David Adrian @dadrian.io · 13/09/2026hey now score probability graphs only do this when the team is under extreme duress 020
David Adrian @dadrian.io · 13/09/2026Ryan Day looks like the evil robot Santa Claus from Santa Clause 2 001
David Adrian @dadrian.io · 12/09/2026Michigan footballstatic.klipy.comGet The Word Out ThereALT: Get The Word Out There 050
David Adrian @dadrian.io · 27/08/2026Since the last time Peikert was on, Michigan football and Michigan basketball both won a national championship. That's the new bar for repeat guests. 064
David Adrian @dadrian.io · 23/08/2026I wrote a post about how security undervalues preventing problems, and how this can be exasperated by AI and the vulnpocalypse, even though AI should actually make robustness much easier for defenders. Read it here: dadrian.io/blog/posts/w...dadrian.ioPlaying whack-a-mole is losingI want to juxtapose two classes of people in the security industry on the defender side of security engineering for products. The first are the Security as Identity people. This goes back to the secur... 092
Reposted by David AdrianDeirdre Connolly¹ ² @durumcrustulum.com · 08/08/2026This was very fun!! Thanks again to our sponsor Teleport 💃🕺 061
Reposted by David AdrianSecurity Cryptography Whatever @scwpod.bsky.social · 27/07/2026Are you coming to Vegas for BlackHat and DEF CON? Come to our happy hour! securitycryptographywhatever.com/events/black...securitycryptographywhatever.comSCWPodCon BlackHat 2026"Security Cryptography Whatever" is hosting a party during BlackHat USA 2026, once again brought to you by Teleport! 142
David Adrian @dadrian.io · 17/07/2026Wrote another thing dadrian.io/blog/posts/h...dadrian.ioHacking is Just BugsMovies and video games make it seem like hacking is simply whoever is smarter at computers breaking into someone else’s system. That’s not quite the case. Hacking is the act of exploiting vulnerabilit... 010
David Adrian @dadrian.io · 03/07/2026New episode! www.youtube.com/watch?v=7ZwQ...youtube.comTrump's Golden Post Quantum EOsYouTube video by Security Cryptography Whatever 021
David Adrian @dadrian.io · 28/06/2026dadrian.io/blog/posts/t...dadrian.ioThe Late ShowThe Late Show always felt like adulthood to me. Growing up, I heard about David Letterman before I was old enough to stay up late enough to watch The Late Show. One of the local radio stations syndica... 120
Reposted by David AdrianFilippo Valsorda @filippo.abyssdomain.expert · 26/06/2026securitycryptographywhatever.com/2026/03/25/a... is very very good. If you read my vulnerabilities post, this podcast episode is much more worth listening to.securitycryptographywhatever.comAI Finds Vulns You Can’t With Nicholas CarliniReturning champion Nicholas Carlini comes back to talk about using Claude for vulnerability research, and the current vulnpocalypse. It’s all very high-brow ... 0377
David Adrian @dadrian.io · 18/06/2026"I just want to live up to my father" *father saves the world and turns into a star* 011
Reposted by David Adrianserena (𝑂𝑓𝑓𝑙𝑖𝑛𝑒) @serena.nz · 11/05/2026american culture is when drink is big 181
David Adrian @dadrian.io · 15/06/2026securitycryptographywhatever.com/2026/06/14/f...securitycryptographywhatever.comFacing the Vulnpocalypse With lcamtufWe talk to Michał Zalewski (lcamtuf) about the vulnpocalypse and if we even need fuzzers anymore. This episode may be export controlled at a future date. Th... 011
David Adrian @dadrian.io · 15/06/2026New episode! We talk to @lcamtuf.coredump.cx about the vulnpocalypse. www.youtube.com/watch?v=uI9C...youtube.comFacing the Vulnpocalypse with lcamtufYouTube video by Security Cryptography Whatever 172
David Adrian @dadrian.io · 01/05/2026I poked around with @exe.dev some, and wrote up how I think their Github integration works, because it's pretty cool. dadrian.io/blog/posts/e...dadrian.ioProxies all the way down.A couple of days ago, exe.dev raised a lot of money1. I decided to poke around with it a little, and signed up. Their trial is 7 days long, so despite having no actual plans, I just started doing stuf... 030
David Adrian @dadrian.io · 26/04/2026There was a 2013-core trend on TikTok a few months ago, hipsters, Brooklyn, third-wave coffee, drug rug and all 110
Reposted by David AdrianPTKU Mega-Booster @emgoblue2023.bsky.social · 24/04/2026Dad’s home $1 for every attendee of 13-10 #charitibundibowl @newap-georgia.bsky.social 6550253
