Sign in

Diego F. Aranha

@dfaranha.bsky.social
811 followers 538 following 185 posts

Associate Professor of Cryptographic Engineering at Aarhus University. dfaranha.github.io

PostsRepliesMedia
Reposted by Diego F. Aranha
Claudio Orlandi @claudiorlandi.bsky.social · 22h
News from #aarhuskrypto: welcome to associate professor Julius Hermelink! With Julius and @dfaranha.bsky.social, we now have a very strong core in crypto engineering and side-channel security, complementing decades of research in foundations and protocols. Welcome Julius!
051
Reposted by Diego F. Aranha
evacide @evacide.bsky.social · 10/09/2026
If you optimize a model to find exploits, you should expect it to find them—and prepare for that. OpenAI didn't. They built a model, removed the safeguards, gave it the ExploitGym task, let it run, and didn't even monitor it. That's human decision-making. mail.cyberneticforests.com/models-dont-...
mail.cyberneticforests.com
Models Don't Go Rogue
Stochastic Flocks & Cybersecurity 'Pandemonium' 💡This essay was drafted from my appearance on Mél Hogan's podcast, The Data Fix, discussing the OpenAI / Hugging Face hack. Embedded below or find it o...
8288111
Diego F. Aranha @dfaranha.bsky.social · 10/09/2026
Teenage Wasteland is a fantastic Netflix documentary, and so needed at this point in time.
020
Diego F. Aranha @dfaranha.bsky.social · 09/09/2026
Hey, look at this technology built by humans after training huge models on troves of data stolen from other humans running inference on GPUs and infrastructure built by humans, and even preserving the human biases present in the training data or creating all kinds of human drama! Let's call it AI.
060
Reposted by Diego F. Aranha
Claudio Orlandi @claudiorlandi.bsky.social · 05/08/2026
News from #aarhuskrypto: we welcome postdocs LaKyah Tyner, Mahak Pancholi, Sebastian Hasler and Hamidreza Khoshakhlagh! users-cs.au.dk/orlandi/cryp...
users-cs.au.dk
Aarhus Crypto Group
021
Diego F. Aranha @dfaranha.bsky.social · 05/08/2026
Não tenho grandes novidades a respeito por não ter participado de nenhum processo ligado à urna eletrônica nos últimos 6 ou 7 anos. Entretanto, continuo trabalhando com pesquisa em voto eletrônico e quebrando sistemas inseguros por aí :D
010
Diego F. Aranha @dfaranha.bsky.social · 04/08/2026
Segunda vez que leio palavras gentis hoje sobre nosso trabalho, muito obrigado!
110
Reposted by Diego F. Aranha
Marcel Ribeiro-Dantas, Ph.D. @mribeirodantas.bsky.social · 04/08/2026
Bora, turma! Experiência super bacana aqui no Brasil :)
011
Diego F. Aranha @dfaranha.bsky.social · 03/08/2026
Severely underappreciated band.
000
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
Tentei interagir e só recebi mais hostilidade e desinformação. Quer saber? Passar bem.
120
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
Tem que fazer voto de pobreza e ai de você se conseguir algum destaque pela competência. Será infinitamente ridicularizado.
120
Reposted by Diego F. Aranha
yaso @yaso.is · 28/07/2026
Não sei como o governo consegue ter a cara de pau de discutir soberania e AI com esses valores desse jeito. Mals ae pelo fogo amigo
183
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
E alegar que precisamos "desmontar urna" para montar qualquer ataque explorando vulnerabilidades no *software* é desinformacão pura de quem nunca leu um relatório ou artigo científico a respeito, nível cloroquina.
000
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
Acho curiosa a idéia de ser injusto receber destaque por fazer um trabalho bem feito e de interesse público. Se o pesquisador vive na torre de marfim, é criticado; se aprimora sistemas de interesse social, é criticado. Concluo que você é tão anti-ciência e anti-cientista quanto aqueles que critica.
100
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
Se você parar para pensar com o cérebro ao invés do fígado, era meu *dever* como funcionário público dar o diagnóstico exato da qualidade do sistema, dada a oportunidade. Nosso trabalho comecou anos antes do Bozo ser eleito, e da pauta ser capturada por politicagem.
100
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
Collendo louros de clickbait como, comédia? O trabalho técnico foi feito com excelência, publicado em eventos científicos de qualidade e premiado. O impacto é claro e eventualmente melhorou o sistema. O que eu deveria fazer a respeito? Morrer em silêncio? Fingir que nada aconteceu?
100
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
* Dependia tanto disso que deixei o Brasil há 8 anos, para nunca mais olhar para trás. Um dos motivos foi exatamente essa hostilidade gratuita com pesquisadores. * Nosso trabalho acadêmico foi conduzido nos moldes permitidos pelo TSE, com resultados publicados e premiados. Onde está a cloroquina?
131
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
Respondendo ao @rofnight.bsky.social por aqui, já que o post original não admite respostas: * Nunca "fiz carreira" com urna eletrônica, muito pelo contrário. Gastei muito tempo e o sistema melhorou por causa disso. * Nunca foi nem meu tema principal de pesquisa, basta olhar artigos publicados.
120
Diego F. Aranha @dfaranha.bsky.social · 28/07/2026
Vamos chegando perto do período eleitoral...
160
Reposted by Diego F. Aranha
Dare Obasanjo @carnage4life.bsky.social · 28/06/2026
Ford has rehired hundreds of senior engineers after replacing them with AI backfired and has cost the company billions of dollars. AI adoption is blamed for Ford being the most recalled automaker in the U.S. with 51 recalls covering over 11 million vehicles in the first half of 2026 alone.
340105163960
Reposted by Diego F. Aranha
Guillaume Hiet @guillaumehiet.bsky.social · 23/06/2026
ISC 2026 submission deadline extended to July 2! Keynotes by Shweta Shinde and Diego Aranha. Submit your latest work in cybersecurity: isc2026.github.io 🇫🇷 Join us in Rennes this October — including a social event at Mont-Saint-Michel!
isc2026.github.io
ISC 2026: Information Security Conference
021
Reposted by Diego F. Aranha
Nadim Kobeissi @nadim.computer · 17/06/2026
Today I learned that a *third* former student got accepted into a top grad program abroad as a direct consequence of my applied cryptography mentorship in Lebanon last year. Walking in Paris with my chest so puffed from pride that it’s pushing cars out of the way and denting buildings
0171
Reposted by Diego F. Aranha
🦇🎃💀 Riana-mator 💀🎃🦇 @riana.bsky.social · 20/05/2026
Reminder that I maintain a periodically-updated reading list of papers at the intersection of E2EE and Trust & Safety; suggestions welcome: docs.google.com/spreadsheets...
docs.google.com
Encryption + Trust & Safety reading list (updated 2026-05-20)
28322
Reposted by Diego F. Aranha
Nadim Kobeissi @nadim.computer · 09/06/2026
Today is both: - First day of the summer semester of my applied cryptography course! WE'RE BACK BABY - Deltarune Chapter 5 is likely to be announced (during today's Nintendo Direct) TODAY IS A GOOD DAY
081
Diego F. Aranha @dfaranha.bsky.social · 09/06/2026
And we just arrived to the final day! * How (anonymous) credential apps are not really anonymous, as in not providing any basic form of unlinkability * Loyalty point multiplication miracles * More DevMode shenanigans * Free groceries for all \o/
100
Diego F. Aranha @dfaranha.bsky.social · 08/06/2026
Day 5 had some great highlights too: * How to get free laundry across machines in the AU campus * A self-sovereign digital identity wallet that was not... very sovereign * How to play GeoGuessr with Chinese IP cameras!
120
Diego F. Aranha @dfaranha.bsky.social · 04/06/2026
Day 4 has started! Craziest "DevMenu" of the day is hidden functionality that pops up after you click the app logo for a total of 7 times. Students found it with LLMs because code was too obfuscated to be readable by humans. We live in strange times indeed!
