<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/1822302.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>Security Cryptography Whatever</title>

  <lastBuildDate>Wed, 16 Sep 2026 16:51:18 -0400</lastBuildDate>
  <link>https://securitycryptographywhatever.com</link>
  <language>en-us</language>
  <copyright>© 2026 Security Cryptography Whatever</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>867836ea-7d1d-5bf7-9fd1-7f76415d62ab</podcast:guid>
  <podcast:txt purpose="verify">scw.pod@gmail.com</podcast:txt>
  <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>true</itunes:explicit>
  <description><![CDATA[Some cryptography & security people talk about security, cryptography, and whatever else is happening.]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:keywords>security, cryptography, whatever</itunes:keywords>
  <itunes:owner>
    <itunes:name>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:name>
    <itunes:email>scw.pod@gmail.com</itunes:email>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/j0mg64drknc1b0xl8t4m5yn6umlo?.jpg</url>
     <title>Security Cryptography Whatever</title>
     <link>https://securitycryptographywhatever.com</link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/j0mg64drknc1b0xl8t4m5yn6umlo?.jpg" />
  <itunes:category text="Technology" />
  <itunes:category text="Science">
    <itunes:category text="Mathematics" />
  </itunes:category>
  <itunes:category text="News">
    <itunes:category text="Tech News" />
  </itunes:category>
  <item>
    <itunes:title>AI Lattice Proofs with Chris Peikert</itunes:title>
    <title>AI Lattice Proofs with Chris Peikert</title>
    <itunes:summary><![CDATA[The robots are at it again, and this time they’re solving, and breaking(?), math and cryptography! Things have been happening in the lattice corner including new leapfrogging complexity results in the closest vector problem (CVP), AND a possible poly-time quantum attack against the dihedral coset problem (DCP) that made everyone freak out for about a week (UPDATE: looks like it’s busted: https://eprint.iacr.org/2026/1693). ALSO, there was an important distinguisher attack against Classic McEl...]]></itunes:summary>
    <description><![CDATA[<p>The robots are at it again, and this time they’re solving, and breaking(?), math and cryptography! Things have been happening in the lattice corner including new leapfrogging complexity results in the closest vector problem (CVP), AND a possible poly-time quantum attack against the dihedral coset problem (DCP) that made everyone freak out for about a week (UPDATE: looks like it’s busted: https://eprint.iacr.org/2026/1693). ALSO, there was an important distinguisher attack against Classic McEliece, which on its face doesn’t sound like a big deal, unless you’re familiar with the track record of efficient distinguishers in the history of code-based cryptography… 😱<br/><br/>To help us make sense  of all this we are joined again by OG friend of the pod Chris Peikert! We had trouble with his audio but tried our best to fix it, apologies.<br/><br/></p><p>Transcript: https://securitycryptographywhatever.com/2026/08/26/ai-lattice-proofs-with-chris-peikert/</p><p><br/>Links:<br/>- https://openai.com/index/ten-advances-in-mathematics/<br/>- https://cdn.openai.com/pdf/ten-proofs-oai.pdf<br/>- https://x.com/ChrisPeikert/status/2083534770403750025<br/>- https://bsky.app/profile/chrispeikert.bsky.social/post/3msp3boueis2z<br/>- https://en.wikipedia.org/wiki/Boolean_satisfiability_problem<br/>- https://knowyourmeme.com/memes/wordcel-shape-rotator-mathcel<br/>- Chen 2024: https://eprint.iacr.org/2024/555<br/>- https://eprint.iacr.org/2026/1630<br/>- https://eprint.iacr.org/2026/1693<br/>- CVP within n^(1/2-ɛ) -  : https://eprint.iacr.org/2026/1655<br/><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>The robots are at it again, and this time they’re solving, and breaking(?), math and cryptography! Things have been happening in the lattice corner including new leapfrogging complexity results in the closest vector problem (CVP), AND a possible poly-time quantum attack against the dihedral coset problem (DCP) that made everyone freak out for about a week (UPDATE: looks like it’s busted: https://eprint.iacr.org/2026/1693). ALSO, there was an important distinguisher attack against Classic McEliece, which on its face doesn’t sound like a big deal, unless you’re familiar with the track record of efficient distinguishers in the history of code-based cryptography… 😱<br/><br/>To help us make sense  of all this we are joined again by OG friend of the pod Chris Peikert! We had trouble with his audio but tried our best to fix it, apologies.<br/><br/></p><p>Transcript: https://securitycryptographywhatever.com/2026/08/26/ai-lattice-proofs-with-chris-peikert/</p><p><br/>Links:<br/>- https://openai.com/index/ten-advances-in-mathematics/<br/>- https://cdn.openai.com/pdf/ten-proofs-oai.pdf<br/>- https://x.com/ChrisPeikert/status/2083534770403750025<br/>- https://bsky.app/profile/chrispeikert.bsky.social/post/3msp3boueis2z<br/>- https://en.wikipedia.org/wiki/Boolean_satisfiability_problem<br/>- https://knowyourmeme.com/memes/wordcel-shape-rotator-mathcel<br/>- Chen 2024: https://eprint.iacr.org/2024/555<br/>- https://eprint.iacr.org/2026/1630<br/>- https://eprint.iacr.org/2026/1693<br/>- CVP within n^(1/2-ɛ) -  : https://eprint.iacr.org/2026/1655<br/><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/19707871-ai-lattice-proofs-with-chris-peikert.mp3" length="36549794" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19707871</guid>
