Sign in

sanketh

@sanketh.bsky.social
264 followers 260 following 19 posts

doctoress of cryptography 🏳️‍⚧️ they/them ✍🏽 ciphertext.blog 🖼️ pfp by astrophysician 🧑🏽‍💼 views=own

PostsRepliesMedia
Reposted by sanketh
The Trandalorian @charliejaneanders.com · 26/09/2026
Instead of: A hill I'm willing to die on I'm gonna start saying: A hill I'm having a picnic on Just... spreading out a blanket with a food basket and staying a long time ✅️ too many ppl dying already ✅️ picnics are cozy n nice ✅️ nobody wants to eject someone having a nice picnic on a hillside
1524945
Reposted by sanketh
Filippo Valsorda @filippo.abyssdomain.expert · 20/04/2026
There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers. This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.
words.filippo.io
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.
312135
Reposted by sanketh
Filippo Valsorda @filippo.abyssdomain.expert · 15/04/2026
I had a whole post on "yes, HKDF is FIPS 140-3 compliant, actually" but now NIST just went and added it by name to the list of Approved algorithms with a change comment saying "it was always compliant, yo" (paraphrased), so yay. words.filippo.io/fips-hkdf/
[April 2026 Update] RFC 5869 is now listed in SP 800-140D, the top-level list of official Approved SSP Generation and Establishment Methods for FIPS 140-3 purposes.1 This makes it as a whole just as Approved as SP 800-108 or SP 800-56C.

The CMVP announced its addition with the comment “even though it is technically compliant to SP 800-56C which is already listed” proving it had always been FIPS 140-3 compliant.

The rest of the post is retained for historical purposes (and because if you want to be precise, you still need to figure out how to list it on your certificate), but most of you can stop reading now.
2346
Reposted by sanketh
Filippo Valsorda @filippo.abyssdomain.expert · 11/04/2026
Alright, it's official! 💰 @matthewdgreen.bsky.social and I bet on what will break first, ML-KEM-768 or X25519. The loser donates to a 501(c)(3) picked by the winner. If you have an opinion on quantum computers or lattices, you can join with a side bet. Just submit a PR! github.com/FiloSottile/...
The Hybrids Long Bet
ML-KEM-768 vs. X25519

This is a public wager between Matthew Green ("Lattice Cryptanalysis side") and Filippo Valsorda ("Quantum Computers side"). Stakes are settled by charitable donation (see Section 7).

It is motivated by views about the security and deployment relevance of the X25519MLKEM768 hybrid handshake. Notwithstanding that motivation, this wager is not about any hybrid handshake, combiner, or protocol composition. The covered constructions are the separate underlying components defined in Section 1.

🗞️ As reported in The Register.

Deadline. December 31, 2040, 23:59:59 UTC.

Stakes.

Main wager: what breaks first, ML-KEM-768 or X25519? → USD $5,000 donation.
Secondary wager: will ML-KEM-768 weaken significantly? → USD $1,000 donation.
Moral win: Filippo Valsorda buys Matthew Green drinks if ML-KEM-512 weakens.
Back bets.

Anyone can join the bet by choosing a side and stakes for the main and/or secondary wager. If the selected side loses, the back bettor donates the staked amount to the charity chosen by the winner. Back bettors don't select arbiters or charities.

