Sign in

Lena Heimberger

@meyira.bsky.social
43 followers 60 following 13 posts

Cryptography and Privacy @tugraz heimberger.xyz

PostsRepliesMedia
Reposted by Lena Heimberger
Techmeme @techmeme.com · 04/06/2026
Sources: Anthropic has embedded around half a dozen forward-deployed engineers within the NSA to help the agency deploy Mythos for offensive cyber operations (Financial Times) Main Link | Techmeme Permalink
11611
Reposted by Lena Heimberger
University of Graz @uni-graz.at · 22/05/2026
📢 Angesichts der drohenden dramatischen Budgetkürzungen rufen die Österreichische Hochschüler:innenschaft und die Universitäten gemeinsam zu großen Kundgebungen auf: 🗓️ Donnerstag, 28. Mai 2026, um 14 Uhr 📍 Treffpunkt Wilhelm Fischer Allee (Stadtpark Graz) #UnisRetten #SparkursStoppen
uni-graz.at
#UnisRetten #SparkursStoppen: Demo am 28. Mai in Graz
Die Österreichische Hochschüler:innenschaft und die Universitäten rufen gemeinsam zu großen Kundgebungen auf. Treffpunkt in Graz ist am 28. Mai um 14 Uhr in der Wilhelm-Fischer-Allee.
0126
Reposted by Lena Heimberger
Julia Partheymüller @schnizzl.bsky.social · 27/05/2026
Zur Erinnerung: Bereits vor den angekündigten Kürzungen war die Beschäftigungssituation prekär - 80% arbeiten befristet. Durch Sparmaßnahmen wird sich die Lage weiter verschärfen. #UnisRetten #SuperGAU
0169
Lena Heimberger @meyira.bsky.social · 21/05/2026
(PhD) Life is easier when you talk to your friends, and a little extra information in your messages can actually prevent MitM attacks. Attaching your current state gives you pretty good detection rates. We formalized, simulated and built it in a custom Signal client- 119 bytes; 5 min to detection.
120
Lena Heimberger @meyira.bsky.social · 08/04/2026
Summer intern wanted! @exhel.bsky.social and I are looking for s/o to work with us this summer @ TU Graz. Helpful background: Android, reversing, or messaging apps Send a short motivation statement+CV to lena.heimberger@tugraz.at and edona.fasllija@tugraz.at #Android #ReverseEngineering #Internship
000
Reposted by Lena Heimberger
Cameron Blevins @cblevins.bsky.social · 03/04/2026
This is so, so well-articulated.
People call this friction "grunt work." Schwartz uses exactly that phrase, and he's right that LLMs can remove it. What he doesn't say, because he already has decades of hard-won intuition and doesn't need the grunt work anymore, is that for someone who doesn't yet have that intuition, the grunt work is the work. The boring parts and the important parts are tangled together in a way that you can't separate in advance. You don't know which afternoon of debugging was the one that taught you something fundamental about your data until three years later, when you're working on a completely different problem and the insight surfaces. Serendipity doesn't come from efficiency. It comes from spending time in the space where the problem lives, getting your hands dirty, making mistakes that nobody asked you to make and learning things nobody assigned you to learn.
97107623880
Reposted by Lena Heimberger
Doreen Riepel @doreenriepel.bsky.social · 18/02/2026
📢 We have extended the deadline for our EC workshop to *Monday AoE*! Submit your talk proposal on any topic related to cryptographic proofs and proof techniques 🤓 Take the opportunity to advertise your ongoing, submitted or published work, or to share other insights related to security proofs
194
Lena Heimberger @meyira.bsky.social · 18/02/2026
Finally got around to upload the slides from my Paris Crypto Day talk "Oblivious Pseudorandom Functions in a Post-Quantum World"- check them out here: heimberger.xyz/docs/cryptod...
heimberger.xyz
030
Lena Heimberger @meyira.bsky.social · 26/01/2026
DCTF26 will happen from March 21, 2026 - March 22, 2026 in Ljubljana, which is most beautiful in Spring. DCTF is my favourite conference of the year. It's technically challenging, student-organized and also free. Please consider submitting to the CFP: cfp.dragonsec.si/dctf26/cfp (speaker dinner!)
