Sign in

François Dupressoir

@francois.dupressoir.eu
109 followers 66 following 69 posts

Proof nerd, dad, computer scientist.

PostsRepliesMedia
Reposted by François Dupressoir
Chloe Martindale @chloelono.mathstodon.xyz.ap.brid.gy · 26/09/2026
Been at FUTURES discovery day today at We the Curious in Bristol with @compscibristol.bsky.social Thank especially to @fdupress and Alma Oracevic who have been spreading the joy of cracking codes alongside me all day!
A tabletop stall at a science fair. There is a treasure chest with coloured chains around it and matching coloured clue cards. There is a poster saying "Can you Crack the Code?", pencils and paper, stickers, and 2 code wheels for solving Caesar ciphers.
001
Reposted by François Dupressoir
ghost malone ergo propter bones @proptermalone.bsky.social · 13/07/2026
just to be excruciatingly clear it is also not okay to shoot the target of your warrant as an arresting LEO. the warrant is not a warrant to shoot someone. it is a warrant for arrest.
131399223
François Dupressoir @francois.dupressoir.eu · 22/05/2026
Sometimes I wonder if it's not the opposite: AI safety is being used to define what human values are (or should be). It has the advantage of coming along with the perfect tech to enforce them.
010
Reposted by François Dupressoir
Doreen Riepel @doreenriepel.bsky.social · 08/05/2026
Join us tomorrow for ProTeCS, one of Eurocrypt’s affiliated events! We are thankful to have two amazing invited speakers, Bart Mennink and Mike Rosulek! We are also happy to have seven contributed talks from the community. Check out our full program here: protecs-workshop.gitlab.io/program
protecs-workshop.gitlab.io
Program
Workshop on Proofs and Proof Techniques for Cryptographic Security. Affiliated with Eurocrypt 2026.
163
François Dupressoir @francois.dupressoir.eu · 04/05/2026
As an outsider to both US and Indian politics and journalism, I find it funny that having to specify "don't make stuff up" is better than journalism. Wait. No. "Worrying" is the word I was looking for.
100
Reposted by François Dupressoir
Sabine Oechsner @proofnerd.bsky.social · 17/04/2026
I'm looking for a PhD student to work with me on formal verification for cryptographic protocols. This is a 4-year position at VU Amsterdam, co-supervised with Kristina Sojakova. Send me an email if you want to know more!
11013
François Dupressoir @francois.dupressoir.eu · 16/04/2026
Yes. It was linked from the section on requirements, which also cites a whole bunch of ETSI standards.
020
François Dupressoir @francois.dupressoir.eu · 16/04/2026
Check Annex A? It's an OpenID cred, it looks like.
110
Reposted by François Dupressoir
ePrint Updates @eprint.ing.bot · 12/04/2026
Optimizing and Implementing Threshold MAYO (Diego Aranha, Giacomo Borin, Sofia Celi, Guilhem Niot) ia.cr/2026/710
Abstract. Threshold signatures distribute trust across multiple parties, eliminating single points of failure and reducing insider and key-exfiltration risks—properties that are increasingly important for high-assurance deployments and recently emphasized by NIST’s Multi-Party Threshold Cryptography (MPTC) initiative. We present a practical t-out-of-n threshold variant and emulation of MAYO, a post-quantum signature candidate to NIST’s call for additional signatures. Our proposal builds upon the threshold MAYO design of Celi, Escudero and Niot (PQCrypto2025), which we significantly refine to achieve practical performance. To this end, we introduce two algorithmic modifications to MAYO tailored for the distributed setting: (1) Explicit-Salt MAYO, which allows for pre-determined salts to enable a single-round online phase; and (2) Depth-Reduced MAYO, which restructures the signing algorithm to minimize the depth of secret-dependent operations. We then propose a unified protocol framework that integrate these techniques, plus other MPC specific optimizations, with the goal of minimizing online latency. Finally, we provide a concrete instantiation and local emulation in the dishonest majority setting, secure against active adversaries. Our emulation shows that threshold signing is practical at typical threshold sizes and amenable to deployment. By releasing an open-source implementation and reporting end-to-end performance, this work offers a concrete reference for the thresholdization of post-quantum signatures. Clearly the aforementioned framework is not limited to MAYO, and can be applied to the UOV family of signatures more generally.
