Interview/profile of Claude Crépeau by Bill Buchanan, a tour of crypto history with the usual amount of deserved reverence.
trending30
01 02 ECB tells banks to inventory crypto and get post-quantum ready, with AI cyber threats as the warm-up act.03 Docs hub for the EU Digital Identity Wallet ARF, with architecture, trust model, annexes, and the usual privacy/ZK footnotes.04 Report on an attested TLS relay flaw hitting WhatsApp and Cocos AI, proof that handshakes still cosplay as security.05 Can an LLM write EasyCrypt proofs, and this repo ships the MCP workflow, benchmarks, and replay logs to find out.06 Need a machine-checked PCS spec and KZG proofs in Isabelle, or just the games and assumptions? This AFP entry has both.07 The hard part isn’t PQC, it’s finding every stray RSA/ECC dependency before the migration spreadsheet explodes.08 FIPS 140 freezes the crypto stack in amber, so you inherit old, opaque code and the bugs in its HSM plumbing.09 Attested TLS Was Supposed to Be the Last Trust Boundary. It Isn't. Formal Methods Show How. hackernoon.comProVerif finds CVE-2026-33697, a relay attack that breaks attested TLS binding, so the last trust boundary wasn't.10 NIST trims the post-quantum signature zoo to 9 Round 3 survivors, while the code-based hopefuls get quietly kicked out.11 Why should a small business care about PQC now? An intro to harvest-now-decrypt-later, crypto-agility, and vendor checklists.12 Research prototype for EasyCrypt lemma proofs, using an MCP agent to spit out admit-free scripts and replay-check them.13 An interview with Claude Crépau, less textbook ZK history, more the quantum teleportation and MPC bits people skip.14 FIPS 140-3 paperwork stops at validation records; the real risk hides in bootloaders, vendor forks, and shipped firmware.15 [tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked? tldrsec.comSecurity newsletter issue on AI vuln hunting, GuardDog 3.0, bug bounty economics, and assorted supply-chain/RAT/jailbreak bits.16 Sony gets a conditional OCC trust charter, the latest stablecoin-friendly bank shell with the usual banking-and-commerce fuss.17 Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - MDSec mdsec.co.ukFirst char in the clear, the rest XORed with a short key, so Dell BIOS passwords fall out of SPI flash dumps.18 Reason piece on declassified FBI files about David Kahn, the crypto historian first treated like a suspect, because of course.19 First-order DPA-hardened ML-DSA on Pavona ACC, with bitsliced masking tricks and benchmarks for ML-DSA-44/65/87.20 First-order masked ML-DSA keygen/signing for Pavona ACC, reusing masked KMAC and aiming at DPA resistance?21 The Handshake That Can't Keep Its Promise: Why Confidential Computing's Flaw Changes the Data Sovereignty Conversation blogs.groupware.org.ukAttested TLS can be relayed, so confidential computing’s data sovereignty pitch takes a CVE-sized hit.22 Rejection sampling, the old side-channel workhorse, beats CDT here with fewer masked ANDs for lattice Gaussians (incl. HAWK).23 Essay argues CRQC progress is turning into classified-capability turf, so disclosure norms start looking like vulnerability ops.24 6 Years Ago, Journalists Exposed the Biggest Spy Operation You’ve Never Heard Of. It Was Buried Again the Same Day. popularmechanics.comA Swiss cipher vendor was allegedly CIA/BND-owned for decades, and the 2020 exposé got buried again almost immediately.25 26 Can remote attestation actually prove you’re talking to the TEE, or just to a relay that forwards the traffic?27 Is indistinguishability obfuscation finally the magic trustless TTP, or still a theorem with a thermal problem?28 DJB critiques the IETF's repeated TLS last call on solo ML-KEM, arguing the process and security story are both wobbly, as usual.29 MIT CSAIL profile of Srini Devadas's 2026 Eckert-Mauchly Award, with his work on secure processors, PUFs, and PAC Privacy.30 ISO finally standardizes Classic McEliece, the 1978 code-based PKE that's still faster and uglier than RSA, just harder to break.