TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Security Cryptography Whatever

    Some cryptography & security people talk about security, cryptography, and whatever else is happening.

    Advertise

    Copyright: © 2024 Security Cryptography Whatever

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Attacking Lattice-based Cryptography with Martin Albrecht Nov 13, 2023
    Show notes

    Returning champion Martin Albrecht joins us to help explain how we measure the security of lattice-based cryptosystems like Kyber and Dilithium against attackers. QRAM, BKZ, LLL, oh my!
    Transcript: https://securitycryptographywhatever.com/2023/11/13/lattice-attacks/
    Links:
    - https://pq-crystals.org/kyber/index.shtml
    - https://pq-crystals.org/dilithium/index.shtml
    - https://eprint.iacr.org/2019/930.pdf
    - https://en.wikipedia.org/wiki/Short_integer_solution_problem
    - Frodo: https://eprint.iacr.org/2016/659
    - https://csrc.nist.gov/CSRC/media/Events/third-pqc-standardization-conference/documents/accepted-papers/ribeiro-saber-pq-key-pqc2021.pdf
    - https://en.wikipedia.org/wiki/Hermite_normal_form
    - https://en.wikipedia.org/wiki/Wagner%E2%80%93Fischer_algorithm
    - https://www.math.auckland.ac.nz/~sgal018/crypto-book/ch18.pdf
    - https://eprint.iacr.org/2019/1161
    - QRAM: https://arxiv.org/abs/2305.10310
    - https://en.wikipedia.org/wiki/Lenstra%E2%80%93Lenstra%E2%80%93Lov%C3%A1sz_lattice_basis_reduction_algorithm
    - MATZOV improved dual lattice attack: https://zenodo.org/records/6412487
    - https://eprint.iacr.org/2008/504.pdf
    - https://eprint.iacr.org/2023/302.pdf


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    Signal's Post-Quantum PQXDH, Same-Origin Policy, E2EE in the Browser Revisted Nov 07, 2023
    Show notes

    We're back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.
    Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc
    Links:
    - https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/
    - https://github.com/superfly/macaroon
    - https://cryspen.com/post/pqxdh/
    - https://eprint.iacr.org/2023/1390.pdf


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    'Jerry Solinas deserves a raise' with Steve Weis Oct 11, 2023
    Show notes

    We explore how the NIST curve parameter seeds were generated, as best we can, with returning champion Steve Weis!
    “At the point where we find an intelligible English string that generates the
    NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore.”
    Transcript: https://securitycryptographywhatever.com/2023/10/12/the-nist-curves
    Links:
    - Steve’s post: https://saweis.net/posts/nist-curve-seed-origins.html
    - ANSI X9.62 ECDSA: https://safecurves.cr.yp.to/grouper.ieee.org/groups/1363/private/x9-62-09-20-98.pdf / FIPS 186-2 https://csrc.nist.gov/files/pubs/fips/186-2/final/docs/fips186-2.pdf
    - “A RIDDLE WRAPPED IN AN ENIGMA”: https://eprint.iacr.org/2015/1018.pdf
    - https://arstechnica.com/information-technology/2015/01/nsa-official-support-of-backdoored-dual_ec_drbg-was-regrettable/
    - https://www.muckrock.com/foi/united-states-of-america-10/origin-of-fips-186-4-elliptic-curves-over-prime-field-seed-parameters-national-institute-of-standards-and-technology-78756/
    - https://www.muckrock.com/foi/united-states-of-america-10/origin-of-fips-186-4-elliptic-curves-over-prime-field-seed-parameters-national-security-agency-78755/
    - Filippo’s bounty: https://words.filippo.io/dispatches/seeds-bounty/
    - Recommendations for Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters - NIST 800-186 with Curve25519 and friends
    - RFC 8422: Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS) Versions 1.2 and Earlier
    - https://www.rfc-editor.org/rfc/rfc4492#section-6
    - https://blog.cryptographyengineering.com/2017/12/19/the-strange-story-of-extended-random/
    - https://en.wikipedia.org/wiki/Bullrun_(decryption_program)
    - https://en.wikipedia.org/wiki/BSAFE
    - https://sockpuppet.org/blog/2015/08/04/is-extended-random-malicious/


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    Cruel Summer: hybrid signatures, Downfall, Zenbleed, 2G downgrades Sep 13, 2023
    Show notes

    We're back from our summer vacation! We're covering a bunch of stuff we saw and did:
    Transcript:
    https://securitycryptographywhatever.com/2023/09/13/cruel-summer/
    Links:
    - Zenbleed: https://lock.cmpxchg8b.com/zenbleed.html
    - Downfall: https://downfall.page
    - Post-quantum Yubikeys: https://security.googleblog.com/2023/08/toward-quantum-resilient-security-keys.html


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    Why do we think anything is secure, with Steve Weis Jun 29, 2023
    Show notes

