@kennyog.bsky.social
Bit flipper
A thread in which @sockpuppet.org presents some of the juiciest morsels from our paper at zkae.io :
17.02.2026 14:19 β π 9 π 1 π¬ 0 π 0A very nice blogpost explaining our work - slices right through the marketing from the vendors: medium.com/reading-sh/y...
17.02.2026 12:59 β π 2 π 1 π¬ 0 π 0We didnβt go as deep on 1password as the others. Probably some interesting things still to be found there.
16.02.2026 11:35 β π 3 π 0 π¬ 1 π 0@dashlane.com advisory: support.dashlane.com/hc/en-us/art...
16.02.2026 08:25 β π 4 π 0 π¬ 0 π 0ETH news article abkut the work: ethz.ch/en/news-and-...
16.02.2026 08:24 β π 7 π 1 π¬ 1 π 0Now we can finally tell you about all 27 of them: zkae.io
Paper to appear at USENIX Security 2026: eprint.iacr.org/2026/058
Joint work with Matilda Backendal, Matteo Scarlata, Giovanni Torrisi
In this "malicious server" threat model, we found a total of 27 vulnerabilities across Bitwarden, Dashlane, LastPass and 1Password.
More than half of them lead to compromise of your passwords.
Do you use a cloud-based password manager? So what's your threat model?
Vendors like Bitwarden, Dashlane, LastPass and 1Password offer you "Zero Knowledge Encryption", with statements like: "Not even the team at Bitwarden can read your data (even
if we wanted to)."
We decided to test this⦠1/n
Miracle of miracles: Deutsche
Bahn runs almost on time!
Almost in Karlsruhe for this talk. Looking forward to some great discussions with the KIT crypto and security community.
11.02.2026 12:00 β π 9 π 1 π¬ 0 π 1"The heroes of my fields have slain one of the four horsemen of the apocalypse, while the heroes of your field gathered in the desert to create a new one" is such a clear, brutal rebuttal to Manhattan Project mythology, and now the most venal idiots alive are bringing back diseases because they can.
23.01.2026 20:10 β π 68 π 19 π¬ 0 π 0The sun still rises. And it will continue to do so. Long after the fascists are gone.
20.01.2026 08:37 β π 13 π 1 π¬ 0 π 0Submission week for the Cryptographic Application Workshop (CAW), an affiliated event at Eurocrypt'26 in Rome! Please submit your talk proposals on constructive real-world crypto using the following instructions before Jan 23, 2026 AoE. All infos on: caw.cryptanalysis.fun.
19.01.2026 20:20 β π 8 π 7 π¬ 1 π 0I insisted that Nadhim Zahawi delete this tweet before joining us, because one of our rules is that everyone in Reform UK has to pretend that Iβm not racist.
13.01.2026 09:28 β π 449 π 134 π¬ 11 π 0Achievement unlocked: I finished the Private Eye Christmas cryptic crossword (#820). Itβs a right corker, thanks to Cyclops for providing the much appreciated Yuletide mental gymnastics! @privateeyenews.bsky.social
25.12.2025 22:55 β π 3 π 0 π¬ 0 π 0Cat sitting on a wall with a doubtful look on its face.
Doubting Tomcat.
25.12.2025 22:41 β π 3 π 0 π¬ 0 π 0Some great talks to come at #RWC026 including 5 (!) from the Applied Cryptography research group @csateth.bsky.social on topics including Signalβs security, designing SecureDrop Next Generation, fuzzing of crypto librariesβ¦. and one mystery topic still under embargo.
19.12.2025 22:27 β π 22 π 5 π¬ 1 π 0Winter sun on Zuriberg.
08.12.2025 22:15 β π 11 π 0 π¬ 0 π 0Nah, I just need more coffee!
18.09.2025 06:18 β π 1 π 0 π¬ 0 π 0When I read βwasβ I feared the worst. Glad to hear Alfred is alive and kicking (and still having impact).
18.09.2025 06:12 β π 0 π 0 π¬ 1 π 0Two carved wooden heads on a Swiss bridge, both looking startled.
Catching up on recent posts on the CFRG mailing list.
01.09.2025 07:04 β π 9 π 0 π¬ 0 π 0Good luck - hope everything goes smoothly and the course is a hit!
02.08.2025 14:03 β π 3 π 0 π¬ 1 π 0I like it! New mascot for the group.
28.07.2025 06:21 β π 1 π 0 π¬ 0 π 0Do I let this guy stay in the garage or gently remove him to a nice damp bit of garden?
28.07.2025 06:15 β π 5 π 0 π¬ 4 π 0Curve25519 is a false friend. Also isnβt it βdefenceβ rather than βdefenseβ? π¬π§
26.07.2025 15:57 β π 2 π 0 π¬ 1 π 0Would it be too salty to say how reassuring it is to find so many new experts in quantum computing and post quantum cryptography suddenly popping up over on LinkedIn?
18.07.2025 11:27 β π 26 π 5 π¬ 0 π 0New reading material dropped.
17.07.2025 07:17 β π 16 π 0 π¬ 0 π 0The Call for Contributed Talks is now open for RWC 2026! And the deadline for submissions is now Oct. 10, 2025.
rwc.iacr.org/2026/contrib...