Sign in

Fredrik Dahlgren

@fegge.bsky.social
363 followers 306 following 119 posts

Cryptography and static analysis @ Trail of Bits

PostsRepliesMedia
Reposted by Fredrik Dahlgren
Ben Adida @benadida.com · 29/09/2026
Ahem... taps 🎙️ We have some news. @voting.works is the first and only open-source voting system to meet federal certification. Ever.
063
Reposted by Fredrik Dahlgren
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 25/09/2026
Italian zero-day maker Dataflow Security generated €63 million in revenue in three years, and the company also has strong ties with former Israeli intelligence veterans, according to an investigation by @irpimedia.eu. irpimedia.irpi.eu/en-inside-th...
irpimedia.irpi.eu
Inside the secretive cyberweapons company that won over Israel’s intelligence elite
Founded in Italy by a young hacker, Dataflow develops code to break into computers and smartphones. Since January, its operations in Israel have been led by Eyal Tsir Cohen, a former senior Mossad off...
0147
Reposted by Fredrik Dahlgren
Miro Haller @mirohaller.bsky.social · 21/09/2026
We finally finished the universal signature forgery for 1024-bit RSA! 2^32 oracle queries, 1200 core years precomputation, 180 core years for an individual forgery, and 3 years of human labor (no AI involved) by Laura, Adam, Nadia, Emmanuel and me to pull of this computation against real HSMs.
14019
Fredrik Dahlgren @fegge.bsky.social · 18/09/2026
Everyone and their mother is using AI to find bugs. We used AI to build static-analysis and formal verification tooling for Miden’s zkVM. The new linter found a signature validation bypass, and the formal verification work resulted in 95 correctness proofs. blog.trailofbits.com/2026/09/18/a...
blog.trailofbits.com
Auditing in the age of (good enough) AI
Before code review even starts, agents let us build custom tooling and formal models. Here’s how six months of building with AI agents helped us find real issues in our Miden zkVM audit.
142
Reposted by Fredrik Dahlgren
François Garillot @huitseeker.bsky.social · 16/09/2026
Formal verification is all the rage, given the excitement about auto-formalization
111
Reposted by Fredrik Dahlgren
Kenny Paterson @kennyog.bsky.social · 10/09/2026
Our latest “Crypto in the Wild” project, analysing secure email gateways. We give 29 cryptographic attacks on 4 different products, from SEPPmail, Cisco, Proton and CipherMail. Paper to appear at ACM CCS 2026.
11911
Fredrik Dahlgren @fegge.bsky.social · 12/09/2026
A new compression side-channel attack on SSH.
054
Fredrik Dahlgren @fegge.bsky.social · 09/09/2026
My colleague Marc found a 20-line Lean ”proof” of Fermat’s last theorem that really fits in the margin! 😁 blog.trailofbits.com/2026/09/09/a...
blog.trailofbits.com
A “proof” of Fermat’s Last Theorem that fits the margin
Fermat’s margin was too narrow for his proof. Ours would have fit just fine, thanks to a wonderfully cursed Lean bug.
221
Fredrik Dahlgren @fegge.bsky.social · 04/09/2026
Claude formalized Fermat’s last theorem in Lean in 11 days using prove2.me. www.anthropic.com/research/for...
anthropic.com
Formalizing Fermat's Last Theorem
Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems.
0133
Reposted by Fredrik Dahlgren
Olivia Guest · Ολίβια Γκεστ @olivia.science · 23/05/2026
sometimes I wonder if people in other fields have any clue what we go through as women in computational fields... (graph from: www.npr.org/sections/mon...)
graph from https://www.npr.org/sections/money/2014/10/21/357629765/when-women-stopped-coding showing medicine, law, and physics as lines going up for percentage of women, while computer science goes dramatically down from the 1980s roughly
841800429
Reposted by Fredrik Dahlgren
Signal @signal.org · 11/08/2026
Introducing Automatic Key Verification! Complementing the existing safety number system, automatic key verification provides an additional, streamlined way to confirm the privacy of your chats. signal.org/blog/automat... TY @cloudflare.social and @trailofbits.bsky.social our independent auditors 💙🙏
signal.org
Introducing Automatic Key Verification
Signal now offers a feature called “automatic key verification” which complements the existing safety number system. Signal is always end-to-end encrypted, and automatic key verification provides an a...
629178
Reposted by Fredrik Dahlgren
Miro Haller @mirohaller.bsky.social · 26/07/2026
Don't forget to register for WAC8! Early registration ends today (July 26). Below is our finalized WAC8 program with 8 exciting talks. More infos on: wac8.cryptanalysis.fun
073
Reposted by Fredrik Dahlgren
ePrint Updates @eprint.ing.bot · 24/07/2026
Bob DyLean: A Framework for the Symbolic Analysis of Cryptographic Protocols in Lean (Théophile Wallez, Cas Cremers) ia.cr/2026/1493
Abstract. Over the last decades, symbolic (Dolev-Yao) methods for the analysis of security protocols have proven to be effective to analyze and establish strong guarantees for widely deployed protocols and systems, such as TLS 1.3, E-voting protocols, EMV, and MLS. On the one hand, analysis methods like Tamarin and ProVerif provide automation and support for user-defined equational theories. On the other hand, methods like DY* offer more flexible and modular reasoning, but hardcode threat models and do not support custom equational theories.