    What does P vs NP have to do with cryptography? Why do people love and laugh about the random oracle model? What's an oracle? What do you mean factoring and discrete log don't have proofs of hardness? How does any of this cryptography stuff work, anyway? We trapped Steve Weis into answering our many questions.
    Transcript:
    https://securitycryptographywhatever.com/2023/06/29/why-do-we-think-anything-is-secure-with-steve-weis/
    Links:
    - The Random Oracle Methodology, Revisited: https://eprint.iacr.org/1998/011.pdf
    - Factoring integers with CADO-NFS: https://www.ens-lyon.fr/LIP/AriC/wp-content/uploads/2015/03/JDetrey-tutorial.pdf
    - On One-way Functions from NP-Complete Problems: https://eprint.iacr.org/2021/513.pdf
    - Seny Kamara's lecture notes on provable security: https://cs.brown.edu/~seny/2950-v/2-provablesecurity.pdf
    - How To Simulate It – A Tutorial on the Simulation Proof Technique: https://eprint.iacr.org/2016/046.pdf
    - A Survey of Leakage-Resilient Cryptography: https://eprint.iacr.org/2019/302
    - A Decade of Lattice Cryptography: https://eprint.iacr.org/2015/939.pdf


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    Elon's Encrypted DMs with Matthew Garrett May 29, 2023
    Show notes

    Are Twitter’s new encrypted DMs unreadable even if you put a gun to Elon’s head? We invited Matthew Garrett on to do a deep decompiled dive into what kind of cryptography actually shipped.
    Transcript:
    https://securitycryptographywhatever.com/2023/05/29/elons-encrypted-dms-with-matthew-garrett/
    Links:
    https://mjg59.dreamwidth.org/66791.html
    https://help.twitter.com/en/using-twitter/encrypted-direct-messages
    https://www.techdirt.com/2023/05/11/twitter-launches-not-actually-encrypted-encrypted-dms/
    BrokenKDF2BytesGenerator: https://github.com/bcgit/bc-java/blob/master/prov/src/main/java/org/bouncycastle/jce/provider/BrokenKDF2BytesGenerator.java#L70
    Analysis from sweis: https://twitter.com/sweis/status/1657082478727933954?s=20
    https://signal.org/docs/specifications/x3dh/
    https://signal.org/docs/specifications/doubleratchet/
    https://support.signal.org/hc/en-us/articles/360007059752-Backup-and-Restore-Messages
    Trail of Bits has not audited nor signed a contract yet, per Platformer: https://www.platformer.news/p/why-you-cant-trust-twitters-encrypted


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    WhatsApp Key Transparency with Jasleen Malvai and Kevin Lewi May 06, 2023
    Show notes

    WhatsApp has announced they’re rolling out key transparency! Doing this at WhatsApp-scale (aka billions and biiillions of keys) is a significant task, so we talked to Jasleen Malvai and Kevin Lewi about how it works.
    Transcript:
    https://securitycryptographywhatever.com/2023/05/06/whatsapp-key-transparency
    Links:
    https://engineering.fb.com/2023/04/13/security/whatsapp-key-transparency/
    https://github.com/facebook/akd
    Parkeet: https://eprint.iacr.org/2023/081.pdf
    CONIKS: https://eprint.iacr.org/2014/1004.pdf
    SEEMless: https://eprint.iacr.org/2018/607.pdf
    WhatsApp Security Whitepaper: https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf
    Keybase key transparency: https://book.keybase.io/docs/server


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    Messaging Layer Security (MLS) with Raphael Robert Apr 22, 2023
    Show notes

    Messaging Layer Security (MLS) 1.0 is (basically) here! We invited Raphael
    Robert, coauthor of the MLS specification to explain it to us and answer our annoying questions (read: why does this exist?)
    Transcript:
    https://securitycryptographywhatever.com/2023/04/22/mls/
    Links:
    - https://messaginglayersecurity.rocks/
    - https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html
    - https://messaginglayersecurity.rocks/mls-architecture/draft-ietf-mls-architecture.html
    - https://github.com/openmls/openmls
    - https://eprint.iacr.org/2022/1533.pdf
    - https://eprint.iacr.org/2020/1327.pdf
    - https://eprint.iacr.org/2022/559.pdf
    - https://signal.org/docs/
    - https://en.wikipedia.org/wiki/Key_encapsulation_mechanism
    - https://twitter.com/beurdouche/status/1220617962182389760
    - https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html#mls-ciphersuites
    - https://www.ietf.org/archive/id/draft-ietf-mls-federation-02.html
    - https://datatracker.ietf.org/wg/mimi/documents/
    - https://competition-policy.ec.europa.eu/dma/dma-workshops/interoperability-workshop_en
    - Yes in the protocol document this is 1.0: https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html#section-6


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    Real World: Crypto (2023) Mar 24, 2023
    Show notes

    Real World Cryptography 2023 is happening any moment now in Tokyo. Also, some phone basebands are broken.
    Links

    • https://rwc.iacr.org/2023/
    • https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html


    Transcript: https://securitycryptographywhatever.com/2023/03/24/rwc-2023/


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    Threema with Kenny Paterson, Matteo Scarlata and Kien Tuong Truong Jan 27, 2023
    Show notes

    Another day, another ostensibly secure messenger that quails under the gaze of some intrepid cryptographers. This time, it's Threema, and the gaze belongs to Kenny Paterson, Matteo Scarlata, and Kien Tuong Truong from ETH Zurich. Get ready for some stunt cryptography, like 2 Fast 2 Furious stunts.
    Transcript:
    https://securitycryptographywhatever.com/2023/01/27/threema/

    Links:
    https://breakingthe3ma.app/
    https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf
    https://threema.ch/en/blog/posts/ibex


    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)


    Previous 1 2 3 4 5 6 7 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights