Nadim Kobeissi

@nadim.computer

Applied cryptographer. Mainly working in the cryptography auditing industry, but sometimes venturing back into academia. https://nadim.computer

We finally finished the universal signature forgery for 1024-bit RSA! 2^32 oracle queries, 1200 core years precomputation, 180 core years for an individual forgery, and 3 years of human labor (no AI involved) by Laura, Adam, Nadia, Emmanuel and me to pull of this computation against real HSMs.

Emmanuel Thomé@emmanuelthome.bsky.social · 3h ago

Forging 1024-bit RSA signatures in nearly SNFS time Hand over your HSM for some time, and we can forge signatures for its key. Arbitrary signatures. Forever. github.com/ucsd-hacc/NS...

Why TeX is Slow and How We Rebuilt It in Pure Rust > ratex is a pure-Rust TeX rebuild that compiles documents 10–70× faster than TeX Live via in-memory packages and smart caching.

Image: Why TeX is Slow and How We Rebuilt It in Pure Rust 


> ratex is a pure-Rust TeX rebuild that compiles documents 10–70× faster than TeX Live via in-memory packages and smart caching.

Brilliant mathematician Emmy Noether was initially barred from teaching at University of Göttingen because she was a woman. She taught for 4 years as a "guest lecturer" under David Hilbert's name. Hilbert, exasperated at the stupidity of the rule: "Gentlemen, this is not a bathing establishment."

From Algebra to Airplane Crashes, Emmy Noether’s Lasting Influence on Mathematics

Emmy Noether, whom some consider the “Mother of Modern Mathematics,” continues to shape modern research and the studies of mathematicians today; including research into the investigation of airplane c...

artsci.tamu.edu

Screenshots of the Philip Morris website. (reminder: they're a leading cigarette company) It's a good calibration point for how good modern marketing is at dressing up pretty much any corporate (or, for that matter, government) behavior and making it sound responsible and safe.

2026-09-18_09-55-11.png2026-09-18_09-55-24.png

A few months ago a student asked me who do I look up to. After thinking about this question for a while, I think my definitive answer is: Salman Rushdie and Norman Finkelstein in terms of intellect and character, and Toby Fox in terms of poetic and artistic output.

TL;DR: using compression before encryption is much weaker than we thought. Tiny length differences can be amplified - almost without limit - and noise-based or bucketization countermeasures are then easy to bypass. Joint work with @prefix-free.bsky.social and Lenka Mareková, to appear at CCS 2026.

ePrint Updates@eprint.ing.bot · last wk.

Criminology: Refined Techniques for Compression Side-Channel Attacks (Yuanming Song, Lenka Mareková, Kenneth G. Paterson) ia.cr/2026/1972

Abstract. It has been known for two decades that performing compression before encryption is dangerous, because it introduces a side channel leaking information about plaintexts through ciphertext lengths: the compressed plaintext length may be visible in the ciphertext length, and the amount of compression obtained is plaintext-dependent; hence an adversary can obtain some leakage about the plaintext via observation of ciphertext lengths. This issue was first pointed out by Kelsey (FSE 2002) and turned into a practical plaintext recovery attack in the form of the CRIME attack on SSL and TLS by Rizzo and Duong in 2012. A long series of variations and attacks against other systems followed. Despite the known dangers, the compress-then-encrypt paradigm is still prevalent in practice today. This may be because the compression-based side channel is susceptible to noise and may require a large number of queries to enable plaintext recovery, and so can be mitigated by either adding noise (e.g. with random padding) or limiting an adversary’s interaction with the system.

We demonstrate that this side channel is much more powerful than previously thought. We focus on the widely-used DEFLATE algorithm in our analysis. We present novel techniques that enable strong amplification of small length differences arising during compression. Our telescoping and chaining amplification techniques exploit the way in which DEFLATE replaces common strings by shorter back-references. Our collision-based amplification technique focusses on exploiting hash table collisions in DEFLATE implementations. This involves a deeper examination (and exploitation) of the internals of DEFLATE than in previous works. These insights result in compressed length differences growing linearly with the length of queries. Compared with length differences of a few bits or bytes in prior work, our new amplification techniques thus enable us to defeat existing noise-based countermeasures.

Finally, we introduce the concept of CRIME automata, these being carefully crafted query strings that enable an attacker to exert fine control over the internal behaviour of DEFLATE and produce differences in the output lengths of the compressor according to various criteria (such as whether the DEFLATE sliding window contains a given target string). In turn, our automata are composed in a modular fashion from gadgets having different functions, including matching against target strings, performing logical operations between other gadgets, and, most importantly, amplifying differences in output lengths using the above-mentioned techniques. We provide multiple, concrete automata designs that serve different attack goals. These designs are supported by experiments and a publicly available codebase demonstrating the power, flexibility, and practical impact of our CRIME automata approach.

Currently waiting outside of a French university in my car to pick up my wife after she finishes teaching her course. That’s right! My wife is now a university professor and I’m so proud of her!!!!