Tip

Do you have an opinion and want to put your money where your mouth is? Do you like raising money for charity through abstruse wagers? Submit a PR and add your name below!
711929
Reposted by sanketh
Kendra Albert @kendraserra.bsky.social · 09/08/2025
Look I can’t help that one of my hobbies is “reading PDFs”
2585
Reposted by sanketh
Security Cryptography Whatever @scwpod.bsky.social · 26/03/2026
NEW EPISODE! The gang learns a bitter lesson about AI and bug finding! Returning champion Nicholas Carlini is back to talk about Claude for vulnerability research. securitycryptographywhatever.com/2026/03/25/a... www.youtube.com/watch?v=_IDb...
youtube.com
AI Finds Vulns You Can't With Nicholas Carlini
YouTube video by Security Cryptography Whatever
2114
Reposted by sanketh
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 09/03/2026
LIVE FROM TAIPEI, IT'S REAL WORLD CRYPTO! #realworldcrypto
56715
sanketh @sanketh.bsky.social · 16/03/2026
Engine safety rule: no men
Airplane window photo of a bright blue jet engine in flight with a small safety sticker showing a crossed-out male restroom-style icon.
011
Reposted by sanketh
Filippo Valsorda @filippo.abyssdomain.expert · 08/01/2026
I have written self-tests for the Python test generator and added tests to the Go tests. Folks, I can confirm we got all the edge cases! 💥 🥳 Thank you so much to everyone who contributed to the > 8,500(!) cores. I would like to credit you, so either reply or DM me your name/handle, if you'd like.
github.com
det-keygen: add RSA deterministic key generation by FiloSottile · Pull Request #197 · C2SP/C2SP
Community Cryptography Specification Project. Contribute to C2SP/C2SP development by creating an account on GitHub.
3386
sanketh @sanketh.bsky.social · 02/01/2026
010
Reposted by sanketh
yomna @rival-elf.bsky.social · 01/02/2024
people are always talking about a hypothetical technologically advanced alien race ... but I always wonder, if they exist, do they also have to deal with PKI?
093
Reposted by sanketh
CardiOnCryptography @bsky.gay · 14/10/2025
look at the size of this bun 🐇 just learned they can get this big (and larger)
0205
sanketh @sanketh.bsky.social · 05/10/2025
010
Reposted by sanketh
Opal @opalescentopal.bsky.social · 27/07/2025
With Tom Lehrer's passing, I suppose this is a moment to share the story of the prank he played on the National Security Agency, and how it went undiscovered for nearly 60 years.
14386183601
Reposted by sanketh
Opal @opalescentopal.bsky.social · 27/07/2025
Tom Lehrer wasn't just a satirist or a musician. He as a comedian who could quietly tell a joke and wait more than SIXTY YEARS for the payoff. That's dedication to craft. We lost an icon.
563902280
Reposted by sanketh
CivicBand @civic.band · 14/05/2025
In 2022, a local #alamtg activist named Rasheed Shabazz was asking around on twitter about digitizing meeting minutes and monthly reports from local organizations as part of his ongoing research into the racial history of Alameda. 1/n
156
sanketh @sanketh.bsky.social · 11/03/2025
quantum agile >> quantum waterfall
110
sanketh @sanketh.bsky.social · 11/03/2025
quantum random artificial intelligence cryptanalysis
000
sanketh @sanketh.bsky.social · 11/03/2025
artificial quantum random intelligence
120
Reposted by sanketh
Phildini, since young times @phildini.net · 16/01/2025
I was literally spinning up LA County as the fires started, and it just finished and pushed today. We'd love someone to dig into fire prevention and land use policy around what happened here
041
Reposted by sanketh
Queer in Cryptography Conference @cryptography.lgbt · 23/11/2024
Quick reminder: the Queer in Cryptography conference is being held 6-7 March, 2025, in Rochester! Come for the conference Thursday and Friday, stay for the fantastic city of Rochester! cryptography.lgbt visitrochester.com
visitrochester.com
Discover Rochester, NY
Explore Rochester's wide ranging culinary scene, festivals, shopping, family friendly attractions, comfortable hotels and more. You are sure to find something to love!
046
Reposted by sanketh
Galaxy Brain @galaxybrain.co · 17/12/2024
Galaxy Brain is excited to announce that we are partnering with @techtonica.bsky.social, a US-based nonprofit helping women and nonbinary adults seeking economic empowerment overcome barriers to technical careers.
133
Reposted by sanketh
Victoria @vkauff.bsky.social · 17/12/2024
My absolutely lukewarm take of the day is that more organizations should hire librarians
063
Reposted by sanketh
Andrew Dunham @andrewd.bsky.social · 13/12/2024
