Don't forget to register for WAC8! Early registration ends today (July 26). Below is our finalized WAC8 program with 8 exciting talks. More infos on: wac8.cryptanalysis.fun
Fredrik Dahlgren
@fegge.bsky.social
Cryptography and static analysis @ Trail of Bits
Bob DyLean: A Framework for the Symbolic Analysis of Cryptographic Protocols in Lean (Théophile Wallez, Cas Cremers) ia.cr/2026/1493
Climate change will manifest as a series of disasters viewed through phones with footage that gets closer and closer until you're the one calmly stating "we're encased in flame"
Kid1, who is both an conductor and engineer for CN and has driven trains through SK wildfires himself, just sent me this video from Ontario. When I tell you they arent paid enough!!! vt.tiktok.com/ZSXkuEadE/
How do the closed-source parts of Apple's Private Cloud Compute work? We had a look at it 🍎👀 Paper: dl.acm.org/doi/abs/10.1... Slides: hpi.de/fileadmin/us...
Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence | Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks
dl.acm.org
I'm happy to report that the twenty-two issues Trail of Bits reported in #curl ten days ago have now all been addressed in one way or another. One of them is a pending CVE. They had an engineer spend a week poking on curl.
Finally, the post about collab w/ @trailofbits.bsky.social is out: blog.trailofbits.com/2026/06/22/i.... #aiohttp was one of the participating projects and got 8 security fixes out of it! #Python
Introducing Patch the Planet
Patch the Planet is our joint initiative with OpenAI to assist critical open-source software in the age of machine-speed vulnerability research.
blog.trailofbits.com
There we go. US Gov tightens post-quantum cryptography transition deadlines for high-value systems to 2030 for key exchange and 2031 for signatures. Also, speeding up the CMVP (FIPS 140 validation) processes. That’s how you know the rush is real. The quantum computers are (potentially) coming.
Securing the Nation Against Advanced Cryptographic Attacks
By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered: Section 1. Background
whitehouse.gov
We’re helping open-source developers fix the internet together with OpenAI. If you’re an open-source maintainer and would like our (pro bono) help, please reach out! blog.trailofbits.com/2026/06/22/i...
Introducing Patch the Planet
Patch the Planet is our joint initiative with OpenAI to assist critical open-source software in the age of machine-speed vulnerability research.
blog.trailofbits.com
Folkhälsomyndighetens generaldirektör fick sparken då hon satte käppar i hjulet för regeringens försök att finansiera statsministerns hustrus verksamhet i herrgården hon fått från friskolelobbyn: www.aftonbladet.se/nyheter/a/Gx... Har Sverige någonsin haft en så korrupt regering?
Skeptisk till ”existentiell hälsa” – fick sparken från myndigheten
Statsministerns fru meddelade att hon ville arbeta med ”existentiell hälsa” på sin herrgård. Ett halvår senare gav regeringen Folkhälsomyndigheten i uppdrag att
aftonbladet.se
Can’t help thinking that this is what happens if you aggresively market your new frontier model as the cyber infinity gauntlet. www.anthropic.com/news/fable-m...
Statement on the US government directive to suspend access to Fable 5 and Mythos 5
The US government has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States.
anthropic.com
The Workshop on Attacks in Cryptography 8 (WAC8) website is finally up, and our call for talks is open. Submit your cool cryptanalysis before July 3! We'll also invite speakers. If you had a favorite cryptographic attack from the last two years that we should invite, please put it in the comments.
Mythos can dribble a bowling ball. Mythos counted to infinity… twice. Mythos can kill two stones with one bird. Mythos can speak Braille. Etc etc…
You know that time we forged a ZK proof to pretend we beat Google at factoring? Well, this time we beat them for real. x.com/trailofbits/...
