Chris Fenner

@chrisfenner.bsky.social

We brought PQC (beginning with ML-DSA and ML-KEM) to TPM 2.0! While it’s only been a year since we last published, the big changes needed for PQC have been in the works since 2022. This was a monumental team effort and I’m so proud of the team for getting it done!

TPM 2.0 Library | Trusted Computing Group

TCG has released the TPM 2.0 Library specification that provides updates to the previous published TPM main specifications. The changes and enhancements compared to the existing TPM 1.2 include: Suppo...

trustedcomputinggroup.org

🙌 “Mistakes in cryptography are not a sin […]. They’re simply a fact of life. As somebody once said, “cryptography is nightmare magic math that cares what color pen you use.” We’re all going to get stuff wrong if we stick around long enough to do something interesting[.]”

Phil M0OFX@philpem.digipres.club.ap.brid.gy · 6mo ago

"aes-js and pyaes provide a default IV in their AES-CTR API" *screams* https://blog.trailofbits.com/2026/02/18/carelessness-versus-craftsmanship-in-cryptography/

I miss when you could post Brave Norman Rockwell Townsperson and the caption could be, like, “R.E.M was wrong to leave ‘Fretless’ off of Out of Time” instead of “The secret police should stop murdering people.”

> RFC 9794 > “The word "hybrid" is also used in cryptography to describe encryption schemes that combine asymmetric and symmetric algorithms [RFC9180], so using it in the post-quantum context overloads it and risks misunderstandings.” > Puts the word “hybrid” on everything

Me several days ago: “why do all the ML-DSA signing test vectors have only up to 2 of ( key seeds, hedging randomness, and mu values )” Me now: “ok guess I’m sending a PR to Wycheproof

Implementing a protocol that uses cryptography is harder than designing a protocol that uses cryptography. Normally I use that to explain to people that they need to minimize excessive complexity in their designs but imagine what designs the team responsible for this code is capable of

Andrew Lilley Brinker@alilleybrinker.com · 6mo ago

Why was this code ever shipped?! This is from the second vuln, where keys' signatures aren't checked before they're stored in the trusted key store. Why would you ever ship a "TODO, actually validate signatures lol" in your secure messenger?!

Image from the Trail of Bits report showing the offending code associated with the second high-severity vulnerability. It includes an empty "else" branch with a "to-do" comment that reads: "TODO (eventually) reject if signature is missing"

Minnesota National Guard members have arrived at a federal building and were directed to distribute donuts, coffee, and hot chocolate to anti-ICE protesters. Guard members were issued reflective vests so they would not be mistaken for federal agents.