Okay, so: the other day I wrote a thread on "you should have rules that ban off-platform harassment". Well, given the latest thread from @safety.bsky.app, I wanted to do a short follow-up to that to talk in more detail about *why* you need policies like that. bsky.app/profile/andr...
12610
Reposted by sanketh
str👻d @str4d.xyz · 12/12/2024
*designing cryptographic protocols* yeah nah, feeling pretty chill, gonna get cozy and figure out how to structure this key tree *trying to parse a QR code from a webcam* what the fuck is this black magic, how do people do this
2353
Reposted by sanketh
Sam Jaques @sejaques.bsky.social · 12/12/2024
2024 update for my chart on the landscape of quantum computing: sam-jaques.appspot.com/quantum_land... Not much visible on the chart, but Google's result (the one with the recent press attention) is a pretty big deal
A chart of quantum computing comparing number of qubits to error rate. This is a very visual chart and is better explained in text on my website.
23915
sanketh @sanketh.bsky.social · 12/12/2024
Argh, I am fully awake at 7:00am. 😐 If you are at #asiacrypt2024, please come to my talk at 9:00am in Track 2 on "Robust AE With Committing Security" (w/ Viet Tung Hoang). If you are a keener and want to read the paper first: eprint.iacr.org/2024/1542
251
Reposted by sanketh
Pratyay Mukherjee @pratyay85.bsky.social · 06/12/2024
#Asiacrypt2024 is almost here. As someone who was born and raised in Kolkata, I decided to provide some unofficial updates/tips and will post them as they come into my mind. Folks, especially who are coming from outside the sub-continent, might find these useful. 1/3
152
sanketh @sanketh.bsky.social · 10/12/2024
Eyy, I now know everything I needed to know about about the torus. #asiacrypt2024
The stage at the asiacrypt2024 best paper session for paper “Revisiting Key Decomposition Techniques for FHE: Simpler, Faster and More Generic”. The presenter Nicolas Gama is at the middle of the stage and the slide shows a quiz on torus approximate arithmetic. This was after the talk explained torus arithmetic.
030
Reposted by sanketh
Phildini, since young times @phildini.net · 01/12/2024
Today in the US is #SmallBusinessSaturday, a day for folks to use their dollars to support small businesses instead of megacorps. If you're looking for ways to vote with your dollars for the world we want, I run two small businesses that are aligned with the values of folks I see here.
142
Reposted by sanketh
Soatok @soatok.bsky.social · 29/11/2024
How Bluesky could implement Limited Audiences / Non-Public Content and private, end-to-end encrypted protocol-native DMs using existing cryptography: soatok.blog/2024/11/29/i...
soatok.blog
Imagining Private Airspaces for Bluesky - Dhole Moments
Recently, I shared my thoughts on the Twitter Exodus. The short of that post is: Even though I’m quite happy on the Fediverse, I think the best outcome is for Bluesky to “win” the…
1124178
Reposted by sanketh
Cody Daigle-Orians @dadstoyevsky.bsky.social · 19/11/2024
This is my new response when my faculty advisor asks how my research project is going.
0283
Reposted by sanketh
EmmaSoso @emmasoso3.bsky.social · 20/11/2024
A celleux qui nous tiennent la main. A celleux qui nous l'ont lâchée, A celleux qui firent nos joies, qu'on aurait aimé voir continuer. 🕯 🫂🏳️‍⚧️✨️ Cœur sur nous aujourd'hui. Une pensée à celleux qui restent. #TDoR
Un personnage tient dans sa main une lumière qui brille
733086
Reposted by sanketh
Emily Tseng @emtseng.bsky.social · 11/11/2024
I’m at #CSCW2024, which feels like the right place to use Bluesky for the first time! I’m recruiting PhD students to UW HCDE who want to think about digital safety from a sociotechnical lens.
13411
Reposted by sanketh
alice @alice.mosphere.at · 09/11/2024
I'd just like to interject for a moment. What you're referring to as Estrogen, is in fact, 17β-Estradiol, or as I've recently taken to calling it, 17β plus Estradiol. Estrogen is not a steroid hormone unto itself, but rather another free component of a fully functioning endocrine system made usef
07813
Reposted by sanketh
Filippo Valsorda @filippo.abyssdomain.expert · 08/11/2024
God bless good tests. I forgot that the GCTR component of AES-GCM is not the same as CTR mode (it has a 32-bit counter) and I had used AES-CTR in the no-AES-NI fallback. Thankfully we have *both* a test for counter wrapping, and a framework to test fallback code even if there's hardware support.
2927
Reposted by sanketh
Maggie Astor @maggieastor.bsky.social · 04/11/2024
