Sign in

Eyal Ronen

@eyalr0.bsky.social
164 followers 136 following 6 posts

Researching applied cryptography and security. School of Computer Science at Tel Aviv University. eyalro.net

PostsRepliesMedia
Reposted by Eyal Ronen
ePrint Updates @eprint.ing.bot · 04/07/2026
3PaaS: Privacy-Preserving Post-Compromise Security as a Service (Cas Cremers, Abhinav Nakarmi, Aleksi Peltonen, Eyal Ronen) ia.cr/2026/1353
Abstract. Post-Compromise Security (PCS) expresses that even after a party has been compromised, it may be able to recover (or “heal”) security afterwards. PCS has been extensively studied, and many end-to-end secure messaging applications include mechanisms, such as the double ratchet, to achieve it.

However, current approaches only work partially, and their healing effects are extremely limited. For example, recent work showed that due to real-world constraints such as resilience against state loss, even highly secure messengers such as Signal may not achieve it in practice. Moreover, since healing is session-specific, healing effects do not carry over to newly spawned sessions, different groups, or different services that use the same identity.

In this work, we tackle these issues by designing the first protocol that can provide PCS as a Service for identities through a third party. The major challenge is privacy: achieving PCS requires regular updates among participants, and involving a third party can lead to significant privacy concerns. Moreover, the type of update that PCS requires (updating a user’s secret, but only once) seems to require servers to verify the users’ identities in a way that contradicts the unlinkability required for privacy: the server should not learn anything about the users’ activities.

We develop the 3PaaS protocol, including the first efficient zero-knowledge proofs for blind signatures, to achieve our goals, and even allow for revocation, without revealing the identity to the server. We formally analyze our protocol for high assurance, provide an implementation of our novel ZK building blocks, and show how our protocol could be used with a messaging application.
Image showing part 2 of abstract.
011
Reposted by Eyal Ronen
What a week, huh? all Wednesdays @whataweekhuh.bsky.social · 18/03/2026
Captain Haddock looking very frazzled, saying, “What a week, huh?”
Tintin leans into the frame and says, “Captain, it’s Wednesday.”
Snowy aka Milou is very excited about the drink he has found.

