Sign in

Tjerand Silde

@tjesi.bsky.social
341 followers 335 following 35 posts

Associate Professor in Cryptology and Research Group Leader at the NTNU Applied Cryptology Lab in Trondheim, Norway. Homepage: tjerandsilde.no Research group: www.ntnu.edu/iik/nacl-lab

PostsRepliesMedia
Reposted by Tjerand Silde
Miro Haller @mirohaller.bsky.social · 21/09/2026
We finally finished the universal signature forgery for 1024-bit RSA! 2^32 oracle queries, 1200 core years precomputation, 180 core years for an individual forgery, and 3 years of human labor (no AI involved) by Laura, Adam, Nadia, Emmanuel and me to pull of this computation against real HSMs.
14019
Reposted by Tjerand Silde
Michael A. Specter 👻 @mikespecter.com · 17/08/2026
We also bought EncroChat's original domain (encrochat.ch) --- it now hosts our paper and other info.
encrochat.ch
A Real-World Law-Enforcement Hack: The Case of Encrochat
0107
Reposted by Tjerand Silde
Kenny Paterson @kennyog.bsky.social · 15/08/2026
Signal is the gold standard for secure messengers. We broke Signal’s integrity (twice) in this paper via message injection attacks. @kientuong114.bsky.social presented this week at #USENIX and he and Noemi will present it again at #WAC (Crypto workshop) this weekend. Catch their talk if you can!
02911
Reposted by Tjerand Silde
Martin R. Albrecht @malb.bsky.social · 15/08/2026
eprint.iacr.org/2026/1693
Screenshot of the title page of the paper. Text:

The ePrint:2026/1591 Quantum Algorithm
Does Not Solve DCP
Aparna Gupte
MIT
Seyoon Ragavan
Google Quantum AI
& MIT
Mark Zhandry
Google Quantum AI
& Stanford University
Abstract
In this note, we formally show that the recent algorithm by Simon (ePrint:2026/1591, August 11 2026) does
not extract the least-significant bit of the dihedral coset problem (DCP) secret with non-negligible guessing advan-
tage, and therefore does not solve DCP. We emphasize that our result is not merely about Simon’s analysis of his
algorithm; we are showing directly that the algorithm cannot possibly work.
Our no-go encompasses a much broader class of algorithms than the specific algorithm by Simon. The main
message of our no-go is that an algorithm for DCP following the template of the reduction by Regev (SIAM Journal
on Computing, 2004) will probably have to make extensive use of the classical Fourier labels in the uncomputation
stage. On the other hand, the algorithm by Simon can be implemented, up to error poly(n)2−n/3, using only the
most-significant third of the classical Fourier labels, and therefore cannot succeed.
To help with verifiability, we release Lean 4 code for our results, available at this GitHub repository.
1214
Reposted by Tjerand Silde
Matthew Green @matthewdgreen.bsky.social · 11/08/2026
If you haven’t seen it, this new paper is great. They expand on a blog post I wrote that showed you could replay encrypted reasoning blobs from AI models. And they turned it into a full jailbreak. stolen-thoughts.com
stolen-thoughts.com
Stolen Thoughts
Encrypted chain-of-thought blocks returned by Anthropic, OpenAI and Google APIs are interchangeable across sessions, users and models. We exploit this to decode hidden reasoning at scale.
210534
Reposted by Tjerand Silde
Signal @signal.org · 11/08/2026
Introducing Automatic Key Verification! Complementing the existing safety number system, automatic key verification provides an additional, streamlined way to confirm the privacy of your chats. signal.org/blog/automat... TY @cloudflare.social and @trailofbits.bsky.social our independent auditors 💙🙏
signal.org
Introducing Automatic Key Verification
Signal now offers a feature called “automatic key verification” which complements the existing safety number system. Signal is always end-to-end encrypted, and automatic key verification provides an a...
629178
Reposted by Tjerand Silde
Chris Peikert @chrispeikert.bsky.social · 10/08/2026
Oh my goodness!!
1268
Reposted by Tjerand Silde
Chris Peikert @chrispeikert.bsky.social · 02/08/2026
1/ Initial reactions after some hours with this groundbreaking result proving the NP-hardness of poly-approx CVP/NCP: It is most likely correct, but more importantly, it is original, elegant, and beautiful! (Also: it is easy to improve, quantitatively.) openai.com/index/ten-ad...
openai.com
Ten advances in mathematics and theoretical computer science
OpenAI shares new results on long-standing open problems in mathematics and theoretical computer science, including advances in geometry, cryptography, and complexity.
210328
Reposted by Tjerand Silde
Bas Westerbaan @bwesterb.bsky.social · 29/07/2026
We support post-quantum authentication now to your origin. First place we deploy PQ certs: many more to come. blog.cloudflare.com/post-quantum...
blog.cloudflare.com
Post-quantum authentication to origins is now supported
Cloudflare now supports post-quantum (PQ) authentication when connecting to customer origin servers via Authenticated Origin Pulls and Custom Origin Trust Store. This is the first step towards providi...
084
Reposted by Tjerand Silde
Henry Yuen @henryyuen.bsky.social · 01/08/2026
Some initial thoughts, and a complicated mix of feelings. Wow. I mean, Erdos problems are cool (I genuinely mean that), I didn't know about the Jacobian conjecture before it got disproved. But this newest batch from OpenAI hits home in a way the previous announcements did not.
232972
Reposted by Tjerand Silde
Huck Bennett @huckbennett.bsky.social · 02/08/2026
