Advertisement · 728 × 90

Posts by Simon Fell

Preview
X is now offering me end-to-end encrypted chat — you probably shouldn't trust it yet | TechCrunch X's new encrypted messaging feature, XChat, has some red flags.

techcrunch.com/2025/09/05/x... shouldn't surprise anyone but quotes me so it's obviously good

7 months ago 20 4 0 0
2 images from hackers as characters converse. "I've got a record. I was Zero Cool." "Zero Cool crashed 1.507 systems in one day, biggest crash in history. Front page New York Times August 10, 1988"

2 images from hackers as characters converse. "I've got a record. I was Zero Cool." "Zero Cool crashed 1.507 systems in one day, biggest crash in history. Front page New York Times August 10, 1988"

Never forget today, when, on this day in 1988, Zero Cool crashed 1,507 systems in one day.

8 months ago 993 374 9 46
Preview
Acclaimed Colorado sci-fi author: Future stupider than I imagined Paonia writer Paolo Bacigalupi reflects on 10 years since the publication of his climate thriller “The Water Knife.”

For once, a very good headline, and of course @paolobacigalupi.bsky.social is not wrong here

www.cpr.org/2025/07/12/i...

9 months ago 1125 176 30 9

So yesterday on X someone from X engineering tweeted at me that X does, in fact, use HSMs and the key ceremonies are “coming soon.” I’ve updated the post but I’ll be honest this whole thing doesn’t fill me with good feelings.

10 months ago 21 1 5 0

Regardless of how good or bad their Juicebox deployment is, at the end of the day, the client code has access to the unencrypted text and/or private key and can do whatever it wants with it.

10 months ago 0 0 1 0

And as you mention without an independently verified key ceremony, there's no way to know if the realm is running on commodity hardware, a poorly configured HSM that can leak keys, or a correctly configured HSM.

10 months ago 3 0 1 0
Preview
A bit more on Twitter/X’s new encrypted messaging Matthew Garrett has a nice post about Twitter (uh, X)’s new end-to-end encryption messaging protocol, which is now called XChat. The TL;DR of Matthew’s post is that from a cryptographic…

I wrote a bit more about X’s new encrypted DMs and the Juicebox protocol. blog.cryptographyengineering.com/2025/06/09/a...

10 months ago 70 27 6 0
Advertisement

Juicebox had 2 realms running on real entrust HSMs managing billions of (test) keys. The impl is complete. That said I’m not aware of any deployments of it outside the ones Juicebox ran.

10 months ago 5 1 1 0
Preview
Don’t Put All Your Juice in One Box At Juicebox, we believe key recovery should be secure, user friendly, and actually… work. That means it has to be more than cryptographic theater. It has to reflect the real world, where systems get h...

If your DMs are “encrypted” but one org holds all the keys, you haven’t distributed trust – you’ve built a backdoor.

Juicebox only works when boundaries are real. Separation isn’t optional.

Replication != distribution.

10 months ago 71 19 0 3