I feel like we’re going to look back at that time in summer 2026 when we thought it was so surprising that models could find new mathematical results that we still wrote Twitter threads about it. I wonder what life will be like then.
Matthew Green
@matthewdgreen.bsky.social
I teach cryptography at Johns Hopkins. https://blog.cryptographyengineering.com
1/ Initial reactions after some hours with this groundbreaking result proving the NP-hardness of poly-approx CVP/NCP: It is most likely correct, but more importantly, it is original, elegant, and beautiful! (Also: it is easy to improve, quantitatively.) openai.com/index/ten-ad...
Ten advances in mathematics and theoretical computer science
OpenAI shares new results on long-standing open problems in mathematics and theoretical computer science, including advances in geometry, cryptography, and complexity.
openai.com
Vanderbilt has done a thing where they announce their commitment to “intellectual freedom” by kowtowing to the Trump administration’s dictation on what Universities should think about. Predictably, the usual folks in SV think it’s great. www.vanderbilt.edu/declaration/
Declaration
The University and Its Purpose: A Declaration of First Principles was adopted by the Vanderbilt University Board of Trust in June 2026. The declaration is organized around three core purposes: Pathbre...
vanderbilt.edu
I wrote up a short blog post giving my thoughts on the new Anthropic cryptanalysis results against HAWK and AES. blog.cryptographyengineering.com/2026/07/29/s...
Some notes about Anthropic’s new results
Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAW…
blog.cryptographyengineering.com
Plants are smart because they know to fuck off when it’s not summer.
All these mathematicians typing “solve famous open conjecture” and getting results, meanwhile I can’t get Fable to even consider most of the dumb cryptography questions I’d like to solve. And when I manage to get one through, it sticks crayons up its nose.
This is an interesting post on Apple defeating liability for CSAM scanning on its systems. I think this is a good decision, but it’s a frustrating one due to some basic technical misunderstandings and oddities of the law. blog.ericgoldman.org/archives/202...
Apple Defeats Liability for Not Scanning iCloud for CSAM, But the Judge Was Not Pleased-Amy v. Apple - Technology & Marketing Law Blog
This case involves Apple’s handling of user-uploaded files hosted in private iCloud storage. Instead of adopting PhotoDNA to scan hosted files for CSAM, Apple created its own proprietary alternative, ...
blog.ericgoldman.org
I’ve been working on a hobby project to crack classical ciphers. The guts of it is to see whether frontier LLMs, given the right tools, can do a good job cracking a broad range of historical ciphers. github.com/matthewdgree...
GitHub - matthewdgreen/decipher: An AI-enabled application for cracking ciphers
An AI-enabled application for cracking ciphers. Contribute to matthewdgreen/decipher development by creating an account on GitHub.
github.com
What kills me about this story is that Meta’s public CSAM scanning clearly does not work, if they’re delivering ads for CSAM content. But this failure will be used as evidence that we need to add scanning for private and encrypted messages. www.bbc.com/news/article...
India: Instagram running ads promoting child sexual abuse material, BBC finds
The ads use terms including “rape” and “child video” and link to content on the messaging app Telegram.
bbc.com
Researchers @citizenlab.ca say EU lawmaker who investigated surveillance was hacked by Israeli spyware @raphae.li www.reuters.com/world/middle...
Researchers say EU lawmaker who investigated surveillance was hacked by Israeli spyware
A former member of the European Parliament who served on a committee investigating abusive surveillance was himself hacked using an Israeli-made spy tool, a Canadian tech watchdog group said on Frid...
reuters.com
Theory question: give an upper bound on the number of vulnerabilities that can be present in an n-bit program.
Apropos of nothing, does anyone else have very happy memories associated with this product?
I don’t think people should panic based on anything djb has written recently. But I do agree with his conclusion that ECC hybrids are a good idea. I also do continue to be skeptical of the “ECC hybrids are just too hard to get right” arguments.
Dems' "Project 2029" first major policy proposal: an online child safety plan — narrowing Sec. 230, banning social media for kids under 16, promoting phone-free childhoods and more. Already backed by Cory Booker, Mikie Sherrill, Randi Weingarten + Jonathan Haidt. LMAOOOOOOOOOOOOOOOOOOO.
One of my beefs with (research) cryptography is that people are overindexing on quantum threats. We finally got crypto to the point where we can do things efficiently, and now we need to rip it all up and switch to lattice schemes at 11,000x the cost.
“Europe needs air conditioning” is true, but it also feels like a talking point explicitly constructed so that people don’t have to pay attention to the effects of rapid climate change.
Counterpoint: the fact that vendors/projects won’t privilege vulnerability reports is hardly a punishment for security researchers. It’s a gift.
We know vulnerability reports are not like ordinary issues. But why? It comes down to needing the scarce insight and temporary confidentiality to protect users. However, now that LLMs can find more or less the same bugs for everyone, none of that matters, and vuln reports are not special anymore.
So apparently anyone with a license plate number can submit it to most DMVs to obtain detailed owner information, provided they claim they’re doing so in the “ordinary course of business” (eg to collect a debt). This isn’t verified or checked.
So Will Cathcart is leaving WhatsApp and this is the new leader that Mark Zuckerberg has chosen.
One of my new favorite gripes is people setting up AI receptionists to answer their phone and telling them nothing, including whether the business is open that day. It’s just the weirdest way to use technology.
I wonder if the frontier LLMs have benchmarks for their human users.
One of the things I’ve noticed in my aging friends is that virulent conservative beliefs and cognitive decline seem highly correlated.
It really seems like we’re going to end up with a choice of doing model inference expensively here in the US or inexpensively in China, and this is going to create a nightmare data sovereignty problem.
God, Claude Fable really knows how to butter me up.
Scoop: Britain has weakened proposed cybersecurity protections for its telecoms networks that were developed in response to the Salt Typhoon espionage campaign, after the companies responsible for implementing the measures lobbied against them.
UK weakens proposed telecoms defenses against Chinese hackers after industry pushback
Britain has weakened proposed cybersecurity protections for its telecoms networks that were developed in response to the Salt Typhoon espionage campaign, after the companies responsible for implementi...
therecord.media
My strongest argument that we’re actually living in a simulation is the three-way light switch. There’s no way that can possibly work.
I wrote a new post about the privacy risks of on-phone agents like Apple’s new Siri, and how private inference isn’t any sort of silver bullet. blog.cryptographyengineering.com/2026/06/09/a...
The future of Siri, or: why private inference isn’t private enough
Yesterday Apple announced a big step towards deploying real AI in their Siri ecosystem. In most ways this is good and inevitable: Siri is one of the world’s most widely-used voice agents, and…
blog.cryptographyengineering.com
Remember the current NIH director going on about protecting researchers from government censorship? Today his people called the police in to forcibly remove my colleagues from their own society meeting for sharing an editorial published in their flagship journal that was critical of him. Gift link
Police Remove Diabetes Experts From Conference for Distributing Critique of Trump Administration
nytimes.com
Does anyone have a connection to Randall Munroe (@xkcd.com) or any way to reach his company? I’m writing a book and wanted to license some of his cartoons but can’t get a response from his licensing or press emails.