Yes, the result itself is very interesting (more on this below). From a skim, I agree with Noah that the paper is not well-written. Am I happy to see LLMs invade TCS? No, it's terrible. Is this the most impactful LLM result about lattices this week? Unclear. 1/
1276
Reposted by Tjerand Silde
Chris Peikert @chrispeikert.bsky.social · 28/07/2026
This is a very cool and exciting discovery by Claude Mythos! It found a serious 𝒎𝒂𝒕𝒉𝒆𝒎𝒂𝒕𝒊𝒄𝒂𝒍 attack on the post-quantum signature scheme HAWK, an "on-ramp" candidate for potential NIST standardization. www.anthropic.com/research/dis...
anthropic.com
Discovering cryptographic weaknesses with Claude
Anthropic researchers find weaknesses in cryptographic algorithms with Claude Mythos Preview
23218
Reposted by Tjerand Silde
Clément Canonne @ccanonne.github.io · 01/08/2026
"We're all worried," as what it means to do research (in my field, Theoretical CS) seems to be shifting, and shifting fast. What to do? Senior researchers must lead by example, knowing that not everything will pan out. What I'm suggesting below may not work everywhere, but here's my own advice: 1/
620351
Reposted by Tjerand Silde
ePrint Updates @eprint.ing.bot · 23/07/2026
The supersingular isogeny problem in time and memory p^(1/3 + o(1)) (Benjamin Wesolowski) ia.cr/2026/1486
Abstract. We prove that under a plausible heuristic assumption (on the smoothness of certain random integers), the supersingular isogeny problem can be solved in time and memory p^(1/3 + o(1)). This improves upon the previous best complexity of p^(1/2) ⋅ (log p)^(O(1)). This problem is arguably the central hard problem underlying isogeny-based cryptography, and the cost of its resolution is a major (and often the only) factor in the choice of secure parameters. The impact on concrete parameter sets remains to be clarified, as the asymptotic advantage of the new algorithm is mitigated by a superpolynomial overhead hiding in the o(1) exponent, and by its high memory requirement.
01511
Reposted by Tjerand Silde
Jim Waterson @jim.londoncentric.media · 23/07/2026
*walks into room of mathematicians* Have you considered DOING A BREAKTHROUGH.
1348454
Reposted by Tjerand Silde
Bas Westerbaan @bwesterb.bsky.social · 09/07/2026
Every year we write about the exciting developments in post-quantum signatures. Last year didn't disappoint. But it's too late. As ekr wrote in 2024 "You go to war with the algorithms you have, not the ones you wish you had." ML-DSA will have to do for now. blog.cloudflare.com/ml-dsa-will-...
blog.cloudflare.com
Why we cannot wait for better post-quantum signature algorithms
NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and sh...
0116
Reposted by Tjerand Silde
Martin R. Albrecht @malb.bsky.social · 01/07/2026
A Real-World Law-Enforcement Hack: The Case of Encrochat martinralbrecht.wordpress.com/2026/07/01/a...
Cover of the paper at https://eprint.iacr.org/2026/1319.pdf
062
Tjerand Silde @tjesi.bsky.social · 11/06/2026
The list of accepted papers to IACR Crypto 2026 is available online: iacr.org/cryptodb/dat...
iacr.org
Papers from CRYPTO 2026
083
Tjerand Silde @tjesi.bsky.social · 10/06/2026
The deadline is coming up in two days!
000
Reposted by Tjerand Silde
ePrint Updates @eprint.ing.bot · 31/05/2026
BRaccoon: Concurrently Secure Blind Lattice Signatures from Raccoon (Lucjan Hanzlik, Mark Manulis, Marzio Mula, Alan Pulval-Dady, Tjerand Silde, Daniel Slamanig) ia.cr/2026/1084
Abstract. Blind signatures are a central primitive for privacy-preserving applications such as e-cash, anonymous credentials, and e-voting. In the post-quantum setting, existing constructions typically follow one of two paradigms: either signatures are realized as non-interactive zero-knowledge (NIZK) proofs of valid underlying signatures, or they are obtained from identification schemes via the Fiat–Shamir transform. In both approaches, the resulting signatures deviate syntactically from standard signatures, incurring additional verification overhead and limiting compatibility with existing infrastructures. In contrast, classical constructions such as blind Schnorr yield signatures that are indistinguishable from ordinary ones. Achieving this property in the lattice setting has remained an open problem.

