David Adrian @dadrian.io · 13/09/2026hey now score probability graphs only do this when the team is under extreme duress 020
David Adrian @dadrian.io · 13/09/2026Ryan Day looks like the evil robot Santa Claus from Santa Clause 2 001
David Adrian @dadrian.io · 12/09/2026Michigan footballstatic.klipy.comGet The Word Out ThereALT: Get The Word Out There 050
David Adrian @dadrian.io · 27/08/2026Since the last time Peikert was on, Michigan football and Michigan basketball both won a national championship. That's the new bar for repeat guests. 064
David Adrian @dadrian.io · 23/08/2026I wrote a post about how security undervalues preventing problems, and how this can be exasperated by AI and the vulnpocalypse, even though AI should actually make robustness much easier for defenders. Read it here: dadrian.io/blog/posts/w...dadrian.ioPlaying whack-a-mole is losingI want to juxtapose two classes of people in the security industry on the defender side of security engineering for products. The first are the Security as Identity people. This goes back to the secur... 092
Reposted by David AdrianDeirdre Connolly¹ ² @durumcrustulum.com · 08/08/2026This was very fun!! Thanks again to our sponsor Teleport 💃🕺 061
Reposted by David AdrianSecurity Cryptography Whatever @scwpod.bsky.social · 27/07/2026Are you coming to Vegas for BlackHat and DEF CON? Come to our happy hour! securitycryptographywhatever.com/events/black...securitycryptographywhatever.comSCWPodCon BlackHat 2026"Security Cryptography Whatever" is hosting a party during BlackHat USA 2026, once again brought to you by Teleport! 142
David Adrian @dadrian.io · 17/07/2026Wrote another thing dadrian.io/blog/posts/h...dadrian.ioHacking is Just BugsMovies and video games make it seem like hacking is simply whoever is smarter at computers breaking into someone else’s system. That’s not quite the case. Hacking is the act of exploiting vulnerabilit... 010
David Adrian @dadrian.io · 03/07/2026New episode! www.youtube.com/watch?v=7ZwQ...youtube.comTrump's Golden Post Quantum EOsYouTube video by Security Cryptography Whatever 021
David Adrian @dadrian.io · 28/06/2026dadrian.io/blog/posts/t...dadrian.ioThe Late ShowThe Late Show always felt like adulthood to me. Growing up, I heard about David Letterman before I was old enough to stay up late enough to watch The Late Show. One of the local radio stations syndica... 120
Reposted by David AdrianFilippo Valsorda @filippo.abyssdomain.expert · 26/06/2026securitycryptographywhatever.com/2026/03/25/a... is very very good. If you read my vulnerabilities post, this podcast episode is much more worth listening to.securitycryptographywhatever.comAI Finds Vulns You Can’t With Nicholas CarliniReturning champion Nicholas Carlini comes back to talk about using Claude for vulnerability research, and the current vulnpocalypse. It’s all very high-brow ... 0377
Reposted by David Adrianserena (𝑂𝑓𝑓𝑙𝑖𝑛𝑒) @serena.nz · 11/05/2026american culture is when drink is big 181
David Adrian @dadrian.io · 15/06/2026New episode! We talk to @lcamtuf.coredump.cx about the vulnpocalypse. www.youtube.com/watch?v=uI9C...youtube.comFacing the Vulnpocalypse with lcamtufYouTube video by Security Cryptography Whatever 172
David Adrian @dadrian.io · 01/05/2026I poked around with @exe.dev some, and wrote up how I think their Github integration works, because it's pretty cool. dadrian.io/blog/posts/e...dadrian.ioProxies all the way down.A couple of days ago, exe.dev raised a lot of money1. I decided to poke around with it a little, and signed up. Their trial is 7 days long, so despite having no actual plans, I just started doing stuf... 030
Reposted by David AdrianPTKU Mega-Booster @emgoblue2023.bsky.social · 24/04/2026Dad’s home $1 for every attendee of 13-10 #charitibundibowl @newap-georgia.bsky.social 6550253
Reposted by David AdrianThomas Ptacek @sockpuppet.org · 30/03/2026I wrote something: sockpuppet.org/blog/2026/03...sockpuppet.orgVulnerability Research Is Cooked 79639
Reposted by David AdrianSecurity Cryptography Whatever @scwpod.bsky.social · 26/03/2026NEW EPISODE! The gang learns a bitter lesson about AI and bug finding! Returning champion Nicholas Carlini is back to talk about Claude for vulnerability research. securitycryptographywhatever.com/2026/03/25/a... www.youtube.com/watch?v=_IDb...youtube.comAI Finds Vulns You Can't With Nicholas CarliniYouTube video by Security Cryptography Whatever 2114
Reposted by David AdrianChris Peikert @chrispeikert.bsky.social · 23/03/2026new Joy of Cryptography just dropped (feat. Post-Quantum Crypto) 1548
Reposted by David AdrianThomas Ptacek @sockpuppet.org · 14/03/2026Extremely psyched about two upcoming SCW guests, one of them this week. We've got very crunch vulnerability research and cryptography stuff coming. 0243
Reposted by David AdrianDeirdre Connolly¹ ² @durumcrustulum.com · 27/02/2026new Merkle Tree Cert only Chrome Quantum Root Store: security.googleblog.com/2026/02/cult...security.googleblog.comCultivating a robust and efficient quantum-safe HTTPSPosted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against ... 083
Reposted by David AdrianThomas Ptacek @sockpuppet.org · 28/02/2026None of you are giving me enough credit for not participating on the TLS working group mailing list. You're welcome. Everything I don't do, I don't do it for you. 2262