Image showing part 2 of abstract.
032
François Dupressoir @francois.dupressoir.eu · 22/03/2026
Yeah, that's evolved into Nearby Share, which then became Quick Share. en.wikipedia.org/wiki/Quick_S...
010
François Dupressoir @francois.dupressoir.eu · 22/03/2026
I think what you're talking about is QuickShare? Google and Samsung both maintain their own, incompatible with each other. I often lean on LocalSend to share files with not-me over the same network. (And I just use syncthing to share with me.)
100
François Dupressoir @francois.dupressoir.eu · 19/03/2026
Can one make money from that?
000
François Dupressoir @francois.dupressoir.eu · 04/03/2026
Quantum computers break ECC as well.
110
Reposted by François Dupressoir
School of Computer Science University of Bristol @compscibristol.bsky.social · 25/02/2026
We’re hiring in Artificial Intelligence We are recruiting two Lecturers / Senior Lecturers in AI to join our growing, world-leading community. 📅 Closing date: 24 March 🔗 Full details & apply: www.bristol.ac.uk/jobs/find/de... Please share with anyone who might be interested.
011
François Dupressoir @francois.dupressoir.eu · 04/02/2026
Corsica?
media.tenor.com
a painting of napoleon giving a thumbs up sign
Alt: a painting of napoleon giving a thumbs up sign
110
François Dupressoir @francois.dupressoir.eu · 31/01/2026
This was a fun piece of work, if your idea of fun is trying to prove false for a month before realising that the RFC and its reference implementation are equivalent for the parameters defined in the RFC (and elsewhere) but not for all values of the parameters. Fortunately for me, it's mine.
021
Reposted by François Dupressoir
Doreen Riepel @doreenriepel.bsky.social · 30/01/2026
Planning your trip to Eurocrypt or looking for an excuse to still go? The reviewers did not appreciate your too involved or too elegant proofs? Consider submitting a talk to ProTeCS (protecs-workshop.gitlab.io), an affiliated event of EC, where we celebrate proofs as independent objects of study!
protecs-workshop.gitlab.io
Call for Presentations
Workshop on Proofs and Proof Techniques for Cryptographic Security. Affiliated with Eurocrypt 2026.
1114
Reposted by François Dupressoir
ePrint Updates @eprint.ing.bot · 25/01/2026
Extending RISC-V to Support Flexible-Radix Multiply-Accumulate Operations (Isaar Ahmad, Hao Cheng, Johann Großschädl, Daniel Page) ia.cr/2026/108
Abstract. Specified as part of the (standard, optional) M extension, the mul and mulhu instructions reflect support for unsigned integer multiplication in RISC-V base Instruction Set Architectures (ISAs) such as RV32I and RV64I: given w-bit integers x and y for a word size w, they respectively produce the less- and more-significant w bits of the (2 · w)-bit product r = x × y. This typically minimal, and hence RISC-like form contrasts sharply with many alternative ISAs. For example, ARMv7-M includes a rich set of multiply and multiply-accumulate instructions; these cater for a wide variety of important use-cases in cryptography, where multi-precision integer arithmetic is often a central requirement. In this paper, we explore the extension of RV32I and RV64I, i.e., an Instruction Set Extension (ISE), with richer support for unsigned integer multiplication. Our design has three central features: 1) it includes dedicated carry propagation and multiply-accumulate instructions, 2) those instructions allow flexible selection of the radix (thus catering for reduced- and full-radix representations), and 3) the design can be considered for any w, and so uniformly across both RV32I and RV64I. A headline outcome of our evaluation is that, for X25519-based scalar multiplication, use of the ISE affords 1.5× and 1.6× improvement for full- and reduced-radix cases, respectively, on RV32I, and 1.3× and 1.7× improvement for full- and reduced-radix cases, respectively, on RV64I.
Image showing part 2 of abstract.
