Sign in

Kien Tuong Truong

@kientuong114.bsky.social
115 followers 104 following 6 posts

PhD Student at ETH Zurich, Cryptography and more

PostsRepliesMedia
Reposted by Kien Tuong Truong
Miro Haller @mirohaller.bsky.social · 26/07/2026
Don't forget to register for WAC8! Early registration ends today (July 26). Below is our finalized WAC8 program with 8 exciting talks. More infos on: wac8.cryptanalysis.fun
073
Reposted by Kien Tuong Truong
Miro Haller @mirohaller.bsky.social · 10/08/2026
You can also register to attend WAC8--the workshop on attacks in cryptography, an affiliated event with Crypto 2026--remotely (for free). Just fill out this google form: forms.gle/1anNohNaJmtA...
forms.gle
WAC8 Remote Registration
Sign up with an email address to receive the Zoom link to attend the workshop on attacks in cryptography 8 (WAC8) remotely. All information about the workshop is on our website: https://wac8.cryptanal...
164
Kien Tuong Truong @kientuong114.bsky.social · 11/03/2026
@hjkl.space, @mirohaller.bsky.social, @laurahetz.bsky.social, Matilda and I are organizing CAW this year! Fun fact: a few talks that appeared at RWC this year have also been presented at CAW in prior years. Good track record! 10th May 2026, Rome caw.cryptanalysis.fun
073
Kien Tuong Truong @kientuong114.bsky.social · 09/03/2026
Just finished presenting this work at Real World Crypto in Taipei :) TL;DR: We found 2 attacks on Signal (Android, Desktop) where a malicious server can inject messages in conversations. Super fun project! Thanks a bunch to Noemi Terzo, @kennyog.bsky.social, and @cryptojedi.bsky.social
0204
Reposted by Kien Tuong Truong
ePrint Updates @eprint.ing.bot · 09/03/2026
Signal Lost (Integrity): The Signal App is More than the Sum of its Protocols (Kien Tuong Truong, Noemi Terzo, Kenneth G. Paterson) ia.cr/2026/484
Abstract. Signal is a secure messaging app offering end-to-end security for pairwise and group communications. It has tens of millions of users, and has heavily influenced the design of other secure messaging apps (including WhatsApp). Signal has been heavily analysed and, as a result, is rightly regarded as setting the “gold standard” for messaging apps by the scientific community. We present two practical attacks that break the integrity properties of Signal in its advertised threat model. Each attack arises from different features of Signal that are poorly documented and have eluded formal security analyses. The first attack, affecting Android and Desktop, arises from Signal’s introduction of identities based on usernames (instead of phone numbers) in early 2022. We show that the protocol for resolving identities based on usernames and on phone numbers introduced a vulnerability that allows a malicious server to inject arbitrary messages into one-to-one conversations under specific circumstances. The injection causes a user-visible alert about a change of safety numbers, but if the users compare their safety numbers, they will be correct. The second attack is even more severe. It arises from Signal’s Sealed Sender (SSS) feature, designed to allow sender identities to be hidden. We show that a combination of two errors in the SSS implementation in Android allows a malicious server to inject arbitrary messages into both one-to-one and group conversations. The errors relate to missing key checks and the loss of context when cryptographic processing is distributed across multiple software components. The attack is undetectable by users and can be mounted at any time, without any preconditions. As far as we can tell, the vulnerability has been present since the introduction of SSS in 2018. We disclosed both attacks to Signal. The vulnerabilities were promptly acknowledged and patched: the first vulnerability was fixed two days after disclosure, while the second one was patched after eight days. Beyond presenting these devastating attacks on Signal’s end-to-end security guarantees, we discuss more broadly what can be learned about the challenges of deploying new security features in complex software projects.
Image showing part 2 of abstract.
02713
Reposted by Kien Tuong Truong
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 09/03/2026
Next up, 'Signal Lost (Integrity): The Signal App is More than the Sum of its Protocols', presented by Noemi Terzo and Kien Tuong Truong #realworldcrypto
122
Reposted by Kien Tuong Truong
Miro Haller @mirohaller.bsky.social · 11/11/2025
The call for talks for CAW 2026 (a workshop affiliated with Eurocrypt) is out! This year's motto is "cryptography under real-world constraints and threat models", but other applied cryptography is also very welcome. All info is on: caw.cryptanalysis.fun.
1128
Kien Tuong Truong @kientuong114.bsky.social · 12/11/2025
For all the people working under the umbrella term of "Real-World Cryptography": you can't miss CAW 2026! Call for Talks is out now :)
010
Kien Tuong Truong @kientuong114.bsky.social · 07/05/2025
Congrats to @KhanhCrypto (who's not on bsky) for the IACR Grammy Award at #Eurocrypt 🥳 Guess I need to pick up the slack, see you at the next rump session! 😉
060
Reposted by Kien Tuong Truong
ePrint Updates @eprint.ing.bot · 28/03/2025
Breaking and Fixing Content-Defined Chunking (Kien Tuong Truong, Simon-Philipp Merz, Matteo Scarlata, Felix Günther, Kenneth G. Paterson) ia.cr/2025/558
Abstract. Content-defined chunking (CDC) algorithms split streams of data into smaller blocks, called chunks, in a way that preserves chunk boundaries when the data is partially changed. CDC is ubiquitous in applications that deduplicate data such as backup solutions, software patching systems, and file hosting platforms. Much like compression, CDC can introduce leakage when combined with encryption: fingerprinting attacks can exploit chunk length patterns to infer information about the data. To address these risks, many systems—mainly in the cloud backup setting—have developed bespoke mitigations by mixing a cryptographic key into the chunking process. We study these keyed CDC (KCDC) schemes “in the wild”, presenting efficient key recovery attacks against five different KCDC schemes, deployed in the backup solutions Borg, Bupstash, Duplicacy, Restic, and Tarsnap. Our attacks are in a realistic threat model that relies only on weak known or chosen-plaintext capabilities. This shows, in particular, that they fail to protect against fingerprinting attacks. To demonstrate practical exploitability, we also present “end-to-end” attacks on three complete encrypted backup applications, namely Borg, Restic and Tarsnap. These build on our attacks on the underlying KCDC schemes. In an effort to tackle these problems, we introduce the first formal treatment for KCDC schemes and propose a provably secure construction that fulfills a strong notion of security. We benchmark our construction against existing (broken) approaches, showing that it has competitive performance. In doing so, we take a step towards making real-world systems that rely on KCDC more resilient to attacks.
Image showing part 2 of abstract.
031
Reposted by Kien Tuong Truong
Kenny Paterson @kennyog.bsky.social · 25/03/2025
Our latest work is out! Breaking and repairing Content-Defined Chunking, with impact across multiple backup systems. Read Kien Tuong Truong’s blog here: blog.ktruong.dev/breaking-cdc
blog.ktruong.dev
Breaking and Fixing Content-Defined Chunking
A collection of my (future) writings about cryptography, music and other random stuff.
1112
Kien Tuong Truong @kientuong114.bsky.social · 25/03/2025
📄 New Blog Post (+paper!): Breaking and Fixing Content-Defined Chunking To be presented at RWC 2025 blog.ktruong.dev/breaking-cdc/ Joint work with @merzsp, @winterdeaf, Felix Günther, @kennyog We analyze Content-Defined Chunking, mostly in backup systems. Read the blog post for more!
blog.ktruong.dev
Breaking and Fixing Content-Defined Chunking
A collection of my (future) writings about cryptography, music and other random stuff.
020