Reposted by David AdrianSecurity Cryptography Whatever @scwpod.bsky.social · 02/02/2026NEW EPISODE! The maintainers of py/cryptography declared that after many years of trying to make it work, they would be moving away from OpenSSL when supporting new functionality and exploring adding other backends: securitycryptographywhatever.com/2026/02/01/p... www.youtube.com/watch?v=dEKB...youtube.comPython Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex GaynorYouTube video by Security Cryptography Whatever 5205
David Adrian @dadrian.io · 21/01/2026I cannot get over how impressive it is what Curt Cignetti accomplished at Indiana 010
David Adrian @dadrian.io · 20/01/2026Indiana shall light this holy ring, release its cleansing flame, and burn a path into the divine beyond! 011
Reposted by David Adrianrmhrisk @rmhrisk.bsky.social · 16/01/2026This is what zero-trust looks like at the infrastructure layer. Identity and encryption match the lifetime of the thing being secured. If your certificate strategy still assumes stable names and year-long validity, it is already behind reality. letsencrypt.org/2026/01/15/6...letsencrypt.org6-day and IP Address Certificates are Generally AvailableShort-lived and IP address certificates are now generally available from Let’s Encrypt. These certificates are valid for 160 hours, just over six days. In order to get a short-lived certificate subscr... 021
Reposted by David AdrianDeirdre Connolly¹ ² @durumcrustulum.com · 12/01/2026dadrian.io/blog/posts/s...dadrian.ioStop inventorying keys.If you have a reason to migrate to post-quantum cryptography (PQC), you should not be inventorying keys for the purpose of migration, and you should stop listening to anyone who suggests that you do s... 052
Reposted by David AdrianThomas Ptacek @sockpuppet.org · 31/12/2025Final SCW of 2025! We had Matt Bernhard on to talk about cryptographic voting systems, in the wake of the IACR election. (Everybody I voted for in the new election won! Woo!) 093
Reposted by David AdrianJoseph Lorenzo Hall, PhD @josephhall.org · 31/12/2025What a fantastic present to end the year! (swear I woke up like this) @mbernhard.com @durumcrustulum.com @sockpuppet.org @dadrian.io @scwpod.bsky.social 171
Reposted by David AdrianFilippo Valsorda @filippo.abyssdomain.expert · 24/11/2025This Bernstein crap drives me up the wall because IT MAKES NO SENSE. Why would the NSA be picking weak crypto to protect US NatSec?! They have mathematicians and clusters in China, too! Dual_EC_DRBG was a NOBUS backdoor. There is NOWHERE to hide a NOBUS backdoor in ML-KEM. 6626
Reposted by David AdrianJeff Hodges @jmhodges.bsky.social · 28/10/2025Wonderful news! The kind of thing a lot of software folks across the world have been working to make possible. So stoked the Chrome folks are pushing us forward 051
Reposted by David AdrianAndrew Whalley @arw.me · 28/10/2025It's time to make HTTPS the web's default, and reap the full security benefit from years worth of HTTPS adoption! security.googleblog.com/2025/10/http...security.googleblog.comHTTPS by defaultOne year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secu... 38926
David Adrian @dadrian.io · 28/10/2025One year from now, Chrome will enable "Always Use Secure Connections" and warn users before plaintext HTTP by default.security.googleblog.comHTTPS by defaultOne year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secu... 0168
David Adrian @dadrian.io · 11/09/2025New post! Stop trying to solve revocation, we already have the answer. dadrian.io/blog/posts/r...dadrian.ioRevocation ain't no thang.Adam Langley wrote about how revocation in the Web PKI doesn’t work over 10 years ago. Since then, the Web PKI has drastically changed for the better, despite not appearing to “solve” revocation. Unfo... 041
David Adrian @dadrian.io · 06/09/2025Kirk Herbstreit is going to be the first person to make a Golden Retriever unlikable. 011
Reposted by David Adrianrmhrisk @rmhrisk.bsky.social · 03/09/2025The bigger issue? Microsoft’s root program still trusts this CA, leaving Edge and Windows users exposed in ways Chrome, Firefox, and Safari users aren’t. The pattern is familiar: long-lived trust, weak oversight, systemic risk. It’s time for Microsoft to step up and fund proper root governance. 👇unmitigatedrisk.comAnother Sleeping Giant: Microsoft’s Root Program and the 1.1.1.1 Certificate Slip | UNMITIGATED RISK 231
David Adrian @dadrian.io · 02/09/2025If you look closely, you can see UNC’s quarterback is not Tom Brady 131
Reposted by David AdrianMatt Bernhard @mbernhard.com · 30/08/2025This game has me feeling like I'm watching Iowa play Iowa. 021
David Adrian @dadrian.io · 29/08/2025Sent this to a girl in California and pretty sure she thinks it’s in another language 120
David Adrian @dadrian.io · 23/08/2025Come for the PGP dunks, stay for the broader discussion of why encrypted email doesn’t make sense 0127
Reposted by David AdrianSimon Fondrie-Teitler @simon.overgrown.garden · 17/08/2025The first part of this interview with my ex-colleague Alex is a great listen if you're a software engineer (or otherwise technical) and are interested in what we were working on as technologists at the Federal Trade Commission. 032