David Adrian @dadrian.io · 24/04/2026Not clear to me this has anything to do with the acquisition, versus it is simply very hard to run a company successfully for nearly 20 years, plus an absurd amount of additional load due to AI. 230
Reposted by David AdrianThomas Ptacek @sockpuppet.org · 30/03/2026I wrote something: sockpuppet.org/blog/2026/03...sockpuppet.orgVulnerability Research Is Cooked 79639
David Adrian @dadrian.io · 26/03/2026Makes it even less surprising that Claude can find them, then! 110
Reposted by David AdrianSecurity Cryptography Whatever @scwpod.bsky.social · 26/03/2026NEW EPISODE! The gang learns a bitter lesson about AI and bug finding! Returning champion Nicholas Carlini is back to talk about Claude for vulnerability research. securitycryptographywhatever.com/2026/03/25/a... www.youtube.com/watch?v=_IDb...youtube.comAI Finds Vulns You Can't With Nicholas CarliniYouTube video by Security Cryptography Whatever 2114
David Adrian @dadrian.io · 26/03/2026In retrospect, if Adderall'd up college kids can find vulnerabilities, it's not too surprising that Claude can, too 110
Reposted by David AdrianChris Peikert @chrispeikert.bsky.social · 23/03/2026new Joy of Cryptography just dropped (feat. Post-Quantum Crypto) 1548
Reposted by David AdrianThomas Ptacek @sockpuppet.org · 14/03/2026Extremely psyched about two upcoming SCW guests, one of them this week. We've got very crunch vulnerability research and cryptography stuff coming. 0243
Reposted by David AdrianDeirdre Connolly¹ ² @durumcrustulum.com · 27/02/2026new Merkle Tree Cert only Chrome Quantum Root Store: security.googleblog.com/2026/02/cult...security.googleblog.comCultivating a robust and efficient quantum-safe HTTPSPosted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against ... 083
Reposted by David AdrianThomas Ptacek @sockpuppet.org · 28/02/2026None of you are giving me enough credit for not participating on the TLS working group mailing list. You're welcome. Everything I don't do, I don't do it for you. 2262
David Adrian @dadrian.io · 08/02/2026media.tenor.combugs bunny is making a funny face with his mouth open and the words `` no '' written below him .ALT: bugs bunny is making a funny face with his mouth open and the words `` no '' written below him . 020
Reposted by David AdrianSecurity Cryptography Whatever @scwpod.bsky.social · 02/02/2026NEW EPISODE! The maintainers of py/cryptography declared that after many years of trying to make it work, they would be moving away from OpenSSL when supporting new functionality and exploring adding other backends: securitycryptographywhatever.com/2026/02/01/p... www.youtube.com/watch?v=dEKB...youtube.comPython Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex GaynorYouTube video by Security Cryptography Whatever 5205
David Adrian @dadrian.io · 21/01/2026I cannot get over how impressive it is what Curt Cignetti accomplished at Indiana 010
David Adrian @dadrian.io · 20/01/2026media.tenor.combugs bunny is making a funny face with his mouth open and the words `` no '' written below him .ALT: bugs bunny is making a funny face with his mouth open and the words `` no '' written below him . 120
David Adrian @dadrian.io · 20/01/2026Indiana shall light this holy ring, release its cleansing flame, and burn a path into the divine beyond! 011
Reposted by David Adrianrmhrisk @rmhrisk.bsky.social · 16/01/2026This is what zero-trust looks like at the infrastructure layer. Identity and encryption match the lifetime of the thing being secured. If your certificate strategy still assumes stable names and year-long validity, it is already behind reality. letsencrypt.org/2026/01/15/6...letsencrypt.org6-day and IP Address Certificates are Generally AvailableShort-lived and IP address certificates are now generally available from Let’s Encrypt. These certificates are valid for 160 hours, just over six days. In order to get a short-lived certificate subscr... 021
Reposted by David AdrianDeirdre Connolly¹ ² @durumcrustulum.com · 12/01/2026dadrian.io/blog/posts/s...dadrian.ioStop inventorying keys.If you have a reason to migrate to post-quantum cryptography (PQC), you should not be inventorying keys for the purpose of migration, and you should stop listening to anyone who suggests that you do s... 052