@fj@mastodon.social
@fj@mastodon.social avatar

fj

@fj@mastodon.social

Cryptographic & Security Engineering at Apple.
Previously: Lead iOS Developer https://mastodon.world/@signalapp

Tooting on all things #cryptography, #security, #climate, European #aerospace, #energy and #mobility

This profile is from a federated server and may be incomplete. Browse more on the original instance.

fj, to random
@fj@mastodon.social avatar

Welcome back on the side of net neutrality America! 👏

Hope it lasts and you don’t name another Ajit Pai next 🙏
https://mastodon.social/

fj, (edited ) to random French
@fj@mastodon.social avatar

🇪🇺🧑‍🚀 Europe has a new class astronauts

👏 Congrats to 🇫🇷 Sophie Adenot, 🇪🇸Pablo Álvarez Fernández, 🇬🇧Rosemary Coogan, 🇧🇪 Raphaël Liégeois and🇨🇭Marco Sieber

Also graduating is 🇦🇺 Katherine Bennell-Pegg, Australia's first female astronaut and trained with ESA astronauts.

https://www.esa.int/Science_Exploration/Human_and_Robotic_Exploration/Watch_live_ESA_astronaut_class_of_2022_graduation_ceremony

fj, (edited ) to random French
@fj@mastodon.social avatar

"Remarkably, these near-hypercubic lattices cover Falcon and most concrete instances of the NTRU cryptosystem:
this is the first provable result showing that breaking NTRU lattices can be reduced to finding shortest lattice vectors in halved dimension, thereby providing a positive response to a conjecture of Gama, Howgrave-Graham and Nguyen at Eurocrypt 2006.”

https://ioc.exchange/@eprint/112312459697738509

fj,
@fj@mastodon.social avatar

@ducasleo Updated sourcing :)

fj, to random French
@fj@mastodon.social avatar

“Six months into the current military offensive, more housing and civilian infrastructure has now been destroyed in Gaza as a percentage, compared to any conflict in memory

More than 15,000 deaths, almost half of all civilian deaths so far, occurred during the first six weeks after October 7, when AI systems seem to have been largely relied upon for target selection.”

https://www.ohchr.org/en/press-releases/2024/04/gaza-un-experts-deplore-use-purported-ai-commit-domicide-gaza-call

fj, (edited ) to random
@fj@mastodon.social avatar

“Over promise and under deliver” was already Tesla’s motto in terms of vehicle’s range, acceleration, quality, autonomous driving, and now for their truck’s resistance …

“It's not exactly confidence-inducing to see a car that's meant to serve as a rugged off-the-grid base — and even a way to get around Mars, according to Tesla CEO Elon Musk — turn into a giant "Tesla Paperweight" after a routine car wash.”
https://axbom.me/objects/358323ac-9dc9-4a60-8afc-7cdced25efe4

fj, to random French
@fj@mastodon.social avatar

⚛️ Major update on the Quantum Algorithm for LWE

Hongxun Wu & Thomas Vidick have found an issue in Step 9, related to how the quantum vector state is composed.

🔐 LWE remains quantum-secure, for now.
”The claim of showing a polynomial time quantum algorithm for solving LWE with polynomial modulus-noise ratios does not hold.”

👉 Quantum algorithms are hard to validate, unlike classical algorithms, you can't just run a proof of concept and extrapolate asymptotics.

https://eprint.iacr.org/2024/555

leah, to random German
@leah@chaos.social avatar

After getting alerted tonight because from Anthropic was scanning a host so aggressively that all 20 cores where saturated I generated a list of IPs (all/mostly AWS) they used for you to block them too.

https://gist.github.com/leahoswald/935f90ba09b3484d15ea6d20d0f2f99a

The bot is used to fuel their AI model so nobody really needs that and after some research they also seem to ignore robots.txt. By by 👋 🤷‍♀️

fj,
@fj@mastodon.social avatar

@leah What rules did you have in your robots.txt? Anthropic claims they respect:
User-agent: anthropic-ai
Disallow: /

