Advertisement · 728 × 90

Posts by Raphael Robert

You can now reply to messages in Air

3 weeks ago 4 0 0 0
Preview
Cryptographic Issues in Matrix’s Rust Library Vodozemac - Dhole Moments Two years ago, I glanced at Matrix’s Olm library and immediately found several side-channel vulnerabilities. After dragging their feet for 90 days, they ended up not bothering to fix any of i…

soatok.blog/2026/02/17/c... #Matrix #security #cryptography

2 months ago 63 36 5 2
Invitation cards in front of a notebook with a MLS sticker.

AIR
• No phone number or email
• End-to-end encrypted
• No metadata retention
• Open-source
• Post-quantum secure
• Based on Messaging Layer Security (MLS) and open standards
• EU-based

Invitation cards in front of a notebook with a MLS sticker. AIR • No phone number or email • End-to-end encrypted • No metadata retention • Open-source • Post-quantum secure • Based on Messaging Layer Security (MLS) and open standards • EU-based

We will be at #FOSDEM and will bring something exciting: Invitation codes for the beta phase of @air.ms, our new secure messenger based on MLS! ✨

Hit @julianmair.com up if you’d like to join the beta with your friends.

2 months ago 20 2 0 3
Invitation cards in front of the ALL CREATURES WELCOME banner

AIR
• No phone number or email
• End-to-end encrypted
• No metadata retention
• Open-source
• Post-quantum secure
• Based on Messaging
Layer Security (MLS) and open standards
• EU-based

Invitation cards in front of the ALL CREATURES WELCOME banner AIR • No phone number or email • End-to-end encrypted • No metadata retention • Open-source • Post-quantum secure • Based on Messaging Layer Security (MLS) and open standards • EU-based

We will be at #39C3 and we brought something exciting: Invitation codes for the beta phase of Air, our new secure messenger based on MLS! ✨

Hit us up if you’d like to join the beta with your friends.

You can also follow @air.ms, where we’ll post updates over time.

3 months ago 30 11 6 2

I think it's a different set of tradeoffs (as is always the case in decentralized environments). So the short answer would be: yes.

5 months ago 1 0 1 0
Preview
Making MLS more decentralized It’s no secret that we at Phoenix R&D are big fans of the Messaging Layer Security (MLS) protocol, having helped it to come into existence. It’s a versatile group key agreement and messaging protocol ...

We made MLS more decentralized! We are excited to share DMLS that brings fork resilience to the MLS protocol, solving a key challenge in distributed systems while maintaining Forward Secrecy.

This work was made possible by @equalitie.bsky.social, who funded it as part of the Breakout program.

5 months ago 32 12 2 1
Preview
EU-Überwachungspläne in der Kritik: Wirtschaftsverbände Bitkom und eco klar gegen Chatkontrolle Die Stimmen gegen die Chatkontrolle werden mehr und lauter. Nun hagelt es deutliche Kritik aus der Wirtschaft. Zudem warnen der Deutsche Journalistenverband und der Anwaltverein vor einer Überwachungs...

Die Stimmen gegen die #Chatkontrolle werden mehr und lauter. Nun hagelt es deutliche Kritik aus der Wirtschaft. Zudem warnen der Deutsche Journalistenverband und der Anwaltverein vor einer Überwachungsinfrastruktur, die schnell ausgebaut werden könnte.

netzpolitik.org/2025/eu-uebe...

6 months ago 300 155 5 5
Preview
Unser Brandbrief zur geplanten Chatkontrolle – eine Gefährdung der digitalen Sicherheit Deutschlands | Phoenix R&D 🚨Der Gesetzentwurf zur #Chatkontrolle sieht vor, dass digitale Kommunikation einschließlich verschlüsselter Nachrichten und Fotos gescannt werden soll.  Die Sicherheit von sicheren Messenger-Diensten ...

🚨 Der Gesetzentwurf zur #Chatkontrolle sieht vor, dass digitale Kommunikation einschließlich verschlüsselter Nachrichten und Fotos gescannt werden soll.

Wir haben uns an die deutsche Bundesregierung gewandt, sich am 14. Oktober gegen den Gesetzesvorschlag der Chatkontrolle auszusprechen.

6 months ago 4 2 0 1
Advertisement
Post image

LinkedIn annonced that it will use your data to train AI models, and craftily chose to use an opt-out mechanism. Deactivate this in your settings now, of you don’t want to give away your content.

7 months ago 1 0 0 0
Preview
Ex-WhatsApp cybersecurity head says Meta endangered billions of users in new suit Attaullah Baig, fired this year, said he had warned Mark Zuckerberg engineers had unaudited access to user data

As an ex head of security of an end-to-end encrypting messenger I can relate

www.theguardian.com/technology/2...

7 months ago 4 0 0 0

Yes. E2EE would be undermined in one way or another.