Viñeta de Tintin
El capitán Haddock, sentado a una mesa y con aspecto de estar agotado, dice: "¡Menuda semana, ¿eh?".
Tintín, a su derecha, le dice: "Capitán, es miércoles".
A la izquierda, Milú mira muy contento la bebida que está en la mesa.
1398140
Reposted by Eyal Ronen
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 09/03/2026
Next up, 'Encryption in the microarchitectural world', presented by Ping-Lun Wang #realworldcrypto
131
Reposted by Eyal Ronen
cascremers.bsky.social @cascremers.bsky.social · 09/03/2026
Very proud and grateful to have won the 2026 #realworldcrypto Levchin prize together with David Basin, Jannik Dreier, and Ralf Sasse for our work on the Tamarin Prover (tamarin-prover.com), as well as having the amazing opportunity to give a keynote at RWC! Hope you enjoyed it! #realworldcrypto2026
tamarin-prover.com
Tamarin prover: Home
0173
Reposted by Eyal Ronen
Real World Crypto Symposium @rwc.iacr.org · 09/03/2026
Huge congrats to the Tamarin Team on winning the Levchin Prize for the Tamarin prover, and its use in the analysis of real-world security protocols. #realworldcrypto2026
1184
Reposted by Eyal Ronen
evacide @evacide.bsky.social · 04/03/2026
The data from your Meta Ray Bans is used to train Meta's AI, which most people don't understand means that humans are looking at the most intimate details of their lives. www.svd.se/a/K8nrV4/met...
svd.se
She Came Out of the Bathroom Naked, Employee Says
Bank details, sex and naked people who seem unaware they are being recorded. Behind Meta’s new smart glasses lies a hidden workforce, uneasy about peering into the most intimate parts of other people’...
11406256
Reposted by Eyal Ronen
Signal @signal.org · 08/09/2025
Until now, if you lost or broke your phone, your Signal message history was *gone,* a real challenge for everyone whose most important conversations happen in Signal. So, with careful design and development, we’re rolling out opt-in secure backups. signal.org/blog/introducing-secure-backups
signal.org
Introducing Signal Secure Backups
In the past, if you broke or lost your phone, your Signal message history was gone. This has been a challenge for people whose most important conversations happen on Signal. Think family photos, sweet...
19689203
Reposted by Eyal Ronen
Matthew Green @matthewdgreen.bsky.social · 05/07/2025
This battle will keep playing out over and over again until they achieve something that their own citizens have made it clear they don’t want. www.techradar.com/vpn/vpn-priv...
techradar.com
The EU wants to decrypt your private data by 2030
The EU Commission unveiled the first step in its security strategy to ensure "lawful and effective" law enforcement access to data
39342
Reposted by Eyal Ronen
Diego F. Aranha @dfaranha.bsky.social · 05/07/2025
Well, this horrible idea refuses to die so we should refuse to let it pass and start organizing again. ec.europa.eu/commission/p...
ec.europa.eu
Commission presents Roadmap for effective and lawful access to data for law enforcement
The European Commission presented today a Roadmap setting out the way forward to ensure law enforcement authorities in the EU have effective and lawful access to data.
27542
Eyal Ronen @eyalr0.bsky.social · 20/06/2025
If any Iron Maiden fans are in the Birmingham area tomorrow (the 21st), I have a couple of Premier Lounge tickets that I unfortunately can't use due to the current situation. #IronMaiden #RunForYourLivesWorldTour #IronMaiden50 @ironmaiden.bsky.social
112
Reposted by Eyal Ronen
Martin R. Albrecht @malb.bsky.social · 14/06/2025
New blog post on our (with @rikkebjerg.bsky.social and @mikaelabrough.bsky.social) USENIX'25 paper "On the Virtues of Information Security in the UK Climate Movement" where I end up reflecting on writing this, for me, unusual work. martinralbrecht.wordpress.com/2025/06/14/o...
martinralbrecht.wordpress.com
On the Virtues of Information Security in the UK Climate Movement
Our paper – titled “On the Virtues of Information Security in the UK Climate Movement” – was accepted at USENIX Security’25. Here’s the abstract: We report on an ethnographic study with members of …
022
Eyal Ronen @eyalr0.bsky.social · 06/06/2025
After a long debate about whether this small typo was worth resubmitting the PDF or not, @IEEESSP 's server stopped responding one minute before the deadline and solved it for us.
130
Reposted by Eyal Ronen
Mathy Vanhoef @vanhoefm.bsky.social · 25/05/2025
All papers should publish their code. Help realize this by becoming an artifact reviewer at NDSS'26, apply here: docs.google.com/forms/d/e/1F... You'll review artifacts of accepted papers. We especially encourage junior/senior PhD students & PostDocs to help. Distinguished reviews will get awards!
docs.google.com
Self-nomination for the Artifact Evaluation Committee of NDSS 2026
We are looking for members of the Artifact Evaluation Committee (AEC) of NDSS 2026. The Network and Distributed System Security symposium adopts an Artifact Evaluation (AE) process allowing authors t...
01210
Reposted by Eyal Ronen
µASC Conference @uasc.cc · 19/05/2025
uASC 2026 will take place on February 3, 2026, in Leuven, Belgium, hosted by KU Leuven. We can't wait to see you next year! Cycle 1 Paper Submission Deadline is July 15, 2025! 👉 uasc.cc #uasc26
