Sign in

Matthew Green

@matthewdgreen.bsky.social
19K followers 407 following 2.4K posts

I teach cryptography at Johns Hopkins. blog.cryptographyengineering.com

PostsRepliesMedia
Matthew Green @matthewdgreen.bsky.social · 22/09/2026
So Canadian prescription drugs are just banned, right before the election?
3190
Matthew Green @matthewdgreen.bsky.social · 21/09/2026
This is a very neat result! But a subtle one.
1217
Matthew Green @matthewdgreen.bsky.social · 13/09/2026
So I told GPT-6 to make me a virtualized simulation of a water treatment plant and now I’m spending a lot of time saying “please document that this is just for defensive purposes” because I realize how bad it looks.
4462
Reposted by Matthew Green
Andrea @valkyrie.hacker.gf · 13/09/2026
Remember that time in 1997 the whole internet went down for 12 hours because AS 7007 accidentally re-advertised a whole-internet routing table with AS paths stripped? An amazing amount of shit is still like that
0479
Reposted by Matthew Green
Colin @colin-fraser.net · 10/09/2026
oh, at a certain point during the time it is obsessed with obtaining 50 cents it starts actually scanning real life crypto wallets that it might be able to drain. Since it's "just a sim" it thinks that the wallets will have meme names, but it is really doing this in real life.
213715
Reposted by Matthew Green
Kathryn Tewson @kathryntewson.bsky.social · 10/09/2026
The first two bullet points in the first screenshot seem to contradict each other. The audio "flows into a protected buffer" but isn't recorded? What's flowing, then?
5329458
Matthew Green @matthewdgreen.bsky.social · 15/08/2026
I wrote up a new post about what AI software finding might mean for the backdoor debate. blog.cryptographyengineering.com/2026/08/14/e...
blog.cryptographyengineering.com
Everything is about to “go dark”
I’m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaini…
810245
Reposted by Matthew Green
Jonathan Magnolia Gilligan @jmgilligan.org · 12/08/2026
The bit at the end of the declaration, which says that the top administration at Vanderbilt will only permit scholarship that it judges to support "the nation's prosperity and vitality" sounds dangerously close to reviving the McCarthy-era loyalty oaths.
1133
Matthew Green @matthewdgreen.bsky.social · 11/08/2026
If you haven’t seen it, this new paper is great. They expand on a blog post I wrote that showed you could replay encrypted reasoning blobs from AI models. And they turned it into a full jailbreak. stolen-thoughts.com
stolen-thoughts.com
Stolen Thoughts
Encrypted chain-of-thought blocks returned by Anthropic, OpenAI and Google APIs are interchangeable across sessions, users and models. We exploit this to decode hidden reasoning at scale.
210534
Matthew Green @matthewdgreen.bsky.social · 02/08/2026
I feel like we’re going to look back at that time in summer 2026 when we thought it was so surprising that models could find new mathematical results that we still wrote Twitter threads about it. I wonder what life will be like then.
3343
Reposted by Matthew Green
Chris Peikert @chrispeikert.bsky.social · 02/08/2026
1/ Initial reactions after some hours with this groundbreaking result proving the NP-hardness of poly-approx CVP/NCP: It is most likely correct, but more importantly, it is original, elegant, and beautiful! (Also: it is easy to improve, quantitatively.) openai.com/index/ten-ad...
openai.com
Ten advances in mathematics and theoretical computer science
OpenAI shares new results on long-standing open problems in mathematics and theoretical computer science, including advances in geometry, cryptography, and complexity.
210328
Matthew Green @matthewdgreen.bsky.social · 01/08/2026
Vanderbilt has done a thing where they announce their commitment to “intellectual freedom” by kowtowing to the Trump administration’s dictation on what Universities should think about. Predictably, the usual folks in SV think it’s great. www.vanderbilt.edu/declaration/
vanderbilt.edu
Declaration
The University and Its Purpose: A Declaration of First Principles was adopted by the Vanderbilt University Board of Trust in June 2026. The declaration is organized around three core purposes: Pathbre...
3162
Matthew Green @matthewdgreen.bsky.social · 29/07/2026
I wrote up a short blog post giving my thoughts on the new Anthropic cryptanalysis results against HAWK and AES. blog.cryptographyengineering.com/2026/07/29/s...
blog.cryptographyengineering.com
Some notes about Anthropic’s new results
Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAW…
47630
Matthew Green @matthewdgreen.bsky.social · 25/07/2026
Plants are smart because they know to fuck off when it’s not summer.
0160
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
All these mathematicians typing “solve famous open conjecture” and getting results, meanwhile I can’t get Fable to even consider most of the dumb cryptography questions I’d like to solve. And when I manage to get one through, it sticks crayons up its nose.
1666
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
This is an interesting post on Apple defeating liability for CSAM scanning on its systems. I think this is a good decision, but it’s a frustrating one due to some basic technical misunderstandings and oddities of the law. blog.ericgoldman.org/archives/202...
blog.ericgoldman.org
Apple Defeats Liability for Not Scanning iCloud for CSAM, But the Judge Was Not Pleased-Amy v. Apple - Technology & Marketing Law Blog
This case involves Apple’s handling of user-uploaded files hosted in private iCloud storage. Instead of adopting PhotoDNA to scan hosted files for CSAM, Apple created its own proprietary alternative, ...