130
Diego F. Aranha @dfaranha.bsky.social · 03/06/2026
static.klipy.com
Star Wars C3PO: We're Doomed!
ALT: Star Wars C3PO: We're Doomed!
010
Diego F. Aranha @dfaranha.bsky.social · 03/06/2026
Users choose a 4-digit PIN code during school years when they are still kids, so one can just use library authentication as an SSN oracle. Fix the PIN, iterate the SSN until one gets a matching pair. There are enough library apps to distribute the load and avoid rate-limiting countermeasures.
110
Diego F. Aranha @dfaranha.bsky.social · 03/06/2026
TIL that the best way to farm social security numbers in Denmark is by exploiting the university library system. The Danish SSN is a concatenation between a birth date and 4 additional digits, some of which form a checksum. Before 2007, there were about 270 valid SSNs per date.
120
Reposted by Diego F. Aranha
Clément Canonne @ccanonne.github.io · 02/06/2026
A list of principles put forth by mathematicians, for mathematicians and other researchers, regarding the use of AI in research. "Number #9 will surprise you!" leidendeclaration.ai
leidendeclaration.ai
Leiden Declaration on Artificial Intelligence and Mathematics
This declaration calls for action to address the challenges posed by the use of artificial intelligence within mathematics research.
02711
Diego F. Aranha @dfaranha.bsky.social · 03/06/2026
182
Diego F. Aranha @dfaranha.bsky.social · 03/06/2026
Day 3 has just started and it's by far the craziest, with one priv escalation. I can't help but think that these apps are only surviving out there because Denmark is a rule-based high-trust society. The tech is embarrassingly bad and wouldn't resist a week in the adversarial environment back home.
140
Diego F. Aranha @dfaranha.bsky.social · 03/06/2026
The highlights in Day 1 were vulnerabilities enabling fare evasion in Danish public transport, and manipulation of payment transactions in multiple shopping apps. Day 2 was less eventful, and focused on transport apps that were much harder to break in comparison.
131
Diego F. Aranha @dfaranha.bsky.social · 03/06/2026
This year's recurrent theme has been "DevMode", where students find hidden functionality in mobile apps that unlock admin functionality. Why would one ship to the app store a mobile app with builtin DevMode that allows the user to bypass security controls?
120
Diego F. Aranha @dfaranha.bsky.social · 03/06/2026
It's that time of the year again: Systems Security exam week! If you remember, this is the final task in my graduate-level course where students put theory to practice and perform security analysis of a mobile app. There's so much broken stuff out there that I am having trouble sleeping at night.
2145
Reposted by Diego F. Aranha
David Slack @slack2thefuture.bsky.social · 02/06/2026
Hilarious and deeply insightful writing by @brianphillips.lol.
Because the truth is, tech doesn't have an image problem. It doesn't have a message problem. It has an intention problem. What's wrong with the axe murderer who broke into my house is not that he hasn't successfully persuaded me to buy into his narrative. What's wrong is that he's trying to kill me with an axe. Similarly, when you launch a product that's designed to put millions of people out of work, block access to sources of verifiable truth, replace human creativity with slop, and lower the barriers to every sort of atrocity, the problem isn't that you haven't told the public a good story about those things. The problem is that you are trying to do them.
3042741645
Reposted by Diego F. Aranha
OpenMedia @openmedia.org · 04/05/2026
🇨🇦's #BillC22 is entering committee study this week - and we're hearing it may become law by end of the month. We never say this: but this is the worst, most privacy-breaking bill we've seen. It MUST be stopped. Speak up against it and read on to learn more: www.openmedia.org/StopC22-bsky 1/
openmedia.org
Stop the Surveillance State: Stop Bill C-22!
🚨 Bill C-22 forces every Canadian internet provider, messaging app & cloud service to build surveillance backdoors and store a year of your data. Foreign state hackers exploited similar legislation in...