7 months ago 1 0 0 0
MLS: The Naked King of End-to-End Encryption Evgeny Poberezkin's blog

There's an article making the rounds with the provocative title "MLS: The Naked King of End-to-End Encryption". It needs some rebuttal.

www.poberezkin.com/posts/2025-0...

tl;dr - MLS is fine. This is a misunderstanding about modularity.

7 months ago 14 4 1 2
Preview
Barking Up The Ratchet Tree – MLS Is Neither Royal Nor Nude - Dhole Moments One of the first rules you learn about technical writing is, “Know your audience.” But often, this sort of advice is given without sufficient weight or practical examples. Instead, you&…

Not long ago, someone (who is likely the founder of SimpleX Chat) wrote a blog post about MLS that contained a pretty blatant factual mistake about MLS' authentication, including an alleged lack of security. Thankfully, @soatok.bsky.social took the time to debunk that: soatok.blog/2025/08/25/b...

7 months ago 10 2 0 0
Post image

I had to see for myself

8 months ago 1 0 1 0
Preview
Combining TLS and MLS: An experiment We did a thing. We combined TLS and MLS into a hybrid protocol. Of course, when things get serious, full names are in order: We combined the Transport Layer Security protocol and the Messaging Layer S...

We did a thing. We combined TLS and MLS into a hybrid protocol.

Why? Because sometimes you need connections that last for weeks, quantum-resistant security, or simpler certificates.

The experiment is open-source. Here's the story 👇

9 months ago 5 4 0 2
Advertisement

We really did do a thing.

9 months ago 2 0 0 0
Preview
Phoenix R&D (Remote): Freelance Junior Product Manager (all genders, part-time) Phoenix R&D GmbH has a remote job opening for Freelance Junior Product Manager (all genders, part-time) (published: 15.05.2025). Apply now or check the other available jobs.

We are #hiring a Freelance Junior Product Manager to help us build the next generation of private & secure messaging.

If you’re interested in joining our team, please apply today!
For friends of secure messaging 🥷, please share our post with potential candidates.

11 months ago 5 5 0 0
Post image

Happy to announce that I’ll be speaking at @passthesaltcon.bsky.social on July 2nd!

I’ll discuss end-to-end encryption with MLS, the growing MLS ecosystem, the MIMI IETF working group, and metadata protection.
It’s my first time attending, and I look forward to connecting with the French community!

11 months ago 2 2 0 0

The idea that you can just “teach computer science” and be apolitical is a beautiful dream that expired in the 2000s, at the latest. Computer science has re-organized every facet of our society: it is inherently political. Instead of taking this idea seriously, we ran from it. Now we live in hell.

11 months ago 239 59 5 8

It's an informational draft, so I think it cannot use normative language, but adding @mallory.techpolicy.social.ap.brid.gy and @claucece.bsky.social who actually wrote this.

11 months ago 1 0 0 0
Definition of End-to-end Encryption This document provides a definition of end-to-end encryption (E2EE) from both the perspective of a regular internet user as well as from the perspective of required properties for implementers.

There has been an attempt by Knodel et al to have a more rigorous definition over at the IETF: www.ietf.org/archive/id/d...

11 months ago 1 0 1 0
Preview
Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages A photograph of Trump administration official Mike Waltz's phone shows him using an unofficial version of Signal designed to archive messages during a cabinet meeting.

www.404media.co/mike-waltz-a...

11 months ago 150 42 2 1
Post image

Hey Google designers, are we sure about this new layout logo in Google Meet?

The negative space around the boxes reminds me of something.

11 months ago 0 0 0 0
Information on RFC 9750 » RFC Editor

The MLS Architecture document – the companion document to the MLS Protocol document – is now finally available as RFC 9750:

www.rfc-editor.org/info/rfc9750

11 months ago 7 2 0 0
Advertisement
Post image

And so it begins, BlueSky complies with censorship requests of an authoritarian regime

1 year ago 2 1 0 0
Preview
The Dangers of End-to-End Encryption Privacy Guides is formally taking a stand against dangerous and frightening technologies.

www.privacyguides.org/articles/202...

1 year ago 2 0 1 0

This might indeed be interesting to inform decisions about the frequency of commits. Our DS design is pretty set already, but it would be interesting to compare the details.

1 year ago 1 0 1 0

MLS is efficient, but what does that mean in practice?

This paper sheds some light on the question by building a test framework for OpenMLS.

arxiv.org/pdf/2502.18303

1 year ago 5 4 1 0

… and now it looks like Apple caved, while Google didn’t: www.forbes.com/sites/zakdof...

1 year ago 0 0 0 0

The SCW podcast team does it again and breaks down a newish, complex and alarming topic into palatable and informative pieces. Excellent questions from @durumcrustulum.com and @dadrian.io expertly answered by @josephhall.org and @matthewdgreen.bsky.social.

Listen to it if you have time!

1 year ago 10 6 0 0