An essay on CAs revoking Windows code-signing certs for malware, and why PKI was never meant to be a software cop.
trending24
01 02 France’s ANSSI makes PQC a certification gate, so legacy encryption now has an expiry date instead of a roadmap.03 Blockstream's Q2 2026 update on PQ Bitcoin, Jade, Liquid, and Lightning, because apparently the quarter had a theme.04 zk.golf turns circuit golf into a competition, with Lean proofs and a Clean-based submission pipeline.05 Blockstream's Simplicity site relaunch, with Liquid mainnet status, proof-before-deployment notes, and contract examples.06 zkNews drops the invite wall, so the ZK crowd can submit links, argue, and upvote in public like it's 2009.07 How did cops pwn EncroChat, and what does that do to your Android update-signing threat model?08 Announcing the Monetization Gateway: charge for any resource behind Cloudflare via x402 blog.cloudflare.comCloudflare's Monetization Gateway bolts x402 onto the edge, so your APIs, pages, and MCP tools can start charging rent.09 Deep dive on Windows revocation providers and trust validation, for when CRL/OCSP's good enough is apparently not.10 Ethereum Foundation’s institutional primer, selling credibly neutral settlement as the thing most chains still can’t fake.11 Threat models are mostly where security arguments go to die, and this guide tries to keep them attached to the system.12 Cloudflare walks through EO 14412's PQC deadlines, then reminds everyone that crypto agility is now mandatory.13 Which wasm runtime actually runs libsodium fastest in 2026, and how much do wide_arithmetic, SIMD, and AOT matter?14 Want a searchable MPC bug tracker and pitfall taxonomy, or just a nicer UI for old implementation mistakes?15 Ethereum Foundation reorganizes into 7 clusters, with privacy, zkEVM, and post-quantum security now on the org chart.16 Blockstream uses the Orchard bug to argue that public supply checks shrink the damage from zk circuit bugs, unlike fully shielded coins.17 The annoying bit was an implicit carry bound, and they proved a Plonky2 U32AddManyGate in Lean after exporting Rust constraints.18 Xiaomi's MJA1 secure chip gets probed via I2C sniffing, flash dumps, and firmware RE, with its command/CRC scheme reconstructed.19 Rust crate ed25519-wasm ports lib25519 to WASM, with Wasmtime benchmarks showing Ed25519 still beats the usual crypto tax.20 Quantum canaries are just stealthy on-chain booby traps, and this post shows Bitcoin Taproot and Ethereum variants.21 Cloudflare's DMARC manager goes GA with IP-level source tracing and SPF limit surfacing, so mail auth fails less mysteriously.22 Hardness of hinted ISIS from the space-time hardness of lattice problems martinralbrecht.wordpress.comSpace-time lattice hardness nails hinted ISIS, so a fast solver would imply poly-memory, single-exponential attacks on classic lattices.23 Scaling Security Insights: how we achieved a 10x increase in global scanning capacity blog.cloudflare.comCloudflare takes Security Insights scans from 10/s to 120/s by reworking Kafka, Postgres writes, and rate limiting.24 RSA keys with periodic zero-bit gaps get factored via polynomials, and the culprit bug was in CompleteFTP.