011
Reposted by François Dupressoir
ePrint Updates @eprint.ing.bot · 25/01/2026
Verified non-recursive calculation of Beneš networks applied to Classic McEliece (Wrenna Robson, Samuel Kelly) ia.cr/2026/107
Abstract. The Beneš network can be utilised to apply a single permutation to different inputs repeatedly. We present novel generalisations of Bernstein’s formulae for the control bits of a Beneš network and from them derive an iterative control bit setting algorithm. We provide verified proofs of our formulae and prototype a a provably correct implementation in the Lean language and theorem prover. We develop and evaluate portable and vectorised implementations of our algorithm in the C programming language. Our implementation utilising Intel’s Advanced Vector eXtensions 2 feature reduces execution latency by 25% compared to the equivalent implementation in the libmceliece software library.
031
François Dupressoir @francois.dupressoir.eu · 07/01/2026
"Designing and crafting good envelopes is really hard, you know?" he writes, for the person whose career is to design and craft really good envelopes to read.
030
François Dupressoir @francois.dupressoir.eu · 07/01/2026
"I want to send you a message. Would you prefer I send it on a postcard, or on a letter inside an envelope?" "Obviously on a postcard. Someone could open the envelope and give you a false sense of security." "Ur. What?"
120
François Dupressoir @francois.dupressoir.eu · 20/12/2025
OK, I've just started skimming through, and the first thing I notice is multi-user security definitions. I'm now sitting up right and wondering if I should go to the office to print it out... This is very nice.
110
François Dupressoir @francois.dupressoir.eu · 20/12/2025
I saw that. And a nice piece of cryptographic design as well.
010
François Dupressoir @francois.dupressoir.eu · 25/11/2025
It's fine as long as all voters get a chance to double vote.
010
François Dupressoir @francois.dupressoir.eu · 21/11/2025
Perfect time to switch to vi.
110
François Dupressoir @francois.dupressoir.eu · 08/10/2025
A joyful face for a joyful book.
020
François Dupressoir @francois.dupressoir.eu · 05/10/2025
SUBMIT
111
Reposted by François Dupressoir
ePrint Updates @eprint.ing.bot · 11/09/2025
Faster Verification of Faster Implementations: Combining Deductive and Circuit-Based Reasoning in EasyCrypt (José Bacelar Almeida et al.) ia.cr/2025/1607
Abstract. We propose a hybrid formal verification approach that combines high-level deductive reasoning and circuit-based reasoning and apply it to highly optimized cryptographic assembly code. Our approach permits scaling up formal verifi- cation in two complementary directions: 1) it reduces the proof effort required for low-level functions where the computation logics are obfuscated by the intricate use of architecture-specific instructions and 2) it permits amortizing the effort of proving one implementation by using equivalence checking to propagate the guarantees to other implementations of the same computation using different optimizations or targeting different architectures. We demonstrate our approach via an extension to the EasyCrypt proof assistant and by revisiting formally verified implementations of ML-KEM in Jasmin. As a result, we obtain the first formally verified implementation of ML-KEM that offers performance comparable to the fastest non-verified implementation in x86-64 architectures.
011
François Dupressoir @francois.dupressoir.eu · 20/07/2025
This is exactly the setup in this 5-bit experiment: the DL instance is set up in a subgroup of the curve of order 2^5 = 32. There's a reason we usually pick prime order subgroups.
000
François Dupressoir @francois.dupressoir.eu · 20/07/2025
Uh... Working in a subgroup of order 32 seems... ill advised. Even with a 256-bit key, if I pick 2^256 as the order of the group I set up my discrete logarithm instance in, Pohlig-Hellman gives a classical attack in 512 guesses max. (256 on average.) No need for a quantum computer here.
100
François Dupressoir @francois.dupressoir.eu · 29/06/2025
You have 12 usable knuckles on each hand. (Usable because you can point to them nicely with your conveniently opposable thumb.)
100
François Dupressoir @francois.dupressoir.eu · 28/06/2025
This is now also implemented in Rosenpass. (With a more complex PQ key exchange layer.) rosenpass.eu
rosenpass.eu
Rosenpass
Build post-quantum-secure VPNs with WireGuard!
020
François Dupressoir @francois.dupressoir.eu · 28/06/2025
Just in case anyone feels really excited, this closed 10 days ago. ICYMI... Tough, you missed it.