We present BRaccoon, the first lattice-based blind signature scheme that achieves concurrent security while producing signatures that are syntactically identical to those of a standard signature scheme. Our construction builds on the rejection-free lattice signature scheme Raccoon, and extends the “blind signatures from a signature assumption” paradigm of Fuchsbauer and Wolf (EUROCRYPT~2024) to lattices. At a high level, we introduce blinding at the commitment stage and enforce correct challenge and response generation via linearly homomorphic encryption combined with NIZK proofs. As a result, BRaccoon signatures preserve the algebraic structure of Raccoon signatures while remaining compact: in an optimized instantiation, signatures are 32 KB, public keys are 10 KB, and total communication is 847 KB for up to 2³² signatures.

A central technical challenge stems from discrete Gaussian sampling, where blinding induces a non-trivial distributional shift that precludes direct security reductions. To overcome this, we introduce a modified scheme Raccoon^(⋆) that explicitly captures this shift. We prove that one-more unforgeability of BRaccoon tightly reduces to the unforgeability of Raccoon^(⋆), which in turn reduces to that of Raccoon.

For a concrete instantiation, we develop a hybrid proof framework that combines lattice-based zero-knowledge arguments for linear relations with arithmetic zk-SNARKs for hash computations, linked via structured commitments. Our work demonstrates that concurrently secure blind signatures with standard-signature syntax can be achieved in the lattice setting, providing a viable path toward practical and interoperable post-quantum privacy-preserving systems.
Image showing part 2 of abstract.Image showing part 3 of abstract.
031
Reposted by Tjerand Silde
Real World Crypto Symposium @rwc.iacr.org · 28/05/2026
The Call for Contributed Talks for the 2027 edition of the Real World Crypto Symposium 2027 is now open. If you’ve built, deployed, broken, measured, migrated, or learned something the community should hear about, submit it. rwc.iacr.org/2027/contrib...
rwc.iacr.org
RWC 2027 call for papers
Real World Crypto Symposium
097
Reposted by Tjerand Silde
Clément Canonne @ccanonne.github.io · 26/05/2026
Congratulations to Tal Rabin, Shubhangi Saraf, and Lisa Zhang, recognized by the SIGACT Distinguished Service Award for their role in making Theoretical Computer Science more welcoming and inclusive with the Women In Theory (WIT) workshop! sigact.org/prizes/servi... (via @gautamkamath.com)
sigact.org
2025 ACM-SIGACT Distinguished Service Award
13412
Reposted by Tjerand Silde
Quanta Magazine @quantamagazine.org · 12/05/2026
Shafi Goldwasser (left), Silvio Micali (right), and Charles Rackoff devised a way to prove that a statement is true without revealing anything about why. www.quantamagazine.org/how-unknowab...
22610
Tjerand Silde @tjesi.bsky.social · 12/05/2026
We have two openings at our Department of Information Security and Communication Technology at NTNU: Associate Professor in Cryptographic Engineering: www.jobbnorge.no/en/available... Professor/Associate Professor in Mobile and Computer Networks: www.jobbnorge.no/en/available... Apply by June 12!
032
Tjerand Silde @tjesi.bsky.social · 11/05/2026
The list of accepted papers to SCN 2026 is available online: scn.unisa.it/scn26/index....
scn.unisa.it
SCN 2026 – List of Accepted Papers
AuthorsTitleAnasuya Acharya, Carmit Hazay and Rahul SatishThe Landscape of Reusable GarblingFoteini Baldimtsi and Aayush YadavAtlantis: Lattice-based Anonymous Tokens with Private Metadata BitRober…
031
Tjerand Silde @tjesi.bsky.social · 11/05/2026
The list of accepted papers to PKC 2026 is available online: pkc.iacr.org/2026/accepte...
pkc.iacr.org
PKC 2026 accepted papers
Public Key Cryptography
042
Tjerand Silde @tjesi.bsky.social · 08/05/2026
Very excited about the International Workshop on Foundations and Applications of Privacy-Enhancing Cryptography (PrivCrypt) that I am co-organizing with @drl3c7er.bsky.social and Lucjan Hanzlik as an affiliated event to IACR Eurocrypt in Rome this Sunday: privcryptworkshop.github.io/program.html
privcryptworkshop.github.io
PrivCrypt 2026
131
Reposted by Tjerand Silde
Filippo Valsorda @filippo.abyssdomain.expert · 20/04/2026
There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers. This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.
words.filippo.io
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.
312135
Reposted by Tjerand Silde
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 25/03/2026
Objects in the quantum mirror are closer than they appear. blog.google/innovation-and-ai/techn…
blog.google
Quantum frontiers may be closer than they appear
An overview of how Google is accelerating its timeline for post-quantum cryptography migration.
074
Reposted by Tjerand Silde
Filippo Valsorda @filippo.abyssdomain.expert · 06/04/2026
Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years. That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.
words.filippo.io
A Cryptography Engineer’s Perspective on Quantum Computing Timelines
The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.
11303123
Reposted by Tjerand Silde
Sam Jaques @sejaques.bsky.social · 09/04/2026
Overdue quantum landscape update: sam-jaques.appspot.com/quantum_land... A 2d chart can only say so much. tl;dr new results are still overhyped, but definitely worth taking seriously. This chart is based on surface codes and a big question now is whether new codes can be practical (=>useless chart)
