Sign in

nora

@nora.bsky.social
306 followers 66 following 60 posts

Engineer and Applied Cryptographer working in the ASML at Harvard’s BKC. Led cryptography R&D at Juicebox and privacy projects at Signal. Passionate about fostering inclusive communities, mentoring women in tech, and building third spaces for creatives.

PostsRepliesMedia
nora @nora.bsky.social · 18/06/2026
(our approach to CGKA is also substantially different, with some different goals in mind)
000
nora @nora.bsky.social · 18/06/2026
There’s certainly some overlap with keyhive, and automerge especially, but also some stark differences. e.g, we allow servers/any single entity to make decisions about conflict resolutions rather than relying on CRDTs, etc while proving that the decisions are being made correctly.
110
nora @nora.bsky.social · 18/06/2026
Our ambition is generally to be server agnostic, such that the protocol can work with a centralized backend or a p2p or decentralized backend.
010
nora @nora.bsky.social · 11/06/2026
that'd be cool to see. we should chat and get a better sense of the shape of what atproto would need and how well it aligns with what we've built so far
140
Reposted by nora
Andy Greenberg @agreenberg.bsky.social · 11/06/2026
Developers from Signal (including its protocol's co-creator) along with Microsoft and Harvard unveil Encrypted Spaces, an open-source codebase for a new generation of private collaboration apps. Think Slack, Discord, Google Docs, all end-to-end encrypted. www.wired.com/story/signal...
wired.com
Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps
The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.
210126
nora @nora.bsky.social · 11/06/2026
Instructions are in the repo. It's still early days and not production-ready, but I'd love to hear your thoughts given the stakes of your work. We're trying to learn from real apps and understand where this model works well, where it falls short, and what research remains to make it practical.
github.com
GitHub - encrypted-spaces/prototype: A cryptographic framework for building collaborative applications over an untrusted server. Research prototype.
A cryptographic framework for building collaborative applications over an untrusted server. Research prototype. - encrypted-spaces/prototype
151
nora @nora.bsky.social · 11/06/2026
Proud to finally share what I've been working on. I'm excited for a future where privacy is normal. encryptedspaces.org
wired.com
Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps
The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.
212030
nora @nora.bsky.social · 13/12/2025
this is terrible, and yet sadly so common. we need a standardized system for ownership over our digital IDs so big tech companies can’t just flip an off switch for your whole digital life (working on it, but it’s a long road). google, microsoft, etc doing this everyday too and users have no recourse
140
Reposted by nora
Emily C. Hughes @emilyhughes.bsky.social · 09/11/2025
pre-writing a devastating obituary for your enemy is god-tier hating of a kind you don’t often see anymore. renaissance haterism. beautiful stuff.
13143604270
Reposted by nora
Art by Emily K @museum.of.emilyk.art · 26/10/2025
"Tzefardea Tzedek" (Frog of Righteousness) As soon as the Portland Frog became a meme, Jewish social media blew up with jokes about the 2nd Passover plague - tzefarde'a (frogs) - and the Rabbinical commentary around it. I knew I had to make a calligraphy piece encompassing all of it. (more in alt.)
Hebrew calligraphy in dark green stretches in lines across the image. Negative space makes room for a simple representation of an inflatable frog costume with a blue bandana. That shape consists of the English translation of the Hebrew, in a lighter green, and in much smaller text.
--
Famously, the Egyptian tyrant causes Egypt to be overrun with frogs because he refuses to free the Hebrew people, but there are additional details that make this a fun one to ponder. For one, the Hebrew says "the frog came up" - ONE frog - even though the rest of the time it says "frogs." So there are a few explanations rabbis have come up with to explain this. One is that a single frog multiplied to create swarms. A more creative explanation is that there was a singular giant frog who traveled and brought destruction. Jewish social media was sharing videos of the Portland Frog protester with the caption, "One Big Frog! One Big Frog!" Of course the frog protesters did multiply, and many were seen in crowds all over the world on "No Kings" Day. This calligraphic work takes the verses addressing the frog plague and combines them to form a simple rendering of the Portland Frog protester. The frog figure itself is made up of the English translations of the Hebrew around it. At the bottom left my signature is in the shape of a lily pad.
14766662004
Reposted by nora
Chanda Prescod-Weinstein 🌌 @chanda.blacksky.app · 02/09/2025
NASA scheduled a major workshop for early career researchers during the most important week of the Jewish calendar, during two of the most important days of that week and expects me to accept that this was “difficult scheduling conflicts” That’s what casual antisemitism sounds like
741737357
Reposted by nora
Emily Hunt @emily.space · 15/08/2025
I really dislike how science has started calling almost any fancy computational technique AI. 🧪 The framing of this entire article makes it sound like a benevolent AI independently made these drugs. That is *pure fantasy*. Instead: a team of scientists made a machine learning model for a study.