As of this morning, @nytguildtech.bsky.social, which represents NYT tech workers, is on strike. Unless it's resolved while today's Wordle is still live, this streak is gone. Here's a 🧵 with info on the picket line and how you can help. PLEASE READ — the rules may not be what you think!
A Wordle stats page showing 997 played, 99% win, 652 current streak, 652 max streak. Guess distribution 1 one, 69 twos, 384 threes, 361 fours, 135 fives, 42 sixes
251351826
Reposted by sanketh
juni 🏳️‍⚧️ @blahaj.rodeo · 02/11/2024
on the internet, everybody knows you’re a dog
1418
Reposted by sanketh
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 01/11/2024
Super double triple confirmed:
151
Reposted by sanketh
juni 🏳️‍⚧️ @blahaj.rodeo · 02/11/2024
voice training final boss: karaoke night at the local dive bar
4281
Reposted by sanketh
juni 🏳️‍⚧️ @blahaj.rodeo · 31/10/2024
what do you think? did i pull it off?
Juniper is a white woman taking a mirror selfie, she’s wearing red leggings, a black witchy top, a pendant necklace, a thin gold belt, and has purple hair. Amity Blight, a cartoon character from the owl house. She’s a witchy girl wearing maroon leggings and a black witchy top. She has purple hair.
131257
Reposted by sanketh
dial ë̈m̈ for mystery 🏳️‍⚧️⚢🐍 @emmeline.northsky.social · 30/10/2024
As a topological mathematician,
021
Reposted by sanketh
Techaro @techaro.lol · 30/10/2024
At Techaro we have no idea what we are doing and hope that we will just stumble towards success. You may think this is a bad thing for us to admit, but at least we're honest about it.
0103
Reposted by sanketh
xtina @normal.bsky.social · 29/10/2024
is there a barkeeper’s girlfriend 😏
361
Reposted by sanketh
Real World Crypto Symposium @rwc.iacr.org · 28/10/2024
Stipend applications for #RealWorldCrypto2025 are now open! These grants support students, early-career researchers, and individuals from underrepresented groups, enabling them to engage with pivotal developments in cryptographic research and applications. rwc.iacr.org/2025/stipend...
rwc.iacr.org
RWC 2025 student stipends
Real World Crypto Symposium
11712
Reposted by sanketh
Sarah Cosgriff 🏳️‍🌈🇵🇭 @acescicomm.bsky.social · 21/10/2024
Looks like #AceInSTEM hasn't been used as a hashtag yet on Bluesky yet... If you are on the asexual spectrum and work in/study STEM, please say hi and help us find others using the hashtag! Hi I'm Sarah (she/they) and I'm a science communicator in the UK 👋 #AceWeek #AceWeek2024
32111
Reposted by sanketh
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 06/10/2024
If you missed my live stream reacting to the final ML-KEM drop, FIPS 203, I've uploaded a tighter edit with a silly thumbnail: youtu.be/oeuM1tLkww4
youtu.be
PQ CRYPTO IS HERE - FIPS 203 ML-KEM
YouTube video by Deirdre Connolly
0142
Reposted by sanketh
ePrint Updates @eprint.ing.bot · 04/10/2024
Robust AE With Committing Security (Viet Tung Hoang, Sanketh Menda) ia.cr/2024/1542
Abstract. There has been a recent interest to develop and standardize Robust Authenticated Encryption (Robust AE) schemes. NIST, for example, is considering an Accordion mode (a wideblock tweakable blockcipher), with Robust AE as a primary application. On the other hand, recent attacks and applications suggest that encryption needs to be committing. Indeed, committing security isalso a design consideration in the Accordion mode. Yet it is unclear how to build a Robust AE with committing security.

In this work, we give a modular solution for this problem. We first show how to transform any wideblock tweakable blockcipher TE to a Robust AE scheme SE that commits just the key. The overhead is cheap, just a few finite-field multiplications and blockcipher calls. If one wants to commit the entire encryption context, one can simply hash the context to derive a 256-bit subkey, and uses SE on that subkey. The use of 256-bit key on SE only means that it has to rely on AES-256 but doesn’t require TE to have 256-bit key.

Our approach frees the Accordion designs from consideration of committing security. Moreover, it gives a big saving for several key-committing applications that don’t want to pay the inherent hashing cost of full committing.
Image showing part 2 of abstract.
021
Reposted by sanketh
J.C., keeper of MiniSquish 🏳️‍⚧️ @insufficient.coffee · 03/04/2024
We had an excellent Open Source Cryptography Workshop last Thursday, bringing together developers, maintainers, and users of open source cryptography in Toronto after #RWC2024. Most of the session recordings are now posted, along with photos & slides. See  oscwork.shop/2024/  #OSCW #OSCW2024
Audience listening to Deirdre Connolly (she/her) (@durumcrustulum.com) discuss ecosystem movement to PQThe sign outside the venue
085