Nick Sullivan's Avatar

Nick Sullivan

@nicksullivan.org

Asymmetries in action

862
Followers
873
Following
75
Posts
27.05.2023
Joined
Posts Following

Latest posts by Nick Sullivan @nicksullivan.org

Preview
Encrypted Client Hello: Closing the SNI Metadata Gap Referencesent-deployment-and-adoption" href="#current-deployment-and-adoption" class="toc-anchor">Current Deployment and Adoptionor">Trial by Firewall-security-systems" href="#adapting-network-securit...

Encrypted Client Hello is now RFC 9849

This RFC defines an extension to Transport Layer Security that improves privacy for web users. Huge team effort and a win for the internet at large. Now to get deployment up...

Some words I wrote about this for @cdt.org: cdt.org/insights/enc...

04.03.2026 14:47 πŸ‘ 29 πŸ” 9 πŸ’¬ 0 πŸ“Œ 2
CryptoJobs - Cryptography Career Opportunities The definitive job board for cryptography professionals. Find opportunities in post-quantum cryptography, zero-knowledge proofs, HSM, TLS/PKI, and applied cryptographic research.

I put together a job site for cryptography roles. It's in alpha, so please send me your bugs!

jobs.cryptography.consulting

01.03.2026 14:37 πŸ‘ 12 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
USENIX Security '26 Enigma Track Call for Participation USENIX Security brings together researchers, practitioners, system programmers, and others to share and explore the latest advances in the security and privacy of computer systems and networks.

USENIX Enigma has published its CFP for 2026: www.usenix.org/conference/u...

Submissions are due March 31, 2026. Looking forward to seeing many of you this year.

27.01.2026 23:12 πŸ‘ 1 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

I’m happy to be joining the USENIX Security ’26 Enigma organizing committee this year, after having the chance to speak at Enigma three times. It has a long history as a home for early, practice-driven security ideas, often where work first gets aired before it’s fully polished or widely deployed.

27.01.2026 23:12 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Software has eaten the world. Banks, hospitals, power grids, planes. If the ground liquefies, everything built on it sinks. We're not talking about bad code anymore. We're talking about infrastructure failure at scale.

15.01.2026 21:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Liquefaction is what happens when shaking meets saturated ground. The soil loses structure and behaves like liquid. Buildings sink. In software: unverified code + relentless velocity + strained review = a codebase that can't hold weight.

15.01.2026 21:41 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

And verification doesn't scale for free. 38% say reviewing AI code takes *more* effort than human code. Werner Vogels calls this verification debt. It compounds silently until something breaks.
πŸ”— buildwithaws.substack.com/p/werner-vog...

15.01.2026 21:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Same survey: 96% of devs don't fully trust AI output. But only 48% say they always verify before committing. That gap is where bugs live. That gap is where security dies.
πŸ”— www.sonarsource.com/company/pres...

15.01.2026 21:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
Post image

Here's where it gets uncomfortable. Devs now say ~42% of their code is AI-generated. Projected to hit 65% by 2027. The codebase is becoming porous.
πŸ”— www.sonarsource.com/company/pres...

15.01.2026 21:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

AI isn't coming; it's already in the pipes. Over 1.1M public repos now depend on an LLM SDK. Almost 700K of those appeared in the last 12 months alone. +178% YoY.
πŸ”— github.blog/news-insight...

15.01.2026 21:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Forget counting lines. Watch the flow. GitHub saw 518M pull requests merged in 2025, up 29% from the year before. That's not growth, that's a flood.
πŸ”— github.blog/news-insight...

15.01.2026 21:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Software Heritage archived over 22 billion unique source files by end of 2024. That's just public code they could find. The real number is unknowable, and growing faster than anyone can track.
πŸ”— annex.softwareheritage.org/public/annua...

15.01.2026 21:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Here's the scale we're dealing with: roughly 2.8 trillion lines of code written in the last 20 years. A huge chunk of that? Just the last two. The acceleration is the story.
πŸ”— medium.com/modern-stack...

15.01.2026 21:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

AI coding is an earthquake for software security. Not a tremor. The kind that liquefies the ground beneath your feet. We're mid-shake and most people are still debating if it's real.
πŸ”— github.blog/news-insight...

15.01.2026 21:41 πŸ‘ 4 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
RWC 2026 registration Real World Crypto Symposium

Registration for Real World Crypto 2026 is now open! rwc.iacr.org/2026/registr...

09.01.2026 13:32 πŸ‘ 8 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Preview
Mailing List Subscribe Made with Tally, the simplest way to create forms.

Also, sign up for my upcoming mailing list! Occasional, high-signal updates: tally.so/r/2EBz4D

09.01.2026 17:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

News! I’ll be joining the Internet Architecture Board(IAB) starting March 2026 at IETF 125 in Shenzhen(I’ll be participating remotely).

The IAB is part of the IETF ecosystem. It looks across Internet protocol work to provide architecture-level oversight and help keep the standards process healthy.

