Miro Haller

@mirohaller.bsky.social

PhD student @ UCSD working on applied cryptography https://mirohaller.com

The Workshop on Attacks in Cryptography 8 (WAC8) website is finally up, and our call for talks is open. Submit your cool cryptanalysis before July 3! We'll also invite speakers. If you had a favorite cryptographic attack from the last two years that we should invite, please put it in the comments.


call for talks

WAC accepts proposals for contributed talks. Submissions will be evaluated based on their relevance to the following topics:
- Cryptanalysis of deployed cryptography
- Cryptanalysis of recently suggested cryptographic schemes or primitives
- New cryptoanalytic techniques
- Systems attacks breaking cryptography or bypassing underlying assumptions

Please include the following information in your contributed talk submission.
- Title.
- Description of the talk content, including: short abstract (to be published on the website on talk acceptance), and one of the following three: extended abstract describing the talk. [preferred option], a full paper and a short description of which aspects the talk will focus on. slides for a presentation, together with either speaker notes or a short outline of the non-visual content of the talk.
- Speaker information: Name, Affiliation, Short bio (to be published on the website on talk acceptance), A brief description of the relevant experience of the speaker, e.g. links to previous talks.

Submit your proposal by email to the organizers at wac@cryptanalysis.fun by July 3, 2026 AoE.

Announcing the preliminary program for Cedarcrypt — our inaugural applied cryptography summer school and conference, July 13–16, 2026 at the American University of Beirut - Mediterraneo in Paphos, Cyprus! An absolutely fantastic program awaits — check it out, register today, and share widely!

Cedarcrypt 2026 — Applied Cryptography Summer School & Conference

Join us for four days of applied cryptography in the Mediterranean. July 13–16, 2026 at AUB Mediterraneo Campus, Paphos, Cyprus.

cedarcrypt.org

Our WOOT paper went out of disclosure today. We found 5 attacks on the Master Lock D1000 which allow unauthorized unlocking, bypassing access revocation, forging log entries, and causing DoS. If you're in Seattle, come to our talk given by Chengsong, one of the students I mentored for this paper.

    Attack 1 (session replay): An adversary in physical proximity of the lock (without ever having a valid account on the lock) can record the Bluetooth Low Energy (BLE) communication of a whole session and replay it to repeat all executed commands, including unlocking the lock.
    Attack 2 (exceeding access): Former guests can continue unlocking the lock after their access has been revoked.
    Attack 3 (clock tampering): Malicious guests can adjust the clock time of the smart lock arbitrarily, extending their own access past expiration or locking out all legitimate users.
    Attack 4 (audit log tampering): An adversary that only knows the lock’s identifier (which is advertised over BLE) can upload arbitrary audit events to the telemetry server, and prevent legitimate audit events from being uploaded. Hence, the adversary can hide their own activities.
    Attack 5 (malformed messages): Without valid access, an adversary can send malformed BLE messages to the lock that make it unresponsive or corrupt memory, which results in a Denial of Service (DoS) for authorized users. A malicious authorized user can even leak the memory of the smart lock.

#CAW offers again a few registration waivers. We hope these waivers will help local (grad/undergrad) students to attend our workshop and get a preview of cryptography beyond the classroom and make their first connections to the community. More info: caw.cryptanalysis.fun#student-regi...

student registration fee waivers

We have funding to cover the registration costs of a few student attendees. To apply, please email the organizers with a short motivation why you want to attend CAW and need funding for doing so until March 21, 2025 AoE.
Miro Haller@mirohaller.bsky.social · last yr.

The preliminary program for the Cryptographic Applications Workshop (CAW) at Eurocrypt'25 is out. #CAW focuses on the construction and analysis of cryptography built for practice. This thread gives a quick overview; the full program and abstracts are here: caw.cryptanalysis.fun#program

Did you get your Eurocrypt decision today? And now either know you'll attend and would like to give an extra talk or need a different reason to go to Madrid? Then consider submitting a talk on applied, constructive cryptography to CAW. Our call for talks is open until Feb 7.

Miro Haller@mirohaller.bsky.social · 2y ago

The 2nd iteration of the Cryptographic Applications Workshop (#CAW) will be at Eurocrypt 2025! #CAW focuses on the construction and analysis of cryptography built for practice, bridging the gap between research and real-world applications. Our call of talks is currently open: caw.cryptanalysis.fun