0109
Reposted by Eyal Ronen
Mathy Vanhoef @vanhoefm.bsky.social · 07/05/2025
New version of the IEEE 802.11 standard that underpins Wi-Fi was has been released. A total of 5969 pages! The number of pages clearly keeps increasing. That includes more features to defend networks, but also more features to potentially abuse 👀
0105
Reposted by Eyal Ronen
arxiv cs.CR @arxiv-cs-cr.bsky.social · 16/04/2025
Bradley Morgan, Gal Horowitz, Sioli O'Connell, Stephan van Schaik, Chitchanok Chuengsatiansup, Daniel Genkin, Olaf Maennel, Paul Montague, Eyal Ronen, Yuval Yarom Slice+Slice Baby: Generating Last-Level Cache Eviction Sets in the Blink of an Eye arxiv.org/abs/2504.11208
022
Reposted by Eyal Ronen
Nigel Smart @smartcryptology.bsky.social · 14/04/2025
Congratulations to the new IACR fellows.... Joan Daemen, Thomas Johansson, Anna Lysyanskaya, Pascal Paillier, J.R. Rao, Alon Rosen, Elaine Shi, Bo-Yin Yang. iacr.org/fellows/ #cryptography
iacr.org
IACR Fellows
03511
Reposted by Eyal Ronen
Fastly @fastly.com · 20/03/2025
If you’re a FOSS project dealing with overwhelming AI scraper bots, we will provide free security services for your project at no cost to you ❤️ #TeamSleep thelibre.news/foss-infrast...
thelibre.news
FOSS infrastructure is under attack by AI companies
LLM scrapers are taking down FOSS projects' infrastructure, and it's getting worse.
08632
Reposted by Eyal Ronen
Real World Crypto Symposium @rwc.iacr.org · 26/03/2025
Congratulations to the legendary Adi Shamir on his Levchin Prize win! Dr. Shamir donated the $10K prize money to students sponsorships.
0137
Reposted by Eyal Ronen
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 26/03/2025
Now we have Adi Shamir's invited talk on 'How to Securely Implement Cryptography in Deep Neural Networks' eprint.iacr.org/2025/288.pdf #realworldcrypto
111
Reposted by Eyal Ronen
Shane Harris @shaneharris.bsky.social · 24/03/2025
In 25 years of covering national security, I’ve never seen a story like this: Senior Trump officials discussed planning for the U.S. attack on Yemen in a Signal group--and inadvertently added the editor-in-chief of The Atlantic. www.theatlantic.com/politics/arc...
theatlantic.com
The Trump Administration Accidentally Texted Me Its War Plans
U.S. national-security leaders included me in a group chat about upcoming military strikes in Yemen. I didn’t think it could be real. Then the bombs started falling.
774165096441
Reposted by Eyal Ronen
Martin R. Albrecht @malb.bsky.social · 16/03/2025
*Friends don’t let friends deploy a cryptographic protocol without a formal cryptographic analysis* martinralbrecht.wordpress.com/2025/03/16/a... @kennyog.bsky.social @eyalr0.bsky.social @lenka.sh
martinralbrecht.wordpress.com
Analysis of the Telegram Key Exchange
Together with Lenka Mareková, Kenny Paterson, Eyal Ronen and Igors Stepanovs, we have finally completed our (first, formal, in-depth, computational) analysis of the Telegram key exchange. This work…
0131
Reposted by Eyal Ronen
Kenny Paterson @kennyog.bsky.social · 11/03/2025
It’s finally out - our 107-page analysis of key exchange in Telegram in which we proved (after massive effort) that the bespoke protocol is ok, if you’re willing to make some uncomfy assumptions on the home-grown KDF. With @malb.bsky.social, @eyalr0.bsky.social, Lenka Mareková and Igors Stepanovs.
14210
Eyal Ronen @eyalr0.bsky.social · 11/03/2025
mensfeld.pl/2025/03/brin... Certificates are hard
mensfeld.pl
Certificate Apocalypse: Bringing Your Chromecast Back from the Dead
Learn how to fix your Chromecast 2 that stopped working on March 9, 2025 due to an expired certificate. Simple workarounds for both regular and factory-reset devices until Google releases an official ...
000
Reposted by Eyal Ronen
Nick Sullivan @nicksullivan.org · 19/02/2025
The tentative program for Real World Crypto 2025 is live! rwc.iacr.org/2025/program... A huge thanks to my co-chair @malb.bsky.social and all the amazing program committee members for helping put this together. I'm looking forward to seeing everyone in Sofia! #realworldcrypto
rwc.iacr.org
RWC 2025 program
Real World Crypto Symposium
0149
Reposted by Eyal Ronen
FakeIacr @fakeiacr.bsky.social · 04/02/2025
Because of new tariffs, submissions to crypto with a non US author have a 20% reduction to their page limit.
1215
Reposted by Eyal Ronen
Martin R. Albrecht @malb.bsky.social · 02/02/2025
The list of accepted talk at @rwc.iacr.org is now available: rwc.iacr.org/2025/accepte... Early registration ends 26 February. CC: programme co-chair @nicksullivan.org
rwc.iacr.org
RWC 2025 accepted papers
Real World Crypto Symposium
32917
Reposted by Eyal Ronen
ePrint Updates @eprint.ing.bot · 27/01/2025
How to Prove False Statements: Practical Attacks on Fiat-Shamir (Dmitry Khovratovich, Ron D. Rothblum, Lev Soukhanov) ia.cr/2025/118
Abstract. The Fiat-Shamir (FS) transform is a prolific and powerful technique for compiling public-coin interactive protocols into non-interactive ones. Roughly speaking, the idea is to replace the random coins of the verifier with the evaluations of a complex hash function.