    <pubDate>Wed, 26 Aug 2026 18:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19707871/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19707871/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19707871/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19707871/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/19707871/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="intro" />
  <psc:chapter start="3:57" title="chris polynomial" />
  <psc:chapter start="6:34" title="square root" />
  <psc:chapter start="9:23" title="code word" />
  <psc:chapter start="13:35" title="another problem" />
  <psc:chapter start="19:44" title="shortest zero vector" />
  <psc:chapter start="22:23" title="worst case" />
  <psc:chapter start="24:55" title="dihedral coset problem" />
  <psc:chapter start="28:20" title="What about FHE?" />
  <psc:chapter start="30:54" title="flashbacks to chen 2024" />
  <psc:chapter start="33:41" title="not-lattices (classic mceliece)" />
  <psc:chapter start="37:15" title="code-based distinguishers, search decision reductions" />
  <psc:chapter start="39:48" title="cross-discipline connections" />
  <psc:chapter start="42:56" title="doubly efficient PIR" />
  <psc:chapter start="46:19" title="post-quantum?" />
</psc:chapters>
    <itunes:duration>3044</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>6</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>An Odyssey of Lattice Cryptography with Mark Schultz-Wu</itunes:title>
    <title>An Odyssey of Lattice Cryptography with Mark Schultz-Wu</title>
    <itunes:summary><![CDATA[We invited Mark Schultz-Wu on the podcast to talk about the history of lattice cryptography. When lattices are explained in plain english, they are actually quite simple! I don't think any of us have ever seen Deirdre so happy. If you're watching the video version, there's a section that's 6.1 minutes long with no cuts and consists just of Deirdre vigorously agreeing with what Mark is saying while smiling. What a time to be alive. Anyway, we are hosting another happy hour in Vegas between Bla...]]></itunes:summary>
    <description><![CDATA[<p>We invited Mark Schultz-Wu on the podcast to talk about the history of lattice cryptography. When lattices are explained in plain english, they are actually quite simple! I don&apos;t think any of us have ever seen Deirdre so happy. If you&apos;re watching the video version, there&apos;s a section that&apos;s 6.1 minutes long with no cuts and consists just of Deirdre vigorously agreeing with what Mark is saying while smiling. What a time to be alive.</p><p>Anyway, we are hosting another happy hour in Vegas between Black Hat and DEF CON! It&apos;s sponsored by <a href='https://goteleport.com/'>Teleport</a>! Thank you to Teleport, and dear readers, you should go check them out. Check out our socials or the podcast site to register.</p><p>Transcript: https://securitycryptographywhatever.com/2026/07/27/lattices-with-mark-schultz-wu/</p><p>Links:</p><ul><li>Mark&apos;s IETF Post <a href='https://mailarchive.ietf.org/arch/msg/tls/HznE1IcCjstEjhh4M1p59qX1JlQ/'>https://mailarchive.ietf.org/arch/msg/tls/HznE1IcCjstEjhh4M1p59qX1JlQ/</a></li><li>NTRU <a href='https://en.wikipedia.org/wiki/NTRU'>https://en.wikipedia.org/wiki/NTRU</a></li><li>The original lattices are hard paper <a href='https://www.scirp.org/reference/referencespapers?referenceid=3401227'>https://www.scirp.org/reference/referencespapers?referenceid=3401227</a></li><li>The original LWE for cryptography paper <a href='https://arxiv.org/abs/2401.03703'>https://arxiv.org/abs/2401.03703</a></li><li>Entropic LWE <a href='https://eprint.iacr.org/2020/119'>https://eprint.iacr.org/2020/119</a></li><li>Dilithium round 3 submission: <a href='https://pq-crystals.org/dilithium/data/dilithium-specification-round3.pdf'>https://pq-crystals.org/dilithium/data/dilithium-specification-round3.pdf</a></li><li>Recent attacks on Classic McEliece: <a href='https://eprint.iacr.org/2024/1694'>https://eprint.iacr.org/2024/1694</a></li><li>Lectures on post-quantum cryptography from Alfred Menezes (an originator of elliptic curve cryptography) <a href='https://www.youtube.com/@cryptography101-alfred'>https://www.youtube.com/@cryptography101-alfred</a></li><li>Falcon <a href='https://csrc.nist.gov/csrc/media/Presentations/2024/falcon/images-media/prest-falcon-pqc2024.pdf'>https://csrc.nist.gov/csrc/media/Presentations/2024/falcon/images-media/prest-falcon-pqc2024.pdf</a></li><li>Regev: <a href='https://cims.nyu.edu/~regev/#research'>https://cims.nyu.edu/~regev/#research</a></li><li>Tightness in Proofs: <a href='https://eprint.iacr.org/2016/360.pdf'>https://eprint.iacr.org/2016/360.pdf</a><br/><br/><br/><br/></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We invited Mark Schultz-Wu on the podcast to talk about the history of lattice cryptography. When lattices are explained in plain english, they are actually quite simple! I don&apos;t think any of us have ever seen Deirdre so happy. If you&apos;re watching the video version, there&apos;s a section that&apos;s 6.1 minutes long with no cuts and consists just of Deirdre vigorously agreeing with what Mark is saying while smiling. What a time to be alive.</p><p>Anyway, we are hosting another happy hour in Vegas between Black Hat and DEF CON! It&apos;s sponsored by <a href='https://goteleport.com/'>Teleport</a>! Thank you to Teleport, and dear readers, you should go check them out. Check out our socials or the podcast site to register.</p><p>Transcript: https://securitycryptographywhatever.com/2026/07/27/lattices-with-mark-schultz-wu/</p><p>Links:</p><ul><li>Mark&apos;s IETF Post <a href='https://mailarchive.ietf.org/arch/msg/tls/HznE1IcCjstEjhh4M1p59qX1JlQ/'>https://mailarchive.ietf.org/arch/msg/tls/HznE1IcCjstEjhh4M1p59qX1JlQ/</a></li><li>NTRU <a href='https://en.wikipedia.org/wiki/NTRU'>https://en.wikipedia.org/wiki/NTRU</a></li><li>The original lattices are hard paper <a href='https://www.scirp.org/reference/referencespapers?referenceid=3401227'>https://www.scirp.org/reference/referencespapers?referenceid=3401227</a></li><li>The original LWE for cryptography paper <a href='https://arxiv.org/abs/2401.03703'>https://arxiv.org/abs/2401.03703</a></li><li>Entropic LWE <a href='https://eprint.iacr.org/2020/119'>https://eprint.iacr.org/2020/119</a></li><li>Dilithium round 3 submission: <a href='https://pq-crystals.org/dilithium/data/dilithium-specification-round3.pdf'>https://pq-crystals.org/dilithium/data/dilithium-specification-round3.pdf</a></li><li>Recent attacks on Classic McEliece: <a href='https://eprint.iacr.org/2024/1694'>https://eprint.iacr.org/2024/1694</a></li><li>Lectures on post-quantum cryptography from Alfred Menezes (an originator of elliptic curve cryptography) <a href='https://www.youtube.com/@cryptography101-alfred'>https://www.youtube.com/@cryptography101-alfred</a></li><li>Falcon <a href='https://csrc.nist.gov/csrc/media/Presentations/2024/falcon/images-media/prest-falcon-pqc2024.pdf'>https://csrc.nist.gov/csrc/media/Presentations/2024/falcon/images-media/prest-falcon-pqc2024.pdf</a></li><li>Regev: <a href='https://cims.nyu.edu/~regev/#research'>https://cims.nyu.edu/~regev/#research</a></li><li>Tightness in Proofs: <a href='https://eprint.iacr.org/2016/360.pdf'>https://eprint.iacr.org/2016/360.pdf</a><br/><br/><br/><br/></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/19546410-an-odyssey-of-lattice-cryptography-with-mark-schultz-wu.mp3" length="55574469" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19546410</guid>
    <pubDate>Mon, 27 Jul 2026 03:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19546410/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19546410/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19546410/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19546410/transcript.vtt" type="text/vtt" />
    <itunes:duration>4629</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Trump&#39;s Golden Post-Quantum EO(s)</itunes:title>
    <title>Trump&#39;s Golden Post-Quantum EO(s)</title>
    <itunes:summary><![CDATA[The dear leader has actually bleated out some not-dumb executive orders (EOs) to accelerate adoption of post-quantum crypto for the US government! This looks to be in response to a flurry of advancements in quantum computing and quantum attack algorithms a few months ago. We cram legalize into our eyeballs— plus, ECDSA.fail!  Watch on YouTube: https://www.youtube.com/watch?v=7ZwQpN_F6P8  Transcript: https://securitycryptographywhatever.com/2026/07/02/trumps-golden-post-quantum-eos Links: - Th...]]></itunes:summary>
    <description><![CDATA[<p>The dear leader has actually bleated out some not-dumb executive orders (EOs) to accelerate adoption of post-quantum crypto for the US government! This looks to be in response to a flurry of advancements in quantum computing and quantum attack algorithms a few months ago. We cram legalize into our eyeballs— plus, ECDSA.fail!<br/><br/>Watch on YouTube: https://www.youtube.com/watch?v=7ZwQpN_F6P8<br/><br/>Transcript: https://securitycryptographywhatever.com/2026/07/02/trumps-golden-post-quantum-eos</p><p>Links:</p><p>- The EO https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/<br/>- CNSA2 https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF<br/>- https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF<br/>- https://www.ecdsa.fail/<br/>- https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/<br/>- https://blog.cloudflare.com/post-quantum-roadmap/<br/>- https://blog.google/innovation-and-ai/technology/research/neutral-atom-quantum-computers/<br/>- https://en.wikipedia.org/wiki/FedRAMP<br/>- https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/<br/>- https://blog.trailofbits.com/2026/04/17/we-beat-googles-zero-knowledge-proof-of-quantum-cryptanalysis/<br/>- https://scottaaronson.blog/?p=9861<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>The dear leader has actually bleated out some not-dumb executive orders (EOs) to accelerate adoption of post-quantum crypto for the US government! This looks to be in response to a flurry of advancements in quantum computing and quantum attack algorithms a few months ago. We cram legalize into our eyeballs— plus, ECDSA.fail!<br/><br/>Watch on YouTube: https://www.youtube.com/watch?v=7ZwQpN_F6P8<br/><br/>Transcript: https://securitycryptographywhatever.com/2026/07/02/trumps-golden-post-quantum-eos</p><p>Links:</p><p>- The EO https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/<br/>- CNSA2 https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF<br/>- https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF<br/>- https://www.ecdsa.fail/<br/>- https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/<br/>- https://blog.cloudflare.com/post-quantum-roadmap/<br/>- https://blog.google/innovation-and-ai/technology/research/neutral-atom-quantum-computers/<br/>- https://en.wikipedia.org/wiki/FedRAMP<br/>- https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/<br/>- https://blog.trailofbits.com/2026/04/17/we-beat-googles-zero-knowledge-proof-of-quantum-cryptanalysis/<br/>- https://scottaaronson.blog/?p=9861<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/19434683-trump-s-golden-post-quantum-eo-s.mp3" length="40789215" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19434683</guid>
    <pubDate>Thu, 02 Jul 2026 02:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19434683/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19434683/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19434683/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19434683/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/19434683/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="init" />
  <psc:chapter start="0:40" title="Emergency PQC Executive Order" />
  <psc:chapter start="3:14" title="wee-ooo wee-ooo quantum computers" />
  <psc:chapter start="11:31" title="FIPS CMVP overhaul" />
  <psc:chapter start="15:15" title="2030, 2031" />
  <psc:chapter start="23:18" title="Fixing CMVP 💀" />
  <psc:chapter start="31:59" title="Public PKI and PQ Certificates" />
  <psc:chapter start="34:26" title="FIPS Validation Bottlenecks" />
  <psc:chapter start="41:21" title="Quantum Computing EO" />
  <psc:chapter start="44:51" title="ECDSA.fail" />
  <psc:chapter start="55:31" title="fin" />
</psc:chapters>
    <itunes:duration>3397</itunes:duration>
    <itunes:keywords>security,cryptography,post-quantum,nist,cmvp,cavp,fedramp</itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Facing the Vulnpocalypse with lcamtuf</itunes:title>
    <title>Facing the Vulnpocalypse with lcamtuf</title>
    <itunes:summary><![CDATA[We talk to Michał Zalewski (lcamtuf) about the vulnpocalypse and if we even need fuzzers anymore. This episode may be export controlled at a future date. Watch on YouTube: https://www.youtube.com/watch?v=uI9CSgB4p9o Transcript: https://securitycryptographywhatever.com/2026/06/14/facing-the-vulnpocalypse-with-lcamtuf https://github.com/google/aflhttps://www.reddit.com/r/claude/comments/1tqtenf/anthropic_said_today_that_mythos_is_coming_to_all/https://github.com/google/clusterfuzzhttps://en.wik...]]></itunes:summary>
    <description><![CDATA[<p>We talk to Michał Zalewski (lcamtuf) about the vulnpocalypse and if we even need fuzzers anymore. This episode may be export controlled at a future date.</p><p>Watch on YouTube: https://www.youtube.com/watch?v=<a href='https://youtu.be/dEKBHI3rodY'>uI9CSgB4p9o</a></p><p>Transcript: https://securitycryptographywhatever.com/2026/06/14/facing-the-vulnpocalypse-with-lcamtuf</p><ul><li><a href='https://github.com/google/afl'>https://github.com/google/afl</a></li><li><a href='https://www.reddit.com/r/claude/comments/1tqtenf/anthropic_said_today_that_mythos_is_coming_to_all/'>https://www.reddit.com/r/claude/comments/1tqtenf/anthropic_said_today_that_mythos_is_coming_to_all/</a></li><li><a href='https://github.com/google/clusterfuzz'>https://github.com/google/clusterfuzz</a></li><li><a href='https://en.wikipedia.org/wiki/Jevons_paradox'>https://en.wikipedia.org/wiki/Jevons_paradox</a></li><li><a href='https://en.wikipedia.org/wiki/XZ_Utils_backdoor'>https://en.wikipedia.org/wiki/XZ_Utils_backdoor</a></li><li><a href='https://en.wikipedia.org/wiki/Brighton_hotel_bombing'>https://en.wikipedia.org/wiki/Brighton_hotel_bombing</a></li><li><a href='https://curl.se/'>https://curl.se/</a></li><li><a href='https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/025_sack.patch.sig'>https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/025_sack.patch.sig</a></li><li><a href='https://www.wired.com/story/last-pass-vulnerability-password-safe/'>https://www.wired.com/story/last-pass-vulnerability-password-safe/</a></li><li><a href='https://nostarch.com/tangledweb'>https://nostarch.com/tangledweb</a></li><li><a href='https://nostarch.com/silence.htm'>https://nostarch.com/silence.htm</a></li><li><a href='https://nostarch.com/practical-doomsday'>https://nostarch.com/practical-doomsday</a></li><li><a href='https://nostarch.com/secret-life-of-circuits'>https://nostarch.com/secret-life-of-circuits</a></li><li><a href='https://www.youtube.com/c/3blue1brown'>https://www.youtube.com/c/3blue1brown</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We talk to Michał Zalewski (lcamtuf) about the vulnpocalypse and if we even need fuzzers anymore. This episode may be export controlled at a future date.</p><p>Watch on YouTube: https://www.youtube.com/watch?v=<a href='https://youtu.be/dEKBHI3rodY'>uI9CSgB4p9o</a></p><p>Transcript: https://securitycryptographywhatever.com/2026/06/14/facing-the-vulnpocalypse-with-lcamtuf</p><ul><li><a href='https://github.com/google/afl'>https://github.com/google/afl</a></li><li><a href='https://www.reddit.com/r/claude/comments/1tqtenf/anthropic_said_today_that_mythos_is_coming_to_all/'>https://www.reddit.com/r/claude/comments/1tqtenf/anthropic_said_today_that_mythos_is_coming_to_all/</a></li><li><a href='https://github.com/google/clusterfuzz'>https://github.com/google/clusterfuzz</a></li><li><a href='https://en.wikipedia.org/wiki/Jevons_paradox'>https://en.wikipedia.org/wiki/Jevons_paradox</a></li><li><a href='https://en.wikipedia.org/wiki/XZ_Utils_backdoor'>https://en.wikipedia.org/wiki/XZ_Utils_backdoor</a></li><li><a href='https://en.wikipedia.org/wiki/Brighton_hotel_bombing'>https://en.wikipedia.org/wiki/Brighton_hotel_bombing</a></li><li><a href='https://curl.se/'>https://curl.se/</a></li><li><a href='https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/025_sack.patch.sig'>https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/025_sack.patch.sig</a></li><li><a href='https://www.wired.com/story/last-pass-vulnerability-password-safe/'>https://www.wired.com/story/last-pass-vulnerability-password-safe/</a></li><li><a href='https://nostarch.com/tangledweb'>https://nostarch.com/tangledweb</a></li><li><a href='https://nostarch.com/silence.htm'>https://nostarch.com/silence.htm</a></li><li><a href='https://nostarch.com/practical-doomsday'>https://nostarch.com/practical-doomsday</a></li><li><a href='https://nostarch.com/secret-life-of-circuits'>https://nostarch.com/secret-life-of-circuits</a></li><li><a href='https://www.youtube.com/c/3blue1brown'>https://www.youtube.com/c/3blue1brown</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/19346543-facing-the-vulnpocalypse-with-lcamtuf.mp3" length="51492748" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19346543</guid>
    <pubDate>Mon, 15 Jun 2026 04:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19346543/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19346543/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19346543/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/19346543/transcript.vtt" type="text/vtt" />
    <itunes:duration>4289</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>AI Finds Vulns You Can&#39;t With Nicholas Carlini</itunes:title>
    <title>AI Finds Vulns You Can&#39;t With Nicholas Carlini</title>
    <itunes:summary><![CDATA[Returning champion Nicholas Carlini comes back to talk about using Claude for vulnerability research, and the current vulnpocalypse. It's all very high-brow stuff, and the gang learns some bitter lessons. Watch on YouTube: https://www.youtube.com/watch?v=_IDbFLu9Ug8 Transcript: https://securitycryptographywhatever.com/2026/03/25/ai-bug-finding/  Links:  - https://red.anthropic.com/2026/zero-days/ - https://unpromptedcon.org/ - Black-hat LLMs   - https://red.anthropic.com/2026/firefox/   ...]]></itunes:summary>
    <description><![CDATA[<p>Returning champion Nicholas Carlini comes back to talk about using Claude for vulnerability research, and the current vulnpocalypse. It&apos;s all very high-brow stuff, and the gang learns some bitter lessons.</p><p>Watch on YouTube: https://www.youtube.com/watch?v=<a href='https://youtu.be/dEKBHI3rodY'>_IDbFLu9Ug8</a></p><p>Transcript: https://securitycryptographywhatever.com/2026/03/25/ai-bug-finding/<br/><br/>Links:<br/><br/>- https://red.anthropic.com/2026/zero-days/<br/>- https://unpromptedcon.org/<br/>- Black-hat LLMs  <br/>- https://red.anthropic.com/2026/firefox/</p><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Returning champion Nicholas Carlini comes back to talk about using Claude for vulnerability research, and the current vulnpocalypse. It&apos;s all very high-brow stuff, and the gang learns some bitter lessons.</p><p>Watch on YouTube: https://www.youtube.com/watch?v=<a href='https://youtu.be/dEKBHI3rodY'>_IDbFLu9Ug8</a></p><p>Transcript: https://securitycryptographywhatever.com/2026/03/25/ai-bug-finding/<br/><br/>Links:<br/><br/>- https://red.anthropic.com/2026/zero-days/<br/>- https://unpromptedcon.org/<br/>- Black-hat LLMs  <br/>- https://red.anthropic.com/2026/firefox/</p><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/18909957-ai-finds-vulns-you-can-t-with-nicholas-carlini.mp3" length="54740309" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18909957</guid>
    <pubDate>Wed, 25 Mar 2026 23:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18909957/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18909957/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18909957/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18909957/transcript.vtt" type="text/vtt" />
    <itunes:duration>4560</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Standardizing Pure PQC</itunes:title>
    <title>Standardizing Pure PQC</title>
    <itunes:summary><![CDATA[Standardizing cryptography involves a lot of opinions. Luckily, the gamer presidents are on it. Come on, you all know the drill. This is the last time I do this.  "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian) ]]></itunes:summary>
    <description><![CDATA[<p>Standardizing cryptography involves a lot of opinions. Luckily, the gamer presidents are on it. Come on, you all know the drill.</p><p>This is the last time I do this.</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Standardizing cryptography involves a lot of opinions. Luckily, the gamer presidents are on it. Come on, you all know the drill.</p><p>This is the last time I do this.</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/18819288-standardizing-pure-pqc.mp3" length="5956661" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18819288</guid>
    <pubDate>Mon, 09 Mar 2026 20:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18819288/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18819288/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18819288/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18819288/transcript.vtt" type="text/vtt" />
    <itunes:duration>494</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor</itunes:title>
    <title>Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor</title>
    <itunes:summary><![CDATA[The Python cryptography module, pyca/cryptography, has mostly been a sane wrapper around a pile of C, so that users get performant cryptography on the many, many platforms Python targets. Therefore its maintainers, Alex Gaynor and Paul Kehrer, have become intimately familiar with OpenSSL. Recently, they declared that after many years of trying to make it work, they announced pyca/cryptography would be moving away from OpenSSL when supporting new functionality and exploring adding other backen...]]></itunes:summary>
    <description><![CDATA[<p>The Python cryptography module, <em>pyca/cryptography</em>, has mostly been a sane wrapper around a pile of C, so that users get performant cryptography on the many, many platforms Python targets. Therefore its maintainers, Alex Gaynor and Paul Kehrer, have become intimately familiar with OpenSSL. Recently, they declared that after many years of trying to make it work, they announced <em>pyca/cryptography</em> would be moving away from OpenSSL when supporting new functionality and exploring adding other backends instead. We invited them on to tell us about what has happened to OpenSSL, even after the investments and improvements following Heartbleed. No guests on this pod represent anyone besides themselves.</p><p>Watch on YouTube: https://www.youtube.com/watch?v=dEKBHI3rodY</p><p><br/>Transcript: https://securitycryptographywhatever.com/2026/02/01/python-cryptography-breaks-up-with-openssl<br/><br/>Links:<br/>- https://cryptography.io/en/latest/statements/state-of-openssl/<br/>- Py Cryptography: https://cryptography.io<br/>- https://archive.openssl-conference.org/2025/presentations/Alex_Gaynor_Paul_Kehrer_The_Python_Cryptographic_Authoritys_OpenSSL_Experience.pdf<br/>- https://securitycryptographywhatever.com/2025/08/16/alex-gaynor/<br/>- https://packages.gentoo.org/packages/media-libs/libsdl<br/>- https://www.youtube.com/watch?v=RUIguklWwx0<br/>- https://datatracker.ietf.org/doc/rfc9180/<br/>- https://docs.openssl.org/3.3/man3/OSSL_PARAM/<br/>- https://openssl.foundation/<br/>- https://github.com/openssl/openssl/issues/17064<br/>- https://www.feistyduck.com/newsletter/issue_132_openssl_performance_still_under_scrutiny<br/>- https://github.com/topazproject/topaz<br/>- https://github.com/actions/runner/issues/1069<br/>- https://crystalhotsauce.com/<br/>- https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467<br/>- https://en.wikipedia.org/wiki/Ship_of_Theseus<br/>- https://boringssl.googlesource.com/boringssl/+/aa202db1d7091b88b80f0a58c630c5c1aefc817d<br/>- https://www.ibm.com/products/open-sdk-for-rust-aix<br/>- https://dadrian.io/blog/posts/corporate-support-xz/<br/>- https://peps.python.org/<br/>- https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ed448/<br/>- https://go.dev/blog/fips140<br/>- https://dadrian.io/blog/posts/roll-your-own-crypto/<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>The Python cryptography module, <em>pyca/cryptography</em>, has mostly been a sane wrapper around a pile of C, so that users get performant cryptography on the many, many platforms Python targets. Therefore its maintainers, Alex Gaynor and Paul Kehrer, have become intimately familiar with OpenSSL. Recently, they declared that after many years of trying to make it work, they announced <em>pyca/cryptography</em> would be moving away from OpenSSL when supporting new functionality and exploring adding other backends instead. We invited them on to tell us about what has happened to OpenSSL, even after the investments and improvements following Heartbleed. No guests on this pod represent anyone besides themselves.</p><p>Watch on YouTube: https://www.youtube.com/watch?v=dEKBHI3rodY</p><p><br/>Transcript: https://securitycryptographywhatever.com/2026/02/01/python-cryptography-breaks-up-with-openssl<br/><br/>Links:<br/>- https://cryptography.io/en/latest/statements/state-of-openssl/<br/>- Py Cryptography: https://cryptography.io<br/>- https://archive.openssl-conference.org/2025/presentations/Alex_Gaynor_Paul_Kehrer_The_Python_Cryptographic_Authoritys_OpenSSL_Experience.pdf<br/>- https://securitycryptographywhatever.com/2025/08/16/alex-gaynor/<br/>- https://packages.gentoo.org/packages/media-libs/libsdl<br/>- https://www.youtube.com/watch?v=RUIguklWwx0<br/>- https://datatracker.ietf.org/doc/rfc9180/<br/>- https://docs.openssl.org/3.3/man3/OSSL_PARAM/<br/>- https://openssl.foundation/<br/>- https://github.com/openssl/openssl/issues/17064<br/>- https://www.feistyduck.com/newsletter/issue_132_openssl_performance_still_under_scrutiny<br/>- https://github.com/topazproject/topaz<br/>- https://github.com/actions/runner/issues/1069<br/>- https://crystalhotsauce.com/<br/>- https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467<br/>- https://en.wikipedia.org/wiki/Ship_of_Theseus<br/>- https://boringssl.googlesource.com/boringssl/+/aa202db1d7091b88b80f0a58c630c5c1aefc817d<br/>- https://www.ibm.com/products/open-sdk-for-rust-aix<br/>- https://dadrian.io/blog/posts/corporate-support-xz/<br/>- https://peps.python.org/<br/>- https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ed448/<br/>- https://go.dev/blog/fips140<br/>- https://dadrian.io/blog/posts/roll-your-own-crypto/<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/18606744-python-cryptography-breaks-up-with-openssl-with-paul-kehrer-and-alex-gaynor.mp3" length="52318206" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18606744</guid>
    <pubDate>Sun, 01 Feb 2026 23:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18606744/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18606744/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18606744/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18606744/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/18606744/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="intro" />
  <psc:chapter start="1:03" title="The Python Cryptographic Authority" />
  <psc:chapter start="4:38" title="fckin OpenSSL" />
  <psc:chapter start="9:50" title="OpenSSL 3" />
  <psc:chapter start="23:17" title="OSSL_PARAM" />
  <psc:chapter start="31:16" title="testing and continuous integration" />
  <psc:chapter start="34:48" title="GitHub Actions, target architectures" />
  <psc:chapter start="35:16" title="flappy tests" />
  <psc:chapter start="35:47" title="Intel SDE, rigorous, stable architecture-dependent impls" />
  <psc:chapter start="38:21" title="Community Maintained Assembly and Bug Handling" />
  <psc:chapter start="39:07" title="Memory Safety and Rust in Cryptography" />
  <psc:chapter start="39:59" title="Recent OpenSSL Vulnerabilities" />
  <psc:chapter start="40:09" title="having the judgment to not write large bits of C code" />
  <psc:chapter start="41:18" title="BoringSSL vs OpenSSL" />
  <psc:chapter start="42:32" title="SSL of Theseus-ying OpenSSL with Rust code" />
  <psc:chapter start="43:38" title="PKCS and P7" />
  <psc:chapter start="47:56" title="there&#39;s Rust in my reptile eggs" />
  <psc:chapter start="57:20" title="The Python Cryptographic Authority, 10 Years In" />
  <psc:chapter start="1:02:55" title="Moving Away from OpenSSL" />
  <psc:chapter start="1:09:38" title="FIPS validating non-C code" />
  <psc:chapter start="1:11:50" title="👋" />
</psc:chapters>
    <itunes:duration>4358</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>The IACR Can&#39;t Decrypt with Matt Bernhard</itunes:title>