We present DyLean, a framework for the symbolic analysis of cryptographic protocols in the Lean theorem prover. Our framework comprises both a flexible general-purpose symbolic semantics, as well as a concrete proof methodology.

DyLean allows defining protocols and expected security properties; its semantics and equational theories can be customized by the user. Furthermore, the semantics are agnostic of the specific proof methodology: our goal is to provide a generic framework that can be used by the community as a foundation to develop various proof methodologies.

Moreover, we provide a concrete proof methodology inspired by DY, based on trace invariants. Thus, DyLean inherits from the qualities of DY: it is able to analyze protocols involving unbounded loops or datastructures, and is able to compose security proofs in a variety of scenarios. Our proof methodology improves on DY* by allowing for user-defined equational theories and threat models. We exercise DyLean on several focused case studies, which include protocols using merkle trees, ratcheting protocols, post-quantum protocols, and protocols analyzed under different equational theories, which demonstrates that DyLean can effectively analyze protocols with each of these features.
Image showing part 2 of abstract.
084
Reposted by Fredrik Dahlgren
jiska @naehrdine.bsky.social · 11/07/2026
How do the closed-source parts of Apple's Private Cloud Compute work? We had a look at it 🍎👀 Paper: dl.acm.org/doi/abs/10.1... Slides: hpi.de/fileadmin/us...
dl.acm.org
Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence | Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks
0175
Reposted by Fredrik Dahlgren
Museum of Twitter @museum-of-twitter.bsky.social · 03/07/2026
Asia Murphy (aka blk icon kylo ren)

i still don't get bitcoin

@Theophite 
Replying to @am_anatiala

imagine if keeping your car idling 24/7 produced solved Sudokus you could trade for heroin
71373259
Reposted by Fredrik Dahlgren
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 17/06/2026
I'm happy to report that the twenty-two issues Trail of Bits reported in #curl ten days ago have now all been addressed in one way or another. One of them is a pending CVE. They had an engineer spend a week poking on curl.
0152
Reposted by Fredrik Dahlgren
#aio-libs: aiohttp and ecosystem @aio-libs.org · 22/06/2026
Finally, the post about collab w/ @trailofbits.bsky.social is out: blog.trailofbits.com/2026/06/22/i.... #aiohttp was one of the participating projects and got 8 security fixes out of it! #Python
blog.trailofbits.com
Introducing Patch the Planet
Patch the Planet is our joint initiative with OpenAI to assist critical open-source software in the age of machine-speed vulnerability research.
065
Reposted by Fredrik Dahlgren
Filippo Valsorda @filippo.abyssdomain.expert · 22/06/2026
There we go. US Gov tightens post-quantum cryptography transition deadlines for high-value systems to 2030 for key exchange and 2031 for signatures. Also, speeding up the CMVP (FIPS 140 validation) processes. That’s how you know the rush is real. The quantum computers are (potentially) coming.
whitehouse.gov
Securing the Nation Against Advanced Cryptographic Attacks
By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered: Section 1.  Background
411030
Fredrik Dahlgren @fegge.bsky.social · 25/06/2026
We’re helping open-source developers fix the internet together with OpenAI. If you’re an open-source maintainer and would like our (pro bono) help, please reach out! blog.trailofbits.com/2026/06/22/i...
blog.trailofbits.com
Introducing Patch the Planet
Patch the Planet is our joint initiative with OpenAI to assist critical open-source software in the age of machine-speed vulnerability research.
061
Reposted by Fredrik Dahlgren
Erik Angner @erikangner.com · 17/06/2026
Folkhälsomyndighetens generaldirektör fick sparken då hon satte käppar i hjulet för regeringens försök att finansiera statsministerns hustrus verksamhet i herrgården hon fått från friskolelobbyn: www.aftonbladet.se/nyheter/a/Gx... Har Sverige någonsin haft en så korrupt regering?
aftonbladet.se
Skeptisk till ”existentiell hälsa” – fick sparken från myndigheten
Statsministerns fru meddelade att hon ville arbeta med ”existentiell hälsa” på sin herrgård. Ett halvår senare gav regeringen Folkhälsomyndigheten i uppdrag att
25518
Fredrik Dahlgren @fegge.bsky.social · 13/06/2026
Can’t help thinking that this is what happens if you aggresively market your new frontier model as the cyber infinity gauntlet. www.anthropic.com/news/fable-m...
anthropic.com
Statement on the US government directive to suspend access to Fable 5 and Mythos 5
The US government has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States.
020
Fredrik Dahlgren @fegge.bsky.social · 12/06/2026
Factoring short-sleeve RSA keys blog.trailofbits.com/2026/06/12/f...
blog.trailofbits.com
Factoring "short-sleeve" RSA keys with polynomials
We found hundreds of weak RSA and DSA keys with biased bits that we could quickly factor using a new polynomial-based cryptanalytic technique.
0134
Reposted by Fredrik Dahlgren
Miro Haller @mirohaller.bsky.social · 11/06/2026
The Workshop on Attacks in Cryptography 8 (WAC8) website is finally up, and our call for talks is open. Submit your cool cryptanalysis before July 3! We'll also invite speakers. If you had a favorite cryptographic attack from the last two years that we should invite, please put it in the comments.

