Sign in

Martin R. Albrecht

@malb.bsky.social
934 followers 308 following 132 posts

Cryptography Professor at King's College London and Principal Research Scientist at SandboxAQ. Erdős–Bacon Number: 6. He/him or they/them. malb.io

PostsRepliesMedia
Reposted by Martin R. Albrecht
Damien Miller @damienmiller.bsky.social · 17h
Anthropic may not have intended to write an excellent ad for GLM 5.3, but that's what they did. www.anthropic.com/research/glm... Unlike Mythos, I might actually have a chance at using GLM for defensive research. Anthropic didn't reply to any of my requests for Mythos access for use on OpenSSH.
anthropic.com
GLM-5.3 and the spread of advanced cyber capabilities
GLM-5.3 can autonomously build end-to-end cyber exploits, but unlike other frontier models, it was released without meaningful safeguards to limit misuse.
517632
Martin R. Albrecht @malb.bsky.social · 26/09/2026
"Antifa: a howto and opsec guide" through the medium of song www.youtube.com/watch?v=Gg-S... genius.com/Genius-engli...
youtube.com
Danger Dan - Keine Angst
YouTube video by Danger Dan
110
Reposted by Martin R. Albrecht
John Stott @jpsastro.bsky.social · 24/09/2026
Had a UKRI funded grant proposal rejected at the "AI triage stage". "This AI-based triage was used only to identify approximately 50% of the strongest proposals to take forward to full human review." 🧪 #academicsky
I am writing to let you know that, unfortunately, your application was not successful.

Review process

As part of the initial triage of the 179 proposals submitted to this call, each was assessed using an AI-based review. Every proposal was read independently by several different AI models against the same seven criteria used to shape this call (including cyber security relevance, research quality and novelty, importance of the problem addressed, feasibility of the project plan, likely outputs and impact, value for money, and responsible research practice), with each model asked to give a score and a written justification with supporting quotations from the text. To guard against any one model's idiosyncrasies, we also ran a second, independent process in which different AI models debated the merits and weaknesses of each proposal before reaching a judgement, again against the same criteria. Scores from both processes were combined to produce an overall ranking. 

This AI-based triage was used only to identify approximately 50% of the strongest proposals to take forward to full human review.  Projects selected for funding were drawn from those that progressed to the full human review stage. We recognise that AI-assisted assessment is a new and evolving part of the review process, and we are continuing to evaluate how well it aligns with the judgements of human reviewers on this call. We will soon produce a document detailing our method, so that others can build upon it and improve it.

