@salusasecondus.bsky.social

A programming cryptographer who tells stories and plays various strange musical instruments. Most of my attention is at Mastodon rather than here: @SalusaSecondus@Wandering.Shop

135 Followers 204 Following 190 Posts Joined Nov 2024
2 days ago

AI generated code is just automated cargo cult programming.

0 1 0 0
3 days ago
Soatok Dreamseeker (@soatok@furry.engineer) At #RealWorldCrypto this year, there was a session on "privacy-enhancing technologies". The first talk in the session was about a new encryption method for Tor. The next two were painful examples of...

#RealWorldCrypto #RWC2026 furry.engineer/@soatok/1162...

7 2 0 1
2 days ago

See me. I speak words!

www.youtube.com/live/00zvMSW...

1 0 0 0
2 days ago

All those years of photography and photo editing paid off!

1 0 1 0
2 days ago

I definitely did better than expected, especially since I'm on my phone and not my monitor. (Though I haven't actually had a calibrated monitor in almost 20 years.)

What's My JND? 0.0034
Can you beat it? www.keithcirkel.co.uk/whats-my-jnd...

1 0 1 0
4 days ago

5/ And on the Strait of Hormuz, they had NO PLAN. I can't go into more detail about how Iran gums up the Strait, but suffice it say, right now, they don't know how to get it safely back open.

Which is unforgiveable, because this part of the disaster was 100% foreseeable.

15,100 3,363 529 505
3 days ago

I have a thought about the ambient conversation.

Performative support for marginalized groups is a good thing, but it is mostly to let fuckheads know that they need to reexamine their assumption that fuckheadedness is commonplace.

117 25 2 1
3 days ago

Those signs, which I personally am not a fan of, serve an important purpose. They signal what is considered acceptable behavior in a neighborhood. It makes it *easier* for people to do the right thing and applies social pressure against the wrong thing.

1 0 0 0
4 days ago
Post image

FLOE!

eprint.iacr.org/2025/2275

#realworldcrypto

6 2 1 0
4 days ago

Next up, 'Random-Access AEAD for Fast Lightweight Online Encryption', presented by Andres Fabrega and Gregory Rubin

#realworldcrypto

3 1 1 1
5 days ago

My mom's advice remains generally good and wise for all couples.

Queen sized bed, king sized duvet/blanket.

Truly, words to love by.

0 0 1 0
6 days ago
Abstract. Signal is a secure messaging app offering end-to-end security for pairwise and group communications. It has tens of millions of users, and has heavily influenced the design of other secure messaging apps (including WhatsApp). Signal has been heavily analysed and, as a result, is rightly regarded as setting the “gold standard” for messaging apps by the scientific community. We present two practical attacks that break the integrity properties of Signal in its advertised threat model. Each attack arises from different features of Signal that are poorly documented and have eluded formal security analyses. The first attack, affecting Android and Desktop, arises from Signal’s introduction of identities based on usernames (instead of phone numbers) in early 2022. We show that the protocol for resolving identities based on usernames and on phone numbers introduced a vulnerability that allows a malicious server to inject arbitrary messages into one-to-one conversations under specific circumstances. The injection causes a user-visible alert about a change of safety numbers, but if the users compare their safety numbers, they will be correct. The second attack is even more severe. It arises from Signal’s Sealed Sender (SSS) feature, designed to allow sender identities to be hidden. We show that a combination of two errors in the SSS implementation in Android allows a malicious server to inject arbitrary messages into both one-to-one and group conversations. The errors relate to missing key checks and the loss of context when cryptographic processing is distributed across multiple software components. The attack is undetectable by users and can be mounted at any time, without any preconditions. As far as we can tell, the vulnerability has been present since the introduction of SSS in 2018. We disclosed both attacks to Signal. The vulnerabilities were promptly acknowledged and patched: the first vulnerability was fixed two days after disclosure, while the second one was patched after eight days. Beyond presenting these devastating attacks on Signal’s end-to-end security guarantees, we discuss more broadly what can be learned about the challenges of deploying new security features in complex software projects.
Image showing part 2 of abstract.