cfp.dragonsec.si
DCTF26
Schedule, talks and talk submissions for DCTF26
000
Lena Heimberger @meyira.bsky.social · 12/01/2026
Schedule for the Paris Crypto Days on January 16th at Telecom Paris: 09:30–10:15: Breakfast 10:15–12:15: T. Debris & A. Chailloux “From Regev’s Reduction to Quantum Advantages” 12:15–14:00: Lunch 14:00–15:00: Lena Heimberger: “Oblivious Pseudorandom Functions in a Post-Quantum World”
100
Reposted by Lena Heimberger
ePrint Updates @eprint.ing.bot · 09/01/2026
Aborting Random Oracles: How to Build them, How to Use them (Gottfried Herold, Dmitry Khovratovich, Mikhail Kudinov, Stefano Tessaro, Benedikt Wagner) ia.cr/2026/016
Abstract. In this work, we initiate the study of aborting hash functions, i.e., hash functions that may abort on a non-negligible fraction of inputs. We introduce the aborting random oracle model (aROM), an idealized framework that extends the standard random oracle model (ROM) to account for aborts. Within this model, we derive bounds for various security notions and establish generic indifferentiability results demonstrating how to construct aborting random oracles from standard ones. Consequently, the derived bounds ultimately hold in the standard ROM. In this way, the aROM and its associated bounds provide a convenient and easy-to-use framework for analyzing cryptographic constructions that rely on potentially aborting hash functions.

To illustrate the utility of our framework, we apply our techniques to two settings: (1) the analysis of SNARK-friendly incomparable hypercube encodings, a core primitive in hash-based signature schemes, and (2) the analysis of grinding in Fiat–Shamir-based non-interactive arguments. Through our generic indifferentiability results, we can easily translate these analyses into concrete security bounds in the standard (non-aborting) random oracle model.
Image showing part 2 of abstract.
022
Reposted by Lena Heimberger
Techmeme @techmeme.com · 09/01/2026
The EU says it is considering designating WhatsApp a "very large platform", after WhatsApp published user numbers above the DSA threshold in February 2025 (Louise Breusch Rasmussen/Reuters) Main Link | Techmeme Permalink
082
Reposted by Lena Heimberger
ePrint Updates @eprint.ing.bot · 02/01/2026
The Cokernel Pairing (Krijn Reijnders) ia.cr/2026/001
Abstract. We study a new pairing, beyond the Weil and Tate pairing. The Weil pairing is a non-degenerate pairing E[m] × E[m] → μ_(m), which operates on the kernel of [m]. Similarly, when μ_(m) ⊆ 𝔽_(q)^(*), the Tate pairing is a non-degenerate pairing E[m](𝔽_(q)) × E(𝔽_(q))/[m]E(𝔽_(q)) → μ_(m), which connects the kernel and the rational cokernel of [m]. We define a pairing
⟨  ⟩_(m) : E(𝔽_(q))/[m]E(𝔽_(q)) × E(𝔽_(q))/[m]E(𝔽_(q)) → μ_(m)
on the rational cokernels of [m], filling the gap left by the Weil and Tate pairing. When E[m] ⊆ E(𝔽_(q)), this pairing is non-degenerate, and can be computed using three Tate pairings, and two discrete logarithms in μ_(m), assuming a basis for E[m]. For m = ℓ prime, this pairing allows us to study E(𝔽_(q))/[ℓ]E(𝔽_(q)) directly and to simplify the computation for a basis of E[ℓ^(k)], and more generally the Sylow ℓ-torsion. This finds natural applications in isogeny-based cryptography when computing ℓ^(k)-isogenies.
043
Lena Heimberger @meyira.bsky.social · 25/11/2025
I'll be around Melbourne for LatticeCC before asiacrypt. Let me know if you want to talk lattices!
000
Reposted by Lena Heimberger
Meredith Whittaker @meredithmeredith.bsky.social · 06/10/2025
📣 Germany's close to reversing its opposition to mass surveillance & private message scanning, & backing the Chat Control bill. This could end private comms-& Signal-in the EU. Time's short and they're counting on obscurity: please let German politicians know how horrifying their reversal would be.
