Do you use a cloud-based password manager? So what's your threat model?
Vendors like Bitwarden, Dashlane, LastPass and 1Password offer you "Zero Knowledge Encryption", with statements like: "Not even the team at Bitwarden can read your data (even
if we wanted to)."
We decided to test this⦠1/n
16.02.2026 08:12 β π 31 π 15 π¬ 2 π 3
Neil Postman quote
Literacy is our greatest weapon to remain robust and defend our humanity in this invasive, modern environment. Here, I recommend 7 books to create more robust humans. And yes, Huxley was right.
perilous.tech/7-books-for-...
28.01.2026 14:14 β π 1 π 1 π¬ 0 π 0
Submission week for the Cryptographic Application Workshop (CAW), an affiliated event at Eurocrypt'26 in Rome! Please submit your talk proposals on constructive real-world crypto using the following instructions before Jan 23, 2026 AoE. All infos on: caw.cryptanalysis.fun.
19.01.2026 20:20 β π 8 π 7 π¬ 1 π 0
Abstract. The paper is currently under embargo, and will be released mid-February 2026.
Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers (Matteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. Paterson) ia.cr/2026/058
14.01.2026 18:04 β π 6 π 1 π¬ 0 π 1
At the gpg.fail talk and omg #39c3
You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message.
Wonβt even blame PGP here. C is unsafe at any speed.
gpg has not fixed it yet.
27.12.2025 16:31 β π 437 π 111 π¬ 4 π 21
RWC 2026 accepted papers
Real World Crypto Symposium
The accepted talks for Real World Crypto 2026 are now online: rwc.iacr.org/2026/accepte...
Thanks to everyone who submitted, and we look forward to the discussions at the symposium.
19.12.2025 19:04 β π 22 π 9 π¬ 0 π 1
The PDF is also available online: archives.phrack.org/issues/72/ph...
More at phrack.org/contact
13.12.2025 09:35 β π 4 π 1 π¬ 0 π 0
USB: the most successful interface that also brings power
We use it every day, but how does it really work? USB has been around for almost 30 years and it evolved into really universal interface ...
I use USB daily but I have no idea how it works π€
USB 2 vs USB 3, USB-A vs USB-C, the PD standardβ¦ this talk is full of interesting details π
And now I even understand why my USB-C power bank doesnβt work with *this* cable unless flipped π
media.ccc.de/v/why2025-25...
19.08.2025 20:04 β π 32 π 9 π¬ 0 π 0
pallet of phrack
ππππππ
5 pallets of zines have landed at @defcon.bsky.social
05.08.2025 03:15 β π 24 π 5 π¬ 0 π 0
Some people keep calling the summer migration to Vegas a campβ¦
But who will sleep in a tent for real? The ones attending @why2025.bsky.social βΊοΈ
27.07.2025 04:27 β π 4 π 1 π¬ 1 π 0
RWC 2026 call for papers
Real World Crypto Symposium
The Call for Contributed Talks is now open for RWC 2026! And the deadline for submissions is now Oct. 10, 2025.
rwc.iacr.org/2026/contrib...
13.07.2025 15:52 β π 13 π 9 π¬ 1 π 0
π Ce jeudi, Vincent Strubel, directeur gΓ©nΓ©ral de l'ANSSI, sera l'invitΓ© de l'Γ©mission @quotidienofficiel.bsky.social β¬ diffusΓ©e sur TMC.
πΊ Rendez-vous ce soir Γ partir de 19h15 sur le canal 10.
12.06.2025 12:20 β π 4 π 2 π¬ 0 π 0
Go Cryptography Security Audit
Go's cryptography libraries underwent an audit by Trail of Bits. Read more about the scope and results.
Three Trail of Bits engineers audited core Go cryptography for a month and found only one low-sev security issue... in unsupported Go+BoringCrypto! πΎ
Years of efforts on testing, limiting complexity, safe APIs, and readability have paid off! β¨
Yes I am taking a victory lap. No I am not sorry. π
19.05.2025 19:07 β π 572 π 83 π¬ 14 π 4
The second Levchin Prize goes to the CADO-NFS team: Emmanuel ThomΓ©, Pierrick Gaudry, and Paul Zimmerman! Congratulations!
#realworldcrypto
26.03.2025 09:24 β π 16 π 5 π¬ 0 π 3
Private key extraction in ECDSA upon signing a malformed input (e.g. a string)
### Summary
Private key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON network input
Note that `elliptic` by...
This is a fascinating vulnerability.
The root causes are implementing deterministic signatures instead of hedged, using a general purpose big number implementation, and leaking its API at the crypto layer.
JavaScript types are a red herring, could have happened in any language.
16.02.2025 10:08 β π 175 π 30 π¬ 3 π 2
more postquantum https://blog.taurushq.com/quantum-doomsday-planning-2-2-the-post-quantum-technology-landscape/
09.05.2023 09:34 β π 4 π 2 π¬ 0 π 0
Baochip makes open-source hardware.
Compte officiel. Β« Un Γ©clairage scientifique des dΓ©bats de sociΓ©tΓ© Β».
- Science et pseudo-sciences (http://afis.org)
- Maison d'Γ©dition : http://book-e-book.com
Official Bluesky page of the Computer Science Department at ETH Zurich. Collected media and news from and about the department.
https://TEE.fail Bot - This bot only replies to mentions. Want a quote? Tag @tee.fail in your message to get it signed with a real TDX attestation key.
Cryptography, privacy, zero knowledge, Rust, Zcash dev, gaming, hardware hackery, art appreciation. He/him.
https://str4d.xyz
https://abyssdomain.expert/@str4d
age18f63qx4gk8x7p4lfuwwglqcan7snvp406q5vmk26g9fmpe9c799qqzzr3w
WHY2025 is an international non-profit outdoor hacker camp/conference taking place in The Netherlands in the summer of 2025.
WHY2025.org
picious until proven otherwise.
Cryptography research and auditing at zkSecurity. Recurring co-host on the ZKPodcast.
nmohnblatt.me
CTF w/ organizers and polygl0ts | ECSC swiss team & ICC team EU 24 | CS student @ EPFL
Established in 1927, SICPA is a Swiss private technology company that supports the effective governance and long-term prosperity of nations. SICPA is best known for protecting the majority of the worldβs banknotes
About SICPA: https://linktr.ee/SICPA_Group
Compte officiel de l'Agence nationale de la sécurité des systèmes d'information (ANSSI) | Retrouvez les alertes de #cybersécurité sur le compte @cert-fr.bsky.social
since 1985
https://phrack.org
The official Real World Cryptography Bluesky feed. Follow us for news of upcoming events.
Unofficial bot tracking the IACR Cryptology ePrint Archive (eprint.iacr.org). Maintained by @str4d.xyz.
Currently only posts about new papers. Author names are linkified to Bluesky accounts (cryptography.social); contact maintainer for inclusion/removal.
Co-founder zksecurity.xyz | Math & crypto | π¦πΉ
Humanizing the web with a user-centric search engine and browser - no ads, no trackers, just you and the product you love: https://kagi.com/
A fully private, cross-chain proof-of-stake network and decentralized exchange for the Cosmos and beyond. PENUMBRA IS HERE: https://penumbra.zone/
Senior Director of Research. Black Hat Review Board Member (AI, ML, and DS track lead) and International public speaker. I focus on emerging technologies and risks at the intersection of humanity and tech. Hype Critic. My writing: https://perilous.tech
navigating the library of babel