Sign in

Security Cryptography Whatever

@scwpod.bsky.social
1.4K followers 3 following 76 posts

@durumcrustulum.com, @sockpuppet.org, @dadrian.io “Freewheelin’ dynamic”. securitycryptographywhatever.com podcasts.apple.com/us/podcast/feed/…

PostsRepliesMedia
Reposted by Security Cryptography Whatever
David Adrian @dadrian.io · 27/08/2026
Since the last time Peikert was on, Michigan football and Michigan basketball both won a national championship. That's the new bar for repeat guests.
064
Security Cryptography Whatever @scwpod.bsky.social · 26/08/2026
NEW EPISODE! Lattices! New complexity results in the closest vector problem & a possible poly-time quantum attack against the dihedral coset problem that made everyone freak out for about a week; ALSO there's a distinguisher attack against Classic McEliece 😱 youtu.be/7_Db0LXQrk0
youtu.be
AI Lattice Proofs With Chris Peikert
YouTube video by Security Cryptography Whatever
1162
Security Cryptography Whatever @scwpod.bsky.social · 14/08/2026
New episode in the can on all these new PQ papers!! 😅😭
040
Security Cryptography Whatever @scwpod.bsky.social · 27/07/2026
Are you coming to Vegas for BlackHat and DEF CON? Come to our happy hour! securitycryptographywhatever.com/events/black...
securitycryptographywhatever.com
SCWPodCon BlackHat 2026
"Security Cryptography Whatever" is hosting a party during BlackHat USA 2026, once again brought to you by Teleport!
142
Security Cryptography Whatever @scwpod.bsky.social · 27/07/2026
NEW EPISODE! We invited Mark Schultz-Wu on the podcast to talk about the history of lattice cryptography. When lattices are explained in plain english, they are actually quite simple! I don’t think any of us have ever seen Deirdre so happy. www.youtube.com/watch?v=1ey8...
youtube.com
An Odyssey of Lattice Cryptography with Mark Schultz-Wu
YouTube video by Security Cryptography Whatever
094
Security Cryptography Whatever @scwpod.bsky.social · 02/07/2026
NEW EPISODE! The dear leader bleated out some executive orders to speed up US gov adoption of post-quantum crypto! Plus, ECDSA dot fail! securitycryptographywhatever.com/2026/07/02/t... podcasts.apple.com/us/podcast/t... www.youtube.com/watch?v=7ZwQ...
youtube.com
Trump's Golden Post Quantum EOs
YouTube video by Security Cryptography Whatever
053
Reposted by Security Cryptography Whatever
Filippo Valsorda @filippo.abyssdomain.expert · 26/06/2026
securitycryptographywhatever.com/2026/03/25/a... is very very good. If you read my vulnerabilities post, this podcast episode is much more worth listening to.
securitycryptographywhatever.com
AI Finds Vulns You Can’t With Nicholas Carlini
Returning champion Nicholas Carlini comes back to talk about using Claude for vulnerability research, and the current vulnpocalypse. It’s all very high-brow ...
0377
Security Cryptography Whatever @scwpod.bsky.social · 22/06/2026
www.youtube.com/watch?v=bjo5...
youtube.com
Standardizing Pure PQ
YouTube video by Security Cryptography Whatever
042
Security Cryptography Whatever @scwpod.bsky.social · 22/06/2026
We swear we don't have a crystal ball:
051
Reposted by Security Cryptography Whatever
Justin Schuh @justinschuh.com · 15/06/2026
TIL I cannot listen to @lcamtuf.coredump.cx at 3x speed. It's never bothered me with other voices I already know from conversation (including the hosts on @scwpod.bsky.social). But I had to slow everything down below 2x to get him out of the uncanny valley.
securitycryptographywhatever.com
Facing the Vulnpocalypse With lcamtuf
We talk to Michał Zalewski (lcamtuf) about the vulnpocalypse and if we even need fuzzers anymore. This episode may be export controlled at a future date. Th...
