Sign in

Miro Haller

@mirohaller.bsky.social
179 followers 112 following 46 posts

PhD student @ UCSD working on applied cryptography mirohaller.com

PostsRepliesMedia
Miro Haller @mirohaller.bsky.social · 21/09/2026
We finally finished the universal signature forgery for 1024-bit RSA! 2^32 oracle queries, 1200 core years precomputation, 180 core years for an individual forgery, and 3 years of human labor (no AI involved) by Laura, Adam, Nadia, Emmanuel and me to pull of this computation against real HSMs.
14019
Reposted by Miro Haller
Kenny Paterson @kennyog.bsky.social · 15/08/2026
Signal is the gold standard for secure messengers. We broke Signal’s integrity (twice) in this paper via message injection attacks. @kientuong114.bsky.social presented this week at #USENIX and he and Noemi will present it again at #WAC (Crypto workshop) this weekend. Catch their talk if you can!
02911
Miro Haller @mirohaller.bsky.social · 11/08/2026
Turns out you can’t assume warrants are always digital so protecting their integrity is actually not (only) a cryptographic problem. Very cool security paper that builds a solution that takes care of real world constraints (including messy physical warrants and bad scanners).
010
Miro Haller @mirohaller.bsky.social · 10/08/2026
You can also register to attend WAC8--the workshop on attacks in cryptography, an affiliated event with Crypto 2026--remotely (for free). Just fill out this google form: forms.gle/1anNohNaJmtA...
forms.gle
WAC8 Remote Registration
Sign up with an email address to receive the Zoom link to attend the workshop on attacks in cryptography 8 (WAC8) remotely. All information about the workshop is on our website: https://wac8.cryptanal...
164
Miro Haller @mirohaller.bsky.social · 26/07/2026
Don't forget to register for WAC8! Early registration ends today (July 26). Below is our finalized WAC8 program with 8 exciting talks. More infos on: wac8.cryptanalysis.fun
073
Miro Haller @mirohaller.bsky.social · 29/06/2026
Time to submit your fresh new cryptanalysis results to WAC8 (Crypto'26 affiliated event) this week. The deadline is on Friday, July 3 (AoE). All infos about the call are on: wac8.cryptanalysis.fun
010
Reposted by Miro Haller
Tianxin Tang @koptxin.bsky.social · 17/06/2026
I am looking for a (fully funded) PhD student working with me in Glasgow on provable security! www.iacr.org/jobs/item/4226
iacr.org
PhD Student
087
Miro Haller @mirohaller.bsky.social · 11/06/2026
The Workshop on Attacks in Cryptography 8 (WAC8) website is finally up, and our call for talks is open. Submit your cool cryptanalysis before July 3! We'll also invite speakers. If you had a favorite cryptographic attack from the last two years that we should invite, please put it in the comments.

call for talks

WAC accepts proposals for contributed talks. Submissions will be evaluated based on their relevance to the following topics:
- Cryptanalysis of deployed cryptography
- Cryptanalysis of recently suggested cryptographic schemes or primitives
- New cryptoanalytic techniques
- Systems attacks breaking cryptography or bypassing underlying assumptions

Please include the following information in your contributed talk submission.
- Title.
- Description of the talk content, including: short abstract (to be published on the website on talk acceptance), and one of the following three: extended abstract describing the talk. [preferred option], a full paper and a short description of which aspects the talk will focus on. slides for a presentation, together with either speaker notes or a short outline of the non-visual content of the talk.
- Speaker information: Name, Affiliation, Short bio (to be published on the website on talk acceptance), A brief description of the relevant experience of the speaker, e.g. links to previous talks.

