Sign in

Marcus Brinkmann

@lambdafu.bsky.social
75 followers 69 following 72 posts

I'm a tempura shrimp and you can't catch me! | 🐢 Terrapin Attack | 🦙 ALPACA Attack | 🦝 Raccoon Attack | 😈 DEMONS Attack | @lambdafu@mastodon.social

PostsRepliesMedia
Marcus Brinkmann @lambdafu.bsky.social · 10/09/2026
We found a new compression side-channel attack against SSH: if you use port forwarding with terminal sessions, a web attacker+eavesdropper can recover a sudo pwd in a few hundred trials. There is only one compression context for all channels. Accepted at CCS 26, preprint: arxiv.org/abs/2609.07709
arxiv.org
Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels
SSH is the standard protocol for secure remote administration of servers. At the transport layer, SSH uses the Binary Packet Protocol (BPP) for encrypted and authenticated communication. Above this, t...
15219
Reposted by Marcus Brinkmann
Natanael, Tech janitor @natanael.bsky.social · 08/09/2026
I guess the people joking satirically about "oh the solution was just out there" will have to revise their view a bit, because Actually, it was in a mathematican's chat logs which it had access to. This isn't even the first time internal secret work leaks via AI
23615
Reposted by Marcus Brinkmann
Nadim Kobeissi @nadim.computer · 22/07/2026
I wrote an essay on Cedarcrypt and on why I teach cryptography in Lebanon. The essay also links to the full Cedarcrypt 2026 photo album, which is now online. symbolic.software/blog/2026-07...
symbolic.software
Why I Teach Cryptography in Lebanon — Symbolic Software
Cedarcrypt's first edition has concluded. On what a year of teaching cryptography in and for Lebanon has meant, why the conference met in Cyprus rather than Beirut, and the decades of work ahead.
0142
Marcus Brinkmann @lambdafu.bsky.social · 16/07/2026
I’m in Lisbon, Portugal, after holding the spiqe.cool workshop, enjoying the weather, food, culture, and nature. Europe is amazing! 🇪🇺
000
Reposted by Marcus Brinkmann
Natanael, Tech janitor @natanael.bsky.social · 09/07/2026
Another vote for Chat Control was fast tracked to 12:00 CEST today! This would force backdoors into chat apps, etc
fightchatcontrol.eu
Fight Chat Control - Protect Digital Privacy in the EU
Learn about the EU Chat Control proposal and contact your representatives to protect digital privacy and encryption.
032
Marcus Brinkmann @lambdafu.bsky.social · 27/04/2026
When we educated people about not clicking on links in emails we should have added that this also applies to instant messages.
000
Reposted by Marcus Brinkmann
Nick Sullivan @nicksullivan.org · 09/04/2026
Want to help shape the cryptography that ends up in Internet standards? CFRG is looking for Crypto Review Panel members. Self-nominations welcome. Two-year renewable term. Send nominations by April 20: cfrg-chairs@ietf.org wiki.ietf.org/group/cfrg/C...
wiki.ietf.org
Crypto Review Panel
023
Marcus Brinkmann @lambdafu.bsky.social · 18/03/2026
Renewable energy is peace energy. unric.org/en/un-climat...
unric.org
UN Climate Chief: Recent weeks show the dangers of fossil fuel dependency
Remarks delivered by UN Climate Change Executive Secretary Simon Stiell at the Green Growth Summit in Brussels
000
Reposted by Marcus Brinkmann
biometlab @biometlab.bsky.social · 17/03/2026
www.theguardian.com/environment/...
theguardian.com
Revealed: the world’s worst mega-leaks of methane driving global heating
Exclusive: Fixing a leak can be simple and equivalent to closing a coal power station, making lack of action maddening, say analysts
8427291297
Marcus Brinkmann @lambdafu.bsky.social · 16/03/2026
Just putting this out there: the amount of software that exists in production vastly exceeds our global capacity to maintain it. And AI is going to make this an ultimate nightmare as often it is now easier to start from scratch than building a framework. Liability law will need updates.
012
Marcus Brinkmann @lambdafu.bsky.social · 15/03/2026
Claude code has a pattern to extend existing code by adding a condition: size_bytes = total_size.to_bytes(4, 'big') if total_size > 0xFFFF else b"\x00\x00" + total_size.to_bytes(2, 'big') - unnecessary here, but I wonder if that is common in the industry to avoid breaking things?
000
Marcus Brinkmann @lambdafu.bsky.social · 11/02/2026
I gave our students two screenshots, one with a valid PGP signature and one with a signature by the attacker (also valid) where the signer had a different eTLD and a spoofed From: address. They complained it was too hard to spot .org instead of .de. We need sender validation for signed PGP emails!