221
Security Cryptography Whatever @scwpod.bsky.social · 15/06/2026
Is all software fucked bc LLMs are so good at finding bugs? Or are LLMs secretly this generation's fuzzers? We invited American Fuzzy Lop's creator and special guest @lcamtuf.coredump.cx on to debate the VuLnPoCaLyPsE www.youtube.com/watch?v=uI9C... securitycryptographywhatever.com/2026/06/14/f...
youtube.com
Facing the Vulnpocalypse with lcamtuf
YouTube video by Security Cryptography Whatever
1102
Reposted by Security Cryptography Whatever
David Adrian @dadrian.io · 15/06/2026
securitycryptographywhatever.com/2026/06/14/f...
securitycryptographywhatever.com
Facing the Vulnpocalypse With lcamtuf
We talk to Michał Zalewski (lcamtuf) about the vulnpocalypse and if we even need fuzzers anymore. This episode may be export controlled at a future date. Th...
011
Reposted by Security Cryptography Whatever
Thomas Ptacek @sockpuppet.org · 30/03/2026
I wrote something: sockpuppet.org/blog/2026/03...
sockpuppet.org
Vulnerability Research Is Cooked
79639
Security Cryptography Whatever @scwpod.bsky.social · 26/03/2026
NEW EPISODE! The gang learns a bitter lesson about AI and bug finding! Returning champion Nicholas Carlini is back to talk about Claude for vulnerability research. securitycryptographywhatever.com/2026/03/25/a... www.youtube.com/watch?v=_IDb...
youtube.com
AI Finds Vulns You Can't With Nicholas Carlini
YouTube video by Security Cryptography Whatever
2114
Reposted by Security Cryptography Whatever
Thomas Ptacek @sockpuppet.org · 14/03/2026
Extremely psyched about two upcoming SCW guests, one of them this week. We've got very crunch vulnerability research and cryptography stuff coming.
0243
Reposted by Security Cryptography Whatever
Chris Fenner @chrisfenner.bsky.social · 10/02/2026
I finally reached the end. This was a super good episode and it gave me all the warm fuzzies about my internal reactions to getting started with Ossl3 for PQC. As a former windows NCrypt provider maintainer, I really thought all my “magic strings to throw at a generic API” was behind me 😭
031
Security Cryptography Whatever @scwpod.bsky.social · 02/02/2026
www.youtube.com/watch?v=dEKB...
youtube.com
Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor
YouTube video by Security Cryptography Whatever
052
Security Cryptography Whatever @scwpod.bsky.social · 02/02/2026
obviously you have to do a string compare to load a nonce key in openssl 3
161
Security Cryptography Whatever @scwpod.bsky.social · 02/02/2026
NEW EPISODE! The maintainers of py/cryptography declared that after many years of trying to make it work, they would be moving away from OpenSSL when supporting new functionality and exploring adding other backends: securitycryptographywhatever.com/2026/02/01/p... www.youtube.com/watch?v=dEKB...
youtube.com
Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor
YouTube video by Security Cryptography Whatever
5205
Reposted by Security Cryptography Whatever
Thomas Ptacek @sockpuppet.org · 28/01/2026
Just recorded the premiere episode of Season VIII of Security Cryptography & W/evs, this time with Alex Gaynor and Paul Kehrer, who have a momentous announcement about pyca/cryptography and OpenSSL.
2243
Reposted by Security Cryptography Whatever
Ben Adida @benadida.com · 31/12/2025
Threshold decryption.... I struggled with that one and still do. Obviously it's a point of fragility to allow one lost share to cancel the election. But true DKG with parties spread across the world is also not obviously easy to implement.
011
Reposted by Security Cryptography Whatever
Ben Adida @benadida.com · 31/12/2025
Yes, it's finite fields, in large part because implementing over elliptic curves, especially with proper hashing for NIZKs, was more complexity than I could handle. Would likely make sense to upgrade to EC at some point but also probably not a huge priority? Happy to hear counter arguments!
111
Reposted by Security Cryptography Whatever
Ben Adida @benadida.com · 31/12/2025
Yes, Helios definitely uses NIZKs to prove proper ballot form. Implemented in 2008 browser JavaScript, which was a fun challenge.
111
Reposted by Security Cryptography Whatever
Ben Adida @benadida.com · 31/12/2025
I abandoned mixnets in Helios v2+ in favor of homomorphic aggregation because of the operational complexity of mixnets. Explained in the 2009 paper: csrc.nist.gov/csrc/media/e...
111
Reposted by Security Cryptography Whatever
Thomas Ptacek @sockpuppet.org · 31/12/2025
Final SCW of 2025! We had Matt Bernhard on to talk about cryptographic voting systems, in the wake of the IACR election. (Everybody I voted for in the new election won! Woo!)