Article on BBC news. 
Title: AI designs antibiotics for gonorrhoea and MRSA superbugs
Description: Two new potential drugs have been designed by AI to kill drug-resistant bacteria, in a major Massachusetts Institute of Technology study.
572255695
Reposted by nora
Gremliny Nussboo @emilynussbaum.bsky.social · 05/08/2025
When I die, please do not write an AI obituary of me *or* code an AI replica, however well-intentioned, but feel free to build a shockingly realistic rotini sculpture & then eat it at my shiva
1792997
Reposted by nora
Rabbi Emily Cohen @thatrabbicohen.bsky.social · 03/08/2025
The fate of ordinary Gazans trapped by Israel in a war zone and ordinary Israelis held hostage by Hamas in a war zone will be one and the same. They are starving. They are buried beside one another. They are cast aside by those with power to save them. For this we weep.
1258
Reposted by nora
Abby Chava Stein @abbystein.bsky.social · 03/08/2025
Read this in full. I'm short: The ADL has fully given up on its mission to fight real antisemitism. Instead, they are focused on unconditional support towards Israel, including justification of antisemitism if it serves that goal. Plus, working with fascists & antisemitic groups and people.
02915
Reposted by nora
Margaret Mitchell @mmitchell.bsky.social · 01/08/2025
🤖 Always on the lookout for potential net positive uses of “AI”, esp for elderly…but the claims here pissed me right off: “There was no way that we could have found enough songwriters out there to be able to create those tracks in an authentic way” 🚫 No. MANY musicians [wc]ould do this. And, 🧵
54616
Reposted by nora
Kendra Albert @kendraserra.bsky.social · 30/06/2025
As a Jewish person who worked at Harvard for 7 years, including much of the period covered by the Department of Ed. investigation, I object deeply to this retaliatory bullshit being laundered as on my behalf. www.ed.gov/about/news/p...
05113
nora @nora.bsky.social · 24/06/2025
I hope you’re preserving scraps of wallpaper for a gallery wall some day when this is all finished!
100
nora @nora.bsky.social · 23/06/2025
We cannot let the AI take our em dashes away! I also use them all the time—so frustrating how it has become such an indicator of ChatGPT!
010
Reposted by nora
Abby Chava Stein @abbystein.bsky.social · 22/06/2025
I have been using the em dash for about 10 years (I only learned English 13 years ago, for context). I even got a whole book I published before ChatGPT to prove it. I am not stopping—too useful!
2152
Reposted by nora
Matthew Green @matthewdgreen.bsky.social · 09/06/2025
I wrote a bit more about X’s new encrypted DMs and the Juicebox protocol. blog.cryptographyengineering.com/2025/06/09/a...
blog.cryptographyengineering.com
A bit more on Twitter/X’s new encrypted messaging
Matthew Garrett has a nice post about Twitter (uh, X)’s new end-to-end encryption messaging protocol, which is now called XChat. The TL;DR of Matthew’s post is that from a cryptographic…
66826
Reposted by nora
Matthew Garrett @mjg59.eicar-test-file.zip · 06/06/2025
This is just a flat out lie and everyone involved is either malicious or incompetent
Screenshot of a dialog from Twitter. It says:

"Messages are now fully encrypted

End-to-end encryption: messages are end-to-end encrypted across all your devices.