000
Marcus Brinkmann @lambdafu.bsky.social · 08/02/2026
I vibe-coded hotcrp bidding helper with Claude. It's a single index.html (+2 JS libs from CDN). Preferences can be im- and exported via CSV. Topics/Keyword scores can be taken from your own publications (just drop in PDFs and run a script). Image shows fake data. Enjoy! github.com/lambdafu/hot...
A screenshot of a web page that shows a list of papers that can be filtered and searched, to enter review preferences for a HotCRP conference.
111
Reposted by Marcus Brinkmann
Nadim Kobeissi @nadim.computer · 29/01/2026
Now's your chance to participate in growing academic cryptography participation in the Middle East and North Africa region: the Africacrypt call for papers is out! Submit your paper and come join us this July in beautiful Hammamet, Tunisia: www.africacrypt2026.tn/call-for-pap...
africacrypt2026.tn
Call for papers
074
Reposted by Marcus Brinkmann
Robert Merget (ic0ns) @ic0nz1.bsky.social · 12/01/2026
Over the past few months, I have left my comfort zone and begun working on Agentic AI systems. For that, I am now trying to fill several roles, so if that sounds like something you'd like to work on with me, please get in touch.
011
Marcus Brinkmann @lambdafu.bsky.social · 06/01/2026
Submissions are now open for the SPIQE Workshop! Submit your work until 12th of March AoE! ⚛️ spiqe.cool
010
Reposted by Marcus Brinkmann
Filippo Valsorda @filippo.abyssdomain.expert · 27/12/2025
At the gpg.fail talk and omg #39c3 You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message. Won’t even blame PGP here. C is unsafe at any speed. gpg has not fixed it yet.
4431108
Marcus Brinkmann @lambdafu.bsky.social · 05/12/2025
I strongly believe that AI will have a lasting impression on human to human communication. Expectations will be presented as prompts rather than as opportunities. The response to non-compliance will be reinforcement rather than reflection. And success will be judged by how well the recipient obeyed.
110
Marcus Brinkmann @lambdafu.bsky.social · 03/12/2025
Announcing SPIQE 2026: 2nd Workshop on Secure Protocol Implementations in the Quantum Era, bringing together researchers and implementers to securely deploy PQC! 📍 Co-located with Euro S&P in Lisbon, Portugal, July 6-10, 2026 spiqe.cool #SPIQE2026 #EuroSP #PostQuantumCrypto
spiqe.cool
SPIQE
031
Marcus Brinkmann @lambdafu.bsky.social · 19/10/2025
Coming back from south east Asia, there are so many small things I immediately notice about my home, the Ruhr area. There is too little workers helping people behave better, like keeping a bit of distance away from the baggage belt (there were no markings either).
310
Marcus Brinkmann @lambdafu.bsky.social · 05/10/2025
This is a friendly reminder that the call for contributed talks to Real World Crypto in Taipei 2026 is open until October 10. We are looking for interesting talks bridging cryptography and its real-world use! Also it’s a great way to meet new people! rwc.iacr.org/2026/contrib...
rwc.iacr.org
RWC 2026 call for papers
Real World Crypto Symposium
196
Marcus Brinkmann @lambdafu.bsky.social · 03/10/2025
Penang Hill, Malaysia
020
Reposted by Marcus Brinkmann
Real World Crypto Symposium @rwc.iacr.org · 28/03/2025
RWC 2026 in Taipei!
0147
Reposted by Marcus Brinkmann
Robert Merget (ic0ns) @ic0nz1.bsky.social · 08/07/2025
We found a new vulnerability in TLS. It's a variant of the ALPACA attack that bypasses current countermeasures. Relativly low impact - but great insight! Check it out: opossum-attack.com
1118
Reposted by Marcus Brinkmann
Sombrerogalaxie 🇬🇱 @messierm104.bsky.social · 28/06/2025
Man lese und lösche umgehend seinen Twitter-Account, falls immer noch nicht geschehen. Unfaßbar, was @arminwolf.at versucht hat und wie er an X, den Iren, der EU und (natürlich) an den USA scheitert.
arminwolf.at
X ist ein rechtsfreier Raum › Blog von Armin Wolf
Warum es praktisch unmöglich ist, anonyme Hass-Postings auf X zu bekämpfen: Die Gesetze sind zu schwach, X ignoriert sie, zuständige ...
49437
Reposted by Marcus Brinkmann
Martin R. Albrecht @malb.bsky.social · 04/06/2025
Eamonn and I received a Zama Cryptanalysis Grant to help with the lattice estimator github.com/malb/lattice.... We hope to hire interns to work on the estimator over two periods over the next 18 months. Zama are still taking applications for this grant, see here: www.zama.ai/post/announc...
github.com
GitHub - malb/lattice-estimator: An attempt at a new LWE estimator
An attempt at a new LWE estimator. Contribute to malb/lattice-estimator development by creating an account on GitHub.