3022381606
Reposted by Lena Heimberger
ePrint Updates @eprint.ing.bot · 03/11/2025
Forging Dilithium and Falcon Signatures by Single Fault Injection (Sven Bauer, Fabrizio De Santis) ia.cr/2025/2029
Abstract. Embedded devices commonly rely on digital signatures to ensure both integrity and authentication. For example, digital signatures are typically verified during the boot process or firmware updates to verify the integrity of a system. They are also used to ensure authenticity of a communication party in secure protocols. Fault injection can be used to tamper with a device in order to cause malfunctioning during cryptographic computations. For example, fault injections can be used to disturb digital signing operations. With the right type of fault an attacker can compute private keys from faulted signatures. However, fault injections can also be used during verification to get maliciously crafted digital signatures accepted during signature verification with catastrophic consequences for the security of an embedded device. In this paper, we introduce new non-obvious fault injection attacks on the verification routines of Dilithium and Falcon signature schemes, which allow an attacker to get signatures for arbitrary messages accepted by fault injection. We demonstrate the feasibility of our attacks by simulations using an ARM Cortex-M4 and the pqm4 library as a target of evaluation and pinpoint vulnerable instructions. Finally, we propose and discuss possible countermeasures against these attacks.
Image showing part 2 of abstract.
032
Reposted by Lena Heimberger
Christopher Patton @cjpatton.bsky.social · 31/10/2025
Anonymous credentials are going to have a big year. In the realm of "fancy" cryptography, they're perhaps the most important primitive we'll need to make PQ. Where do we stand? Lena Heimberger spent part of the summer finding out. blog.cloudflare.com/pq-anonymous...
blog.cloudflare.com
Policy, privacy and post-quantum: anonymous credentials for everyone
The world is adopting anonymous credentials for digital privacy, but these systems are vulnerable to quantum computers. This post explores the cryptographic challenges and promising research paths tow...
042
Reposted by Lena Heimberger
Thibault @thibmeu.com · 30/10/2025
@cjpatton.bsky.social and @meyira.bsky.social also dive into how we can make these primitives post-quantum secure blog.cloudflare.com/pq-anonymous...
blog.cloudflare.com
Policy, privacy and post-quantum: anonymous credentials for everyone
The world is adopting anonymous credentials for digital privacy, but these systems are vulnerable to quantum computers. This post explores the cryptographic challenges and promising research paths tow...
021
Lena Heimberger @meyira.bsky.social · 30/10/2025
Anonymous credentials are mostly talked about in the context of age verification. We also looked how to use them to verify bots, laying the foundation for a new version of rate limiting- more refined, with more functionality, and still private! blog.cloudflare.com/private-rate...
blog.cloudflare.com
Anonymous credentials- rate-limiting bots and agents without compromising privacy
As AI agents change how the Internet is used, they create a challenge for security. We explore how Anonymous Credentials can rate limit agent traffic and block abuse without tracking users or compromi...
000
Reposted by Lena Heimberger
Thibault @thibmeu.com · 30/10/2025
Most AI traffic comes from massive shared, platforms. If one user is abusive, how do you rate-limit them without blocking everyone? IP blocks won't work. We explore private rate limits, a way to stop abuse without tracking users. blog.cloudflare.com/private-rate...
blog.cloudflare.com
Anonymous credentials- rate-limiting bots and agents without compromising privacy
As AI agents change how the Internet is used, they create a challenge for security. We explore how Anonymous Credentials can rate limit agent traffic and block abuse without tracking users or compromi...
132
Reposted by Lena Heimberger
str👻d @str4d.xyz · 20/10/2025
Update: the claimed bugfix is refuted!
031
Reposted by Lena Heimberger
Matthew Green @matthewdgreen.bsky.social · 14/10/2025
This is amazing research by Nadia Heninger and her co-authors Wenyi Morty Zhang, Annie Dai, Keegan Ryan, Dave Levin and Aaron Schulman. TL;DR a huge number of satellite links over our heads are totally unencrypted. satcom.sysnet.ucsd.edu
satcom.sysnet.ucsd.edu
🛰️ SATCOM Security
Research project homepage for SATCOM Security: papers, source code, and recent satellite communications vulnerabilities.