I wish there was the possibility to have more general rules so we don't have to know about each of the user agents of these bots.

https://mastodon.social/@fj/112280775190792281

cc @sindarina

fj, to random
@fj@mastodon.social avatar

Is this advice even actionable?
Are there any HSM vendors (not enclaves) providing inference solutions with HSM-private weights?

https://media.defense.gov/2024/Apr/15/2003439257/-1/-1/0/CSI-DEPLOYING-AI-SYSTEMS-SECURELY.PDF#page11

fj, to random
@fj@mastodon.social avatar

The proliferation of AI crawlers is really making the blocklisting in robots.txt no longer practical since there is no robots.txt rule that can exclude all AI crawlers, each having a separate agent string.

On the other hand, only allowing large search engines is strengthening their dominant position.

I would prefer being able to qualify the usage rather than the agent.

Usage: “SearchEngine”
Disallow:

Usage: “TrainingData”
Disallow:/

fj, to random French
@fj@mastodon.social avatar

.@nigel_paul_smart has a great note on the proposed Quantum Attack on LWE and its implications for various constructions that rely on LWE hardness.

Parameters for Kyber, Dilithium and TFHE are not affected by this quantum attack, but BGV might.
And even then, the algorithm make it complicated to be implemented on a quantum computer.

https://nigelsmart.github.io/LWE.html

samir, to random
@samir@functional.computer avatar

People in Switzerland: where do companies sell their old hardware?

I’d happily take a couple of old servers rather than buying a new one, but I have no idea where to look.

fj,
@fj@mastodon.social avatar

@samir I buy and sell on anibis.ch and www.ricardo.ch

fj, to random French
@fj@mastodon.social avatar

Documentaire fascinant sur la DGSE avec quelques détails d’interventions en Mauritanie, l’analyse des armes chimiques de Bashar Al-Assad, les informations qu’ils avaient avant l’invasion de l’Ukraine mais la différence de politique de divulgation de ce type d’informations à titre dissuasif …
https://www.france.tv/documentaires/societe/5817897-dgse-la-fabrique-des-agents-secrets.html

dbrgn, to random
@dbrgn@chaos.social avatar
fj,
@fj@mastodon.social avatar

@dbrgn Living the dream 😍

fj, to random
@fj@mastodon.social avatar

Just woke up learning that Sophia d’Antoine was ran over while walking in Upper East Side by a 72-year-old speeding in a Land Rover SUV.

I'll remember Sophia as an inspiring person, telling me a bunch of insightful facts about binary constraints solving after her talk at @hack_lu 2015

https://www.thedailybeast.com/founder-of-cybersecurity-startup-dies-after-being-struck-by-an-suv

fj, (edited ) to random
@fj@mastodon.social avatar

⚛️🇪🇺 The 2 years countdown starts today to establish the roadmap for the EU’s transition to Post-Quantum Cryptography

Of note, the Commission’s recommendation is to deploy hybrids and does not exclude Quantum Key Distribution
« This should lead to the deployment across the Union of PQC into existing public administration systems and critical infrastructures via hybrid schemes that may combine PQC with existing cryptographic approaches or with QKD»

https://ec.europa.eu/newsroom/dae/redirection/document/104249
https://social.network.europa.eu/

fj, (edited ) to random
@fj@mastodon.social avatar

GitHub Pages are useful, but be careful to not set it up with a DNS Wildcard.
It allows anyone on GitHub to host content on your subdomains, and it's actively being used, by paid GitHub accounts, to host scams

https://www.fredericjacobs.com/blog/2024/04/11/DNS-GitHubPages/

ooni, to random
@ooni@mastodon.social avatar

❗️Tanzania: Surge in online LGBTIQ censorship and other targeted blocks
https://ooni.org/post/2024-tanzania-lgbtiq-censorship-and-other-targeted-blocks/

Our latest report documents extensive LGBTIQ censorship & the blocking of Change.org, Global Fund for Women, GlobalGiving, Open Society Foundations, Clubhouse and ProtonVPN (among others) in based on OONI data. 🧵

fj,
@fj@mastodon.social avatar

@ooni Does that also happen after an Encrypted Client Hello? 🤔
https://datatracker.ietf.org/doc/draft-ietf-tls-esni/

fj, to random
@fj@mastodon.social avatar

Nice analysis by Bruno Blanchet that proves that HPKE with ML-KEM (or any other IND-CCA2 KEM) does provide IND-CCA2 security.

