Security Cryptography Whatever

@scwpod.bsky.social

@durumcrustulum.com, @sockpuppet.org, @dadrian.io “Freewheelin’ dynamic”. https://securitycryptographywhatever.com https://podcasts.apple.com/us/podcast/feed/id1578405214

TIL I cannot listen to @lcamtuf.coredump.cx at 3x speed. It's never bothered me with other voices I already know from conversation (including the hosts on @scwpod.bsky.social). But I had to slow everything down below 2x to get him out of the uncanny valley.

Facing the Vulnpocalypse With lcamtuf

We talk to Michał Zalewski (lcamtuf) about the vulnpocalypse and if we even need fuzzers anymore. This episode may be export controlled at a future date. Th...

securitycryptographywhatever.com

I finally reached the end. This was a super good episode and it gave me all the warm fuzzies about my internal reactions to getting started with Ossl3 for PQC. As a former windows NCrypt provider maintainer, I really thought all my “magic strings to throw at a generic API” was behind me 😭

Just recorded the premiere episode of Season VIII of Security Cryptography & W/evs, this time with Alex Gaynor and Paul Kehrer, who have a momentous announcement about pyca/cryptography and OpenSSL.

Threshold decryption.... I struggled with that one and still do. Obviously it's a point of fragility to allow one lost share to cancel the election. But true DKG with parties spread across the world is also not obviously easy to implement.

Yes, it's finite fields, in large part because implementing over elliptic curves, especially with proper hashing for NIZKs, was more complexity than I could handle. Would likely make sense to upgrade to EC at some point but also probably not a huge priority? Happy to hear counter arguments!

Yes, Helios definitely uses NIZKs to prove proper ballot form. Implemented in 2008 browser JavaScript, which was a fun challenge.