12225198
Reposted by Diego F. Aranha
Laurens @laurenshof.online · 02/06/2026
the even more fun problem is, that because NL Wallet uses remote app attestation, it checks Googles servers for verification every time you use the app, meaning that Google holds a kill switch for our national ID wallet
35114
Reposted by Diego F. Aranha
ePrint Updates @eprint.ing.bot · 31/05/2026
A gentle introduction to lattice-based cryptography (Alfred Menezes) ia.cr/2026/1098
Abstract. We present the quantum-safe Kyber key encapsulation mechanism (ML-KEM) and the Dilithium signature scheme (ML-DSA). We also develop the mathematical background on lattices needed to understand why Kyber and Dilithium are regarded as lattice-based cryptosystems, and we provide insight into the computational hardness of the underlying lattice problems. The exposition is intended to be accessible to senior undergraduate students and beginning graduate students.
0187
Reposted by Diego F. Aranha
Tjerand Silde @tjesi.bsky.social · 08/05/2026
We are happy to host Stefano Tessaro (@stefanotessaro.bsky.social), Anja Lehmann, Gregor Seiler, and Sofia Celi (@claucece.bsky.social) as keynote speakers in addition to the contributed talks. Check out the abstracts here: privcryptworkshop.github.io/keynotes.html
privcryptworkshop.github.io
PrivCrypt 2026
042
Reposted by Diego F. Aranha
Markus Eichhorn @markuseichhorn.bsky.social · 07/05/2026
Bingo! Do I win a prize now?
Comic strip titles self-sabotaging academic habits that feel normal, featuring nine panels.
1122583
Reposted by Diego F. Aranha
Chris @chrisdkmx.skyen.live · 23/04/2026
(ifølge Diego Aranha udtryk for et bredt og markant skift i Silicon Valley, der i årtier stod for åbenhed, ærlighed og liberale værdier. Nu er de blevet lukkede, de gnubber åbenlyst skuldre med den amerikanske præsident og leverer med glæde til forsvarsministeriet.) Tænk over det.
172
Diego F. Aranha @dfaranha.bsky.social · 07/05/2026
static.klipy.com
That's Not How It Works! That's Not How Any Of This Works!
ALT: That's Not How It Works! That's Not How Any Of This Works!
030
Reposted by Diego F. Aranha
Sabine Oechsner @proofnerd.bsky.social · 17/04/2026
I'm looking for a PhD student to work with me on formal verification for cryptographic protocols. This is a 4-year position at VU Amsterdam, co-supervised with Kristina Sojakova. Send me an email if you want to know more!
11013
Diego F. Aranha @dfaranha.bsky.social · 26/04/2026
Another one? We just semi-survived Chat Control.
030
Reposted by Diego F. Aranha
Alex Blechman @alexblechman.bsky.social · 18/04/2026
It’s inaccurate to say Mario is brave and Luigi is cowardly Luigi is afraid of death, so he runs away from danger. Mario is afraid of living, so he runs towards death. Both brothers are cowards in their own way
96155213053
Reposted by Diego F. Aranha
Filippo Valsorda @filippo.abyssdomain.expert · 15/04/2026
There are only two bug classes left: complexity and memory safety. CurveBall (CVE-2020-0601)? Complexity. BigSig (CVE-2021-43527)? Memory safety. Log4Shell (CVE-2021-44228)? Complexity. BlueKeep (CVE-2019-0708)? Memory safety. Heartbleed looks like memory safety, but it's actually complexity.
513917
Diego F. Aranha @dfaranha.bsky.social · 15/04/2026
That's how I teach it to my students as well.
030
Diego F. Aranha @dfaranha.bsky.social · 14/04/2026
We performed a security analysis of the LINE messenger in our latest paper, "LINE-Break: Cryptanalysis and Reverse Engineering of Letter Sealing", to appear in ACM ASIACCS’26. Joint work with Thomas Kingo Mogensen and Adam B. Hansen @csaudk.bsky.social. Full technical details at linebreak.info
linebreak.info
We analyze its underlying end-to-end encryption (E2EE) protocol Letter Sealing v2 (LSv2) and show that a TLS Man-in-the-Middle (MitM) or malicious server can compromise integrity, authenticity, and confidentiality in various experimentally verified attacks.
1122