Sign in

Daniel Hugenroth

@lambda.bsky.social
338 followers 60 following 33 posts

Computer Security Researcher @ Cambridge (www.danielhugenroth.com) and Co-Founder @ Light Squares (www.lightsquares.dev)

PostsRepliesMedia
Daniel Hugenroth @lambda.bsky.social · 18/08/2026
Had a look at how cargo-vet is doing (spoiler: growing quickly). I really enjoy it for my projects and was wondering how projects deal with audit burden (especially with many crate updates). Wrote up a little summary here: lightsquares.dev/blog/cargo-v... 🦀
lightsquares.dev
A look at cargo-vet in 2026
Cargo-vet requires audits of third-party Rust dependencies before they ship. We analyzed 408 open-source projects to measure adoption, audit workload, exemptions, and audit lag.
121
Reposted by Daniel Hugenroth
Martin Kleppmann @martin.kleppmann.com · 08/12/2025
New blog post! ✨ I argue that AI will make formal verification go mainstream. martin.kleppmann.com/2025/12/08/a... Three reasons for this: 1. LLMs are getting increasingly good at writing proofs using proof assistants. This will make formal verification vastly cheaper than it's been to date.
martin.kleppmann.com
Prediction: AI will make formal verification go mainstream — Martin Kleppmann’s blog
1416929
Daniel Hugenroth @lambda.bsky.social · 10/11/2025
@arberesford.bsky.social and I are giving a talk on deploying secure whistleblower technology in practice this Wednesday (12th Nov) at the @cst.cam.ac.uk in Cambridge (3pm)—covering the five year journey of CoverDrop. 🙌 Join us online or in-person: www.cst.cam.ac.uk/seminars/lis...
cst.cam.ac.uk
From research lab to newsroom: deploying secure whistleblower technology in practice | Department of Computer Science and Technology
In a functioning democracy, a free press plays a vital role in holding powerful institutions to account. But for journalism to thrive, citizens must be able to contact reporters securely—especially wh...
130
Daniel Hugenroth @lambda.bsky.social · 24/10/2025
How to trust that the binaries that we deploy are truthfully built from the correct source code? 🤝 Just back from ACM CCS '25 🌏 where we presented Attestable Builds as a solution to this challenge. It complements Reproducible Builds and uses TEEs as a trust anchor. With @coderlime.bsky.social
The picture shows Mario and Daniel presenting the last slide of their presentation at ACM CCS 2025 in Taipei. The text on the slide reads: A-Bs provide source-to-binary provenance using TEEs and sandboxing; complements Reproducible Builds and both can be combined in an any-trust model; practical evaluation (see our GitHub) and formal verification using Tamarin.
151
Daniel Hugenroth @lambda.bsky.social · 29/07/2025
One of my favourite CoverDrop details: out-of-band verification of the trusted organization key which signs the entire key hierarchy. Its digest is included in the imprint of every printed Guardian newspaper, removing the need to trust CAs 🔑🗞️ more details: www.coverdrop.org
The picture shows a smartphone and the imprint of a newspaper. The smartphone displays a screen from the SecureMessaging feature showing a key digest. The newspaper imprint shows the same digest. The digest consists of a number of randomly-looking letters and digits.
16229
Daniel Hugenroth @lambda.bsky.social · 19/07/2025
Audits of AI/ML systems while protecting model IP and keeping the audit data confidential 🤫 @inxoy.bsky.social is at the ICML TAIG workshop today, presenting our work on Attestable Audits: arxiv.org/html/2506.23... with Bill Marino and @arberesford.bsky.social
arxiv.org
Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments
033
Daniel Hugenroth @lambda.bsky.social · 17/07/2025
Super excited that Jenny is presenting our new paper on "Web Authentication and Recovery in the Age of E2EE" at PETS today! 🎉🎉 Tons of interesting insights for a world in which we are moving away from passwords, and E2EE data becomes more long-term and critical. petsymposium.org/popets/2025/...
petsymposium.org
131
Daniel Hugenroth @lambda.bsky.social · 27/06/2025
CoverDrop involved users from the very beginning—avoiding the “solution looking for problem” trap. Big shout out to @mansoor.bsky.social , Diana, and @arberesford.bsky.social for getting this right from the very beginning by running two very insightful workshops with journalists and engineers.
140
Daniel Hugenroth @lambda.bsky.social · 20/06/2025
This announcement really should have our lead Rustaceans @itsibitzi.dev and @zekehg.bsky.social on top 🦀! CoverDrop's implementation journey has been demonstrating the immense strengths that lie in Rust's type system and the mature tool chain. Looking forward to all the talk in September!
