Sign in

Marcus Brinkmann

@lambdafu.bsky.social
75 followers 69 following 72 posts

I'm a tempura shrimp and you can't catch me! | 🐢 Terrapin Attack | 🦙 ALPACA Attack | 🦝 Raccoon Attack | 😈 DEMONS Attack | @lambdafu@mastodon.social

PostsRepliesMedia
Reposted by Marcus Brinkmann
pixelatedboat aka “mr bluesky” @pixelatedboat.bsky.social · 02/10/2026
Sad news everyone. Our beloved friend the computer has now become a hated enemy
167123872643
Marcus Brinkmann @lambdafu.bsky.social · 12/09/2026
Most SSH endpoints are behind a VPN anyway.
000
Marcus Brinkmann @lambdafu.bsky.social · 12/09/2026
Yes even earlier with John Kelseys 2002 Paper. But the SSH community didn’t react back then, perhaps because there was no attacker model with a working exploit.
020
Marcus Brinkmann @lambdafu.bsky.social · 10/09/2026
We found a new compression side-channel attack against SSH: if you use port forwarding with terminal sessions, a web attacker+eavesdropper can recover a sudo pwd in a few hundred trials. There is only one compression context for all channels. Accepted at CCS 26, preprint: arxiv.org/abs/2609.07709
arxiv.org
Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels
SSH is the standard protocol for secure remote administration of servers. At the transport layer, SSH uses the Binary Packet Protocol (BPP) for encrypted and authenticated communication. Above this, t...
15219
Reposted by Marcus Brinkmann
Natanael, Tech janitor @natanael.bsky.social · 08/09/2026
I guess the people joking satirically about "oh the solution was just out there" will have to revise their view a bit, because Actually, it was in a mathematican's chat logs which it had access to. This isn't even the first time internal secret work leaks via AI
23615
Marcus Brinkmann @lambdafu.bsky.social · 08/09/2026
I think this requires a bingo card.
011
Marcus Brinkmann @lambdafu.bsky.social · 31/08/2026
I‘m getting strong AI vibes on the language in the article.
110
Marcus Brinkmann @lambdafu.bsky.social · 31/07/2026
You can check out the EU cyber resilience act.
000
Reposted by Marcus Brinkmann
Nadim Kobeissi @nadim.computer · 22/07/2026
I wrote an essay on Cedarcrypt and on why I teach cryptography in Lebanon. The essay also links to the full Cedarcrypt 2026 photo album, which is now online. symbolic.software/blog/2026-07...
symbolic.software
Why I Teach Cryptography in Lebanon — Symbolic Software
Cedarcrypt's first edition has concluded. On what a year of teaching cryptography in and for Lebanon has meant, why the conference met in Cyprus rather than Beirut, and the decades of work ahead.
0142
Marcus Brinkmann @lambdafu.bsky.social · 16/07/2026
I’m in Lisbon, Portugal, after holding the spiqe.cool workshop, enjoying the weather, food, culture, and nature. Europe is amazing! 🇪🇺
000
Reposted by Marcus Brinkmann
Natanael, Tech janitor @natanael.bsky.social · 09/07/2026
Another vote for Chat Control was fast tracked to 12:00 CEST today! This would force backdoors into chat apps, etc
fightchatcontrol.eu
Fight Chat Control - Protect Digital Privacy in the EU
Learn about the EU Chat Control proposal and contact your representatives to protect digital privacy and encryption.
032
Marcus Brinkmann @lambdafu.bsky.social · 08/07/2026
Operational IT security in Europe is awful 😞 see also www.ccc.de/de/updates/2.... But comparing an eye tracker with self driving doesn’t make sense. FSD collects and uploads massive amounts of data (necessary as training data).
ccc.de
CCC | Wir wissen, wo dein Auto steht
Der Chaos Computer Club ist eine galaktische Gemeinschaft von Lebewesen für Informationsfreiheit und Technikfolgenabschätzung.
000
Marcus Brinkmann @lambdafu.bsky.social · 08/07/2026
For Europe this is lightning speed. 🙃 2015, Volvo said that it would accept full liability for self driving, which made me think this is inevitable. I don’t think EU wants to just rubberstamp Tesla FSD but there are many intermediate steps, including stopping cars heading into walls or people.
000
Marcus Brinkmann @lambdafu.bsky.social · 08/07/2026
I don’t see resistance to Advanced Self driving in Europe? And the asymmetry is that it is much easier to demonstrate the effectiveness of a passive warning system compared to autonomous driving. Is that really strange?