call for talks

WAC accepts proposals for contributed talks. Submissions will be evaluated based on their relevance to the following topics:
- Cryptanalysis of deployed cryptography
- Cryptanalysis of recently suggested cryptographic schemes or primitives
- New cryptoanalytic techniques
- Systems attacks breaking cryptography or bypassing underlying assumptions

Please include the following information in your contributed talk submission.
- Title.
- Description of the talk content, including: short abstract (to be published on the website on talk acceptance), and one of the following three: extended abstract describing the talk. [preferred option], a full paper and a short description of which aspects the talk will focus on. slides for a presentation, together with either speaker notes or a short outline of the non-visual content of the talk.
- Speaker information: Name, Affiliation, Short bio (to be published on the website on talk acceptance), A brief description of the relevant experience of the speaker, e.g. links to previous talks.

Submit your proposal by email to the organizers at wac@cryptanalysis.fun by July 3, 2026 AoE.
074
Fredrik Dahlgren @fegge.bsky.social · 08/06/2026
Mythos can dribble a bowling ball. Mythos counted to infinity… twice. Mythos can kill two stones with one bird. Mythos can speak Braille. Etc etc…
A screenshot of a tweet hyping Anthropic’s new model Claude Mythos. The tweet reads:

Mythos 5: We're Not Ready
- Mythos is extremely strong at SVG generation, producing highly detailed outputs that can take several minutes to create
- It is exceptionally good at creating graphics, games, websites, and complex Ul designs
- Mythos is expected to set a new bar for web development and frontend generation, especially for design heavy workflows
- It can also generate surprisingly good music through code
- Anthropic's data suggests Mythos can achieve up to 52x training code speedups in certain optimization tasks, compared to roughly 4x for skilled humans on similar workloads
- Mythos is expected to be extremely expensive, the public version will likely be a nerfed version of the current testing model
139022
Fredrik Dahlgren @fegge.bsky.social · 05/06/2026
You know that time we forged a ZK proof to pretend we beat Google at factoring? Well, this time we beat them for real. x.com/trailofbits/...
x.com
Trail of Bits on X: "We beat Google's quantum circuit again, and we didn't have to forge a proof this time. Today we're releasing trailmix, a toolkit for quantum "kickmix" circuits. It includes 5 new circuits we built for elliptic curve addition, the hardest part of Shor's algorithm. https://t.co/X3jYoU5udB" / X
We beat Google's quantum circuit again, and we didn't have to forge a proof this time. Today we're releasing trailmix, a toolkit for quantum "kickmix" circuits. It includes 5 new circuits we built for elliptic curve addition, the hardest part of Shor's algorithm. https://t.co/X3jYoU5udB
0121
Fredrik Dahlgren @fegge.bsky.social · 11/05/2026
This is amazing!
040
Reposted by Fredrik Dahlgren
Catalin Cimpanu @campuscodi.risky.biz · 10/05/2026
The FreeBSD team has patched a remote code execution in its operating system that impacts all versions released since 2005 Tracked as CVE-2026-42511, the vulnerability resides in the FreeBSD DHCP client and is extremely easy to exploit aisle.com/blog/aisle-d...
03919
Reposted by Fredrik Dahlgren
Miro Haller @mirohaller.bsky.social · 04/05/2026
The Cryptographic Applications Workshop (CAW) happens this Sunday in Rome! Just a reminder that if you're not coming to Rome you can still attend remotely. Just register here: forms.gle/2JZ7hLs8diQM... before May 8. See caw.cryptanalysis.fun for more infos and our program.
Program of CAW, also on our website: https://caw.cryptanalysis.fun/
086
Reposted by Fredrik Dahlgren
Aidan Moher @aidanmoher.com · 01/05/2026
Remaking Stand By Me but they find an alive guy.
1311718