514768
Reposted by Lena Heimberger
Alec Muffett @alecmuffett.bsky.social · 14/10/2025
Why Signal’s post-quantum makeover is an amazing engineering achievement | Ars Technica alecmuffett.com/article/117370 #EndToEndEncryption #PostQuantum #signal
alecmuffett.com
Why Signal’s post-quantum makeover is an amazing engineering achievement | Ars Technica
Happy to read this, not least because I’ve often seen the push for rapid adoption of PQ as coming from intelligence agencies seeking to sow confusion & discord; having a well researched h…
073
Reposted by Lena Heimberger
ePrint Updates @eprint.ing.bot · 17/10/2025
Graeffe-Based Attacks on Poseidon and NTT Lower Bounds (Ziyu Zhao, Antonio Sanso, Giuseppe Vitto, Jintai Ding) ia.cr/2025/1916
Abstract. Poseidon and Poseidon2 are cryptographic hash functions crafted for efficient zero-knowledge proof systems and have seen wide adoption in practical applications. We introduce the use of the Graeffe transform in univariate polynomial solving within this line of work. The proposed method streamlines the root recovery process in interpolation attacks and achieves several orders of magnitude acceleration in practical settings, enabling a new and more efficient class of attacks against Poseidon targeting round-reduced permutations and constrained input/output instances. We release open-source code and describe our method in detail, demonstrating substantial improvements over prior approaches: reductions in wall time by a factor of 2¹³ and in memory usage by a factor of 2^(4.5). Memory-access costs for NTTs turn out to be a dominant barrier in practice. And we prove that this cost increases at least as the 4/3-power of the input size (up to logarithmic factors), which suggests the commonly used pseudo-linear cost model may underestimate the true resource requirements. This behavior contrasts with multivariate equation solving, whose main bottleneck remains finite-field linear algebra. We argue that, when selecting parameters, designers should account for interpolation-based attacks explicitly, since their practical hardness is determined by different, and sometimes stronger, resource constraints than those of multivariate techniques.
Image showing part 2 of abstract.
053
Lena Heimberger @meyira.bsky.social · 17/10/2025
Javascript just became a bit more trustworthy using transparency protocols! This is a really cool deployment and shows how tk use transparency in ither places than certificates! blog.cloudflare.com/improving-th...
blog.cloudflare.com
Improving the trustworthiness of Javascript on the Web
Today, there's no way to audit a site’s client-side code as it changes, making it hard to trust sites that use cryptography. We preview a specification we coauthored that adds auditability to the web.
000
Reposted by Lena Heimberger
Martin R. Albrecht @malb.bsky.social · 24/06/2025
Slides of my talk titled "Lattices give us KEMs and FHE, but where are the efficient lattice PETs? -- By Example of (Verifiable) Oblivious PRFs" given at spiqe-workshop.github.io are here: github.com/malb/talks/b... Thanks @kennyog.bsky.social and @jurajsomorovsky.bsky.social for inviting me.
github.com
0124
Reposted by Lena Heimberger
COSIC @cosic.bsky.social · 16/06/2025
Registration for the Leuven Isogeny Days 6 is now open! 📅 10–12 Sept 2025 @ KU Leuven Morning: research talks Afternoon: brainstorming sessions More info: www.esat.kuleuven.be/cosic/projec... #isogeny #isocrypt #erc #postquantum
0119
Reposted by Lena Heimberger
Andrea Basso @andreavbasso.bsky.social · 10/06/2025
We (finally) published all the material from this course on SQIsign, including lecture slides and exercise sheets for the Sage laboratory. Available here: github.com/andreavico/S...
