Sign in

宋苑铭 SONG Yuanming

@prefix-free.bsky.social
36 followers 73 following 2 posts

Dilettante cryptographer/cinephile. 来日方长

PostsRepliesMedia
Reposted by 宋苑铭 SONG Yuanming
ePrint Updates @eprint.ing.bot · 13/09/2026
Criminology: Refined Techniques for Compression Side-Channel Attacks (Yuanming Song, Lenka Mareková, Kenneth G. Paterson) ia.cr/2026/1972
Abstract. It has been known for two decades that performing compression before encryption is dangerous, because it introduces a side channel leaking information about plaintexts through ciphertext lengths: the compressed plaintext length may be visible in the ciphertext length, and the amount of compression obtained is plaintext-dependent; hence an adversary can obtain some leakage about the plaintext via observation of ciphertext lengths. This issue was first pointed out by Kelsey (FSE 2002) and turned into a practical plaintext recovery attack in the form of the CRIME attack on SSL and TLS by Rizzo and Duong in 2012. A long series of variations and attacks against other systems followed. Despite the known dangers, the compress-then-encrypt paradigm is still prevalent in practice today. This may be because the compression-based side channel is susceptible to noise and may require a large number of queries to enable plaintext recovery, and so can be mitigated by either adding noise (e.g. with random padding) or limiting an adversary’s interaction with the system.

We demonstrate that this side channel is much more powerful than previously thought. We focus on the widely-used DEFLATE algorithm in our analysis. We present novel techniques that enable strong amplification of small length differences arising during compression. Our telescoping and chaining amplification techniques exploit the way in which DEFLATE replaces common strings by shorter back-references. Our collision-based amplification technique focusses on exploiting hash table collisions in DEFLATE implementations. This involves a deeper examination (and exploitation) of the internals of DEFLATE than in previous works. These insights result in compressed length differences growing linearly with the length of queries. Compared with length differences of a few bits or bytes in prior work, our new amplification techniques thus enable us to defeat existing noise-based countermeasures.

