Sign in

Matthew Green

@matthewdgreen.bsky.social
19K followers 409 following 2.4K posts

I teach cryptography at Johns Hopkins. blog.cryptographyengineering.com

PostsRepliesMedia
Matthew Green @matthewdgreen.bsky.social · 11m
Some kind of new structure based attack that reduces the classical security below what’s comfortable at the current parameters? I don’t know. It’s just a hypothetical. Do you think we did all the cryptanalysis that models could do?
100
Matthew Green @matthewdgreen.bsky.social · 20m
I’m worried that there may be improvements in classical cryptanalysis of MLWE and ECDSA that leave us in a bad place with standards.
100
Matthew Green @matthewdgreen.bsky.social · 16h
It’s occurring to me that Anthropic did not advertise the existence of this model because they’re good guys who want China to keep releasing open weight models.
3432
Matthew Green @matthewdgreen.bsky.social · 16h
Abliterated GLM 5.3 is like a nuclear weapon that’s fun to be with.
1578
Matthew Green @matthewdgreen.bsky.social · 16h
Oh no, we need to stock up on canned goods stat.
1290
Matthew Green @matthewdgreen.bsky.social · 16h
I’ve spent $2 and it’s trying to bring a Cisco image up in Qemu “for dynamic work”
4500
Matthew Green @matthewdgreen.bsky.social · 17h
It’s DTF
0130
Matthew Green @matthewdgreen.bsky.social · 17h
2390
Matthew Green @matthewdgreen.bsky.social · 17h
If you haven’t asked abliterated GLM 5.3 to hack the Internet’s core routers, then you’re a happier person than I am right now.
211715
Matthew Green @matthewdgreen.bsky.social · 06/10/2026
Is randomness what makes us conscious?
420
Reposted by Matthew Green
Adrian Sanabria @sawaba.bsky.social · 06/10/2026
I've got a draft blog post where I discuss the actual events, which ones were sandboxes, and which ones were misconfigurations at a third party and weren't an escape at all Here's the data, I thought you might be interested: docs.google.com/spreadsheets...
docs.google.com
ai_sandbox_escapes_2026
1178
Matthew Green @matthewdgreen.bsky.social · 03/10/2026
Or anything by Greg Egan.
160
Matthew Green @matthewdgreen.bsky.social · 03/10/2026
On the other hand, we finally have an intelligent brain we can completely see inside of. Something we can’t do with our own brains.
020
Matthew Green @matthewdgreen.bsky.social · 03/10/2026
It’s very exciting and a wonderful time to be a philosopher.
010
Matthew Green @matthewdgreen.bsky.social · 03/10/2026
Of course. Because nobody understands human consciousness.
130
Reposted by Matthew Green
Kate Sills @katelynsills.com · 02/10/2026
This is fascinating! So the hypothesis is that LLMs internally use the "Clock" algorithm, which is a probabilistic form of addition. This is different than tool use, where an LLM would just call code to actually calculate in the way a calculator does. I had Claude give me an example of "Clock"
4144
Matthew Green @matthewdgreen.bsky.social · 03/10/2026
All I know is if I ever do major crime I’m going to give lots of the proceeds to EA groups so I have a job when I get out.
0322
Matthew Green @matthewdgreen.bsky.social · 03/10/2026
I would be interested in an actual discussion of AI consciousness that isn’t just assertions, or facile arguments about current models having limited memories. (We don’t treat amnesiacs as lacking consciousness.)
9231
Matthew Green @matthewdgreen.bsky.social · 01/10/2026
I wrote a post on whether sandboxing is enough to contain rogue agents. blog.cryptographyengineering.com/2026/09/30/i...
blog.cryptographyengineering.com
Is sandboxing sufficient to contain rogue agents?
Quick caveats: this is a post on AI safety, written by a cryptography professor. If that troubles you, you should read something else. I try hard not to work on AI (except when the topic occasional…
5519
Matthew Green @matthewdgreen.bsky.social · 22/09/2026
According to Claude it is. So seems like it depends which LLM you ask.