“Bruno models the base mode of HPKE, single shot API in CryptoVerif, and showed that if the KEM is IND-CCA2, then so is HPKE.
Since CryptoVerif is PQ-sound, that proves the security of the HPKE base mode, with the single shot API when the KEM is a post-quantum IND-CCA2 KEM.” via Karthikeyan Bhargavan on the CFRG mailing list

https://gitlab.inria.fr/bblanche/CryptoVerif/-/blob/crypto-library-pq-version/examples/hpke/hpke.base.indcca2.ocv?ref_type=heads

fj,
@fj@mastodon.social avatar

The post-quantum transition is causing us to abstract cryptographic protocols over Key Encapsulation Mechanisms as opposed to Diffie-Hellman-like non-interactive key exchanges.

These two papers on the binding models for KEMs are great reads on the gotchas of working with KEMs and the properties they may or may not have.

https://eprint.iacr.org/2023/1933
https://eprint.iacr.org/2024/523

fj, to random
@fj@mastodon.social avatar

Welcome to the age of AI-translated newsletters.

In the middle of the newsletter, a paragraph is missing and they sent it out with this error: “Unable to perform API call to GPT. Missing original asset text from the source database.”

fj, to random
@fj@mastodon.social avatar
fj, to random
@fj@mastodon.social avatar

💬🔒⚛️ Delighted to announce iMessage PQ3, our formally-verified protocol for end-to-end encryption that provides the strongest post-quantum protections against “Harvest Now, Decrypt Later” attackers by not only performing a quantum-secure key establishment, but also performing post-quantum ongoing rekeying.

Support for PQ3 will start to roll out with the public releases of iOS 17.4, iPadOS 17.4, macOS 14.4, and watchOS 10.4
https://security.apple.com/blog/imessage-pq3/

fj,
@fj@mastodon.social avatar

I was thrilled to present “Designing iMessage PQ3: Quantum-Secure Messaging at Scale" at last month
https://www.youtube.com/watch?v=RVbHElGe518

fj, to random
@fj@mastodon.social avatar

Safety Improvements such as 's Navigation Message Authentication should be adopted faster, with GPS interference levels on the rise in Europe.

“On December 26, a large swathe of land and water between Växjö in the north, Stralsund and Neubrandenburg in the west, Łódź in the south, and Białystok in the east was red, indicating a GPS interference level of more than 10%”
https://cepa.org/article/a-2024-resolution-for-the-west-prepare-for-disaster/

fj,
@fj@mastodon.social avatar

Interesting footage from Victor Alegre, an A330 capitain at Iberia Airlines, experiencing interference.

> Spoofing overflying Arabia & Egypt FL360
At first comment IRS Position and GPS Position at same time: 1 degree error Latitude, 2 degrees error Longitude, 34.000 ft Altitude error causing GPWS PULL UP.

The Flight Management Guidance Envelope Computer (which can disable GNSS inputs) thinks the aircraft is too low, causing pull up warnings.

video/mp4

fj,
@fj@mastodon.social avatar

Maybe we should re-consider the cost cutting plans of removing VOR and DMEs that are going to make our Swiss and European airspace in the coming years more dependent on , without having alternative radio navigation methods?
https://www.skyguide.ch/fr/media-centre/post/106302

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • everett
  • osvaldo12
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • kavyap
  • Durango
  • ngwrru68w68
  • cubers
  • JUstTest
  • DreamBathrooms
  • khanakhh
  • anitta
  • modclub
  • ethstaker
  • tester
  • GTA5RPClips
  • cisconetworking
  • tacticalgear
  • megavids
  • Leos
  • normalnudes
  • lostlight
  • All magazines