000
François Dupressoir @francois.dupressoir.eu · 24/06/2025
Other governments are still (for now) linking government procurement and transition, and generally aligned on adoption. (France likes XMSS, Germany also likes Classic McEliece.) Also strong signs that other countries are picking up the advocacy piece. I'm not going to say it so I don't jinx it.
110
Reposted by François Dupressoir
ePrint Updates @eprint.ing.bot · 20/06/2025
Threshold Signatures Reloaded: ML-DSA and Enhanced Raccoon with Identifiable Aborts (Giacomo Borin, Sofía Celi, Rafael del Pino, Thomas Espitau, Guilhem Niot, Thomas Prest) ia.cr/2025/1166
Abstract. Threshold signatures enable multiple participants to collaboratively produce a digital signature, ensuring both fault tolerance and decentralization. As we transition to the post-quantum era, lattice-based threshold constructions have emerged as promising candidates. However, existing approaches often struggle to scale efficiently, lack robustness guarantees, or are incompatible with standard schemes — most notably, the NIST-standard ML-DSA. In this work, we explore the design space of Fiat-Shamir-based lattice threshold signatures and introduce the two most practical schemes to date. First, we present an enhanced TRaccoon-based [DKM+24] construction that supports up to 64 participants with identifiable aborts, leveraging novel short secret-sharing techniques to achieve greater scalability than previous state-of-the-art methods. Second — and most importantly — we propose the first practical ML-DSA-compatible threshold signature scheme, supporting up to 6 users. We provide full implementations and benchmarks of our schemes, demonstrating their practicality and efficiency for real-world deployment as protocol messages are computed in at most a few milliseconds, and communication cost ranges from 10.5 kB to 525 kB depending on the threshold.
Image showing part 2 of abstract.
072
François Dupressoir @francois.dupressoir.eu · 20/06/2025
That is called a cryptographic reduction.
030
François Dupressoir @francois.dupressoir.eu · 20/06/2025
An emoji, crying with laughter. Heavy tears are streaming down its face, suggesting that it is also crying with crying.
010
François Dupressoir @francois.dupressoir.eu · 18/06/2025
The joys of the Outlook web client.
110
François Dupressoir @francois.dupressoir.eu · 14/06/2025
"we are simply moving assumptions to a different level of the stack" is all cryptography has ever been about, though. In the end, it's all about informing risk management decisions and moving risk. The fact that there's nerdy stuff in the way means we get clever people working on it, which is nice.
020
François Dupressoir @francois.dupressoir.eu · 14/06/2025
I think you simplified that a bit too far, there... The article (and its actual title) are very clear that being fluent with multiplication is good, but that the practice of teaching to the test is not.
000
François Dupressoir @francois.dupressoir.eu · 07/06/2025
A tool that fails safe is more worthy of trust than a tool that fails badly, though. Given that a hybrid KEM is a KEM, I expect it to be made by the tool makers, not by the tool users.
100
François Dupressoir @francois.dupressoir.eu · 08/05/2025
Sorry I missed it, and happy birthday!
120
François Dupressoir @francois.dupressoir.eu · 04/05/2025
I might need to start reining in the beard. I look very preacher-y. Thanks for organising. Looking forward to participate without standing at the front next year :)
120
François Dupressoir @francois.dupressoir.eu · 18/04/2025
I'd like a lawyer, now.
010
François Dupressoir @francois.dupressoir.eu · 18/04/2025
I simply read the second "breaking" as in breaking news and temporarily found you extremely clever.
110
François Dupressoir @francois.dupressoir.eu · 09/04/2025
vim + vimtex (github.com/lervag/vimtex) + sioyek (sioyek.info) Not sure how good sioyek is on mac.
sioyek.info
Sioyek
021
François Dupressoir @francois.dupressoir.eu · 03/04/2025
Douglas (@douglas.stebila.ca), Cas and Vincent are excellent speakers indeed. Much less sure about that second guy.
020
François Dupressoir @francois.dupressoir.eu · 21/03/2025
Slush 'za?
120
François Dupressoir @francois.dupressoir.eu · 17/03/2025
Thank you for your service.
110
François Dupressoir @francois.dupressoir.eu · 11/03/2025
Sorry to have to miss it. I'll try to make sure I enable Bristol people who are most affected to join.
010