Advertisement ยท 728 ร— 90

Posts by sanketh

Preview
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.

There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers.

This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.

22 hours ago 109 26 3 2
[April 2026 Update] RFC 5869 is now listed in SP 800-140D, the top-level list of official Approved SSP Generation and Establishment Methods for FIPS 140-3 purposes.1 This makes it as a whole just as Approved as SP 800-108 or SP 800-56C.

The CMVP announced its addition with the comment โ€œeven though it is technically compliant to SP 800-56C which is already listedโ€ proving it had always been FIPS 140-3 compliant.

The rest of the post is retained for historical purposes (and because if you want to be precise, you still need to figure out how to list it on your certificate), but most of you can stop reading now.

[April 2026 Update] RFC 5869 is now listed in SP 800-140D, the top-level list of official Approved SSP Generation and Establishment Methods for FIPS 140-3 purposes.1 This makes it as a whole just as Approved as SP 800-108 or SP 800-56C. The CMVP announced its addition with the comment โ€œeven though it is technically compliant to SP 800-56C which is already listedโ€ proving it had always been FIPS 140-3 compliant. The rest of the post is retained for historical purposes (and because if you want to be precise, you still need to figure out how to list it on your certificate), but most of you can stop reading now.

I had a whole post on "yes, HKDF is FIPS 140-3 compliant, actually" but now NIST just went and added it by name to the list of Approved algorithms with a change comment saying "it was always compliant, yo" (paraphrased), so yay.

words.filippo.io/fips-hkdf/

5 days ago 34 6 2 0

Alright, it's official! ๐Ÿ’ฐ

@matthewdgreen.bsky.social and I bet on what will break first, ML-KEM-768 or X25519. The loser donates to a 501(c)(3) picked by the winner.

If you have an opinion on quantum computers or lattices, you can join with a side bet. Just submit a PR!

github.com/FiloSottile/...

1 week ago 117 29 7 2

Look I canโ€™t help that one of my hobbies is โ€œreading PDFsโ€

8 months ago 44 2 1 0
AI Finds Vulns You Can't With Nicholas Carlini
AI Finds Vulns You Can't With Nicholas Carlini YouTube video by Security Cryptography Whatever

NEW EPISODE!

The gang learns a bitter lesson about AI and bug finding! Returning champion Nicholas Carlini is back to talk about Claude for vulnerability research.

securitycryptographywhatever.com/2026/03/25/a...
www.youtube.com/watch?v=_IDb...

3 weeks ago 10 4 2 0

LIVE FROM TAIPEI, IT'S REAL WORLD CRYPTO!

#realworldcrypto

1 month ago 67 15 5 3
Airplane window photo of a bright blue jet engine in flight with a small safety sticker showing a crossed-out male restroom-style icon.

Airplane window photo of a bright blue jet engine in flight with a small safety sticker showing a crossed-out male restroom-style icon.

Engine safety rule: no men

1 month ago 1 1 0 0

Oh noooooooooooo ๐Ÿซ 

1 month ago 1 0 1 0
Preview
det-keygen: add RSA deterministic key generation by FiloSottile ยท Pull Request #197 ยท C2SP/C2SP Community Cryptography Specification Project. Contribute to C2SP/C2SP development by creating an account on GitHub.

I have written self-tests for the Python test generator and added tests to the Go tests.

Folks, I can confirm we got all the edge cases! ๐Ÿ’ฅ ๐Ÿฅณ

Thank you so much to everyone who contributed to the > 8,500(!) cores. I would like to credit you, so either reply or DM me your name/handle, if you'd like.

3 months ago 38 6 3 0
Advertisement
3 months ago 1 0 0 0

people are always talking about a hypothetical technologically advanced alien race ... but I always wonder, if they exist, do they also have to deal with PKI?

2 years ago 9 3 0 0

look at the size of this bun ๐Ÿ‡ just learned they can get this big (and larger)

6 months ago 20 5 0 0
6 months ago 1 0 0 0

With Tom Lehrer's passing, I suppose this is a moment to share the story of the prank he played on the National Security Agency, and how it went undiscovered for nearly 60 years.

8 months ago 8649 3611 143 715

Tom Lehrer wasn't just a satirist or a musician.

He as a comedian who could quietly tell a joke and wait more than SIXTY YEARS for the payoff.

That's dedication to craft.

We lost an icon.

8 months ago 3913 283 56 21

In 2022, a local #alamtg activist named Rasheed Shabazz was asking around on twitter about digitizing meeting minutes and monthly reports from local organizations as part of his ongoing research into the racial history of Alameda.

1/n

11 months ago 5 6 1 1

quantum agile >> quantum waterfall

1 year ago 1 0 1 0

quantum random artificial intelligence cryptanalysis

1 year ago 0 0 0 1

artificial quantum random intelligence

1 year ago 2 0 1 1
Advertisement

I was literally spinning up LA County as the fires started, and it just finished and pushed today.

We'd love someone to dig into fire prevention and land use policy around what happened here

1 year ago 4 1 0 0

๐Ÿž๐Ÿž๐Ÿž๐Ÿฅบ

1 year ago 1 0 0 0
Preview
Discover Rochester, NY Explore Rochester's wide ranging culinary scene, festivals, shopping, family friendly attractions, comfortable hotels and more. You are sure to find something to love!

Quick reminder: the Queer in Cryptography conference is being held 6-7 March, 2025, in Rochester! Come for the conference Thursday and Friday, stay for the fantastic city of Rochester!

cryptography.lgbt

visitrochester.com

1 year ago 4 6 0 0

ruuuuuuude

1 year ago 1 0 0 0

Galaxy Brain is excited to announce that we are partnering with @techtonica.bsky.social, a US-based nonprofit helping women and nonbinary adults seeking economic empowerment overcome barriers to technical careers.

1 year ago 3 3 1 0

My absolutely lukewarm take of the day is that more organizations should hire librarians

1 year ago 6 3 0 0

Okay, so: the other day I wrote a thread on "you should have rules that ban off-platform harassment". Well, given the latest thread from @safety.bsky.app, I wanted to do a short follow-up to that to talk in more detail about *why* you need policies like that.

bsky.app/profile/andr...

1 year ago 26 10 1 2

*designing cryptographic protocols* yeah nah, feeling pretty chill, gonna get cozy and figure out how to structure this key tree

*trying to parse a QR code from a webcam* what the fuck is this black magic, how do people do this

1 year ago 35 3 2 1
A chart of quantum computing comparing number of qubits to error rate. This is a very visual chart and is better explained in text on my website.

A chart of quantum computing comparing number of qubits to error rate. This is a very visual chart and is better explained in text on my website.

2024 update for my chart on the landscape of quantum computing: sam-jaques.appspot.com/quantum_land...

Not much visible on the chart, but Google's result (the one with the recent press attention) is a pretty big deal

1 year ago 39 15 2 1
Advertisement

the talk went well. โœจ

1 year ago 3 0 0 0

Argh, I am fully awake at 7:00am. ๐Ÿ˜

If you are at #asiacrypt2024, please come to my talk at 9:00am in Track 2 on "Robust AE With Committing Security" (w/ Viet Tung Hoang). If you are a keener and want to read the paper first: eprint.iacr.org/2024/1542

1 year ago 5 1 2 0