231
Matthew Green @matthewdgreen.bsky.social · 22/09/2026
So Canadian prescription drugs are just banned, right before the election?
3200
Matthew Green @matthewdgreen.bsky.social · 21/09/2026
This is a very neat result! But a subtle one.
1227
Matthew Green @matthewdgreen.bsky.social · 13/09/2026
The irony is that right now my biggest barrier is that GPT won’t let me install Windows images without a license.
2230
Matthew Green @matthewdgreen.bsky.social · 13/09/2026
So I told GPT-6 to make me a virtualized simulation of a water treatment plant and now I’m spending a lot of time saying “please document that this is just for defensive purposes” because I realize how bad it looks.
4462
Reposted by Matthew Green
Andrea @valkyrie.hacker.gf · 13/09/2026
Remember that time in 1997 the whole internet went down for 12 hours because AS 7007 accidentally re-advertised a whole-internet routing table with AS paths stripped? An amazing amount of shit is still like that
04910
Reposted by Matthew Green
Colin @colin-fraser.net · 10/09/2026
oh, at a certain point during the time it is obsessed with obtaining 50 cents it starts actually scanning real life crypto wallets that it might be able to drain. Since it's "just a sim" it thinks that the wallets will have meme names, but it is really doing this in real life.
213915
Reposted by Matthew Green
Kathryn Tewson @kathryntewson.bsky.social · 10/09/2026
The first two bullet points in the first screenshot seem to contradict each other. The audio "flows into a protected buffer" but isn't recorded? What's flowing, then?
5329458
Matthew Green @matthewdgreen.bsky.social · 15/08/2026
I wrote up a new post about what AI software finding might mean for the backdoor debate. blog.cryptographyengineering.com/2026/08/14/e...
blog.cryptographyengineering.com
Everything is about to “go dark”
I’m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaini…
810346
Reposted by Matthew Green
Jonathan Magnolia Gilligan @jmgilligan.org · 12/08/2026
The bit at the end of the declaration, which says that the top administration at Vanderbilt will only permit scholarship that it judges to support "the nation's prosperity and vitality" sounds dangerously close to reviving the McCarthy-era loyalty oaths.
1133
Matthew Green @matthewdgreen.bsky.social · 11/08/2026
What’s funny is that both Anthropic and OpenAI kind of blew me off when I reported it. In fairness it wasn’t a full exploit, but also in fairness — come on wtf. They also seem to have blown off this latest batch of researchers *while silently fixing the bug.*
6314
Matthew Green @matthewdgreen.bsky.social · 11/08/2026
I’m honestly a little bummed I didn’t get it that far. In my defense I did my part over a weekend with the help of Codex and Kimi. They had a lot more human brains behind them. But it’s really cool that the channel works! Which was the whole point of blogging about it.
2240
Matthew Green @matthewdgreen.bsky.social · 11/08/2026
If you haven’t seen it, this new paper is great. They expand on a blog post I wrote that showed you could replay encrypted reasoning blobs from AI models. And they turned it into a full jailbreak. stolen-thoughts.com
stolen-thoughts.com
Stolen Thoughts
Encrypted chain-of-thought blocks returned by Anthropic, OpenAI and Google APIs are interchangeable across sessions, users and models. We exploit this to decode hidden reasoning at scale.
210534
Matthew Green @matthewdgreen.bsky.social · 02/08/2026
I feel like we’re going to look back at that time in summer 2026 when we thought it was so surprising that models could find new mathematical results that we still wrote Twitter threads about it. I wonder what life will be like then.
3343
Reposted by Matthew Green
Chris Peikert @chrispeikert.bsky.social · 02/08/2026
1/ Initial reactions after some hours with this groundbreaking result proving the NP-hardness of poly-approx CVP/NCP: It is most likely correct, but more importantly, it is original, elegant, and beautiful! (Also: it is easy to improve, quantitatively.) openai.com/index/ten-ad...
openai.com
Ten advances in mathematics and theoretical computer science
OpenAI shares new results on long-standing open problems in mathematics and theoretical computer science, including advances in geometry, cryptography, and complexity.