Feedback on your application

Your application was not selected to progress beyond the AI triage stage.  To provide transparency on the outcome of this assessment, we are sharing below the scores (out of 5) from each of the two AI review processes described above, together with the mean score across the two processes.
40414219
Reposted by Martin R. Albrecht
Miro Haller @mirohaller.bsky.social · 21/09/2026
We finally finished the universal signature forgery for 1024-bit RSA! 2^32 oracle queries, 1200 core years precomputation, 180 core years for an individual forgery, and 3 years of human labor (no AI involved) by Laura, Adam, Nadia, Emmanuel and me to pull of this computation against real HSMs.
14019
Reposted by Martin R. Albrecht
Nadim Kobeissi @nadim.computer · 13/09/2026
We were fired by our accountant because apparently Cedarcrypt and my Lebanon course are money laundering operations: www.linkedin.com/posts/nadimk...
linkedin.com
Applied Cryptography — Symbolic Software | Nadim Kobeissi
This week, my company Symbolic Software was fired by our accountant from the Cabinet Nathalie Langy & Associés, because I tried to help my applied cryptography students in Lebanon by paying my teachin...
0113
Reposted by Martin R. Albrecht
Kenny Paterson @kennyog.bsky.social · 13/09/2026
TL;DR: using compression before encryption is much weaker than we thought. Tiny length differences can be amplified - almost without limit - and noise-based or bucketization countermeasures are then easy to bypass. Joint work with @prefix-free.bsky.social and Lenka Mareková, to appear at CCS 2026.
12415
Reposted by Martin R. Albrecht
Kenny Paterson @kennyog.bsky.social · 10/09/2026
Our latest “Crypto in the Wild” project, analysing secure email gateways. We give 29 cryptographic attacks on 4 different products, from SEPPmail, Cisco, Proton and CipherMail. Paper to appear at ACM CCS 2026.
11911
Martin R. Albrecht @malb.bsky.social · 30/08/2026
Worth a read on who/what Autistici/Inventati is, the tech collective designated as a "Specially Designated Global Terrorist" by the US cavallette.noblogs.org/2026/08/10083
cavallette.noblogs.org
[REPOST] The Server Called Paranoia: Defend Autistici/Inventati Before September 25
Ripubblichiamo (in inglese) un bel post di Sabot Media che ripercorre la nostra storia e la collega a quanto sta avvenendo con la nostra iscrizione nella lista delle organizzazioni globali terroristic...
031
Reposted by Martin R. Albrecht
Michael A. Specter 👻 @mikespecter.com · 17/08/2026
We also bought EncroChat's original domain (encrochat.ch) --- it now hosts our paper and other info.
encrochat.ch
A Real-World Law-Enforcement Hack: The Case of Encrochat
0107
Martin R. Albrecht @malb.bsky.social · 17/08/2026
As funny as it is that they simply dropped frida.re on Encrochat devices, to me the two big Encrochat questions that still aren't resolved are:
frida.re
Frida • A world-class dynamic instrumentation toolkit
Observe and reprogram running programs on Windows, macOS, GNU/Linux, iOS, watchOS, tvOS, Android, FreeBSD, and QNX
144
Martin R. Albrecht @malb.bsky.social · 15/08/2026
eprint.iacr.org/2026/1693
Screenshot of the title page of the paper. Text:

The ePrint:2026/1591 Quantum Algorithm
Does Not Solve DCP
Aparna Gupte
MIT
Seyoon Ragavan
Google Quantum AI
& MIT
Mark Zhandry
Google Quantum AI
& Stanford University
Abstract
In this note, we formally show that the recent algorithm by Simon (ePrint:2026/1591, August 11 2026) does
not extract the least-significant bit of the dihedral coset problem (DCP) secret with non-negligible guessing advan-
tage, and therefore does not solve DCP. We emphasize that our result is not merely about Simon’s analysis of his
algorithm; we are showing directly that the algorithm cannot possibly work.
Our no-go encompasses a much broader class of algorithms than the specific algorithm by Simon. The main
message of our no-go is that an algorithm for DCP following the template of the reduction by Regev (SIAM Journal
on Computing, 2004) will probably have to make extensive use of the classical Fourier labels in the uncomputation
stage. On the other hand, the algorithm by Simon can be implemented, up to error poly(n)2−n/3, using only the
most-significant third of the classical Fourier labels, and therefore cannot succeed.
To help with verifiability, we release Lean 4 code for our results, available at this GitHub repository.
1214
Martin R. Albrecht @malb.bsky.social · 01/08/2026
OpenAI claim a proof that CPV is NP-hard for polynomial approximation factors. openai.com/index/ten-ad...
Screenshot of the text: "Closest vector problem. Polynomial-factor hardness of approximation for the closest vector problem, a foundational lattice question related to post-quantum cryptography."
084
Reposted by Martin R. Albrecht
Chris Peikert @chrispeikert.bsky.social · 28/07/2026
This is a very cool and exciting discovery by Claude Mythos! It found a serious 𝒎𝒂𝒕𝒉𝒆𝒎𝒂𝒕𝒊𝒄𝒂𝒍 attack on the post-quantum signature scheme HAWK, an "on-ramp" candidate for potential NIST standardization. www.anthropic.com/research/dis...
anthropic.com
Discovering cryptographic weaknesses with Claude
Anthropic researchers find weaknesses in cryptographic algorithms with Claude Mythos Preview
23218
Martin R. Albrecht @malb.bsky.social · 23/07/2026
I recommend you read @nadim.computer's excellent write-up of why he teaches in Lebanon symbolic.software/blog/2026-07...
symbolic.software
Why I Teach Cryptography in Lebanon — Symbolic Software
Cedarcrypt's first edition has concluded. On what a year of teaching cryptography in and for Lebanon has meant, why the conference met in Cyprus rather than Beirut, and the decades of work ahead.
1144
Martin R. Albrecht @malb.bsky.social · 21/07/2026
Our timeline really is Terminator: The Next Token Prediction openai.com/index/huggin...
openai.com
OpenAI and Hugging Face partner to address security incident during model evaluation
OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.
010
Martin R. Albrecht @malb.bsky.social · 01/07/2026
A Real-World Law-Enforcement Hack: The Case of Encrochat martinralbrecht.wordpress.com/2026/07/01/a...
Cover of the paper at https://eprint.iacr.org/2026/1319.pdf
062
Martin R. Albrecht @malb.bsky.social · 29/06/2026
The abductions and torture continue in Kenya xcancel.com/KTNNewsKE/st... www.standardmedia.co.ke/national/art...
xcancel.com
110
Martin R. Albrecht @malb.bsky.social · 12/06/2026
Hardness of hinted ISIS from the space-time hardness of lattice problems martinralbrecht.wordpress.com/2026/06/12/h...
Morpheus (from the movie The Matrix) asking: "What if I told you that ISIS is hard even given a trapdoor"
0102
Martin R. Albrecht @malb.bsky.social · 11/06/2026
Dear Journalists, That "crosshair" you're referring to is a Celtic cross, a well-known white supremacist logo: en.wikipedia.org/wiki/Celtic_... www.adl.org/sites/defaul... This is what these rioters are: white supremacists.
A screenshot of https://www.ft.com/content/bbdf1851-1255-4217-9544-e87c8044b5cb?syn-25a6b1a6=1A screenshot of https://www.theguardian.com/uk-news/2026/jun/11/how-the-belfast-stabbing-was-the-spark-to-a-fuse-loaded-with-grievance-and-provocation
061
Reposted by Martin R. Albrecht
Ei/PSI @ei-psi.bsky.social · 08/06/2026
Security in Times of Surveillance eipsi.win.tue.nl/surveillance... w Marrtin Albrecht @malb.bsky.social Chloé Berthélémy (EDRi), Rikke Bjerg Jensen (RHUL), Thomas Lohninger @socialhack.bsky.social Björn Ruytenberg @0xiphorus.infosec.exchange.ap.brid.gy Carmela Troncoso @carmelatroncoso.bsky.social
143
Reposted by Martin R. Albrecht
Signal @signal.org · 08/06/2026
Our statement on the UK gov't's demand that all content on all devices sold or used in the UK be scanned, on the presumption of nudity, using a dystopian combination of age verification & content scanning. This proposal will not safeguard children. It endangers us all. signal.org/blog/pdfs/20...
signal.org
351451656
Martin R. Albrecht @malb.bsky.social · 03/06/2026
Leiden Declaration on Artificial Intelligence and Mathematics leidendeclaration.ai#declaration
Screenshot of text that reads:

All of these challenges arise at a moment when the consequences of large-scale investment in artificial intelligence are being widely discussed in regard to warfare, mass surveillance, political disruption, and environmental damage. These raise grave ethical concerns. By failing to act, we run the risk of becoming complicit in the support of technologies which threaten much more than the practice of mathematics.