The FS transform is known to be sound in the random oracle model (i.e., when the hash function is modeled as a totally random function). However, when instantiating the random oracle using a concrete hash function, there are examples of protocols in which the transformation is not sound. So far all of these examples have been contrived protocols that were specifically designed to fail.

In this work we show such an attack for a standard and popular interactive succinct argument, based on the GKR protocol, for verifying the correctness of a non-determinstic bounded-depth computation. For every choice of FS hash function, we show that a corresponding instantiation of this protocol, which was been widely studied in the literature and used also in practice, is not (adaptively) sound when compiled with the FS transform. Specifically, we construct an explicit circuit for which we can generate an accepting proof for a false statement.

We further extend our attack and show that for every circuit C and desired output y, we can construct a functionally equivalent circuit C^(*), for which we can produce an accepting proof that C^(*) outputs y (regardless of whether or not this statement is true). This demonstrates that any security guarantee (if such exists) would have to depend on the specific implementation of the circuit C, rather than just its functionality.

Lastly, we also demonstrate versions of the attack that violate non-adaptive soundness of the protocol – that is, we generate an attacking circuit that is independent of the underlying cryptographic objects. However, these versions are either less practical (as the attacking circuit has very large depth) or make some additional (reasonable) assumptions on the underlying cryptographic primitives.
Image showing part 2 of abstract.
03817
Reposted by Eyal Ronen
Real World Crypto Symposium @rwc.iacr.org · 14/01/2025
Registration for RWC 2025 is open! register.iacr.org/conferences/...
register.iacr.org
Before proceeding • IACR
066
Reposted by Eyal Ronen
Mathy Vanhoef @vanhoefm.bsky.social · 14/01/2025
After an embargo of 8 months, we are glad to finally share our USENIX Security '25 paper! We found more than 4 MILLION vulnerable tunneling servers by scanning the Internet. These vulnerable servers can be abused as proxies to launch DDoS attacks and possibly to access internal networks.
25725
Reposted by Eyal Ronen
Benjamin Dowling @bedow.bsky.social · 10/01/2025
Excited to announce a funded PhD position analysing the Social Foundations of Cryptography here at King's College London with me and @malb.bsky.social . Applications open now, feel free to reach out for a chat. social-foundations-of-cryptography.gitlab.io Link in next post!
social-foundations-of-cryptography.gitlab.io
Social Foundations of Cryptography · An EPSRC funded research project grounding cryptographic notions in ethnographic findings.
1108
Reposted by Eyal Ronen
Daniel Gruss @gruss.cc · 05/01/2025
CFP for uASC 25 is still open. We have rolling reviews, and 1 submission is already accepted. If you have interesting results on microarchitecture security (incl. weak threat models or reproducing prior work), check out the CFP at uasc.cc The CFP closes **Jan 28**
uasc.cc
1st Microarchitecture Security Conference (uASC '25)
189