100
Marcus Brinkmann @lambdafu.bsky.social · 15/06/2026
I looked at the 1972/73 code and it has a hash table of 100 entries a 8 bytes. Apparently earlier systems used a 40-50 charset and could encode a six character symbol and some extra bits in a double word on 18 bit computers (SQUOZE and RADIX-50). Going from six to eight must have felt generous.
020
Marcus Brinkmann @lambdafu.bsky.social · 07/06/2026
So why don’t we reverse engineer the device, identify any remote link and deactivate it? I don’t think that’s too hard, so if we are unwilling to do than maybe we should reevaluate the way we do things.
100
Marcus Brinkmann @lambdafu.bsky.social · 07/06/2026
Did you pay for it? No? Then you are the product not the app. If WhatsApp is vibecoding your feedback is going into the next agent‘s prompt.
000
Marcus Brinkmann @lambdafu.bsky.social · 07/05/2026
Very interesting, also the other bugs in OpenSSH.
020
Marcus Brinkmann @lambdafu.bsky.social · 04/05/2026
Well I have some confusing experiences. I use 1Password and sometimes I am kicked into a flow where I log in on my laptop and have to scan a QR code with my phone. But in general when that happens I have something important to do and can’t be bothered to investigate so it will stay that way 4ever.
000
Marcus Brinkmann @lambdafu.bsky.social · 02/05/2026
Well, yes. But this is the first 3d headset that doesn’t make me nauseous and that is usable for a wide range of glasses wearers. The resolution and image stability is fantastic. I think only a better Vision Pro can replace a Vision Pro. It’s also great as an accessibility device for some.
010
Marcus Brinkmann @lambdafu.bsky.social · 27/04/2026
When we educated people about not clicking on links in emails we should have added that this also applies to instant messages.
000
Reposted by Marcus Brinkmann
Nick Sullivan @nicksullivan.org · 09/04/2026
Want to help shape the cryptography that ends up in Internet standards? CFRG is looking for Crypto Review Panel members. Self-nominations welcome. Two-year renewable term. Send nominations by April 20: cfrg-chairs@ietf.org wiki.ietf.org/group/cfrg/C...
wiki.ietf.org
Crypto Review Panel
023
Marcus Brinkmann @lambdafu.bsky.social · 08/04/2026
The long term risk is that people will believe their software is secure when the AI can’t find a vulnerability.
110
Marcus Brinkmann @lambdafu.bsky.social · 08/04/2026
I’m starting to think these are all pump and dump schemes.
000
Marcus Brinkmann @lambdafu.bsky.social · 18/03/2026
Renewable energy is peace energy. unric.org/en/un-climat...
unric.org
UN Climate Chief: Recent weeks show the dangers of fossil fuel dependency
Remarks delivered by UN Climate Change Executive Secretary Simon Stiell at the Green Growth Summit in Brussels
000
Marcus Brinkmann @lambdafu.bsky.social · 18/03/2026
My only problem is that the raw garlic in my salsa overpowers everything else when left in the fridge overnight. It basically has to be made and enjoyed fresh.
110
Reposted by Marcus Brinkmann
biometlab @biometlab.bsky.social · 17/03/2026
www.theguardian.com/environment/...
theguardian.com
Revealed: the world’s worst mega-leaks of methane driving global heating
Exclusive: Fixing a leak can be simple and equivalent to closing a coal power station, making lack of action maddening, say analysts
8427281297
Marcus Brinkmann @lambdafu.bsky.social · 16/03/2026
Just putting this out there: the amount of software that exists in production vastly exceeds our global capacity to maintain it. And AI is going to make this an ultimate nightmare as often it is now easier to start from scratch than building a framework. Liability law will need updates.
012
Marcus Brinkmann @lambdafu.bsky.social · 15/03/2026
Claude code has a pattern to extend existing code by adding a condition: size_bytes = total_size.to_bytes(4, 'big') if total_size > 0xFFFF else b"\x00\x00" + total_size.to_bytes(2, 'big') - unnecessary here, but I wonder if that is common in the industry to avoid breaking things?
000
Marcus Brinkmann @lambdafu.bsky.social · 08/03/2026
Why?
100
Marcus Brinkmann @lambdafu.bsky.social · 16/02/2026
On the plus side, LLMs don’t hold their noses at hard to read code like GnuPG (I remember your students complaining about it). dev.gnupg.org/T8044
dev.gnupg.org
⚓ T8044 gpg-agent stack buffer overflow in pkdecrypt using KEM
010
Marcus Brinkmann @lambdafu.bsky.social · 13/02/2026
I am not familiar with verified code. Is it common to have admit, lax and delayed proof statements? Great write up, thanks!