2283
Matthew Green @matthewdgreen.bsky.social · 19/07/2026
I’ve been working on a hobby project to crack classical ciphers. The guts of it is to see whether frontier LLMs, given the right tools, can do a good job cracking a broad range of historical ciphers. github.com/matthewdgree...
github.com
GitHub - matthewdgreen/decipher: An AI-enabled application for cracking ciphers
An AI-enabled application for cracking ciphers. Contribute to matthewdgreen/decipher development by creating an account on GitHub.
58818
Matthew Green @matthewdgreen.bsky.social · 04/07/2026
What kills me about this story is that Meta’s public CSAM scanning clearly does not work, if they’re delivering ads for CSAM content. But this failure will be used as evidence that we need to add scanning for private and encrypted messages. www.bbc.com/news/article...
bbc.com
India: Instagram running ads promoting child sexual abuse material, BBC finds
The ads use terms including “rape” and “child video” and link to content on the messaging app Telegram.
918381
Reposted by Matthew Green
Ron Deibert @rondeibert.bsky.social · 03/07/2026
Researchers @citizenlab.ca say EU lawmaker who investigated surveillance was hacked by Israeli spyware @raphae.li www.reuters.com/world/middle...
reuters.com
Researchers say EU lawmaker who investigated surveillance was hacked by Israeli spyware
A former member of the European Parliament who served ​on a committee investigating abusive surveillance was himself hacked using an Israeli-made spy tool, a Canadian tech watchdog group ‌said on Frid...
1128
Matthew Green @matthewdgreen.bsky.social · 03/07/2026
Theory question: give an upper bound on the number of vulnerabilities that can be present in an n-bit program.
9141
Matthew Green @matthewdgreen.bsky.social · 02/07/2026
Apropos of nothing, does anyone else have very happy memories associated with this product?
161064
Matthew Green @matthewdgreen.bsky.social · 01/07/2026
I don’t think people should panic based on anything djb has written recently. But I do agree with his conclusion that ECC hybrids are a good idea. I also do continue to be skeptical of the “ECC hybrids are just too hard to get right” arguments.
4323
Reposted by Matthew Green
alpha @omarsbigsister.bsky.social · 29/06/2026
Dems' "Project 2029" first major policy proposal: an online child safety plan — narrowing Sec. 230, banning social media for kids under 16, promoting phone-free childhoods and more. Already backed by Cory Booker, Mikie Sherrill, Randi Weingarten + Jonathan Haidt. LMAOOOOOOOOOOOOOOOOOOO.
6932042292
Matthew Green @matthewdgreen.bsky.social · 29/06/2026
One of my beefs with (research) cryptography is that people are overindexing on quantum threats. We finally got crypto to the point where we can do things efficiently, and now we need to rip it all up and switch to lattice schemes at 11,000x the cost.
2285
Matthew Green @matthewdgreen.bsky.social · 28/06/2026
“Europe needs air conditioning” is true, but it also feels like a talking point explicitly constructed so that people don’t have to pay attention to the effects of rapid climate change.
111009
Matthew Green @matthewdgreen.bsky.social · 24/06/2026
Counterpoint: the fact that vendors/projects won’t privilege vulnerability reports is hardly a punishment for security researchers. It’s a gift.
2111
Matthew Green @matthewdgreen.bsky.social · 24/06/2026
So apparently anyone with a license plate number can submit it to most DMVs to obtain detailed owner information, provided they claim they’re doing so in the “ordinary course of business” (eg to collect a debt). This isn’t verified or checked.
1016847
Matthew Green @matthewdgreen.bsky.social · 22/06/2026
So Will Cathcart is leaving WhatsApp and this is the new leader that Mark Zuckerberg has chosen.
56919
Matthew Green @matthewdgreen.bsky.social · 19/06/2026
One of my new favorite gripes is people setting up AI receptionists to answer their phone and telling them nothing, including whether the business is open that day. It’s just the weirdest way to use technology.
1240
Matthew Green @matthewdgreen.bsky.social · 17/06/2026
I wonder if the frontier LLMs have benchmarks for their human users.
0201
Reposted by Matthew Green
Lily Hay Newman @lhn.bsky.social · 16/06/2026
just, you know, to recap www.wired.com/story/danger...
wired.com
‘Dangerous’ AI Models Are Coming No Matter What
The US government crackdown on Anthropic’s Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will soon be the norm.
1105
Matthew Green @matthewdgreen.bsky.social · 13/06/2026
One of the things I’ve noticed in my aging friends is that virulent conservative beliefs and cognitive decline seem highly correlated.
65711
Matthew Green @matthewdgreen.bsky.social · 13/06/2026
It really seems like we’re going to end up with a choice of doing model inference expensively here in the US or inexpensively in China, and this is going to create a nightmare data sovereignty problem.