093
Reposted by Security Cryptography Whatever
v* @0x.vg · 04/12/2025
@scwpod.bsky.social did the impossible and converted me to a podcast gxrlie
021
Security Cryptography Whatever @scwpod.bsky.social · 31/12/2025
NEW EPISODE! The IACR lost the keys to decrypt their encrypted election results. We welcome Matt Bernhard who works on secure voting systems to explain which Helios bits are homomorphically additive or not and more: securitycryptographywhatever.com/2025/12/30/i... www.youtube.com/watch?v=euw_...
securitycryptographywhatever.com
The IACR Can
The International Association of Cryptologic Research (IACR) held their regular election using secure voting software called Helios…and lost the keys to decr...
1123
Security Cryptography Whatever @scwpod.bsky.social · 31/10/2025
NEW EPISODE! Apple did a new security thing for their latest phones with memory integrity enforcement, we did a deep a dive as we could given that we couldn't get anyone from Apple to come on our podcast 😭 podcasts.apple.com/us/podcast/a... open.spotify.com/episode/0DhC... youtu.be/9FJwOI2PliU
youtu.be
Apple’s Memory Integrity Enforcement
YouTube video by Security Cryptography Whatever
3133
Security Cryptography Whatever @scwpod.bsky.social · 23/08/2025
yw
060
Reposted by Security Cryptography Whatever
Calum @zootm.bsky.social · 23/08/2025
I have just today discovered that podcasts can be chapterised, and that apparently @scwpod.bsky.social is painstakingly broken into chapters with often-joke names
Chapter view of a podcast app showing chapters named “pgp for encrypted email”, “fcking metadata”, “m-m-m-metadata”, “SMTP m-m-m-metadata”, and “dkim, spam”
031
Reposted by Security Cryptography Whatever
David Adrian @dadrian.io · 23/08/2025
Come for the PGP dunks, stay for the broader discussion of why encrypted email doesn’t make sense
0127
Security Cryptography Whatever @scwpod.bsky.social · 23/08/2025
NEW EPISODE! An OpenPGP.js bug gave us an excuse to tear encrypted email via PGP to shreds. William Woodruff joined us to explain the vuln & indulge our gnashing of teeth on why email was never meant to be encrypted: securitycryptographywhatever.com/2025/08/22/s... www.youtube.com/watch?v=IoL3...
youtube.com
Stop Using Encrypted Email with William Woodruff
YouTube video by Security Cryptography Whatever
22111
Reposted by Security Cryptography Whatever
Simon Fondrie-Teitler @simon.overgrown.garden · 17/08/2025
The first part of this interview with my ex-colleague Alex is a great listen if you're a software engineer (or otherwise technical) and are interested in what we were working on as technologists at the Federal Trade Commission.
032
Security Cryptography Whatever @scwpod.bsky.social · 16/08/2025
NEW EPISODE! We chat with friend of the pod and special guest Alex Gaynor, former deputy chief technologist at the FTC and all around good Security Person™. Join for nerdery about WebAuthn, stay for accidentally melting down GitHub APIs around November 2020! youtu.be/gBoGvyvsSi4
youtu.be
Alex Gaynor
YouTube video by Security Cryptography Whatever
041
Security Cryptography Whatever @scwpod.bsky.social · 31/07/2025
First round of invites going out tonight!
000
Reposted by Security Cryptography Whatever
Security Cryptography Whatever @scwpod.bsky.social · 29/07/2025
Transcript: securitycryptographywhatever.com/2025/07/29/v...
securitycryptographywhatever.com
Vegas, Baby!
We’re throwing a party in Vegas! Someone called it SCWPodCon last year, and the name stuck. It’s sponsored by Teleport, the infrastructure identity company. ...
032
Reposted by Security Cryptography Whatever
Security Cryptography Whatever @scwpod.bsky.social · 29/07/2025
Come to SCWPodCon, sponsored by Teleport! securitycryptographywhatever.com/events/black...
securitycryptographywhatever.com
SCWPodCon BlackHat 2025
"Security Cryptography Whatever" is hosting a party during BlackHat USA, brought to you by Teleport! Get tickets now!
112
Reposted by Security Cryptography Whatever
Security Cryptography Whatever @scwpod.bsky.social · 29/07/2025
New episode! Come to SCWPodCon, sponsored by Teleport! www.youtube.com/watch?v=tbnh...
youtube.com
Vegas, Baby!