A cluttered and complicated chart relating qubit counts to qubit error rates, comparing today's devices to cryptographic attacks.
15122
Reposted by Tjerand Silde
Matthew Green @matthewdgreen.bsky.social · 13/03/2026
The EU seems to be going in the right direction when it comes to mass message scanning. Unfortunately, the fact that this vote was necessary proves that we’re still in the dark timeline. cyberinsider.com/eu-votes-to-...
cyberinsider.com
EU votes to restrict mass scanning of people’s private messages
The European Parliament has voted to curb untargeted mass scanning of private communications in the EU, in a key 'Chat Control' development.
47733
Reposted by Tjerand Silde
carmelatroncoso.bsky.social @carmelatroncoso.bsky.social · 02/03/2026
Governments worldwide turn to age-based access control to Internet services to protect children. More than 370 scientists call for a moratorium until there is a good understanding of their feasibility, effectiveness, and societal impact: csa-scientist-open-letter.org/ageverif-Feb...
csa-scientist-open-letter.org
1510
Reposted by Tjerand Silde
Hanne Østli Jakobsen @hannejakobsen.bsky.social · 27/02/2026
Har vært på leting etter snill, trygg og ikke-amerikansk telefon. Jeg fant ut to ting: 1) At det er umulig å komme helt i mål, og hvorfor 2) Hvorfor det likevel er verdt å forsøke Håper du vil lese! Artikkelen er også blitt en slags podkast i lydutgaven, et eksperiment, om du heller vil lytte
morgenbladet.no
(+) Jakten på en fri, snill og akkurat passe dum telefon
Vi vil bli fri, bryte de mobile livene våre vekk fra tekoligarkene og overvåkningsgigantene. Og det har aldri vært flere europeiske alternativer. Skal det være en Mudita eller en Dumbdroid eller en Jo...
2286
Reposted by Tjerand Silde
Finn Lützow-Holm Myrstad @finnmyrstad.bsky.social · 27/02/2026
Have you noticed that digital products and services are getting worse? So have we! Today we are publishing our new report, Breaking Free: Pathways to a fair technological future. vimeo.com/1168468796?f...
vimeo.com
The Enshittificator
Digital products and services keep getting worse. In the new report Breaking Free: Pathways to a fair technological future, the Norwegian Consumer Council has delved…
48557
Tjerand Silde @tjesi.bsky.social · 23/02/2026
Some accepted papers at IACR Eurocrypt 2026 are now available online: iacr.org/cryptodb/dat...
iacr.org
Papers from EUROCRYPT 2026
042
Tjerand Silde @tjesi.bsky.social · 20/02/2026
Published an opinion piece (in Norwegian) about PQC (yay) vs QKD (buu) in @digi.no today, together with @jonathan.isogeny.club, Kristian Gjøsteen (NTNU), Øyvind Ytrehus (UiB), and Morten Øygarden (UiB): www.digi.no/artikler/deb...
digi.no
Spekulativ kvanteteknologi løser ikke sikkerhetsproblemene våre
Kvantedatamaskiner kan i fremtiden knekke dagens kryptografi. Derfor må vi sikre at data som sendes i dag ikke kan leses av morgendagens angripere.
051
Reposted by Tjerand Silde
Damien Robert @damienrobert.bsky.social · 20/02/2026
I am very happy to announce that thanks to the hard work of many people (The "MIKE Team"), we now have a working implementation in SageMath of MIKE (Module Isogeny Key Exchange).
198
Reposted by Tjerand Silde
ETH CS Department @csateth.bsky.social · 17/02/2026
A team of computer scientists from the Applied Cryptography Group, including Matteo Scarlata, Professor Kenny Paterson, Giovanni Torrisi and Matilda Backendal, have discovered serious security vulnerabilities in three popular cloud-based password managers. Read more ⬇️
092
Tjerand Silde @tjesi.bsky.social · 12/02/2026
My colleague Jeongeun Park has an open PhD position in Post-Quantum Cryptography for Privacy Preserving Protocols at NTNU in Trondheim with application deadline March 20: www.jobbnorge.no/en/available...
jobbnorge.no
PhD Candidate in Post-Quantum Cryptography for Privacy Preserving Protocols (295226) | NTNU - Norwegian University of Science and Technology
Job title: PhD Candidate in Post-Quantum Cryptography for Privacy Preserving Protocols (295226), Employer: NTNU - Norwegian University of Science and Technology, Deadline: Friday, March 20, 2026
020
Tjerand Silde @tjesi.bsky.social · 05/02/2026
I am co-organising (with @drl3c7er.bsky.social and Lucjan Hanzlik) a workshop on Privacy-Enhancing Cryptography in Rome on May 10 as an affiliated event to IACR Eurocrypt. Submit your best PEC-work (3-page extended abstract) for presentation by February 25th: privcryptworkshop.github.io
privcryptworkshop.github.io
PrivCrypt 2026
1119
Reposted by Tjerand Silde
Miro Haller @mirohaller.bsky.social · 19/01/2026
Submission week for the Cryptographic Application Workshop (CAW), an affiliated event at Eurocrypt'26 in Rome! Please submit your talk proposals on constructive real-world crypto using the following instructions before Jan 23, 2026 AoE. All infos on: caw.cryptanalysis.fun.
187
Reposted by Tjerand Silde
Martin R. Albrecht @malb.bsky.social · 13/01/2026
Social Foundations of Cryptography: Autumn School London, UK | 15 to 17 September 2026 social-foundations-of-cryptography.gitlab.io/school
We're hosting an Autumn School in London, UK, from 15 to 17 September 2026, to bring together ethnographers and cryptographers to discuss ways in which the two fields can be meaningfully brought into conversation.