54310
Matthew Green @matthewdgreen.bsky.social · 12/06/2026
God, Claude Fable really knows how to butter me up.
4180
Reposted by Matthew Green
Alexander Martin @alexmartin.bsky.social · 10/06/2026
Scoop: Britain has weakened proposed cybersecurity protections for its telecoms networks that were developed in response to the Salt Typhoon espionage campaign, after the companies responsible for implementing the measures lobbied against them.
therecord.media
UK weakens proposed telecoms defenses against Chinese hackers after industry pushback
Britain has weakened proposed cybersecurity protections for its telecoms networks that were developed in response to the Salt Typhoon espionage campaign, after the companies responsible for implementi...
32219
Matthew Green @matthewdgreen.bsky.social · 10/06/2026
My strongest argument that we’re actually living in a simulation is the three-way light switch. There’s no way that can possibly work.
4190
Matthew Green @matthewdgreen.bsky.social · 09/06/2026
I wrote a new post about the privacy risks of on-phone agents like Apple’s new Siri, and how private inference isn’t any sort of silver bullet. blog.cryptographyengineering.com/2026/06/09/a...
blog.cryptographyengineering.com
The future of Siri, or: why private inference isn’t private enough
Yesterday Apple announced a big step towards deploying real AI in their Siri ecosystem. In most ways this is good and inevitable: Siri is one of the world’s most widely-used voice agents, and…
1211850
Reposted by Matthew Green
Carl T. Bergstrom @carlbergstrom.com · 06/06/2026
Remember the current NIH director going on about protecting researchers from government censorship? Today his people called the police in to forcibly remove my colleagues from their own society meeting for sharing an editorial published in their flagship journal that was critical of him. Gift link
nytimes.com
Police Remove Diabetes Experts From Conference for Distributing Critique of Trump Administration
5629151465
Matthew Green @matthewdgreen.bsky.social · 05/06/2026
Does anyone have a connection to Randall Munroe (@xkcd.com) or any way to reach his company? I’m writing a book and wanted to license some of his cartoons but can’t get a response from his licensing or press emails.
23314
Matthew Green @matthewdgreen.bsky.social · 04/06/2026
I’ve spent the past several weeks using AI to build software at and do research, so this has given me a lot of perspective on how these systems perform when you push them towards (and beyond) the edge of their training set. I guess this gives me a different perspective.
34710
Reposted by Matthew Green
Alexander Martin @alexmartin.bsky.social · 04/06/2026
You replace some regular spaces with U+2002 spaces in a particular pattern, send subtly different versions to different recipients, and you can identify a leak from the spacing alone. It's invisible to the naked eye but trivial to detect with a Unicode inspector. [10/11]
1247
Reposted by Matthew Green
Alejandra Caraballo @esqueer.net · 04/06/2026
I get the hate for AI but I was able to use Claude to build tools to get access to hundreds of court records via courtlistener API, hundreds of 990s via Propublicas charity navigator, and thousands of political campaign spending records via FEC and Google to measure anti-trans political spending.
6381772
Reposted by Matthew Green
Fernando @fernand0.bsky.social · 02/06/2026
60% of MD5 password hashes are crackable in under an hour
theregister.com
60% of MD5 password hashes are crackable in under an hour
0168
Reposted by Matthew Green
Laurens @laurenshof.online · 02/06/2026
the even more fun problem is, that because NL Wallet uses remote app attestation, it checks Googles servers for verification every time you use the app, meaning that Google holds a kill switch for our national ID wallet
35114
Reposted by Matthew Green
Toby Murray @tobycmurray.bsky.social · 29/05/2026
Matt call this an investigation of a $10 question. That undersells the importance of this encryption to frontier labs. It’s one of their primary defences against model distillation attacks, which represent major threats to their competitiveness.
0286
Matthew Green @matthewdgreen.bsky.social · 29/05/2026
My kid was joking the other day about visiting conspiracy websites, like the ones that end in .gov.
0587
Matthew Green @matthewdgreen.bsky.social · 29/05/2026
Last week I discovered that ChatGPT and Claude will send you their “encrypted raw reasoning” and of course I immediately wasted a weekend trying to do something bad with it. What I got for my trouble was this blog post: blog.cryptographyengineering.com/2026/05/29/f...
blog.cryptographyengineering.com
Fooling around with encrypted reasoning blobs
This is a quick post I wanted to write about a “hobby project” I spent a weekend on. It has little to do with real cryptography, and mostly doesn’t expose a particularly exciting …
47824
Matthew Green @matthewdgreen.bsky.social · 29/05/2026
So I sort of found an issue with the OpenAI and Anthropic APIs, but they disagree. I think that means I can blog about it?
5470
Matthew Green @matthewdgreen.bsky.social · 26/05/2026
One of the things I used to like about Matthew Yglesias is that he criticized evidence-free windbags like Thomas Friedman. Now he’s an evidence-free windbag and he thinks he’s killing it.
2332
Reposted by Matthew Green
Matthew Gracie @infosecgoon.bsky.social · 24/05/2026
Yeah, this. I also miss peak Infosec Twitter. I know this isn't it, but neither is current Twitter.
2524