State-of-the-art privacy: There's no way for anyone, including X, to read your messages.

Set up a passcode: In order to secure your messages, you'll need to set up a 4-digit passcode."
45213
nora @nora.bsky.social · 07/06/2025
Ah, to be clear the virtual HSM here is a juicebox implemented version just for testing the code without costly hardware. It doesn’t even attempt any protections. Which one are you talking about?
100
nora @nora.bsky.social · 06/06/2025
Belatedly! That could indicate either an HSM or a virtual HSM (meant for testing, not secure). The /livez endpoint suggests they're using the code as-is from main. Request timing makes me suspect a virtual HSM, but it's not definitive.
100
nora @nora.bsky.social · 06/06/2025
Please do!
010
nora @nora.bsky.social · 06/06/2025
It's totally possible! If you find something concrete, definitely let me know. NCC audited the design and code and there were a number of other folks who reviewed, but mistakes happen and this is the first time its being used in production at this kind of scale.
110
nora @nora.bsky.social · 06/06/2025
There's a few others out there using it, but with similar misunderstandings. In hindsight, it's probably not well engineered for most developers to not shoot themselves in the foot. But I'd love to see it used well! It's much more efficient than similar things, like WhatsApps HSM setup
000
nora @nora.bsky.social · 06/06/2025
Signal ended up doing their own thing, relying heavily on confidential compute (AWS nitro and the like) which I think is less ideal, but to some degree follows the same premise. www.usenix.org/conference/o...
usenix.org
Secret Key Recovery in a Global-Scale End-to-End Encryption System | USENIXusenix_logo_notag_white
110
nora @nora.bsky.social · 06/06/2025
The hope was to carry on the work we did at Signal on Secure Value Recovery, but diversify away from SGX/a singular hardware failure point.
signal.org
Technology Preview for secure value recovery
At Signal, we want to make privacy simple. From the beginning, we’ve designed Signal so that your information is in your hands rather than ours. Technologies like Signal Protocol secure your messages ...
110
nora @nora.bsky.social · 06/06/2025
The organization doesn't exist anymore. We created the protocol, played with the idea of offering it as saas (we run HSMs for people), pitched around, and eventually scrapped it due to minimal interest. Open sourced and published stuff to the world, and mostly I thought that was that until now!
210
nora @nora.bsky.social · 06/06/2025
Yes, I know about that theoretical ceremony :) I linked that pdf above, but noone who worked on Juicebox (and developed that ceremony) worked with Twitter to do this, and given they haven't published the results of a ceremony I must assume one never happened (despite it being our intended design)
110
nora @nora.bsky.social · 06/06/2025
And I have good reason to suspect those realms using noise are at _best_ are HSMs that haven't gone through a signing ceremony, but much more likely virtualized HSMs
010
nora @nora.bsky.social · 06/06/2025
I don't know for sure but I strongly suspect they aren't. They use noise for some realms (which points towards HSMs, but not guarantee), but realm-a.x.com and realm-b.x.com don't use noise at all and definitely aren't HSMs. Since they only require 2 realms to recover, basically they don't have HSMs
120
nora @nora.bsky.social · 06/06/2025
Do you have evidence that Twitter conducted a ceremony? I would definitely be curious if there is a protocol bug (so we can fix it), but not quite sure the avenue you're getting at
010
nora @nora.bsky.social · 06/06/2025
if you haven't done that, then anything goes – you could just push new code to the HSM to allow unlimited guesses or decrypt and exfiltrate the registration state to allow offline brute forcing
120
nora @nora.bsky.social · 06/06/2025
It's totally possible I'm missing something, but if the HSM realm has been setup correctly (e.g. a signing ceremony was performed, with verifiable code deployed, and the programming keys destroyed) I don't see how an imposter realm with the same ID could exfiltrate the state needed to make guesses
110
nora @nora.bsky.social · 06/06/2025
