Great news! Germ DM is now quantum secure! We’re deploying post-quantum cryptography (PQC) in 3.0.9, available today. 1/7
With 3.0.9, Germ DM is now quantum secure.
Great news! Germ DM is now quantum secure! We’re deploying post-quantum cryptography (PQC) in 3.0.9, available today. 1/7
With 3.0.9, Germ DM is now quantum secure.
If you weren't aware, I had a small part in helping design TLS 1.3 back in the day. Today, I presented some new work at the TLS working group meeting in Vienna to upgrade its the key schedule from SHA-2 (the workhorse) to Keccak, the algorithm behind SHA-3. www.ietf.org/archive/id/d...
XOF-based key schedules for TLS 1.3
TLS 1.3 runs its entire key schedule on HKDF over SHA-2. This document defines an extension that replaces that schedule with one built on an extendable-output function (XOF): the negotiated KDF gove...
ietf.org
The CFRG is holding a last call for two documents on hybrid KEMs: a mechanism that lets you safely combine a post-quantum KEM and a classical algorithm into a single construction. mailarchive.ietf.org/arch/msg/cfr... Reply on-list if you agree this should be published or have technical concerns.
[CFRG] RG Last Call on draft-irtf-cfrg-hybrid-kems-12 and draft-irtf-cfrg-concrete-hybrid-kems-04
Search IETF mail list archives
mailarchive.ietf.org
It feels disingenuous to recognize the difference between an informational RFC published by the IETF and the Independent Submission stream, but not recognize the difference between standards track and informational RFCs. Is an RFC and RFC, or do you care about the Category: and Stream: at the top?
Every lock needs a key. The hard part is not always designing the lock. Sometimes it is getting the key to the person who needs it. That is the problem I look at in the third post in my CDT series on Encrypted Client Hello. cdt.org/insights/dis...
Distributing the Keys for Private Access to the Web
Breaking the DNS Dependencych-22" class="toc-anchor">ECH’s Catch-22thing-strange-in-the-dns" href="#something-strange-in-the-dns" class="toc-anchor">Something Strange in the DNS use it. That’s the fun...
cdt.org
I'm in Toronto discussing how websites can specify their preferences regarding how their content is used by search engines and AI crawlers. Here's what we have so far:
Want to help shape the cryptography that ends up in Internet standards? CFRG is looking for Crypto Review Panel members. Self-nominations welcome. Two-year renewable term. Send nominations by April 20: cfrg-chairs@ietf.org wiki.ietf.org/group/cfrg/C...
Crypto Review Panel
wiki.ietf.org
ECH exposed a hard truth about privacy technology: you can win at the protocol layer and still lose at the deployment layer. I wrote about it here: cdt.org/insights/do-...
Do Not Stick Out: The Dynamics of the ECH Rollout
Lessons Learned-ech-traffic-stuck-out" href="#why-ech-traffic-stuck-out" class="toc-anchor">Why ECH Traffic Stuck Out">The Paradox of Privacy Adoption: Standing Out to Disappearss="toc-anchor">Case St...
cdt.org
I had a wonderful time at RWC again this year. What a lovely group of people.
The room gets philosophical. Cryptography & Society chaired by Nick Sullivan ( @nicksullivan.org ): what is crypto hiding from itself? Security vs. interoperability? CRA policy? Proofs that aren't enough? And Nadim Kobeissi on teaching crypto in post-crisis Lebanon. #realworldcrypto
I’m back in Taipei for Real World Crypto, then Tokyo next week for IETF by proxy. Let me know if you’re around!
Encrypted Client Hello is now RFC 9849 This RFC defines an extension to Transport Layer Security that improves privacy for web users. Huge team effort and a win for the internet at large. Now to get deployment up... Some words I wrote about this for @cdt.org: cdt.org/insights/enc...
Encrypted Client Hello: Closing the SNI Metadata Gap
Referencesent-deployment-and-adoption" href="#current-deployment-and-adoption" class="toc-anchor">Current Deployment and Adoptionor">Trial by Firewall-security-systems" href="#adapting-network-securit...
cdt.org
I put together a job site for cryptography roles. It's in alpha, so please send me your bugs! jobs.cryptography.consulting
CryptoJobs - Cryptography Career Opportunities
The definitive job board for cryptography professionals. Find opportunities in post-quantum cryptography, zero-knowledge proofs, HSM, TLS/PKI, and applied cryptographic research.
jobs.cryptography.consulting
I’m happy to be joining the USENIX Security ’26 Enigma organizing committee this year, after having the chance to speak at Enigma three times. It has a long history as a home for early, practice-driven security ideas, often where work first gets aired before it’s fully polished or widely deployed.
