Cedarcrypt 2026 - Applied Cryptography Summer School & Conference
Join us for four days of applied cryptography in the Mediterranean. July 13-16, 2026 at AUB Mediterraneo Campus, Paphos, Cyprus.
Come be part of Cedarcrypt, our historic new initiative to grow cryptography research, development and representation in the Levant region!
We're seeking speakers and workshop leaders: our call for submissions is open! Learn more: cedarcrypt.org
Please spread the word!
03.02.2026 14:20
👍 10
🔁 7
💬 0
📌 1
The Russian way of war is not working either. Maybe it's war that is the problem?
10.03.2026 13:38
👍 47
🔁 8
💬 1
📌 1
Abstract. Signal is a secure messaging app offering end-to-end security for pairwise and group communications. It has tens of millions of users, and has heavily influenced the design of other secure messaging apps (including WhatsApp). Signal has been heavily analysed and, as a result, is rightly regarded as setting the “gold standard” for messaging apps by the scientific community. We present two practical attacks that break the integrity properties of Signal in its advertised threat model. Each attack arises from different features of Signal that are poorly documented and have eluded formal security analyses. The first attack, affecting Android and Desktop, arises from Signal’s introduction of identities based on usernames (instead of phone numbers) in early 2022. We show that the protocol for resolving identities based on usernames and on phone numbers introduced a vulnerability that allows a malicious server to inject arbitrary messages into one-to-one conversations under specific circumstances. The injection causes a user-visible alert about a change of safety numbers, but if the users compare their safety numbers, they will be correct. The second attack is even more severe. It arises from Signal’s Sealed Sender (SSS) feature, designed to allow sender identities to be hidden. We show that a combination of two errors in the SSS implementation in Android allows a malicious server to inject arbitrary messages into both one-to-one and group conversations. The errors relate to missing key checks and the loss of context when cryptographic processing is distributed across multiple software components. The attack is undetectable by users and can be mounted at any time, without any preconditions. As far as we can tell, the vulnerability has been present since the introduction of SSS in 2018. We disclosed both attacks to Signal. The vulnerabilities were promptly acknowledged and patched: the first vulnerability was fixed two days after disclosure, while the second one was patched after eight days. Beyond presenting these devastating attacks on Signal’s end-to-end security guarantees, we discuss more broadly what can be learned about the challenges of deploying new security features in complex software projects.
Image showing part 2 of abstract.
Signal Lost (Integrity): The Signal App is More than the Sum of its Protocols (Kien Tuong Truong, Noemi Terzo, Kenneth G. Paterson) ia.cr/2026/484
09.03.2026 01:23
👍 24
🔁 13
💬 0
📌 1
Was thinking that the famous scene in Downfall is exactly how I expect “the end” for the current bloke being played.
06.03.2026 09:30
👍 0
🔁 0
💬 0
📌 0
IP66 — Free IP Geolocation Database
A free, open IP Geolocation database in MMDB format. Includes ASN, country, and continent data. Updated daily. Licensed under CC BY 4.0.
IP66: an MMDB-compatible IP Geolocation Database with ASN, country, and continent data. Free to use, no license keys required, updated every day. #Network ip66.dev
06.03.2026 08:05
👍 2
🔁 2
💬 0
📌 0
Thought I'd sahre the Swiss Cyber Security starter pack again.
Am I missing somebody?
go.bsky.app/4xD359p
06.03.2026 08:38
👍 4
🔁 2
💬 0
📌 0
holy fuckin shit lmao
a supply chain attack perpetrated by a prompt injection in a github ISSUE TITLE
eh. coding agents? what could go wrong
06.03.2026 05:11
👍 380
🔁 97
💬 12
📌 2
You don’t follow it if the Boss says otherwise, I suspect.
04.03.2026 15:12
👍 1
🔁 0
💬 0
📌 0
"watch the Pasdaran walk into the US bases" kind of show?
04.03.2026 10:31
👍 1
🔁 0
💬 1
📌 0
inevitably, Alexander was not your run off the mill bloke, was he?
03.03.2026 09:22
👍 1
🔁 0
💬 0
📌 0
Well, Alexander the Great did manage to successfully put feet on the ground in Persia.
03.03.2026 09:11
👍 2
🔁 0
💬 1
📌 0
Epic Slurry?
03.03.2026 08:43
👍 1
🔁 0
💬 0
📌 0
good morning everyone project your personal imposter syndrome onto this gif ur welcome
03.03.2026 08:08
👍 135
🔁 35
💬 5
📌 3
I can't remember the name of the op any longer, is it Epic Fail?
03.03.2026 08:19
👍 3
🔁 0
💬 1
📌 0
Disappearance of Emanuela Orlandi - Wikipedia
oh, I also forgot about the Emanuela Orlandi story which is, probably, an ante-litteram Epstein in Vatican sauce¹. But, having said this, it would have been covered by the previous keywords. Objectively, the Vatican has a millennial history of power…
__
¹ en.wikipedia.org/wiki/Disappe...
03.03.2026 08:18
👍 1
🔁 0
💬 0
📌 0
Oh don’t start with the Swiss Guard murders… there’s a whole web of intrigue there. Some keywords: P2, Card. Marcinkus, Banda della Magliana, IOR, Enimont, etc.
03.03.2026 06:41
👍 2
🔁 0
💬 1
📌 0
I'm saddened to see that literally nothing has changed in 30 years since I was making the same remarks on Usenet.
02.03.2026 19:47
👍 2
🔁 0
💬 1
📌 0
"The power of accurate observation is commonly called cynicism by those who have not got it."
— George Bernard Shaw (1856–1950)
23.02.2026 13:24
👍 28
🔁 9
💬 0
📌 0
The normalisation of war is the saddest part in all of this…
02.03.2026 12:56
👍 2
🔁 0
💬 0
📌 0
Lands of Packets
TTL exceeded.
I would like to collect texts from the scene about FX in his memory. A collection of obituaries that will then be posted on phenoelit.de.
If anyone would like to contribute, please contact me.
Mail: joernchen@phenoelit.de
Signal: jrn.07
02.03.2026 08:32
👍 15
🔁 7
💬 0
📌 0
tcpdump(8) - OpenBSD manual pages
I was reminded today that you can use OpenBSD tcpdump(8) as a quick and dirty firewall.
# tcpdump -B drop -i em0 udp and port 69
This drop packets completely in the network interfaces interrupt handler!
02.03.2026 05:15
👍 6
🔁 5
💬 1
📌 1
RIP FX - You are a legend
02.03.2026 05:03
👍 56
🔁 25
💬 6
📌 2
As much as I hate saying it: “better the Devil you know.” I sincerely hope this is for the best but recent history has sadly shown otherwise.
01.03.2026 09:01
👍 1
🔁 0
💬 0
📌 0
somewhere it turns on the fans to max and bricks the machine?
28.02.2026 10:56
👍 0
🔁 0
💬 0
📌 0
The FIFA peace prize was a mockery to begin with…
28.02.2026 10:24
👍 2
🔁 0
💬 0
📌 0
taking out all potential replacements for current regime who are not liked?
28.02.2026 10:15
👍 0
🔁 0
💬 0
📌 0