Trail of Bits on X: "We beat Google's quantum circuit again, and we didn't have to forge a proof this time. Today we're releasing trailmix, a toolkit for quantum "kickmix" circuits. It includes 5 new circuits we built for elliptic curve addition, the hardest part of Shor's algorithm. https://t.co/X3jYoU5udB" / X
We beat Google's quantum circuit again, and we didn't have to forge a proof this time. Today we're releasing trailmix, a toolkit for quantum "kickmix" circuits. It includes 5 new circuits we built for elliptic curve addition, the hardest part of Shor's algorithm. https://t.co/X3jYoU5udB
x.com
This is amazing!
Incredibly proud to have been part of this effort and collaboration to enable end-to-end encrypted messaging over RCS for users across the world in iOS 26.5. iMessage continues to offer the best security available to the most users at scale. www.apple.com/newsroom/2026/0...
The FreeBSD team has patched a remote code execution in its operating system that impacts all versions released since 2005 Tracked as CVE-2026-42511, the vulnerability resides in the FreeBSD DHCP client and is extremely easy to exploit aisle.com/blog/aisle-d...
The Cryptographic Applications Workshop (CAW) happens this Sunday in Rome! Just a reminder that if you're not coming to Rome you can still attend remotely. Just register here: forms.gle/2JZ7hLs8diQM... before May 8. See caw.cryptanalysis.fun for more infos and our program.
Love that pigeons are apparently ~ the same category of mythical beasts as goblins and gremlins.
This is an actual line that was added to the official system prompt for Codex for GPT-5.5 by OpenAI. Usually the system prompt is as minimal as possible, so I assume it would otherwise mention goblins a lot. AIs are weird.
Do you want to see the "big picture" on climate change? Here it is. Emissions are on the left, and include CO2, CH4, N2O, and f-gases. Natural CO2 sinks (from healthy forests & oceans) are on the right. And carbon removal, what little there is, is on the right, too. All expressed as GWP100.
There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers. This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.
words.filippo.io
Two weeks ago, Google published a paper proving in zero-knowledge that they had an efficient implementation of Shor's algorithm. Today, Trail of Bits can prove that we have an even better implementation which beats Google's on all metrics! 🫢 blog.trailofbits.com/2026/04/17/w...
Orban has conceded the election in Hungary and Europe has one less dictator. This is worth celebrating! ❤️ www.theguardian.com/world/live/2...
Hungary election live: Viktor Orbán concedes defeat in Hungarian election after 16 years in power
Long-serving prime minister beaten by opposition after early results showed clear lead
theguardian.com
“You shouldn't transition to post-quantum because you are confident quantum computing will happen; you should only avoid transitioning because you are confident quantum computing will not happen, and none of the experts are confident in that anymore.”
Overdue quantum landscape update: sam-jaques.appspot.com/quantum_land... A 2d chart can only say so much. tl;dr new results are still overhyped, but definitely worth taking seriously. This chart is based on surface codes and a big question now is whether new codes can be practical (=>useless chart)
The additional cost of ONE fossil fuel price spike on the scale of 2022 = the ENTIRE COST of Net Zero by 2050. We get precisely nothing in return for the first cost, and a whole new, more secure and cheaper energy system from the second one. #NoBrainer www.theccc.org.uk/2026/03/11/c...
Cost of Net Zero by 2050 less than a single fossil fuel price shock – CCC - Climate Change Committee
The independent, statutory body tested its cost and energy security conclusions against different scenarios. It found that the total additional cost of a single fossil fuel price spike of 2022 magnitu...
theccc.org.uk
So well deserved.
Very proud and grateful to have won the 2026 #realworldcrypto Levchin prize together with David Basin, Jannik Dreier, and Ralf Sasse for our work on the Tamarin Prover (tamarin-prover.com), as well as having the amazing opportunity to give a keynote at RWC! Hope you enjoyed it! #realworldcrypto2026
UPDATE: The European Parliament voted today to *end* untargeted mass scanning of private communications, firmly rejecting the error-prone and unconstitutional surveillance practices of recent years! Next: trilogue negotiations w/ Commission and Council.