I'd argue it's less than not great, it's bad. Since they're not using HSMs for Juicebox, and they control all the realms, they have the ability to easily brute force anyone's 4-digit PIN and get their stored secret. It's basically just backdoored.
13415
nora @nora.bsky.social · 06/06/2025
So you can rely on distributed trust, with just software realms, if you're sure organizations wont collude (risky). The protocol is really meant to be used with at least 1 HSM backed realm in the mix. Twitter's implementation is all software realms that they host, totally broken.
juicebox.xyz
Don’t Put All Your Juice in One Box
At Juicebox, we believe key recovery should be secure, user friendly, and actually… work. That means it has to be more than cryptographic theater. It has to reflect the real world, where systems get h...
130
nora @nora.bsky.social · 06/06/2025
No need for a MITM here, since the registration state is stored unencrypted in the database. With HSM realms, the unencrypted state never leaves the HSM.
130
nora @nora.bsky.social · 06/06/2025
With software realms alone, there's no protection from an admin making as many guesses as they want if the realms collude. Crucially, this only works if you're 100% relying on software realms, since you can't verify if you have the right unlockKey (and right PIN) unless you have a quorum of realms.
140
nora @nora.bsky.social · 06/06/2025
To be clear, Twitter definitely didn't do this, since they're not even using HSMs. They're only using software realms, and all of them are hosted by Twitter. Their implementation is basically just a backdoor.
152
nora @nora.bsky.social · 06/06/2025
The noise session with an HSM backed realm allows you to attest that a realm is using the correct private key (that only the HSM knows). This assumes you've done a good public HSM key ceremony, that ends with destroying the keys that allow you to re-program it.
github.com
130
nora @nora.bsky.social · 06/06/2025
The general idea is that some external thing to Juicebox (e.g. your website that has login) generates per-realm auth tokens for your users, before you can start making requests to realms. Those JWT are signed for a specific realm, and have an "aud" field that prevents reuse for a different realm.
141
nora @nora.bsky.social · 06/06/2025
The MITM between realms *shouldn't* be possible. A realm can't relay a user's request to another realm, pretending to be the user, because authorization tokens are scoped to a given realm. An HSM (running as designed) will reject a token that was created for a different realm.
github.com
130
nora @nora.bsky.social · 06/06/2025
I wrote a little thing pointing out how they could use Juicebox the right way... but I'm sure it will fall on deaf ears.
021
nora @nora.bsky.social · 06/06/2025
A great write up! FWIW I can confirm they're not using HSMs looking at the Juicebox related network traffic. It's incredible to me that people keep trying to roll their own things, when the Signal Protocol is right there, even with a nice (actually Rust!) implementation they could use off the shelf.
331
nora @nora.bsky.social · 06/06/2025
If your DMs are “encrypted” but one org holds all the keys, you haven’t distributed trust – you’ve built a backdoor. Juicebox only works when boundaries are real. Separation isn’t optional. Replication != distribution.
juicebox.xyz
Don’t Put All Your Juice in One Box
At Juicebox, we believe key recovery should be secure, user friendly, and actually… work. That means it has to be more than cryptographic theater. It has to reflect the real world, where systems get h...
06919
nora @nora.bsky.social · 02/05/2025
We are truly living in the worst world. Who asked to have AI monitor every aspect of their digital lives, by default? These features should be opt-in, not out. If you can even justify their existence at all.
010
Reposted by nora
Emily Greenwald @emilymbgreenwald.bsky.social · 28/04/2025
A dragon emerges from an egg, within a nest among others waiting to hatch atop a majestic castle. The dragon is embedded with a DragonRNA, a DNA strand covalently extended with an RNA tail. Variants of precursor DNAs are backlit by a glowing polymerase within each egg,
132