Note showing zero-length nonces break GCM/GMAC by exposing GHASH key and enabling forgeries, because standards love footguns.
trending501
01 02 So what actually makes AI private now, local models, TEEs, federated training, or just wishful thinking?03 Minimmit, Multimmit and the New Consensus Frontier with Patrick O'Grady - ZK PODCAST zeroknowledge.fmWhat are Minimmit and Multimmit, and why does Commonware call them an anti-framework for faster consensus?04 A categorical string-diagram UC treatment that makes composition theorem proofs graphical, and quietly fixes a few standard-SUC warts.05 What does PQC readiness actually look like? Inventory, criticality tiers, pilots, vendor checks, rollback tests, roadmap.06 Paper on Unicity's aggregation layer: Radix SMTs, AIR over Plonky3, no trusted setup, and the usual millisecond claims.07 What can go wrong in QaaS? A STRIDE map for the whole pipeline, from orchestration to execution.08 Sui adds optional post-quantum signatures, ML-DSA-65 for accounts and SLH-DSA-SHA2-128s for vaults, no seed migration.09 A paper on replacing Keccak grinding in MPC-in-the-head signatures with AES, then proving the constant factor isn't folklore.10 Blockstream's SHRINCS parameter search, with size and speed tradeoffs against SLH-DSA plus a reproducible explorer.11 Paper proposes S-FoMs and a rubric to score quantum software security, quantifying what prior art mostly hand-waved.12 CryptoDaily says Sui is eyeing ML-DSA-65 for accounts and SLH-DSA for vaults, with a 2027 mainnet if reports hold.13 Distributed Monotone Policy Encryption with Stronger Security for DNFs and Threshold Policies from Lattices eprint.iacr.orgFirst statically secure distributed monotone-policy encryption from lattices, with compact DNF and threshold schemes plus equivocal DPE.14 Private Identity-based Bulletin Boards for Anonymous Messaging and Other Online Services eprint.iacr.orgPIB^3 adds private identity-based bulletin boards, basically searchable HIBE for anonymous messaging with multi-server proto.15 Turns hard-label model extraction into inner-product algebra, ditching SVD clustering and extending to max-pooling CNNs.16 The Hidden Life of Public Safety Communications Signals: A Comparative Security Analysis of TETRA, TETRAPOL, and P25 arxiv.orgPaper on TETRA/TETRAPOL/P25, showing encrypted radios still leak topology, mobility, identities, and key-management trivia.17 Draft claims a polynomial-time quantum attack on DCP, with shaky reductions to LWE and possible ML-KEM fallout.18 Can Plantard arithmetic plus a code generator make a faster verified NTT, or just a fancier proof chain?19 Categorical string diagrams for UC, with a composition theorem and a cleanup of the usual TM-era bookkeeping.20 Blockchain Empowered Trustworthy Agent Networks: Foundations, Taxonomy, and Future Directions arxiv.orgSurvey on using blockchains as a shared trust layer for open agent networks, with a 5-axis taxonomy and risk mapping.21 Combating Knowledge Corruption in Agent Systems: A Byzantine-Tolerant Secure Collaborative RAG Framework arxiv.orgSecureCollaRAG adds Byzantine tolerance and GNN credibility scoring to collaborative RAG, basically poison-resistant retriever gossip for...22 SFAFFT speeds up boolean polynomial multiplication and makes HQC arithmetic measurably less annoying across platforms.23 Preprint on sub-cubic homomorphic matrix multiplication via self-dual normal bases and Strassen-style tensor tricks, because cubic was to...24 A spec for opaque rotating refresh tokens, with server-state semantics, CAS replay checks, and 10 impls to keep honest.25 DEF CON 34 repo with slides and PoCs for bypassing thin-client FDE via boot/firmware bugs, not by cracking the crypto.26 First adaptive-input-secure multi-epoch PSU, finally moving past PSI, with uOKVS-based add/delete updates and cardinality-only leakage.27 HP ThinPro’s TPM-sealed LUKS key falls to a tweak in the unencrypted boot partition, since PCRs miss initramfs and kernel.28 The Block on Sui adding NIST post-quantum signatures for opt-in accounts, because future-proofing now ships in phases.29 [tl;dr sec] #340 - Anthropic and Meta Agents be Hackin', Agentic Incident Response Notebooks, Figma's AI Code Scanning tldrsec.comSecurity newsletter issue on agent misbehavior, marimo incident-response notebooks, Figma's AI code scanning, and assorted cloud weirdness.30 From Cyber Defense To Cyber Resilience: Implementing Post-Quantum Cryptography, Zero Trust, And AI Governance In The Quantum Era + Video undercodetesting.comSo how do you migrate to PQC, Zero Trust, and AI governance without turning ops into a compliance zoo?