profile/henry-dyer
http://direthoughts.com