09.01.2026 17:17 πŸ‘ 5 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Embedding Human Rights in Technical Standard-Setting: Institutional Change and Governance Standards engineers discussing support for human rights in technical standards This July, just before a week of meetings on internet protocol details in Madrid, CDT invited a group of engineers β€” leaders from industry and civil society and participants in the Internet Engineering Task Force and World Wide Web Consortium β€” to a workshop organized […]

CDT’s @npdoty.techpolicy.social.ap.brid.gy and Visiting Fellow @nicksullivan.org joined a UN OHCHR workshop in Madrid with engineers, industry, and civil society to explore how technical standards affect internet users’ human rights. Read their recap of the event:

18.12.2025 17:30 πŸ‘ 4 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Post image

At #IETF124 in MontrΓ©al @ietf.org last month I gave a talk about Measuring & Understanding ECH deployments as @ooni.org.

ECH is becoming a Frontline for whether the Internet remains Open, Private, and Resilient.

We need to Document Censorship, to Protect our Internet.

πŸ“Ή youtu.be/OmBNQKZtO3Q

09.12.2025 09:09 πŸ‘ 3 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0

The β€œcosmic-ray bit-flip” thing actually being real and serious enough to recall every A320 on the planet was not on my 2025 bingo card.

30.11.2025 13:37 πŸ‘ 7 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
A small number of samples can poison LLMs of any size Anthropic research on data-poisoning attacks in large language models

This is an obvious but important result, but I'm not a fan of this characterization of poisoning as an attack. There are legitimate reasons to poison, especially if you consider an AI company to be the malicious party rather than the victim.

www.anthropic.com/research/sma...

17.11.2025 14:12 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Trello Organize anything, together. Trello is a collaboration tool that organizes your projects into boards. In one glance, know what's being worked on, who's working on what, and where something is in a pro...

Session 2 of the ARMOR side meeting starts today at 4 PM EST. We’ll be digging into next steps and shaping where this work goes next.

Agenda: trello.com/c/p4fjRkcl
Slides: github.com/grittygrease...
Join the list: mailman3.irtf.org/mailman3/lis...

06.11.2025 17:07 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

The first ARMOR meeting was a success with 4 great presentations on different aspects of real-world protocol resilience by @vinifortuna.com , Brien Colwell, @distributeddave.bsky.social , and @hellais.bsky.social.

06.11.2025 17:06 πŸ‘ 5 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Preview
Encrypted Client Hello: Closing the SNI Metadata Gap Referencesent-deployment-and-adoption" href="#current-deployment-and-adoption" class="toc-anchor">Current Deployment and Adoptionor">Trial by Firewall-security-systems" href="#adapting-network-security-systems" class="toc-anchor">Adapting Network Security Systemsy-sni-became-the-last-privacy-gap" class="toc-anchor">Why SNI Became the Last Privacy Gapre-metadata-leaks" class="toc-anchor">Background: Where Metadata Leakste, whether governments like it or not. Encrypted Client Hello (ECH) is nearing final IETF standardization [1]. It closes the last remaining metadata leak in HTTPS connections by encrypting the Server Name […]

New guest post from CDT Visiting Fellow & IETF expert @nicksullivan.org: Encrypted Client Hello (ECH) closes the final major privacy gap in HTTPS by encrypting the Server Name Indication (SNI) β€” a milestone for online privacy. 🌐 Read more:

23.10.2025 15:46 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Global Encryption Day 2025 – Global Encryption Coalition Join us on 21 October 2025 for the 5th-annual Global Encryption Day!

Today is Global Encryption Day hosted by Global Encryption Coalition.

Check it out here: www.globalencryption.org/2025/07/glob...

21.10.2025 18:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Paris - participate - SplinterCon December 8-10, 2025 For guests Everyone interested in attending SplinterCon Paris as a guest should apply through the form below. Due to limited capacity and ambition to keep the meeting…

The SplinterCon conference about the splintering Internet is coming up in Paris early December and has opened its call for presentations. It’s a great venue for early ideas in security, networking, and cryptography. Deadline: Oct 31, 2025. Apply here: splintercon.net/paris-partic...

21.10.2025 18:54 πŸ‘ 1 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Honored to be nominated for the Internet Architecture Board (IAB) for 2026–27. The IAB sets the Internet’s long-term technical direction and oversees the RFC Series and the IETF/IRTF. Feedback to the nominating committee is welcome: datatracker.ietf.org/nomcom/2025/..., I'd appreciate it!

21.10.2025 18:48 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
IETF 124 Meeting Agenda

At IETF124, the CFRG (where I co-chair) is testing a new session format: the first slot for new work and informational presentations, the second for consensus and advancing drafts. MLS (secure messaging) is also finalizing its extensions framework.
Full Agenda: datatracker.ietf.org/meeting/124/...

21.10.2025 18:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Encrypted Client Hello: Closing the SNI Metadata Gap Referencesent-deployment-and-adoption" href="#current-deployment-and-adoption" class="toc-anchor">Current Deployment and Adoptionor">Trial by Firewall-security-systems" href="#adapting-network-securit...

My new explainer with @cdt.org covers how ECH closes one of the last major metadata gaps in HTTPS by making hostnames private. It’s been approved as an Internet Standard and is close to getting an RFC number: cdt.org/insights/enc...

21.10.2025 18:45 πŸ‘ 2 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Trello Organize anything, together. Trello is a collaboration tool that organizes your projects into boards. In one glance, know what's being worked on, who's working on what, and where something is in a pro...

We are hosting a side meeting for the ARMOR mailing list on Nov 3 at 19:00 EST (Duluth Room). We’ll be discussing how to make network protocols resilient in adversarial environments. Remote attendance welcome via WebEx: trello.com/c/8hhaa23A

21.10.2025 18:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0