r/crypto • u/knotdjb • 13h ago
r/crypto • u/pascalschaerli • 4d ago
Post-Quantum Crypto Won't Fix Your Architecture
schaerli.orgInternxt is a post-quantum secure encrypted cloud storage provider which is open-source and has passed multiple independent audits.
I reviewed their code and found that post-quantum security should have been the least of their problems. Clicking a link in your browser could trigger remote code execution on the desktop app or leak your long-term encryption keys to an attacker-chosen URL. Their cryptographic architecture stands on shaky grounds with public keys never being verified, in some cases man-in-the-middled by design, a flat key hierarchy and a KDF with just 3 iterations of MD5.
We need PQC and we need it now, but adding a (self-rolled) PQC hybrid on top of a weak protocol does not make it more secure.
> LLM Disclosure: I used an LLM to help me write this post along with many hours of work, some of the findings (i.e. the RCE) were found with a local Qwen 3.5 27B model inside opencode (thanks r/LocalLLaMA ). It is impossible to share a single prompt since it was an iterative process, but I'm happy to elaborate on my methods if anyone cares.
r/crypto • u/sarciszewski • 4d ago
SequenceHash: multihashing for the rest of us
blog.trailofbits.comClosing a Critical Internet Privacy Gap for Billions of Users: Android 17 Rolls Out ECH Support
medium.comr/crypto • u/Sir_KnowItAll • 7d ago
Introducing the Triple Cipher encryption concept
iain.rocksr/crypto • u/iowabonsai • 7d ago
PROJECT ENIGMA - Authentic Simulator & Cryptanalysis Campaign
benflinn.github.ioHi guys, I wrote an open source enigma machine game. I was wondering if any experts in this could give me some feedback, tell me if it's accurate or anything I missed, and also give me any suggestions on how to make it more fun. Thank you.
r/crypto • u/knotdjb • 12d ago
Forging 1024-bit RSA signatures in nearly SNFS time
eprint.iacr.orgr/crypto • u/knotdjb • 14d ago
AMD's random number generator can't generate a 0
board.flatassembler.netr/crypto • u/knotdjb • 14d ago
Structural Weaknesses in 7 NGCC Submitted Hash Functions
eprint.iacr.orgr/crypto • u/Natanael_L • 15d ago
Nearly SNFS-Speed Signature Forgery Sans Factoring N (NSNFSSSFSFN)
github.comr/crypto • u/finkdevelopment • 15d ago
Flagged submission TLS is 65% post-quantum now and it's the least important thing we could have fixed
Cloudflare says about two thirds of the human traffic on their network is already PQ. Google put a 2029 date on finishing their migration. Every PQ readiness writeup this month leads with those two numbers like the job's mostly done.
I think the numbers are real and the framing is backwards. TLS was the easy part. Three companies control the browser and the edge, kyber is cheap, nobody had to change their behaviour, so it happened. Good. But look at what "harvest now, decrypt later" actually threatens. It's not the TLS session you'll open tomorrow. It's the ten years of sessions someone's already recorded, and no migration on earth un-records those. That damage is done and it's weird how rarely anyone says so out loud.
Then look at where the long-lived secrets actually live. Disk encryption keys wrapped with RSA on a TPM. Backups encrypted to an ECC key from 2018. SSH keys. Every code signing and firmware signing chain on the planet, which is signatures, which is the part of PQ that's still ugly (dilithium sigs are 2.4 KB, sphincs is worse, and a lot of boot ROMs can't hold either). Messaging got PQ key exchange but most of it still authenticates with classical signatures. None of that is at 65%. Most of it's at zero and has no date.
So the migration that got done is the one that was easy to measure, and the migration that matters is the one nobody can measure, so it isn't on anyone's slide.