AI coding is an earthquake for software security. Not a tremor. The kind that liquefies the ground beneath your feet. We're mid-shake and most people are still debating if it's real. 🔗 github.blog/news-insight...
Registration for Real World Crypto 2026 is now open! rwc.iacr.org/2026/registr...
RWC 2026 registration
Real World Crypto Symposium
rwc.iacr.org
News! I’ll be joining the Internet Architecture Board(IAB) starting March 2026 at IETF 125 in Shenzhen(I’ll be participating remotely). The IAB is part of the IETF ecosystem. It looks across Internet protocol work to provide architecture-level oversight and help keep the standards process healthy.
CDT’s @npdoty.techpolicy.social.ap.brid.gy and Visiting Fellow @nicksullivan.org joined a UN OHCHR workshop in Madrid with engineers, industry, and civil society to explore how technical standards affect internet users’ human rights. Read their recap of the event:
Embedding Human Rights in Technical Standard-Setting: Institutional Change and Governance
Standards engineers discussing support for human rights in technical standards This July, just before a week of meetings on internet protocol details in Madrid, CDT invited a group of engineers — leaders from industry and civil society and participants in the Internet Engineering Task Force and World Wide Web Consortium — to a workshop organized […]
cdt.org
At #IETF124 in Montréal @ietf.org last month I gave a talk about Measuring & Understanding ECH deployments as @ooni.org. ECH is becoming a Frontline for whether the Internet remains Open, Private, and Resilient. We need to Document Censorship, to Protect our Internet. 📹 youtu.be/OmBNQKZtO3Q
The “cosmic-ray bit-flip” thing actually being real and serious enough to recall every A320 on the planet was not on my 2025 bingo card.
This is an obvious but important result, but I'm not a fan of this characterization of poisoning as an attack. There are legitimate reasons to poison, especially if you consider an AI company to be the malicious party rather than the victim. www.anthropic.com/research/sma...
A small number of samples can poison LLMs of any size
Anthropic research on data-poisoning attacks in large language models
anthropic.com
The first ARMOR meeting was a success with 4 great presentations on different aspects of real-world protocol resilience by @vinifortuna.com , Brien Colwell, @distributeddave.bsky.social , and @hellais.bsky.social.
New guest post from CDT Visiting Fellow & IETF expert @nicksullivan.org: Encrypted Client Hello (ECH) closes the final major privacy gap in HTTPS by encrypting the Server Name Indication (SNI) — a milestone for online privacy. 🌐 Read more:
Encrypted Client Hello: Closing the SNI Metadata Gap
Referencesent-deployment-and-adoption" href="#current-deployment-and-adoption" class="toc-anchor">Current Deployment and Adoptionor">Trial by Firewall-security-systems" href="#adapting-network-security-systems" class="toc-anchor">Adapting Network Security Systemsy-sni-became-the-last-privacy-gap" class="toc-anchor">Why SNI Became the Last Privacy Gapre-metadata-leaks" class="toc-anchor">Background: Where Metadata Leakste, whether governments like it or not. Encrypted Client Hello (ECH) is nearing final IETF standardization [1]. It closes the last remaining metadata leak in HTTPS connections by encrypting the Server Name […]
cdt.org
Here are seven things I’m looking forward to in the next month. Tomorrow, I’ll be guest lecturing with Kyle Hogan at NYU for Sunoo Park’s class on public interest tech. The theme: bikeshedding and how to get things done in internet standards.
Global network interference and traffic disruption are on the rise. In 2024, governments in 41 countries blocked websites and in 25 countries entire social platforms were restricted (freedomhouse.org/report/freed...).
The Struggle for Trust Online
Around the world, voters have been forced to make major decisions about their future while navigating a censored, distorted, and unreliable information space.
freedomhouse.org
Continuing our look at the Enigma track talks is "Fighting Fire with Venom: Adversarial Defense Against Unauthorized Web Crawling," presented by independent technologist Nick Sullivan. 1/3
Tomorrow on USENIX Security’s Enigma track, I’ll unveil Venom, a new framework to sting back at rogue AI web crawlers with some adversarial mischief. If you’re around Seattle, come say hi or ping me! www.usenix.org/conference/u...
Fighting Fire with Venom: Adversarial Defense Against Unauthorized Web Crawling | USENIX
usenix.org
The digital identity space is approaching a dangerous precipice. newdesigncongress.org/en/note/2025...
The Mask-Off Moment for Digital Identity
Our 18-month investigation reveals how digital identity systems create brittle societies. This foreword traces eight case studies that demonstrate the catastrophic failures of digital identity across ...
newdesigncongress.org
The Call for Contributed Talks is now open for RWC 2026! And the deadline for submissions is now Oct. 10, 2025. rwc.iacr.org/2026/contrib...
RWC 2026 call for papers
Real World Crypto Symposium
rwc.iacr.org