We thus feel that there is an urgent need for a considered response from the mathematical community. The following constitute brief descriptions of actionable recommendations. We encourage professional organizations to endorse this Declaration, and to add provisions according to their own values, priorities, and governance.
030
Martin R. Albrecht @malb.bsky.social · 22/05/2026
arstechnica.com/security/202... with a quote by @bedow.bsky.social on how we saw/see no evidence of what they're alleging.
arstechnica.com
Texas AG sues Meta over claims that WhatsApp doesn't provide end-to-end encryption
Critics note a lack of factual support in lawsuit filed by US Senate candidate.
061
Martin R. Albrecht @malb.bsky.social · 22/05/2026
I'm reading some papers on AI safety (don't ask). Is the entire field really so naive that they think speaking of "human values" makes sense? Have these people not switched on the news ever? I know we computer scientists do not excell at thinking about the actual world we live in, but this is extra.
242
Martin R. Albrecht @malb.bsky.social · 11/05/2026
Soooo ePrint blocked the Eurocrypt WiFi for too many requests
0151
Reposted by Martin R. Albrecht
Richard Barnes @ipv.sx · 06/05/2026
Similar to the E2E encryption debates in that nerding harder will not square the policy circle. Dissimilar to the E2E encryption debates in that the policy world is proceeding nonetheless, as @matthewdgreen.bsky.social said at the top.
021
Martin R. Albrecht @malb.bsky.social · 24/03/2026
‘They singled out non-white, foreign-born workers’: the restaurants raided by Britain’s version of ICE www.theguardian.com/uk-news/2026...
theguardian.com
‘They singled out non-white, foreign-born workers’: the restaurants raided by Britain’s version of ICE
They’re not armed and they keep a relatively low profile. But the Home Office’s immigration compliance and enforcement officers have searched thousands of business in pursuit of illegal workers. Are t...
052
Martin R. Albrecht @malb.bsky.social · 23/03/2026
Fabio is looking for a PhD student in "Explainable, Knowledge-driven AI and ML for Systems Security" fabio.pierazzi.com/opportunity/...
fabio.pierazzi.com
Opportunity for Ph.D. at UCL CS | Fabio Pierazzi
Competitive, Fully-Funded Opportunity for 4-Year Ph.D. at UCL Computer Science (Home/UK candidates only)
032
Reposted by Martin R. Albrecht
Miro Haller @mirohaller.bsky.social · 20/03/2026
The program for our Eurocrypt affiliated event CAW on May 10 is (mostly) finalized and published on: caw.cryptanalysis.fun We received many super exciting submissions! To register, select our workshop during conference registration on the Eurocrypt website once that opens: eurocrypt.iacr.org/2026/
Screenshot of the program of CAW from https://caw.cryptanalysis.fun/.
1135
Martin R. Albrecht @malb.bsky.social · 19/03/2026
.@nadim.computer is looking for an intern: symbolic.software/blog/2026-03...
symbolic.software
Summer 2026 Research Internship at Symbolic Software
We're looking for a research intern to join us this summer and contribute to new papers on real-world cryptographic constructions.
013
Martin R. Albrecht @malb.bsky.social · 10/03/2026
Not Safe for Politics Cellebrite Used on Kenyan Activist and Politician Boniface Mwangi citizenlab.ca/research/cel...
citizenlab.ca
Not Safe for Politics: Cellebrite Used on Kenyan Activist and Politician Boniface Mwangi - The Citizen Lab
Following the widely-condemned arrest in July 2025 of prominent Kenyan opposition voice Boniface Mwangi, the Citizen Lab analyzed artefacts from devices seized during the arrest. We found that Cellebr...
042
Reposted by Martin R. Albrecht
Deirdre Connolly¹ ² @durumcrustulum.com · 10/03/2026
'deep hanging out' (technical term) #realworldccrypto
111
Reposted by Martin R. Albrecht
Deirdre Connolly¹ ² @durumcrustulum.com · 10/03/2026
"Cryptography is also a social science unaware of itself." #realworldcrypto
131
Reposted by Martin R. Albrecht
Kien Tuong Truong @kientuong114.bsky.social · 09/03/2026
Just finished presenting this work at Real World Crypto in Taipei :) TL;DR: We found 2 attacks on Signal (Android, Desktop) where a malicious server can inject messages in conversations. Super fun project! Thanks a bunch to Noemi Terzo, @kennyog.bsky.social, and @cryptojedi.bsky.social
0204
Reposted by Martin R. Albrecht
Nadim Kobeissi @nadim.computer · 07/03/2026
I just donated to help equip Lebanon's first responders and firefighters with essential life-saving supplies to help them deal with the massive crises unfolding due to Israeli attacks on civilian areas. Please consider donating: fundahope.com/en/campaigns...
fundahope.com
Equipping Lebanon's First Responders 2026
March 2026: We are fundraising to equip Lebanon’s national first responders - The Civil Defense (الدفاع المدني) with essential and life-saving supp
144
Martin R. Albrecht @malb.bsky.social · 03/03/2026
Fernando is looking for a PhD student www.iacr.org/jobs/item/4164 Fernando is excellent, you should consider applying.
iacr.org
PhD position in Cryptanalysis
154
Reposted by Martin R. Albrecht
Thomas Ptacek @sockpuppet.org · 17/02/2026
"presenting a cornucopia of practical attacks". These are my favorite words ever to have occurred in a cryptography paper.
3549
Reposted by Martin R. Albrecht
Kenny Paterson @kennyog.bsky.social · 17/02/2026
A thread in which @sockpuppet.org presents some of the juiciest morsels from our paper at zkae.io :
zkae.io
Zero Knowledge (About) Encryption
0121
Martin R. Albrecht @malb.bsky.social · 17/02/2026
“Based on these ethnographic findings, we initiate the cryptographic study of at-compromise security” martinralbrecht.wordpress.com/2026/02/17/b...
0111
Reposted by Martin R. Albrecht
ePrint Updates @eprint.ing.bot · 06/02/2026
Hardness of hinted ISIS from the space-time hardness of lattice problems (Martin R. Albrecht, Russell W. F. Lai, Eamonn W. Postlethwaite) ia.cr/2026/187
Abstract. We initiate the study of basing the hardness of hinted ISIS problems (i.e. with trapdoor information, or ‘hints’) on the previously conjectured space-time hardness of lattice problems without hints. We present two main results.