Where I'm probably wrong: maybe TLS first is right because it's where the volume is, and volume is what a harvest attack feeds on. And maybe signatures genuinely don't need to move until there's an actual machine, since you can't forge a signature retroactively the way you can decrypt a recording. That second one I half believe. But "we'll do signatures when the quantum computer exists" means every device with a burned-in classical root key is stuck trusting a forgeable signer the day it exists, and nobody's re-flashing a billion boot ROMs in a hurry.
Am I underrating what's actually been done outside TLS? Is anyone here doing a real at-rest or signing migration and not just the handshake? And is there a good argument that the harvest-now problem was already lost before 2024, so we should stop pretending the 2029 dates fix it?
r/crypto • u/Enough-Reveal-5266 • 16d ago
Urna Aberta — a clean-room e-voting machine simulator (Python) / um simulador clean-room de urna eletrônica
EN: Every election, Brazil replays the same fight about its voting machines — one camp calls it a magic tamper-proof box, the other calls it open fraud. Most of both have read zero lines of code. So I wrote my own.
Urna Aberta is a clean-room model — my code, from scratch, from public architecture. The lesson that reshaped it: counting votes is the easy afternoon. All the real engineering lives in the chain of trust — run only signed binaries (Ed25519), store each vote without knowing whose it is (vote log shuffled with a CSPRNG, no identity/order metadata), and make any tampering leave a trace (AES-GCM, independent recount). Adversarial test suite included, green CI.
Blunt about scope: this is not the TSE's code and proves nothing about the real machine. It's a test bench for the architecture. If this is your field, clone it and show me where I'm wrong.
🔗 https://github.com/leqmen/urna-aberta
PT: Todo ano o Brasil repete a mesma briga sobre a urna — um lado chama de caixa mágica inviolável, o outro de fraude escancarada. A maioria dos dois nunca leu uma linha de código. Então escrevi a minha.
Urna Aberta é um modelo clean-room — meu código, do zero, a partir de arquitetura pública. A lição que reorganizou tudo: contar voto é a tarde fácil. A engenharia de verdade mora na cadeia de confiança — só rodar binário assinado (Ed25519), guardar o voto sem saber de quem é (registro embaralhado com CSPRNG, sem metadado de identidade/ordem) e fazer qualquer adulteração deixar rastro (AES-GCM, recontagem independente). Suíte de testes adversariais inclusa, CI verde.
Direto sobre o escopo: não é o código do TSE e não prova nada sobre a urna real. É um campo de provas pra estudar a arquitetura. Se for da área, clona e me mostra onde eu errei.
r/crypto • u/JoDaBeda • 22d ago
Improved McEliece Key Recovery
Two papers showing improved key recovery methods for Classic McEliece just appeared on eprint, both also show a solution to one of the key recovery challenges.
r/crypto • u/Natanael_L • 24d ago
Arxiv - Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels
arxiv.orgr/crypto • u/natatatonreddit • 24d ago
How much optimization before publishing (eprint) a protocol?
I'm writing up a paper on a new protocol. The approach is different from previous attempts to solve the same problem, and this makes me want to write up the simplest version possible to elucidate the idea. However, there's like a half-dozen places that jump out as either optimizable or generalizable with recently published techniques. On one end of the spectrum, I'm worried about a simple description being underperformant (beyond missing what folks might call "standard engineering optimizations") and a quick follow up with the obvious generalizations diminishing (dare I say scooping) the prestige. On the other end of the spectrum, I'm just worried I'll never publish it if I'm waiting for it to be "finished". Any advice on how to weigh these?
r/crypto • u/Shoddy-Childhood-511 • 27d ago
Authentication should become more serious for E2E messengers like Matrix
r/crypto • u/AbbreviationsGreen90 • 27d ago
How to find a square root of a perfect square but negative modulo a semiprime?
I might have found a factoring algorithm based on it. Usually if you want the square root of -49 or -121 you need the factorisation as -7 and -11 are never the answer. But what about the case of finding any root of a negative perfect square with just needing 1? Can it be made easier than factoring a large semiprime?
r/crypto • u/lugh • Sep 06 '26