YouTube video by Security Cryptography Whatever
103
Security Cryptography Whatever @scwpod.bsky.social · 29/07/2025
New episode! Come to SCWPodCon, sponsored by Teleport! www.youtube.com/watch?v=tbnh...
youtube.com
Vegas, Baby!
YouTube video by Security Cryptography Whatever
103
Reposted by Security Cryptography Whatever
Deirdre Connolly¹ ² @durumcrustulum.com · 16/07/2025
pew pew pew www.youtube.com/watch?v=vtt8...
youtube.com
This Quantum Attack Is Live Now
YouTube video by Deirdre Connolly
084
Security Cryptography Whatever @scwpod.bsky.social · 17/07/2025
Signups are still open! Sponsored by Teleport!
020
Security Cryptography Whatever @scwpod.bsky.social · 10/07/2025
We're throwing another SCWPodCon in Vegas! It's in the liminal space between BlackHat and DEF CON. Be there, or have FOMO. We'll provide the drinks, you provide the conversation. Sign up here: securitycryptographywhatever.com/events/black...
securitycryptographywhatever.com
SCWPodCon BlackHat 2025
"Security Cryptography Whatever" is hosting a party during BlackHat USA. Get tickets now!
120
Security Cryptography Whatever @scwpod.bsky.social · 10/07/2025
Should we throw another BlackHat party?
110
Reposted by Security Cryptography Whatever
David Adrian @dadrian.io · 06/07/2025
Wrote some words about memory safety and JITs. Basically, there are things we want out of hardware, but it's not MTE and it still involves migrating to memory safe languages dadrian.io/blog/posts/m...
dadrian.io
Sandboxes? In my process? It's more likely than you think.
Discussions around memory safety often focus on choice of language, and how the language can provide memory safety guarantees. Unfortunately, choosing a language is a decision made at the start of a p...
053
Security Cryptography Whatever @scwpod.bsky.social · 08/06/2025
Still have one more slot for a sponsor for our annual Vegas event, poke @dadrian.io if you have money.
012
Security Cryptography Whatever @scwpod.bsky.social · 19/05/2025
NEW EPISODE! It seems like everyone that deploys E2EE encrypted cloud storage seems to mess it up, often in new and creative ways. Our special guests Matilda Backendal, Jonas Hofmann, & Kien Tuong Trong give us a tour & discuss how to actually build one securely: www.youtube.com/watch?v=sizL...
youtube.com
051
Reposted by Security Cryptography Whatever
Thomas Ptacek @sockpuppet.org · 19/05/2025
This one was super fun. We talked with Jonas Hofmann, Kien Tuong Trong, and Matilda Backendal about a cross-section study of "E2EE" secure storage (not messaging, storage). Backendal is working to formalize that problem (it wasn't already!) Fun bugs! securitycryptographywhatever.com/2025/05/19/e...
securitycryptographywhatever.com
E2EE Storage Done Right with Matilda Backendal Jonas Hofmann and Kien Tuong Trong
It seems like everyone that tries to deploy end-to-end encrypted cloud storage seems to mess it up, often in new and creative ways. Our special guests Matild...
181
Security Cryptography Whatever @scwpod.bsky.social · 06/05/2025
Our guest Nicholas Carlini and his coauthors just won Best Paper at Eurocrypt 2025: eprint.iacr.org/2024/1580.pdf
1123
Security Cryptography Whatever @scwpod.bsky.social · 24/03/2025
Migrating the US government to quantum-resistant cryptography is hard, luckily the gamer presidents are on it. This episode is very not safe for work, nor does it reflect the political opinions of, well, anybody. podcasts.apple.com/us/podcast/p... securitycryptographywhatever.com/2025/03/23/p...
securitycryptographywhatever.com
Picking Quantum Resistant Algorithms
Migrating the US government to quantum-resistant cryptography is hard, luckily the gamer presidents are on it. This episode is extremely not safe for work, n...
1101
Reposted by Security Cryptography Whatever
Daniel Garnier-Moiroux @garnier.wf · 22/03/2025
I’ve been working on webauthn and passkeys on and off for > 1 year, and I can’t believe I missed this @scwpod.bsky.social with Adam Langley from Google, dating back to … 2022 🤯 If you’re interested in technical details about passkeys, it’s very good! securitycryptographywhatever.com/2022/08/11/p...
securitycryptographywhatever.com
Passkeys with Adam Langley
Adam Langley (Google) comes on the podcast to talk about the evolution of WebAuthN and Passkeys! David’s audio was a little finicky in this one. Believe us,...
1255