github.com
GitHub - andreavico/SQIsign_summer_school: Slides and worksheets for the introductory course on SQIsign held in Trento in May 2025
Slides and worksheets for the introductory course on SQIsign held in Trento in May 2025 - andreavico/SQIsign_summer_school
11616
Lena Heimberger @meyira.bsky.social · 10/06/2025
🖤🕯️ #graz
000
Reposted by Lena Heimberger
Ben Cartwright-Cox @benjojo.bsky.social · 27/05/2025
On May 20th 2025 a BGP message was propagated that triggered some surprisingly disruptive behaviours with two major BGP implementations make up a lot of the internet. In a new blog post, I will dissect what that message was, and my thoughts on how it happened: blog.benjojo.co.uk/post/bgp-att...
blog.benjojo.co.uk
BGP handling bug causes widespread internet routing instability
0328
Reposted by Lena Heimberger
ePrint Updates @eprint.ing.bot · 26/05/2025
Poseidon and Neptune: Gröbner Basis Cryptanalysis Exploiting Subspace Trails (Lorenzo Grassi, Katharina Koschatko, Christian Rechberger) ia.cr/2025/954
Abstract. At the current state of the art, algebraic attacks are the most efficient method for finding preimages and collisions for arithmetization-oriented hash functions, such as the closely related primitives Poseidon/Poseidon2 and Neptune. In this paper, we revisit Gröbner basis (GB) attacks that exploit subspace trails to linearize some partial rounds, considering both sponge and compression modes.

Starting from Poseidon’s original security evaluation, we identified some inaccuracies in the model description that may lead to misestimated round requirements. Consequently, we reevaluate and improve the proposed attack strategy. We find that depending on the concrete instantiation, the original security analysis of Poseidon under- or overestimates the number of rounds needed for security. Moreover, we demonstrate that GB attacks leveraging subspace trails can outperform basic GB attacks for Poseidon/Poseidon2 and Neptune.

We propose a variant of the previous attack strategy that exploits a crucial difference between Poseidon/Poseidon2 and Neptune: while Poseidon’s inverse round functions have a high degree, Neptune’s inverse external rounds maintain the same degree as the forward rounds. Using this new model, we demonstrate that Neptune’s security in compression mode cannot be reduced to its security against the Constrained-Input-Constrained-Output (CICO) problem. To the best of our knowledge, this is the first time a concrete example has been provided where finding preimages is easier than solving the corresponding CICO problem.

Our results emphasize the importance of considering the mode of operation in security analysis while confirming the overall security of Poseidon/Poseidon2 and Neptune against the presented algebraic attacks.
Image showing part 2 of abstract.
031
Reposted by Lena Heimberger
ePrint Updates @eprint.ing.bot · 26/05/2025
Breaking Poseidon Challenges with Graeffe Transforms and Complexity Analysis by FFT Lower Bounds (Ziyu Zhao, Jintai Ding) ia.cr/2025/950
Abstract. Poseidon and Poseidon2 are cryptographic hash functions designed for efficient zero-knowledge proof protocols and have been widely adopted in Ethereum applications. To encourage security research, the Ethereum Foundation announced a bounty program in November 2024 for breaking the Poseidon challenges, i.e. solving the CICO (Constrained Input, Constrained Output) problems for round-reduced Poseidon constructions. In this paper, we explain how to apply the Graeffe transform to univariate polynomial solving, enabling efficient interpolation attacks against Poseidon. We will provide an open-source code and details our approach for solving several challenges valued at $20000 in total. Compared to existing attacks, we improves 2^{13} and 2^{4.5} times in wall time and memory usage, respectively. For all challenges we solved, the cost of memory access turns out to be an essential barrier, which makes the security margin much larger than expected. We actually prove that the memory access cost for FFT grows as the 4/3-power of the input size, up to a logarithmic factor. This indicates the commonly used pseudo linear estimate may be overly conservative. This is very different from multivariate equation solving whose main bottleneck is linear algebra over finite fields. Thus, it might be preferable to choose parameters such that the best known attack is interpolation, as it presents more inherent hardness.
Image showing part 2 of abstract.
