Pascal Junod

@cryptopathe.me

applied cryptographer - certified nerd god - head of cryptography & research at duokey - founder modulo p - ex-Snap - co-founder ex-strong.codes - has-been professor - trail runner - aidjolat

Riddle of the day: your MacBook Pro mouse AND trackpad left click do not work anymore. In normal mode. In safe mode. Even in boot options menu. Trackpad right click does not work as well, but mouse right click is functional. Keyboard is functional. What's the root cause?

Wow! Alfred Menezes just published this 182 page "A Gentle Introduction to Lattice-Based Cryptography" paper. I just skimmed through it, but it looks like an invaluable resource if you want to study lattices and how they're used in (PQ) Cryptography. eprint.iacr.org/2026/1098

A gentle introduction to lattice-based cryptography

We present the quantum-safe Kyber key encapsulation mechanism (ML-KEM) and the Dilithium signature scheme (ML-DSA). We also develop the mathematical background on lattices needed to understand why Kyb...

eprint.iacr.org

"I don't want to install Signal, because in <COUNTRY>, it is used by criminals" <--- not the first time I hear this kind of argument. Any really powerful punchline in store?

New post: "Hybrid Constructions Are a Safety Blanket, and That's Fine" Companion piece to @soatok.bsky.social's post today. Hybrid KEMs hedge against a real retroactive threat. Hybrid signatures have a place too, but the case is less urgent. The real risk? Slowing PQ adoption.

Hybrid Constructions Are a Safety Blanket, and That's Fine

Why Symbolic Software agrees with Soatok's position on hybrid post-quantum constructions: hybrids are compelling for KEMs, far less necessary for signatures, and the real risk is migration friction.

symbolic.software

Encrypted Client Hello is now RFC 9849 This RFC defines an extension to Transport Layer Security that improves privacy for web users. Huge team effort and a win for the internet at large. Now to get deployment up... Some words I wrote about this for @cdt.org: cdt.org/insights/enc...

Encrypted Client Hello: Closing the SNI Metadata Gap

Referencesent-deployment-and-adoption" href="#current-deployment-and-adoption" class="toc-anchor">Current Deployment and Adoptionor">Trial by Firewall-security-systems" href="#adapting-network-securit...

cdt.org

Do you use a cloud-based password manager? So what's your threat model? Vendors like Bitwarden, Dashlane, LastPass and 1Password offer you "Zero Knowledge Encryption", with statements like: "Not even the team at Bitwarden can read your data (even if we wanted to)." We decided to test this… 1/n

We do prefer clarity to obscurity. We do prefer facts to claims, and we do prefer shared knowledge to guarded secrets. That’s why we open sourced the apps in 2021. Today, we go a step further, by open sourcing the server code. You are more than welcome to examine it 😎.

Bild