1114
Reposted by Marcus Brinkmann
Ruhr-Universität Bochum @ruhr-uni-bochum.de · 20/05/2025
Kinderschutz im Netz bleibt oft Theorie: Informatikerin Veelasha Moonsamy untersuchte mit Kolleg*innen aus Belgien und den Niederlanden rund 70.000 Werbeanzeigen auf Webseiten für Kinder – mit alarmierenden Ergebnissen. 👉 news.rub.de/wissenschaft... (Foto: Roberto Schirdewahn)
Blaue Fläche, auf der in weißer Schrift ein Zitat steht von Veelasha Moonsamy: "Die Werbeanzeigen auf Webseiten für Kinder waren eine bunte Mischung mit einigen alamierenden Inhalten." Daneben in einem Kreis ein Portraitfoto der Forscherin.
083
Reposted by Marcus Brinkmann
Ruhr-Universität Bochum @ruhr-uni-bochum.de · 14/05/2025
Als Mitglied des Exzellenzclusters CASA erforscht @veelasha.bsky.social die Systeme unseres alltäglichen Gebrauchs, wie etwa unsere Smartphones. Am 22. Mai entscheidet sich, ob CASA und damit die Forschung von Moonsamy und ihren Kolleg*innen weiter gefördert wird. Daumen drücken! 🤞
072
Reposted by Marcus Brinkmann
Christian Mainka @chearix.de · 05/05/2025
Goodbye @ruhr-uni-bochum.de Hello @uni-wuppertal.bsky.social Today is my first day at BUW. Super excited to join this awesome place. Looking forward to many interesting projects and collaborations. If you would like to join or collaborate with our brand new IT security group get in touch with me.
092
Reposted by Marcus Brinkmann
Fabian Bäumer @skrillor.bsky.social · 16/04/2025
We (@lambdafu.bsky.social & me) found a critical security vulnerability in the #Erlang/OTP SSH daemon that allow attackers to execute arbitrary code via network access on devices running Erlang/OTP SSH servers. This vulnerability is #CVE-2025-32433, patches out now. Estimated CVSSv3 10.
173
Marcus Brinkmann @lambdafu.bsky.social · 12/04/2025
LaTeX goes berserk when seeing _.
020
Reposted by Marcus Brinkmann
Nadim Kobeissi @nadim.computer · 01/04/2025
Any hummus not made to the exact specifications of The Correct Hummus recipe serves as a sign of humanity’s continued moral decay, and only helps bring forth the end times. zenodo.org/records/1511...
zenodo.org
The Correct Hummus
Ignorance and depravity fill this world. People wander around, blind, thinking that they are eating “hummus” when in reality they are ingesting an abomination — a chalky, soulless paste, often cold, o...
022
Reposted by Marcus Brinkmann
Martin R. Albrecht @malb.bsky.social · 21/03/2025
Update on crypto.iacr.org/2025/
 Given recent instances of US visa holders and residents being detained or deported by US immigration authorities, we understand that some members of our community may not feel safe traveling to the US for Crypto this year. We want to assure everyone that we will provide the option to present and attend remotely.
26639
Reposted by Marcus Brinkmann
Kenny Paterson @kennyog.bsky.social · 28/02/2025
Come join us at the SPIQE workshop in Munich in June! spiqe-workshop.github.io - we are now open for paper submissions and talk proposals on all aspects of secure protocol implementation for the post-quantum era.
spiqe-workshop.github.io
Secure Protocol Implementations in the Quantum Era (SPIQE)
Secure Protocol Implementations in the Quantum Era (SPIQE)
065
Reposted by Marcus Brinkmann
Robert Habeck @robert-habeck.de · 21/02/2025
Die nächsten vier Jahre werden die entscheidenden sein. Wir können nicht stehen bleiben, wo wir sind. Deshalb sage ich es mit aller Dringlichkeit: Veränderung braucht den Willen zur Verantwortung. Und genau dafür bitte ich am Sonntag um Eure und Ihre Stimme. youtu.be/UE0_-84oqwo
youtu.be
Endspurt, Zielgerade!
YouTube video by Robert Habeck
1052854636
Reposted by Marcus Brinkmann
Ruhr-Universität Bochum @ruhr-uni-bochum.de · 29/01/2025
Sicherheitslücken in Prozessoren von #Apple führen dazu, dass über die Browser Safari und Chrome sensible Daten ausgespäht werden können. Das haben Forschende des Exzellenzcluster CASA herausgefunden. #ITsecurity
news.rub.de
Sicherheitslücken in Apple-Prozessoren entdeckt
Leistung und Geschwindigkeit werden immer weiter verbessert – die Sicherheit bleibt auf der Strecke.
0137
Marcus Brinkmann @lambdafu.bsky.social · 23/01/2025
Hello Bluesky! I did a thing and now I am the proud owner of the greatest hat in the world! 🎓
060