Fredrik Dahlgren @fegge.bsky.social · 28/04/2026
Love that pigeons are apparently ~ the same category of mythical beasts as goblins and gremlins.
010
Reposted by Fredrik Dahlgren
Daniel Wiklander @dwiklander.se · 24/04/2026
Den här bilden säger så mycket:
2207
Reposted by Fredrik Dahlgren
Dr. Jonathan Foley @globalecoguy.bsky.social · 19/04/2026
Do you want to see the "big picture" on climate change? Here it is. Emissions are on the left, and include CO2, CH4, N2O, and f-gases. Natural CO2 sinks (from healthy forests & oceans) are on the right. And carbon removal, what little there is, is on the right, too. All expressed as GWP100.
13364162
Reposted by Fredrik Dahlgren
Filippo Valsorda @filippo.abyssdomain.expert · 20/04/2026
There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers. This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.
words.filippo.io
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.
312135
Fredrik Dahlgren @fegge.bsky.social · 17/04/2026
Two weeks ago, Google published a paper proving in zero-knowledge that they had an efficient implementation of Shor's algorithm. Today, Trail of Bits can prove that we have an even better implementation which beats Google's on all metrics! 🫢 blog.trailofbits.com/2026/04/17/w...
A table listing total operations, number of qubits, and Toffoli-gate count for Google's low-gate and low-qubit implementations, and Trail of Bits' implementation. The Trail of Bits implementation beats Google's on every metric.
18230
Fredrik Dahlgren @fegge.bsky.social · 17/04/2026
Basically every home-grown E2EE protocol be like:
1174
Fredrik Dahlgren @fegge.bsky.social · 12/04/2026
Orban has conceded the election in Hungary and Europe has one less dictator. This is worth celebrating! ❤️ www.theguardian.com/world/live/2...
theguardian.com
Hungary election live: Viktor Orbán concedes defeat in Hungarian election after 16 years in power
Long-serving prime minister beaten by opposition after early results showed clear lead
010
Reposted by Fredrik Dahlgren
Chris Peikert @chrispeikert.bsky.social · 09/04/2026
“You shouldn't transition to post-quantum because you are confident quantum computing will happen; you should only avoid transitioning because you are confident quantum computing will not happen, and none of the experts are confident in that anymore.”
095
Reposted by Fredrik Dahlgren
George Monbiot @georgemonbiot.bsky.social · 13/03/2026
The additional cost of ONE fossil fuel price spike on the scale of 2022 = the ENTIRE COST of Net Zero by 2050. We get precisely nothing in return for the first cost, and a whole new, more secure and cheaper energy system from the second one. #NoBrainer www.theccc.org.uk/2026/03/11/c...
theccc.org.uk
​​​​Cost of Net Zero by 2050 less than a single fossil fuel price shock​ – CCC  - Climate Change Committee
The independent, statutory body tested its cost and energy security conclusions against different scenarios. It found that the total additional cost of a single fossil fuel price spike of 2022 magnitu...
191152559
Fredrik Dahlgren @fegge.bsky.social · 12/03/2026
So well deserved.
010
Reposted by Fredrik Dahlgren
Fight Chat Control @fightchatcontrol.bsky.social · 12/03/2026
UPDATE: The European Parliament voted today to *end* untargeted mass scanning of private communications, firmly rejecting the error-prone and unconstitutional surveillance practices of recent years! Next: trilogue negotiations w/ Commission and Council.
5402183
Reposted by Fredrik Dahlgren
David Ho @davidho.bsky.social · 12/03/2026
The 2026 National Science Foundation budget is $8.75 Billion.
nytimes.com
First 6 Days of Iran War Cost U.S. $11.3 Billion, Pentagon Says
4044152028
Fredrik Dahlgren @fegge.bsky.social · 05/03/2026
A complete authentication bypass in pac4j-jwt. 😬 www.codeant.ai/security-res...
codeant.ai
CVE-2026-29000: Critical Auth Bypass in pac4j-jwt: Full PoC Using Only a Public Key
