Advertisement · 728 × 90

Posts by Diego F. Aranha

There are only two bug classes left: complexity and memory safety.

CurveBall (CVE-2020-0601)? Complexity.
BigSig (CVE-2021-43527)? Memory safety.
Log4Shell (CVE-2021-44228)? Complexity.
BlueKeep (CVE-2019-0708)? Memory safety.

Heartbleed looks like memory safety, but it's actually complexity.

5 days ago 122 17 4 0

That's how I teach it to my students as well.

5 days ago 2 0 0 0
Preview
We analyze its underlying end-to-end encryption (E2EE) protocol Letter Sealing v2 (LSv2) and show that a TLS Man-in-the-Middle (MitM) or malicious server can compromise integrity, authenticity, and confidentiality in various experimentally verified attacks.

We performed a security analysis of the LINE messenger in our latest paper, "LINE-Break: Cryptanalysis and Reverse Engineering of Letter Sealing", to appear in ACM ASIACCS’26.

Joint work with Thomas Kingo Mogensen and Adam B. Hansen @csaudk.bsky.social. Full technical details at linebreak.info

6 days ago 10 1 1 0
Post image

Impossible to disagree with a single word that Ben Rhodes (Obama era NSC official) is saying here:

1 week ago 23140 7596 469 389

I should add to this: winner of best paper award at Eurocrypt 2026!!

As a single author. During his PhD. Incredible achievement!(protip: he will graduate soon-ish 👀)

2 weeks ago 3 3 0 0

CC @janiceascari.bsky.social @rubensvalente.bsky.social @ritchieguy.bsky.social @dfaranha.bsky.social @camposmello.bsky.social @miriamleitao7.bsky.social @igorgadelham.bsky.social @dharazim.bsky.social @imont.bsky.social @shalders.bsky.social

2 weeks ago 1 1 0 0
Craptology debrisPrint Snarkive

Enjoy your April....

debrisprint.iacr.org

2 weeks ago 8 4 0 0
PhD position in Cryptanalysis

Fernando is looking for a PhD student www.iacr.org/jobs/item/4164 Fernando is excellent, you should consider applying.

1 month ago 5 4 1 0
Post image Post image

Speaker Nikolas Melissaris talks about What Is Cryptography Hiding from Itself? by Diego F. Aranha and Nikolas Melissaris.

1 month ago 9 3 0 0
Advertisement

The room gets philosophical. Cryptography & Society chaired by Nick Sullivan ( @nicksullivan.org ): what is crypto hiding from itself? Security vs. interoperability? CRA policy? Proofs that aren't enough? And Nadim Kobeissi on teaching crypto in post-crisis Lebanon. #realworldcrypto

1 month ago 8 3 1 0
Preview
Cedarcrypt 2026 - Applied Cryptography Summer School & Conference Join us for four days of applied cryptography in the Mediterranean. July 13-16, 2026 at AUB Mediterraneo Campus, Paphos, Cyprus.

Come be part of Cedarcrypt, our historic new initiative to grow cryptography research, development and representation in the Levant region!

We're seeking speakers and workshop leaders: our call for submissions is open! Learn more: cedarcrypt.org

Please spread the word!

2 months ago 11 7 0 2

So much ICE out there today in South Minneapolis. They’re prowling around harassing schools.

Stay frosty, friends

1 month ago 449 162 6 5
Preview
WhatsApp Encryption, a Lawsuit, and a Lot of Noise It’s not every day that we see mainstream media get excited about encryption apps! For that reason, the past several days have been fascinating, since we’ve been given not one but sever…

I wrote a short blog post on the WhatsApp lawsuit, or whatever it is. blog.cryptographyengineering.com/2026/02/02/w...

2 months ago 49 26 2 5
An NYT headline reads “Federal Officers Shoot Person in Minneapolis”

An NYT headline reads “Federal Officers Shoot Person in Minneapolis”

It has gotten so bad that the @nytimes.com has stopped using the passive voice to describe the violence.

2 months ago 4872 1172 60 56
Post image

Software error in continuous glucose monitors caused 736 serious injuries, and seven deaths. abbott.mediaroom.com/press-releas...

2 months ago 12 9 0 0

Bad news for other minorities, for the media, for civil society, the rule of law and democracy, too

3 months ago 1 1 0 0

Bad news for immigrants in Europe.

3 months ago 0 0 1 0
Advertisement

Come work with Peter Scholl @schollster.bsky.social and me in Aarhus!

4 months ago 4 2 0 0

If you want to impose strict deadline and word counts, enable the REBUTTAL feature in HotCRP which gives word count to authors and a system-wide deadline.

4 months ago 1 0 2 0

If you believe that smart people cannot do utterly dumb things, just look at the Eurocrypt'26 rebuttal process.

4 months ago 5 2 1 0

And started a Cryptanalysis division in the kitchen!

4 months ago 1 0 1 0
Post image

Achievement unlocked.

4 months ago 3 0 1 0
Video

Know your rights. Protect your neighbors.

New York is — and always will be — a city for all immigrants.

4 months ago 29688 7269 317 367
Post image

CRITICAL security vulnerability in a really popular web framework React server. Maximum severity (CVSS: 10.0). Unauthenticated remote code execution. May be WORMABLE. Patch immediately. This could get very nasty. Patch this, and all that depends on it (like Next.js) react.dev/blog/2025/12...

4 months ago 21 8 0 0

I think it’s pretty clear at this point that one of the main impacts of LLMs is to disrupt thinking: to make it so that far too many people never properly learn how to do it, and then to control the output so there are thoughts that people never learn how to think.

4 months ago 1795 499 32 37

The "What are the best gifts for men?" in the end is some dystopian shit.

4 months ago 0 0 1 0
Advertisement

My thoughts on the IACR election issue (since many have asked privately):

- This was an honest accident, and Moti Yung deserves being cut some slack. Yes, it’s a silly mistake, but mistakes happen.

- The IACR board reacted excellently and scheduled timely follow up elections.

Continued in thread

4 months ago 7 2 1 0

git push -f

5 months ago 0 0 0 0
Preview
Against ‘chat control’: we can’t eliminate child abuse by eliminating privacy Banning online anonymity tools like Tor won’t stop crime. It will only drive people underground and normalize government control over the internet

Against ‘chat control’: we can’t eliminate child abuse by eliminating privacy

6 months ago 65 22 3 1
Preview
a woman in a purple sweater says they are the same picture ALT: a woman in a purple sweater says they are the same picture

The “age verification” and the “human identification” problem are the same problem. It upsets me to be around people who think they’re working on the first, but don’t understand they’re actually working on the second.

6 months ago 113 32 3 3