122
Reposted by Lena Heimberger
Christian Knabenhans @cknabs.bsky.social · 20/05/2025
I'm happy to finally open-source lattirust, a library for lattice-based zero-knowledge/succinct arguments! Lattirust is somewhat like arkworks, but for lattices; and like lattigo, but for arguments. ➔ github.com/lattirust
github.com
lattirust
Lattice zero-knowledge/succinct arguments, and more - lattirust
23216
Lena Heimberger @meyira.bsky.social · 20/05/2025
We're studying user messaging behaviour to get data for a simulation for key transparency. If you have 10 minutes, please fill out this survey: survey.tugraz.at/mobile-messe... (if you are around Graz and fill it out before Thursday, you may win a free drink at the local CTF team's fundraiser!)
survey.tugraz.at
User Behaviour in Mobile Messengers
000
Reposted by Lena Heimberger
ePrint Updates @eprint.ing.bot · 28/03/2025
Private SCT Auditing, Revisited (Lena Heimberger, Christopher Patton, Bas Westerbaan) ia.cr/2025/556
Abstract. In order for a client to securely connect to a server on the web, the client must trust certificate authorities (CAs) only to issue certificates to the legitimate operator of the server. If a certificate is miss-issued, it is possible for an attacker to impersonate the server to the client. The goal of Certificate Transparency (CT) is to log every certificate issued in a manner that allows anyone to audit the logs for miss-issuance. A client can even audit a CT log itself, but this would leak sensitive browsing data to the log operator. As a result, client-side audits are rare in practice. In this work, we revisit private CT auditing from a real-world perspective. Our study is motivated by recent changes to the CT ecosystem and advancements in Private Information Retrieval (PIR). First, we find that checking for inclusion of Signed Certificate Timestamps (SCTs) in a log — the audit performed by clients — is now possible with PIR in under a second and under 100kb of communication with minor adjustments to the protocol that have been proposed previously. Our results also show how to scale audits by using existing batching techniques and the algebraic structure of the PIR protocols, in particular to obtain certificate hashes by included in the log. Since PIR protocols are more performant with smaller databases, we also suggest a number of strategies to lower the size of the SCT database for audits. Our key observation is that the web will likely transition to a new model for certificate issuance. While this transition is primarily motivated by the need to adapt the PKI to larger, post-quantum signature schemes, it also removes the need for SCT audits in most cases. We present the first estimates of how this transition may impact SCT auditing, based on data gathered from public CT logs. We find that large scale deployment of the new issuance model may reduce the number of SCT audits needed by a factor of 1,000, making PIR-based auditing practical to deploy.
Image showing part 2 of abstract.
001
Reposted by Lena Heimberger
ePrint Updates @eprint.ing.bot · 25/02/2025
Leap: A Fast, Lattice-based OPRF With Application to Private Set Intersection (Lena Heimberger, Daniel Kales, Riccardo Lolato, Omid Mir, Sebastian Ramacher, Christian Rechberger) ia.cr/2025/333
Abstract. Oblivious pseudorandom functions (OPRFs) are an important primitive in privacy-preserving cryptographic protocols. The growing interest in OPRFs, both in theory and practice, has led to the development of numerous constructions and variations. However, most of these constructions rely on classical assumptions. Potential future quantum attacks may limit the practicality of those OPRFs for real-world applications.

To close this gap, we introduce Leap, a novel OPRF based on heuristic lattice assumptions. Fundamentally, Leap builds upon the Spring [BBL+15] pseudorandom function (PRF), which relies on the learning with rounding assumption, and integrates techniques from multi-party computation, specifically Oblivious Transfer (OT) and Oblivious Linear Evaluation (OLE). With this combination of oblivious protocols, we construct an OPRF that evaluates in less than a millisecond on a modern computer.

Efficiency-wise, our prototype implementation achieves computation times of just 11 microseconds for the client and 750 microseconds for the server, excluding some base OT preprocessing overhead. Moreover, Leap requires an online communication cost of 23 kB per evaluation, where the client only has to send around 380 bytes online. To demonstrate the practical applicability of Leap, we present an efficient private set intersection (PSI) protocol built on top of Leap. This application highlights the potential for the integration of Leap into various privacy-preserving applications: We can compute an unbalanced set intersection with set sizes of 2^24 and 2^15 in under a minute of online time and just over two minutes overall.
Image showing part 2 of abstract.
011