100
Marcus Brinkmann @lambdafu.bsky.social · 11/02/2026
I gave our students two screenshots, one with a valid PGP signature and one with a signature by the attacker (also valid) where the signer had a different eTLD and a spoofed From: address. They complained it was too hard to spot .org instead of .de. We need sender validation for signed PGP emails!
000
Marcus Brinkmann @lambdafu.bsky.social · 10/02/2026
I’m sorry you had a bad exp. It absolutely can be, but at least for me that’s rare. I prefer „coordinated vuln. disclosure“ because it doesn’t imply other ways are irresponsible. Anyway I would hate to be boxed in one form of disclosure. Interests of stakeholders can be aligned, why not use that?
000
Marcus Brinkmann @lambdafu.bsky.social · 08/02/2026
My experience: It's surprisingly usable. First result was within 5 minutes, fine tuning was done after two hours. Another two hours for adding convenience features, and a final hour for testing and cutting a release.
010
Marcus Brinkmann @lambdafu.bsky.social · 08/02/2026
Main features: Filter by topics, keywords (from title and abstracts), text, or preference. Sort by number, title, score, preference. Show all abstracts or just one, show topics. Navigate and rank by keyboard. Undo and redo. Everything is stored in local storage (just reload the CSV and it's there).
100
Marcus Brinkmann @lambdafu.bsky.social · 08/02/2026
I vibe-coded hotcrp bidding helper with Claude. It's a single index.html (+2 JS libs from CDN). Preferences can be im- and exported via CSV. Topics/Keyword scores can be taken from your own publications (just drop in PDFs and run a script). Image shows fake data. Enjoy! github.com/lambdafu/hot...
A screenshot of a web page that shows a list of papers that can be filtered and searched, to enter review preferences for a HotCRP conference.
111
Marcus Brinkmann @lambdafu.bsky.social · 30/01/2026
When the AI wars come, we will wish the browser war back.
000
Reposted by Marcus Brinkmann
Nadim Kobeissi @nadim.computer · 29/01/2026
Now's your chance to participate in growing academic cryptography participation in the Middle East and North Africa region: the Africacrypt call for papers is out! Submit your paper and come join us this July in beautiful Hammamet, Tunisia: www.africacrypt2026.tn/call-for-pap...
africacrypt2026.tn
Call for papers
074
Marcus Brinkmann @lambdafu.bsky.social · 25/01/2026
Anything in particular? I wouldn’t even know where to look for news and stories on that industry.
100
Marcus Brinkmann @lambdafu.bsky.social · 13/01/2026
The decent thing would be to delete the inbox every afternoon before heading home. Then everybody has a fighting chance.
020
Reposted by Marcus Brinkmann
Robert Merget (ic0ns) @ic0nz1.bsky.social · 12/01/2026
Over the past few months, I have left my comfort zone and begun working on Agentic AI systems. For that, I am now trying to fill several roles, so if that sounds like something you'd like to work on with me, please get in touch.
011
Marcus Brinkmann @lambdafu.bsky.social · 06/01/2026
Submissions are now open for the SPIQE Workshop! Submit your work until 12th of March AoE! ⚛️ spiqe.cool
010
Reposted by Marcus Brinkmann
Filippo Valsorda @filippo.abyssdomain.expert · 27/12/2025
At the gpg.fail talk and omg #39c3 You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message. Won’t even blame PGP here. C is unsafe at any speed. gpg has not fixed it yet.
4431108
Marcus Brinkmann @lambdafu.bsky.social · 27/12/2025
What are good alternatives?
000
Marcus Brinkmann @lambdafu.bsky.social · 10/12/2025
We are just waiting for our AI token quota to reset.
000
Marcus Brinkmann @lambdafu.bsky.social · 10/12/2025
At least they now know we didn’t withdraw our submission.
100
Marcus Brinkmann @lambdafu.bsky.social · 05/12/2025
The university library Münster has a clear opinion on this matter. upload.wikimedia.org/wikipedia/co...
010
Marcus Brinkmann @lambdafu.bsky.social · 05/12/2025
I strongly believe that AI will have a lasting impression on human to human communication. Expectations will be presented as prompts rather than as opportunities. The response to non-compliance will be reinforcement rather than reflection. And success will be judged by how well the recipient obeyed.
110
Marcus Brinkmann @lambdafu.bsky.social · 03/12/2025
Announcing SPIQE 2026: 2nd Workshop on Secure Protocol Implementations in the Quantum Era, bringing together researchers and implementers to securely deploy PQC! 📍 Co-located with Euro S&P in Lisbon, Portugal, July 6-10, 2026 spiqe.cool #SPIQE2026 #EuroSP #PostQuantumCrypto
spiqe.cool
SPIQE
031