Finally, we introduce the concept of CRIME automata, these being carefully crafted query strings that enable an attacker to exert fine control over the internal behaviour of DEFLATE and produce differences in the output lengths of the compressor according to various criteria (such as whether the DEFLATE sliding window contains a given target string). In turn, our automata are composed in a modular fashion from gadgets having different functions, including matching against target strings, performing logical operations between other gadgets, and, most importantly, amplifying differences in output lengths using the above-mentioned techniques. We provide multiple, concrete automata designs that serve different attack goals. These designs are supported by experiments and a publicly available codebase demonstrating the power, flexibility, and practical impact of our CRIME automata approach.
Image showing part 2 of abstract.Image showing part 3 of abstract.
041
Reposted by 宋苑铭 SONG Yuanming
Marcus Brinkmann @lambdafu.bsky.social · 10/09/2026
We found a new compression side-channel attack against SSH: if you use port forwarding with terminal sessions, a web attacker+eavesdropper can recover a sudo pwd in a few hundred trials. There is only one compression context for all channels. Accepted at CCS 26, preprint: arxiv.org/abs/2609.07709
arxiv.org
Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels
SSH is the standard protocol for secure remote administration of servers. At the transport layer, SSH uses the Binary Packet Protocol (BPP) for encrypted and authenticated communication. Above this, t...
15219
Reposted by 宋苑铭 SONG Yuanming
Sixth Tone @sixthtone.bsky.social · 12/09/2026
A growing number of Chinese students studying abroad are turning cooking videos into viral hits across Chinese social media. On Douyin, the Chinese version of TikTok, the hashtag “international students hunong cooking” — using the term “to do something halfheartedly” — has amassed 2.1 billion views.
sixthtone.com
Pizza Bao, Spaghetti Stir-Fry: Chinese Students Hack Home Cooking Abroad
To save money and recall nostalgic flavors from home, Chinese students abroad are increasingly posting videos online of themselves making Chinese classic dishes, with some innovative, low-budget takes.
092
Reposted by 宋苑铭 SONG Yuanming
Sixth Tone @sixthtone.bsky.social · 08/06/2026
A documentary director who set out to explore the lives of Chinese and American teens revisits unreleased footage of the murder suspect when he was 16.
sixthtone.com
Boy in the Frame: The Chinese Filmmaker Who Captured Luigi Mangione
A documentary director who set out to explore the lives of Chinese and American teens revisits unreleased footage of the murder suspect when he was 16.
031
Reposted by 宋苑铭 SONG Yuanming
Made in China Journal @madeinchinajournal.com · 15/04/2026
How did Kaifeng's old Jewish community go from revival to erasure? @jordynhaime.bsky.social traces the forces that recast Judaism as foreign in China, from missionaries to rising nationalism to CCP ethnic policy, asking whether any revival is possible without rethinking the Chinese nation itself.
madeinchinajournal.com
From Revival to Erasure: Ebbs and Flows of Judaism in Kaifeng | Made in China Journal
Foreign missionary contact, the rise of nationalism, and ethnic identification work undertaken under the rule of the Chinese Communist Party culminated in the construction of ‘Jews’ as an ethnic ident...
1126
Reposted by 宋苑铭 SONG Yuanming
ePrint Updates @eprint.ing.bot · 09/03/2026
Signal Lost (Integrity): The Signal App is More than the Sum of its Protocols (Kien Tuong Truong, Noemi Terzo, Kenneth G. Paterson) ia.cr/2026/484
Abstract. Signal is a secure messaging app offering end-to-end security for pairwise and group communications. It has tens of millions of users, and has heavily influenced the design of other secure messaging apps (including WhatsApp). Signal has been heavily analysed and, as a result, is rightly regarded as setting the “gold standard” for messaging apps by the scientific community. We present two practical attacks that break the integrity properties of Signal in its advertised threat model. Each attack arises from different features of Signal that are poorly documented and have eluded formal security analyses. The first attack, affecting Android and Desktop, arises from Signal’s introduction of identities based on usernames (instead of phone numbers) in early 2022. We show that the protocol for resolving identities based on usernames and on phone numbers introduced a vulnerability that allows a malicious server to inject arbitrary messages into one-to-one conversations under specific circumstances. The injection causes a user-visible alert about a change of safety numbers, but if the users compare their safety numbers, they will be correct. The second attack is even more severe. It arises from Signal’s Sealed Sender (SSS) feature, designed to allow sender identities to be hidden. We show that a combination of two errors in the SSS implementation in Android allows a malicious server to inject arbitrary messages into both one-to-one and group conversations. The errors relate to missing key checks and the loss of context when cryptographic processing is distributed across multiple software components. The attack is undetectable by users and can be mounted at any time, without any preconditions. As far as we can tell, the vulnerability has been present since the introduction of SSS in 2018. We disclosed both attacks to Signal. The vulnerabilities were promptly acknowledged and patched: the first vulnerability was fixed two days after disclosure, while the second one was patched after eight days. Beyond presenting these devastating attacks on Signal’s end-to-end security guarantees, we discuss more broadly what can be learned about the challenges of deploying new security features in complex software projects.
Image showing part 2 of abstract.
02713
Reposted by 宋苑铭 SONG Yuanming
Made in China Journal @madeinchinajournal.com · 24/02/2026
The new issue of the Made in China Journal is out! This time we explore how queerness offers a lens for understanding contemporary Chinese society, as state visions of family and citizenship collide with diverse lived realities and unevenly translated global LGBTQIA+ discourses.
madeinchinajournal.com
Queer China | Made in China Journal
Across the world, debates around gender and sexuality have become closely tied to questions of belonging, citizenship, and moral order. In China, these issues have taken on particular urgency as the s...
0146
Reposted by 宋苑铭 SONG Yuanming
China Law Translate / Jeremy Daum @chinalawtranslate.bsky.social · 16/02/2026
There is so much going on in the Draft Cybercrime Law that I can't do it justice: - fortifying real-name registration - threatening VPNs - China's first penalties for possession of CSAM - cyberviolence protections - New offenses for enabling cybercrime (including converting gains to crypto)
chinalawtranslate.com
China's Draft Cybercrime Law
The draft is already controversial, with some commentators concerned that it increases online surveillance, fortifies censorship, and extends long-arm jurisdiction to conduct overseas. While it is not...
2149
Reposted by 宋苑铭 SONG Yuanming
Made in China Journal @madeinchinajournal.com · 19/02/2026
In this essay, @queercomrades.bsky.social explores how the classical Chinese story of the Rabbit God has been reinterpreted across the global Chinese diaspora in recent years, highlighting creative reimaginings that promote an open and undogmatic vision of queer Chinese identity and heritage.
madeinchinajournal.com
Performing the Rabbit God | Made in China Journal
This essay examines how the classical Chinese story of the Rabbit God has been reinterpreted in the global Chinese diaspora in recent years. Using the examples of Andrew Thomas Huang’s 2019 film The K...
064
宋苑铭 SONG Yuanming @prefix-free.bsky.social · 22/07/2025
For Chinese history nerds (if any): I came across 陈公博 Chen Gongbo’s master’s thesis on the early history of CCP/CPC at archive.org/details/comm... The Chinese translation is much easier to find online (look up 共产主义运动在中国)
archive.org
THE COMMUNIST MOVEMENT IN CHINA An Essay Written in 1924 by Ch'en Kung-Po : C Kung-Po : Free Download, Borrow, and Streaming : Internet Archive
000
Reposted by 宋苑铭 SONG Yuanming
Made in China Journal @madeinchinajournal.com · 02/05/2025
A Facebook post unearthed a legend: the lost MingKwai typewriter, designed by Lin Yutang in 1947, resurfaced in a NY basement. Hailed as a marvel yet dismissed as a failure, its rediscovery revives debates over innovation, identity, and what it means to be Chinese, writes @yangyangcheng.bsky.social.
madeinchinajournal.com
Lost and Found: The Unexpected Journey of the MingKwai Typewriter | Made in China Journal
It began as an innocuous inquiry on Facebook. Nelson Felix, a resident of New York State, posted in the group ‘What’s My Typewriter Worth?’ about a curious find he made while clearing out the basement...
11300126
宋苑铭 SONG Yuanming @prefix-free.bsky.social · 17/04/2025
😭😭
000