Pascal Junod
@cryptopathe.me
applied cryptographer - certified nerd god - head of cryptography & research at duokey - founder modulo p - ex-Snap - co-founder ex-strong.codes - has-been professor - trail runner - aidjolat
Genuine question for academic cryptographers: does it still make sense to work on non-PQ-secure primitives?
I had this one sitting in my draft queue before I went on vacation, and forgot to hit publish. I hope nobody starved. So please enjoy my rant on hybrid signatures. https://keymaterial.net/2026/06/18/on-hybrid-signatures/
Riddle of the day: your MacBook Pro mouse AND trackpad left click do not work anymore. In normal mode. In safe mode. Even in boot options menu. Trackpad right click does not work as well, but mouse right click is functional. Keyboard is functional. What's the root cause?
Wow! Alfred Menezes just published this 182 page "A Gentle Introduction to Lattice-Based Cryptography" paper. I just skimmed through it, but it looks like an invaluable resource if you want to study lattices and how they're used in (PQ) Cryptography. eprint.iacr.org/2026/1098
A gentle introduction to lattice-based cryptography
We present the quantum-safe Kyber key encapsulation mechanism (ML-KEM) and the Dilithium signature scheme (ML-DSA). We also develop the mathematical background on lattices needed to understand why Kyb...
eprint.iacr.org
Modern way to introduce engineering students to cybersecurity: let them vibe-code an app, then red team it. Write-ups: olivier.amacker.dev/305.2-applie... and gdbateaux.github.io/305.2-applie...
The Silent Hijack: How a Simple Rename Compromised an Entire Healthcare System
olivier.amacker.dev
"I don't want to install Signal, because in <COUNTRY>, it is used by criminals" <--- not the first time I hear this kind of argument. Any really powerful punchline in store?
Hybrid Constructions: The Post-Quantum Safety Blanket The funny thing about safety blankets is they can double as stage curtains for security theater. Art: CMYKat "When will a cryptography relevant quantum computer exist?" is a question many technologists are pondering as they stare into crystal…
Hybrid Constructions: The Post-Quantum Safety Blanket
The funny thing about safety blankets is they can double as stage curtains for security theater. Art: CMYKat "When will a cryptography relevant quantum computer exist?" is a question many technologists are pondering as they stare into crystal balls or entrails. Two people I admire recently made a public long bet about that question, with a $5000 donation to charity as stakes.
soatok.blog
New post: "Hybrid Constructions Are a Safety Blanket, and That's Fine" Companion piece to @soatok.bsky.social's post today. Hybrid KEMs hedge against a real retroactive threat. Hybrid signatures have a place too, but the case is less urgent. The real risk? Slowing PQ adoption.
Hybrid Constructions Are a Safety Blanket, and That's Fine
Why Symbolic Software agrees with Soatok's position on hybrid post-quantum constructions: hybrids are compelling for KEMs, far less necessary for signatures, and the real risk is migration friction.
symbolic.software
Overdue quantum landscape update: sam-jaques.appspot.com/quantum_land... A 2d chart can only say so much. tl;dr new results are still overhyped, but definitely worth taking seriously. This chart is based on surface codes and a big question now is whether new codes can be practical (=>useless chart)
Objects in the quantum mirror are closer than they appear. https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/
Quantum frontiers may be closer than they appear
An overview of how Google is accelerating its timeline for post-quantum cryptography migration.
blog.google
Huge congrats to Bennett and Brassard for the well-deserved award, but the highlighted sentence from the ACM announcement (www.acm.org/media-center...) is a rather odd take on PQC ...
Real real-world cryptography
I was deeply humbled by the unbelievably positive reaction to my talk at Real World Crypto 2026 in Taipei about my experiences teaching applied cryptography in post-crisis Lebanon. The full video for the talk is now available: www.youtube.com/watch?v=z_Hx...
Unpopular opinion: people speaking about "key shards" don't know what they are talking about.
Encrypted Client Hello is now RFC 9849 This RFC defines an extension to Transport Layer Security that improves privacy for web users. Huge team effort and a win for the internet at large. Now to get deployment up... Some words I wrote about this for @cdt.org: cdt.org/insights/enc...
Encrypted Client Hello: Closing the SNI Metadata Gap
Referencesent-deployment-and-adoption" href="#current-deployment-and-adoption" class="toc-anchor">Current Deployment and Adoptionor">Trial by Firewall-security-systems" href="#adapting-network-securit...
cdt.org
I wrote a new post on anonymous credentials and how to build them. All of this is in service on a longer future post on how these will fit into age verification systems. blog.cryptographyengineering.com/2026/03/02/a...
Anonymous credentials: an illustrated primer
This post has been on my back burner for well over a year. It’s been sitting here unwritten, not because the topic is unimportant — in fact, with every single month that goes by, I become mor…
blog.cryptographyengineering.com
"Although our algorithm does not break Dilithium, it is at least 50 bits faster than the recent algorithm of Ducas, Engelberts and Loyer [DEL25] in Crypto 2025 for all security levels." 👀
Solving SIS in any norm via Gaussian sampling (Amaury Pouly, Yixin Shen) ia.cr/2026/225
"Looks like I’ve found new bug in Libsodium library." www.linkedin.com/posts/oleg-t...
You are viewing this page in an unauthorized frame window. | Oleg T.
Looks like I’ve found new bug in Libsodium library. This bug (or vulnerability) resembles CVE-2025-69277 (https://lnkd.in/d-ZAwnRU) but affects checking of points for x25519 curve. Function crypto_...
linkedin.com
Do you use a cloud-based password manager? So what's your threat model? Vendors like Bitwarden, Dashlane, LastPass and 1Password offer you "Zero Knowledge Encryption", with statements like: "Not even the team at Bitwarden can read your data (even if we wanted to)." We decided to test this… 1/n
The Verification Theater: When Formal Methods Create False Assurance in Cryptographic Libraries (Nadim Kobeissi) ia.cr/2026/192
I wrote a short blog post on the WhatsApp lawsuit, or whatever it is. blog.cryptographyengineering.com/2026/02/02/w...
WhatsApp Encryption, a Lawsuit, and a Lot of Noise
It’s not every day that we see mainstream media get excited about encryption apps! For that reason, the past several days have been fascinating, since we’ve been given not one but sever…
blog.cryptographyengineering.com
We do prefer clarity to obscurity. We do prefer facts to claims, and we do prefer shared knowledge to guarded secrets. That’s why we open sourced the apps in 2021. Today, we go a step further, by open sourcing the server code. You are more than welcome to examine it 😎.
A decade is an eternity in security. 🛡️ Ten years ago, we released the Clang Hardening Cheat Sheet. Today, the landscape has changed. @0xTRIKKSS & @bcreusillet break down the latest mitigations to keep your code secure. 🔗Read the update: blog.quarkslab.com/clang-harden...
Security is hard, even for the big boys: or how a supply-chain attack had the potential to compromise every AWS account (‼️). As a reminder, AWS powers one third of the "cloud". www.wiz.io/crying-out-c...
CodeBreach: Hijacking the AWS Console with Yuval Avrahami | Wiz
CodeBreach: how a tiny regex bug in AWS CodeBuild created a serious cloud supply-chain risk
wiz.io