Sign in

Matteo Scarlata

@hjkl.space
60 followers 113 following 5 posts

software occultist

PostsRepliesMedia
Reposted by Matteo Scarlata
Miro Haller @mirohaller.bsky.social · 21/09/2026
We finally finished the universal signature forgery for 1024-bit RSA! 2^32 oracle queries, 1200 core years precomputation, 180 core years for an individual forgery, and 3 years of human labor (no AI involved) by Laura, Adam, Nadia, Emmanuel and me to pull of this computation against real HSMs.
14019
Reposted by Matteo Scarlata
Kenny Paterson @kennyog.bsky.social · 10/09/2026
Our latest “Crypto in the Wild” project, analysing secure email gateways. We give 29 cryptographic attacks on 4 different products, from SEPPmail, Cisco, Proton and CipherMail. Paper to appear at ACM CCS 2026.
11911
Reposted by Matteo Scarlata
Thomas Ptacek @sockpuppet.org · 17/02/2026
"presenting a cornucopia of practical attacks". These are my favorite words ever to have occurred in a cryptography paper.
3549
Matteo Scarlata @hjkl.space · 17/02/2026
You mean Professor Matilda Backendal! 😉
020
Reposted by Matteo Scarlata
Filippo Valsorda @filippo.abyssdomain.expert · 16/02/2026
Frog and Toad with a box illustration. Badly edited text.

Frog put the KEY in a box. "There," he said. "Now we will not SIGN MALICIOUS MESSAGES."
"But we can ASK THE HSM," said Toad.
"That is true," said Frog.
124935
Matteo Scarlata @hjkl.space · 16/02/2026
I always assumed that #passwordmanagers were simple objects -- create a database, encrypt it, send it to the server, done. I could not have been more wrong! At zkae.io, we take a look at all the hidden complexity in cloud password managers, and the #attacks that result from that. (ia.cr/2026/058)
zkae.io
Zero Knowledge (About) Encryption
184
Reposted by Matteo Scarlata
Kenny Paterson @kennyog.bsky.social · 16/02/2026
Do you use a cloud-based password manager? So what's your threat model? Vendors like Bitwarden, Dashlane, LastPass and 1Password offer you "Zero Knowledge Encryption", with statements like: "Not even the team at Bitwarden can read your data (even if we wanted to)." We decided to test this… 1/n
23215
Reposted by Matteo Scarlata
Miro Haller @mirohaller.bsky.social · 11/11/2025
The call for talks for CAW 2026 (a workshop affiliated with Eurocrypt) is out! This year's motto is "cryptography under real-world constraints and threat models", but other applied cryptography is also very welcome. All info is on: caw.cryptanalysis.fun.
1128
Reposted by Matteo Scarlata
Miro Haller @mirohaller.bsky.social · 09/04/2025
This year, #CAW offers the option for remote participation to make our Eurocrypt workshop accessible to the members of our community that cannot or prefer not to travel to Madrid. Register on our website before May 2 (free): caw.cryptanalysis.fun The updated program is below.
062
Reposted by Matteo Scarlata
Kenny Paterson @kennyog.bsky.social · 25/03/2025
Our latest work is out! Breaking and repairing Content-Defined Chunking, with impact across multiple backup systems. Read Kien Tuong Truong’s blog here: blog.ktruong.dev/breaking-cdc
blog.ktruong.dev
Breaking and Fixing Content-Defined Chunking
A collection of my (future) writings about cryptography, music and other random stuff.
1112