130
Reposted by Daniel Hugenroth
Nieman Lab @niemanlab.org · 09/06/2025
The Guardian app’s own data flows make leaks indistinguishable from regular traffic — cutting off one of the easiest ways for a repressive government or a corporate boss to identify a leaker. www.niemanlab.org/2025/06/the-...
niemanlab.org
The Guardian’s new whistleblower tool buries leaks to journalists within its own readers’ everyday traffic
Think "I am Spartacus!" — but for leakers.
14622
Reposted by Daniel Hugenroth
Martin Kleppmann @martin.kleppmann.com · 09/06/2025
Congratulations @lambda.bsky.social! Today @theguardian.com is launching a new way for whistleblowers to anonymously contact journalists, based on years-long research by Daniel and other colleagues. www.theguardian.com/gnm-press-of...
theguardian.com
The Guardian launches Secure Messaging, a world-first from a media organisation, in collaboration with the University of Cambridge
Secure Messaging is a new innovation for confidential story-sharing and source protection, underpinning the Guardian’s commitment to investigative journalism. The Guardian has published the open sourc...
1396151
Daniel Hugenroth @lambda.bsky.social · 09/06/2025
We launched CoverDrop 🎉 providing sources with a secure and anonymous way to talk to journalists. Having started five years ago as a PhD research project, this now ships within the Guardian app to millions of users—all of which provide cover traffic. Paper, code, and more info: www.coverdrop.org
coverdrop.org
CoverDrop: Blowing the Whistle Through A News App
15920
Daniel Hugenroth @lambda.bsky.social · 28/04/2025
Greatly enjoyed talking at JKU Linz about our Sloth 🦥 library which uses Secure Enclaves (SEs) for key stretching and deniable encryption. Importantly, it works around Android/iOS API limitations and, therefore, Sloth is available to regular apps on most smartphones without modifications.
Panorama of Linz
100
Daniel Hugenroth @lambda.bsky.social · 07/04/2025
It's done! The final lecture slides and notes for "P79 Cryptography and Protocol Engineering" are now online: www.cl.cam.ac.uk/teaching/242... 🎉. This is the first time that @martin.kleppmann.com and I have done this course—we very much welcome feedback, corrections, and suggestions for next time
cl.cam.ac.uk
Department of Computer Science and Technology – Course pages 2024–25: Cryptography and Protocol Engineering – Course materials
2275
Daniel Hugenroth @lambda.bsky.social · 29/01/2025
I am quite excited that our brand-new module "P79: Cryptography and Protocol Engineering" has its first lecture today! @martin.kleppmann.com and I designed the course to bridge the gap between mathematical ideas and the challenge of implementing secure cryptography in the real world. @cst.cam.ac.uk
4608
Reposted by Daniel Hugenroth
Martin Kleppmann @martin.kleppmann.com · 06/12/2024
The PaPoC workshop is once again accepting submissions on distributed consistency. Deadline 15 January papoc-workshop.github.io/2025/cfp.html
papoc-workshop.github.io
Call for Papers
The 12th Workshop on Principles and Practice of Consistency for Distributed Data
0398
Reposted by Daniel Hugenroth
Martin Kleppmann @martin.kleppmann.com · 28/11/2024
My CS department @cst.cam.ac.uk is now on Bluesky, with a properly validated domain handle. Please give them a warm welcome!
31199
Daniel Hugenroth @lambda.bsky.social · 23/04/2024
I went down a rabbit hole studying HKDF implementations for Android and wrote up some impressions: www.danielhugenroth.com/posts/2024_0...
danielhugenroth.com
Android HKDF implementations
This article discusses several open-source implementations of the HKDF scheme for Android. Since HKDF is a relatively simple algorithm, it allows for a good case study of cryptographic code. The prima...
000
Daniel Hugenroth @lambda.bsky.social · 04/05/2023
I'll be speaking at TUM in Munich next week about "🎢 Rollercoaster: An Efficient Group-Multicast Scheme for Mix Networks". Say Hi if you're around, or join online: hedgedoc.net.in.tum.de/s/xDwzUxvFV#…
030
Reposted by Daniel Hugenroth
Martin Kleppmann @martin.kleppmann.com · 02/05/2023
New paper! 📄✨ It turns out that all text collaboration algorithms have an interleaving problem, and we fixed it for the first time. Very proud of this work with Matthew Weidner and Seph Gentle arxiv.org/abs/2305.00583
arxiv.org
The Art of the Fugue: Minimizing Interleaving in Collaborative Text Editing
Existing algorithms for replicated lists, which are widely used in collaborative text editors, suffer from a problem: when two users concurrently insert text at the same position in the document,...
0246