"presenting a cornucopia of practical attacks". These are my favorite words ever to have occurred in a cryptography paper.
You mean Professor Matilda Backendal! 😉
A team of computer scientists from the Applied Cryptography Group, including Matteo Scarlata, Professor Kenny Paterson, Giovanni Torrisi and Matilda Backendal, have discovered serious security vulnerabilities in three popular cloud-based password managers. Read more ⬇️
I always assumed that #passwordmanagers were simple objects -- create a database, encrypt it, send it to the server, done. I could not have been more wrong! At zkae.io, we take a look at all the hidden complexity in cloud password managers, and the #attacks that result from that. (ia.cr/2026/058)
Zero Knowledge (About) Encryption
zkae.io
Do you use a cloud-based password manager? So what's your threat model? Vendors like Bitwarden, Dashlane, LastPass and 1Password offer you "Zero Knowledge Encryption", with statements like: "Not even the team at Bitwarden can read your data (even if we wanted to)." We decided to test this… 1/n
The call for talks for CAW 2026 (a workshop affiliated with Eurocrypt) is out! This year's motto is "cryptography under real-world constraints and threat models", but other applied cryptography is also very welcome. All info is on: caw.cryptanalysis.fun.
This year, #CAW offers the option for remote participation to make our Eurocrypt workshop accessible to the members of our community that cannot or prefer not to travel to Madrid. Register on our website before May 2 (free): caw.cryptanalysis.fun The updated program is below.
Our latest work is out! Breaking and repairing Content-Defined Chunking, with impact across multiple backup systems. Read Kien Tuong Truong’s blog here: blog.ktruong.dev/breaking-cdc
Breaking and Fixing Content-Defined Chunking
A collection of my (future) writings about cryptography, music and other random stuff.
blog.ktruong.dev