1.  If there exists an efficient algorithm for hinted ISIS that outputs solutions a constant factor longer than the hints, then there exists a single-exponential time and polynomial memory zero-centred spherical Gaussian sampler solving hinted SIS with norm a constant factor shorter than the hints.

2.  Assume the existence of a chain of algorithms for hinted ISIS each taking as input Gaussian hints whose norms decrease by a constant factor at each step in the chain, then there exists a single-exponential time and polynomial memory algorithm for SIS with norm a quasilinear factor from optimal.

The existence of such hinted ISIS solvers implies single-exponential time and polynomial memory algorithms for worst-case lattice problems, contradicting a conjecture by Lombardi and Vaikuntanathan (CRYPTO’20) and all known algorithms. This suggests that hinted ISIS is hard.

Apart from advancing our understanding of hinted lattice problems, an immediate consequence is that signing the same message twice in GPV-style [Gentry–Peikert–Vaikuntanathan, STOC’08] schemes (without salting or derandomisation) likely does not compromise unforgeability. Also, cryptanalytic attempts on the One-More-ISIS problem [Agrawal–Kirshanova–Stehlé-Yadav, CCS’22] likely will need to overcome the conjectured space-time hardness of lattices.
Image showing part 2 of abstract.
022
Martin R. Albrecht @malb.bsky.social · 01/02/2026
Apropos of nothing, here's a piece on Reform's plans for a British ICE: shado-mag.com/articles/opi... Here's the policy document: web.archive.org/web/20260127... Here's a piece on the Labour Government's practice of emulating the US' celebration of brutality: www.theguardian.com/politics/202...
shado-mag.com
Inside Reform’s plans for a fascist takeover
In today's article shado editor Elia Ayoub discusses Reform’s “Operation Restore Justice”, the risks of a British ICE and how we can resist.
021
Reposted by Martin R. Albrecht
Chris Peikert @chrispeikert.bsky.social · 24/01/2026
This is right. This is the message. This is the urgency. Minneapolis and so many other places are living under paramilitary occupation and tyranny by out of control, unaccountable federal thugs. This cannot stand. www.youtube.com/shorts/hyqtA...
youtube.com
ICE is full of COWARDS. They are all absolute, pathetic, untrained COWARDS. DEFUND AND PROSECUTE.
YouTube video by Seth Moulton
061
Martin R. Albrecht @malb.bsky.social · 13/01/2026
Social Foundations of Cryptography: Autumn School London, UK | 15 to 17 September 2026 social-foundations-of-cryptography.gitlab.io/school
We're hosting an Autumn School in London, UK, from 15 to 17 September 2026, to bring together ethnographers and cryptographers to discuss ways in which the two fields can be meaningfully brought into conversation.

This is also the premise of our Social Foundations of Cryptography project: to ground cryptography in ethnography. Here, we rely on ethnographic methods, rather than our intuition, to surface security notions that we then formalise and sometimes realise using cryptography.