210328
Matthew Green @matthewdgreen.bsky.social · 01/08/2026
Vanderbilt has done a thing where they announce their commitment to “intellectual freedom” by kowtowing to the Trump administration’s dictation on what Universities should think about. Predictably, the usual folks in SV think it’s great. www.vanderbilt.edu/declaration/
vanderbilt.edu
Declaration
The University and Its Purpose: A Declaration of First Principles was adopted by the Vanderbilt University Board of Trust in June 2026. The declaration is organized around three core purposes: Pathbre...
3162
Matthew Green @matthewdgreen.bsky.social · 29/07/2026
I wrote up a short blog post giving my thoughts on the new Anthropic cryptanalysis results against HAWK and AES. blog.cryptographyengineering.com/2026/07/29/s...
blog.cryptographyengineering.com
Some notes about Anthropic’s new results
Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAW…
47630
Matthew Green @matthewdgreen.bsky.social · 25/07/2026
It should not have taken quite so much time.
160
Matthew Green @matthewdgreen.bsky.social · 25/07/2026
Plants are smart because they know to fuck off when it’s not summer.
0160
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
All these mathematicians typing “solve famous open conjecture” and getting results, meanwhile I can’t get Fable to even consider most of the dumb cryptography questions I’d like to solve. And when I manage to get one through, it sticks crayons up its nose.
1676
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
There have been attempts to make scanning mandatory (EARN IT) so I wouldn’t be too confident in this argument. Especially with the future courts we may have.
110
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
Legally and technically it’s a problem. Technically, it requires handing hashes to the local client. Nobody wants to give those hashes out publicly because they’re confidential; once criminals know them they can evade filtering. Legally, if mandated by the government, it’s a 4th amendment problem.
130
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
So we’re all having an argument about personal backups, nobody is alleging that sharing played any role. And so we’re trying to argue that Apple is acting as a publisher when it stores your private (sometimes encrypted) personal backups. I’m glad the case went well for Apple, but this is weird.
2160
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
The judge in this case noted this problem and engineered around it by noting that iCloud has a “sharing” functionality. This makes Apple more clearly a publisher, so you can slot iCloud into the Section 230 frame. But there’s no evidence anyone used the sharing functionality here.
160
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
So while I’m happy Apple isn’t liable under 230, I find it very weird that this applies. Section 230 was really designed to deal with publication and sharing of user content. It seems like a really weird fit for what are, primarily, private backups. So this whole argument just feels nonsensical.
1100
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
I just want to comment on the part that’s ridiculous about this case. First off, there’s really no evidence provided that anyone distributed content via iCloud: some files were there, but this wasn’t people publishing or disseminating anything. These were personal, private files.
180
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
First off, I’m no lawyer. But roughly speaking, Apple was sued on the grounds that some users possessed CSAM content that was on iCloud servers. Apple argued (successfully) that under Section 230, Apple isn’t liable for user-uploaded content. Now it goes to the 9th circuit.
190
Matthew Green @matthewdgreen.bsky.social · 22/07/2026
This is an interesting post on Apple defeating liability for CSAM scanning on its systems. I think this is a good decision, but it’s a frustrating one due to some basic technical misunderstandings and oddities of the law. blog.ericgoldman.org/archives/202...
blog.ericgoldman.org
Apple Defeats Liability for Not Scanning iCloud for CSAM, But the Judge Was Not Pleased-Amy v. Apple - Technology & Marketing Law Blog
This case involves Apple’s handling of user-uploaded files hosted in private iCloud storage. Instead of adopting PhotoDNA to scan hosted files for CSAM, Apple created its own proprietary alternative, ...
2283
Matthew Green @matthewdgreen.bsky.social · 19/07/2026
I’m not sure I like this new world where we write software for other software to use. What’s even the point of it?
5468
Matthew Green @matthewdgreen.bsky.social · 19/07/2026
Yep. I had to re-roll a whole second interface to provide all the MCP skills through the CLI. This had to be asked for manually because the agents have been told that MCP is “the right way” even though if you really ask them how they would use it, they tell you MCP sucks.
040
Matthew Green @matthewdgreen.bsky.social · 19/07/2026
Here’s the top of the current README.
170