Submit your proposal by email to the organizers at wac@cryptanalysis.fun by July 3, 2026 AoE.
074
Miro Haller @mirohaller.bsky.social · 04/05/2026
The Cryptographic Applications Workshop (CAW) happens this Sunday in Rome! Just a reminder that if you're not coming to Rome you can still attend remotely. Just register here: forms.gle/2JZ7hLs8diQM... before May 8. See caw.cryptanalysis.fun for more infos and our program.
Program of CAW, also on our website: https://caw.cryptanalysis.fun/
086
Reposted by Miro Haller
Nadim Kobeissi @nadim.computer · 17/04/2026
Announcing the preliminary program for Cedarcrypt — our inaugural applied cryptography summer school and conference, July 13–16, 2026 at the American University of Beirut - Mediterraneo in Paphos, Cyprus! An absolutely fantastic program awaits — check it out, register today, and share widely!
cedarcrypt.org
Cedarcrypt 2026 — Applied Cryptography Summer School & Conference
Join us for four days of applied cryptography in the Mediterranean. July 13–16, 2026 at AUB Mediterraneo Campus, Paphos, Cyprus.
095
Miro Haller @mirohaller.bsky.social · 20/03/2026
The program for our Eurocrypt affiliated event CAW on May 10 is (mostly) finalized and published on: caw.cryptanalysis.fun We received many super exciting submissions! To register, select our workshop during conference registration on the Eurocrypt website once that opens: eurocrypt.iacr.org/2026/
Screenshot of the program of CAW from https://caw.cryptanalysis.fun/.
1135
Miro Haller @mirohaller.bsky.social · 19/01/2026
Submission week for the Cryptographic Application Workshop (CAW), an affiliated event at Eurocrypt'26 in Rome! Please submit your talk proposals on constructive real-world crypto using the following instructions before Jan 23, 2026 AoE. All infos on: caw.cryptanalysis.fun.
187
Miro Haller @mirohaller.bsky.social · 11/11/2025
The call for talks for CAW 2026 (a workshop affiliated with Eurocrypt) is out! This year's motto is "cryptography under real-world constraints and threat models", but other applied cryptography is also very welcome. All info is on: caw.cryptanalysis.fun.
1128
Miro Haller @mirohaller.bsky.social · 11/08/2025
Our WOOT paper went out of disclosure today. We found 5 attacks on the Master Lock D1000 which allow unauthorized unlocking, bypassing access revocation, forging log entries, and causing DoS. If you're in Seattle, come to our talk given by Chengsong, one of the students I mentored for this paper.
    Attack 1 (session replay): An adversary in physical proximity of the lock (without ever having a valid account on the lock) can record the Bluetooth Low Energy (BLE) communication of a whole session and replay it to repeat all executed commands, including unlocking the lock.
    Attack 2 (exceeding access): Former guests can continue unlocking the lock after their access has been revoked.
    Attack 3 (clock tampering): Malicious guests can adjust the clock time of the smart lock arbitrarily, extending their own access past expiration or locking out all legitimate users.
    Attack 4 (audit log tampering): An adversary that only knows the lock’s identifier (which is advertised over BLE) can upload arbitrary audit events to the telemetry server, and prevent legitimate audit events from being uploaded. Hence, the adversary can hide their own activities.
    Attack 5 (malformed messages): Without valid access, an adversary can send malformed BLE messages to the lock that make it unresponsive or corrupt memory, which results in a Denial of Service (DoS) for authorized users. A malicious authorized user can even leak the memory of the smart lock.
2103
Miro Haller @mirohaller.bsky.social · 02/05/2025
The CAW workshop at Eurocrypt 2025 is just around the corner! Quick reminder that you can sign up (for free) to attend remotely by filling out this form until tomorrow (afternoon CEST): forms.gle/5JUMmYBj9LHW... The program on the website: caw.cryptanalysis.fun
030
Miro Haller @mirohaller.bsky.social · 09/04/2025
This year, #CAW offers the option for remote participation to make our Eurocrypt workshop accessible to the members of our community that cannot or prefer not to travel to Madrid. Register on our website before May 2 (free): caw.cryptanalysis.fun The updated program is below.
062
Miro Haller @mirohaller.bsky.social · 18/03/2025
#CAW offers again a few registration waivers. We hope these waivers will help local (grad/undergrad) students to attend our workshop and get a preview of cryptography beyond the classroom and make their first connections to the community. More info: caw.cryptanalysis.fun#student-regi...
student registration fee waivers

We have funding to cover the registration costs of a few student attendees. To apply, please email the organizers with a short motivation why you want to attend CAW and need funding for doing so until March 21, 2025 AoE.
153
Miro Haller @mirohaller.bsky.social · 18/03/2025
The preliminary program for the Cryptographic Applications Workshop (CAW) at Eurocrypt'25 is out. #CAW focuses on the construction and analysis of cryptography built for practice. This thread gives a quick overview; the full program and abstracts are here: caw.cryptanalysis.fun#program
197
Miro Haller @mirohaller.bsky.social · 31/01/2025
Did you get your Eurocrypt decision today? And now either know you'll attend and would like to give an extra talk or need a different reason to go to Madrid? Then consider submitting a talk on applied, constructive cryptography to CAW. Our call for talks is open until Feb 7.
100
Miro Haller @mirohaller.bsky.social · 07/01/2025
The 2nd iteration of the Cryptographic Applications Workshop (#CAW) will be at Eurocrypt 2025! #CAW focuses on the construction and analysis of cryptography built for practice, bridging the gap between research and real-world applications. Our call of talks is currently open: caw.cryptanalysis.fun
caw.cryptanalysis.fun
CAW
Cryptographic Applications Workshop
196