Our intention is to 'flip' the typical relationship between the computer and social sciences, where the latter has traditionally ended up in a service role to the former. Rather, we want to put cryptography at the mercy of ethnography.

But how do we do this? How do we as cryptographers interact with and make sense of ethnographic field data? How can we refine, improve or extend this interaction? What obstacles do we face when we make cryptography rely on ethnographic data which is inherently 'messy'? How do we handle that cryptographic notions tend to require some form of generalisation but ethnographic findings can only be particular?

How do ethnographers retain the richness of ethnographic field data in conversations with cryptographic work? Indeed, our project has already highlighted some limitations of our approach. It has brought to the fore concrete challenges in 'letting the ethnographic data speak' while still making it speak to cryptography.

The Autumn School is an opportunity to explore these questions jointly across ethnography and cryptography, through a series of talks, group discussions and activities.

We say a bit more about the programme and registration for the Autumn School here.
196
Martin R. Albrecht @malb.bsky.social · 05/01/2026
Come work with us! Lecturer (≅ Assistant Professor/Juniorprofessor/Maître de conférences) in Cryptography at King’s College London martinralbrecht.wordpress.com/2026/01/05/l...
martinralbrecht.wordpress.com
Lecturer (≅ Assistant Professor/Juniorprofessor/Maître de conférences) in Cryptography at King’s College London 2026
We are looking to recruit a lecturer in cryptography at King’s College London to work with us within the cybersecurity group: I think it’s fair to say we got strong expertise in lattice-based and p…
0106
Martin R. Albrecht @malb.bsky.social · 23/11/2025
There is a lot to be appreciated about someone with an actual humanities education and a capacity to think writing about AGI. www.eruditorumpress.com/blog/on-inco... by @eruditorumpress.com
eruditorumpress.com
On Incomputable Language: An Essay on AI
An incidental consequence of having written a book on tech-fascism and the so-called rationalist movement is that I find myself periodically queried for my thoughts on artificial intelligence. On the ...
031
Reposted by Martin R. Albrecht
Stefano Tessaro @stefanotessaro.bsky.social · 22/11/2025
And now we are famous: www.nytimes.com/2025/11/21/w... - congratulations to all colleagues who made the NYT (both through quotes, by playing a role, or by being on this picture)
nytimes.com
Cryptographers Held an Election. They Can’t Decrypt the Results.
24211
Martin R. Albrecht @malb.bsky.social · 23/10/2025
Two stories from King's College London: 1/ A student is at risk of losing their visa over their Palestine activism www.cage.ngo/articles/leg... 2/ Equality, Diversity and Inclusion removed from job ads: www.timeshighereducation.com/news/pressur... Does that remind you of anything?
timeshighereducation.com
Pressure prompts universities to revise EDI recruitment ads
Universities change job requirements after free speech groups raise concerns following new legislation
081
Martin R. Albrecht @malb.bsky.social · 21/10/2025
I was today's years old when I realised that "we" give developers an object called the Advanced Encryption Standard which is not an encryption algorithm (but a pseudorandom permutation) and then we are shocked when we encounter yet another ECB mode in the wild. 🙃
3192
Reposted by Martin R. Albrecht
Ian Miers @secparam.bsky.social · 09/10/2025
Discord user IDs getting leaked is the entirely predictable consequence of requiring platforms to do age verification. That data never goes away, it spreads. In this case, into appeals in a breached customer support database. And predictably, it can get worse. www.404media.co/the-discord-...
404media.co
The Discord Hack is Every User’s Worst Nightmare
A hack impacting Discord’s age verification process shows in stark terms the risk of tech companies collecting users’ ID documents. Now the hackers are posting peoples’ IDs and other sensitive informa...
164
Martin R. Albrecht @malb.bsky.social · 09/10/2025
So, Discord implemented true ID age verification and this turned into a privacy disaster, am I reading this right? discord.com/press-releas...
discord.com
Update on a Security Incident Involving Third-Party Customer Service | Discord
At Discord, protecting the privacy and security of our users is a top priority. That’s why it’s important to us that we’re transparent with them about events that impact their personal information.
050