This is also the premise of our Social Foundations of Cryptography project: to ground cryptography in ethnography. Here, we rely on ethnographic methods, rather than our intuition, to surface security notions that we then formalise and sometimes realise using cryptography.

Our intention is to 'flip' the typical relationship between the computer and social sciences, where the latter has traditionally ended up in a service role to the former. Rather, we want to put cryptography at the mercy of ethnography.

But how do we do this? How do we as cryptographers interact with and make sense of ethnographic field data? How can we refine, improve or extend this interaction? What obstacles do we face when we make cryptography rely on ethnographic data which is inherently 'messy'? How do we handle that cryptographic notions tend to require some form of generalisation but ethnographic findings can only be particular?

How do ethnographers retain the richness of ethnographic field data in conversations with cryptographic work? Indeed, our project has already highlighted some limitations of our approach. It has brought to the fore concrete challenges in 'letting the ethnographic data speak' while still making it speak to cryptography.

The Autumn School is an opportunity to explore these questions jointly across ethnography and cryptography, through a series of talks, group discussions and activities.

We say a bit more about the programme and registration for the Autumn School here.
196
Reposted by Tjerand Silde
Martin R. Albrecht @malb.bsky.social · 05/01/2026
Come work with us! Lecturer (≅ Assistant Professor/Juniorprofessor/Maître de conférences) in Cryptography at King’s College London martinralbrecht.wordpress.com/2026/01/05/l...
martinralbrecht.wordpress.com
Lecturer (≅ Assistant Professor/Juniorprofessor/Maître de conférences) in Cryptography at King’s College London 2026
We are looking to recruit a lecturer in cryptography at King’s College London to work with us within the cybersecurity group: I think it’s fair to say we got strong expertise in lattice-based and p…
0106
Reposted by Tjerand Silde
Hanne Østli Jakobsen @hannejakobsen.bsky.social · 04/01/2026
0144
Tjerand Silde @tjesi.bsky.social · 28/10/2025
www.jobbnorge.no/en/available...
jobbnorge.no
Professor/Associate Professor in Cybersecurity (287959) | NTNU - Norwegian University of Science and Technology
Job title: Professor/Associate Professor in Cybersecurity (287959), Employer: NTNU - Norwegian University of Science and Technology, Deadline: Monday, December 1, 2025
000
Reposted by Tjerand Silde
Matthew Green @matthewdgreen.bsky.social · 10/10/2025
Germany has agreed to stop ChatControl for now, due to huge amounts of public pressure. Good job! The bad news is that it could come back as soon as December, and the German government has interpreted the feedback as a need to “moderate” the proposal.
114246
Reposted by Tjerand Silde
Ian Miers @secparam.bsky.social · 09/10/2025
Discord user IDs getting leaked is the entirely predictable consequence of requiring platforms to do age verification. That data never goes away, it spreads. In this case, into appeals in a breached customer support database. And predictably, it can get worse. www.404media.co/the-discord-...
404media.co
The Discord Hack is Every User’s Worst Nightmare
A hack impacting Discord’s age verification process shows in stark terms the risk of tech companies collecting users’ ID documents. Now the hackers are posting peoples’ IDs and other sensitive informa...
164
Reposted by Tjerand Silde
Diego F. Aranha @dfaranha.bsky.social · 06/10/2025
Someone please make me understand how Denmark can be at the same time freaking out about hybrid war with Russia AND pushing for government-mandated spyware as Chat Control.
182
Reposted by Tjerand Silde
Rosamunde Van Brakel @rosamundevb.bsky.social · 06/10/2025
What is chat control? Good video explainer developed by @carmelatroncoso.bsky.social and team at Max Planck Institute for Security and Privacy #chatcontrol www.youtube.com/watch?v=-y2O...
youtube.com
What is Chat Control?
YouTube video by Max Planck Institute for Security and Privacy
077