CodeAnt AI found a critical authentication bypass in pac4j-jwt where an attacker can impersonate any user using only the RSA public key. Full PoC and disclosure.
020
Reposted by Fredrik Dahlgren
ePrint Updates @eprint.ing.bot · 05/03/2026
Secure Cloud Storage: Modularization, Network Adversaries and Adaptive Corruptions (Jonas Janneck, Doreen Riepel) ia.cr/2026/434
Abstract. End-to-end cloud storage solutions are deployed at large scale, yet recent works have demonstrated severe attacks against their confidentiality and integrity. Motivated by this, a first formal treatment of secure cloud storage was given at CRYPTO 2024 by Backendal, Davis, Günther, Haller and Paterson (BDGHP). They define syntax and security notions, capturing client-to-client security of cloud storage schemes with respect to a password distribution. They also give an efficient construction using the Two-Hash Diffie-Hellman (2HDH) OPRF and standard cryptographic building blocks, which they prove secure under selective corruptions in the random oracle model. However, several aspects of practical security guarantees remain open. We extend and refine the work of BDGHP along multiple dimensions, advancing the analysis of secure cloud storage schemes. First, we prove that their construction can be proven secure against adaptive corruptions (with a slight modification), circumventing technical challenges posed by file sharing. Second, we modularize the scheme further by introducing an abstraction for the authentication procedure. This allows us to identify the concrete role of 2HDH and alternative instantiations. Third, we introduce a weaker model that captures adversaries who can arbitrarily control the network, except during registration. This allows us to prove concrete guarantees about online password guessing attacks, whereas the stronger model inherently allows for offline guessing. Finally, we formalize and prove explicit authentication, relying on the security of our new authentication abstraction and the MAC scheme, where the latter was previously not used in the security analysis.
Image showing part 2 of abstract.
021
Reposted by Fredrik Dahlgren
Anders Nilsson @etwasanders.bsky.social · 25/02/2026
Två citatrubriker med tillhörande bilder:
1.	”Jag var inte färdig med målningen” + bild på Jesusmålningen i en spansk kyrka som förstördes av en amatörmålare.
2.	”Romina Pourmokhtari (L): ’Vi är inte färdiga med klimatarbete i Sverige’” + bild på nöjd klimat- och miljöminister.
726698
Reposted by Fredrik Dahlgren
Gadi Evron @gadievron.bsky.social · 16/01/2026
I'm a Trail of Bits fan. Can you blame me? A couple of days ago they released Claude Code skills, from reversing and vuln research to burnout detection. github.com/trailofbits/...
github.com
GitHub - trailofbits/skills: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows - trailofbits/skills
0114
Reposted by Fredrik Dahlgren
Sharon 🪳🌹 @sharonk.bsky.social · 21/01/2026
come on become a world power [EU]
121369210
Fredrik Dahlgren @fegge.bsky.social · 22/01/2026
Interesting post/research by Sean Heelan investigating the current state of exploit generation using frontier models like GPT-5.2 and Opus 4.5. sean.heelan.io/2026/01/18/o...
sean.heelan.io
On the Coming Industrialisation of Exploit Generation with LLMs
Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS Javascript interpreter. I adde…
000
Reposted by Fredrik Dahlgren
Bert Hubert 🇺🇦🇪🇺🇺🇦 @berthubert.bsky.social · 23/12/2025
I do appreciate the US state department strengthening my case here with their sanctions on former EU officials & other supporters of EU digital safety acts just now: berthub.eu/articles/pos...
berthub.eu
It is no longer safe to move our governments and societies to US clouds - Bert Hubert
The very short version: it is madness to continue transferring the running of European societies and governments to American clouds. Not only is it a terrible idea given the kind of things the “King o...
18355