Signal Lost (Integrity): The Signal App is More than the Sum of its Protocols (Kien Tuong Truong, Noemi Terzo, Kenneth G. Paterson) ia.cr/2026/484

25 13 0 1
5 days ago

Just finished presenting this work at Real World Crypto in Taipei :)

TL;DR: We found 2 attacks on Signal (Android, Desktop) where a malicious server can inject messages in conversations.

Super fun project! Thanks a bunch to Noemi Terzo, @kennyog.bsky.social, and @cryptojedi.bsky.social

15 3 0 0
5 days ago
Post image

We are proud to share that Professor David Basin and Dr Ralf Sasse from D-INFK, together with Professors Cas Cremers and Jannik Dreier, have received the Levchin Prize for Real-World Cryptography. Congratulations! 🥳

Read more: inf.ethz.ch/news-and-eve...

5 1 0 0
1 week ago

Off to #RealWorldCrypto to present my work on online (streaming) and random-access encryption!

Taipei, here I come!

1 0 0 0
1 week ago

None at all.

Smooth, safe, interfaces. If they need to think about the tool at all it means there is room for improvement.

0 0 0 0
1 week ago
Post image

The United States if it was an Oregon donor

198 23 7 1
1 week ago

I once, accidentally, did a headstand in fire.

2 0 1 0
1 week ago

It's only a man trap if it's from the Isle of Mann. Otherwise it's just a sparkling vestibule.

59 7 2 0
2 weeks ago
Preview
Cryptography Engineering Has An Intrinsic Duty of Care To understand my point, I need to first explain three different cryptography attack papers / blog posts. I promise this won't be boring. Three Little Dislcosures Misuse-Prone Ciphers For All In a blog post titled Carelessness versus craftsmanship in cryptography, cryptography analyst and Queer in Cryptography emcee Opal Wright delves into the misuse-prone and side-channel-riddled JavaScript and Python implementations of the AES block cipher.

Cryptography engineering has an intrinsic duty of care.

79 22 5 0
2 weeks ago

Yeah. Reads fine to me (programmer/cryptographer).

0 0 0 0
2 weeks ago

I think that along with their beliefs in eugenics and pre-germ theory, they've also brought back phrenology.

Honestly, I'd support prescriptive phrenology in their cases.

0 0 0 0
2 weeks ago
Preview
Saturday Morning Breakfast Cereal - Conversation Saturday Morning Breakfast Cereal - Conversation

Haha, this one was written about 5 years before chatgpt launched. www.smbc-comics.com/comic/conver...

373 123 15 5
1 month ago

The greatest offense to being presented with LLM generated text isn't just them thinking it coul be helpful to me, it's specifically that they think I'd be better off from *them* being the ones doing it despite their lack of context and lack knowledge about my process

13 3 2 1
3 weeks ago
Preview
Cryptographic Issues in Matrix’s Rust Library Vodozemac - Dhole Moments Two years ago, I glanced at Matrix’s Olm library and immediately found several side-channel vulnerabilities. After dragging their feet for 90 days, they ended up not bothering to fix any of i…

soatok.blog/2026/02/17/c... #Matrix #security #cryptography

64 37 5 2
3 weeks ago

Context: soatok.blog/2026/02/17/c...

17 5 1 0
3 weeks ago
Preview
Instagram Create an account or log in to Instagram - Share what you're into with the people who get you.

One nice thing about Instagram as a host for my short form vidya is you don't need to post every day to maintain momentum. That was really wearing me down on Tiktok.

Also check me out here for the curious: www.instagram.com/jabrassey/

1 1 0 0
1 month ago

I'm convinced AI is our generation's radium - a discovery with genuinely useful applications in specific, controlled circumstances that we stupidly put in everything from kid's toys to toothpaste until we realised the harm far too late where future generations will ask if we were out of our minds.

17,930 5,442 246 257
1 month ago

the nazis have once again forgotten one of the most important rules in combat: never get involved in a logistics war with the americans

190 38 4 4
1 month ago

It's on broadcast in the Seattle area. NBC 5.1 looks to have it.

0 0 0 0