    <title>The IACR Can&#39;t Decrypt with Matt Bernhard</title>
    <itunes:summary><![CDATA[The International Association of Cryptologic Research held their regular election using secure voting software called Helios…and lost the keys to decrypt the results, leaving them with no choice but to throw out the vote and call a new election. Hilarity ensues. We welcome special guest Matt Bernhard who actually works on secure voting systems to explain which bits are homomorphically additive or not.   Watch on YouTube: https://www.youtube.com/watch?v=euw_yqAQFI8  Transcript: https://securit...]]></itunes:summary>
    <description><![CDATA[<p>The International Association of Cryptologic Research held their regular election using secure voting software called Helios…and lost the keys to decrypt the results, leaving them with no choice but to throw out the vote and call a new election. Hilarity ensues. We welcome special guest Matt Bernhard who actually works on secure voting systems to explain which bits are homomorphically additive or not.<br/><br/></p><p>Watch on YouTube: https://www.youtube.com/watch?v=euw_yqAQFI8<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/12/30/iacr-helios<br/><br/>Links:</p><p>- NYT: https://www.nytimes.com/2025/11/21/world/cryptography-group-lost-election-results.html<br/>- IACR Memo: https://www.iacr.org/news/item/27138<br/>- https://www.iacr.org/elections/<br/>- https://vote.heliosvoting.org/faq<br/>- https://github.com/Election-Tech-Initiative/electionguard<br/>- https://www.usenix.org/legacy/events/sec08/tech/full_papers/adida/adida.pdf<br/>- https://www.iacr.org/elections/eVoting/about-helios.html<br/>- https://www.iacr.org/elections/eVoting/<br/>- https://crypto.ethz.ch/publications/files/CrGeSc97b.pdf<br/>- https://electionguard.vote/<br/>- https://eprint.iacr.org/2025/1901<br/>- https://freeandfair.us/blog/open-free-election-technology/<br/>- https://www.starvoting.org/<br/>- https://mbernhard.com/<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>The International Association of Cryptologic Research held their regular election using secure voting software called Helios…and lost the keys to decrypt the results, leaving them with no choice but to throw out the vote and call a new election. Hilarity ensues. We welcome special guest Matt Bernhard who actually works on secure voting systems to explain which bits are homomorphically additive or not.<br/><br/></p><p>Watch on YouTube: https://www.youtube.com/watch?v=euw_yqAQFI8<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/12/30/iacr-helios<br/><br/>Links:</p><p>- NYT: https://www.nytimes.com/2025/11/21/world/cryptography-group-lost-election-results.html<br/>- IACR Memo: https://www.iacr.org/news/item/27138<br/>- https://www.iacr.org/elections/<br/>- https://vote.heliosvoting.org/faq<br/>- https://github.com/Election-Tech-Initiative/electionguard<br/>- https://www.usenix.org/legacy/events/sec08/tech/full_papers/adida/adida.pdf<br/>- https://www.iacr.org/elections/eVoting/about-helios.html<br/>- https://www.iacr.org/elections/eVoting/<br/>- https://crypto.ethz.ch/publications/files/CrGeSc97b.pdf<br/>- https://electionguard.vote/<br/>- https://eprint.iacr.org/2025/1901<br/>- https://freeandfair.us/blog/open-free-election-technology/<br/>- https://www.starvoting.org/<br/>- https://mbernhard.com/<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/18434266-the-iacr-can-t-decrypt-with-matt-bernhard.mp3" length="40937003" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18434266</guid>
    <pubDate>Tue, 30 Dec 2025 21:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18434266/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18434266/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18434266/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18434266/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/18434266/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="hello" />
  <psc:chapter start="0:30" title="iacr elections" />
  <psc:chapter start="1:03" title="this academic association actually puts on multiple successful conferences" />
  <psc:chapter start="2:13" title="Helios" />
  <psc:chapter start="3:31" title="crypto voting&#39;s hard" />
  <psc:chapter start="9:41" title="wat do Helios" />
  <psc:chapter start="29:19" title="no really voting online is hard" />
  <psc:chapter start="30:08" title="fax me" />
  <psc:chapter start="31:53" title="voting by blockchain, without the blockchain" />
  <psc:chapter start="32:57" title="the homomorphic specifics of Helios" />
  <psc:chapter start="34:45" title="privacy in voting" />
  <psc:chapter start="42:06" title="yet again reducing problems to key management" />
  <psc:chapter start="45:18" title="Election Guard" />
  <psc:chapter start="45:27" title="other verifiable voting systems" />
  <psc:chapter start="47:09" title="secure voting SDK" />
  <psc:chapter start="50:17" title="secure voting involves D20s" />
  <psc:chapter start="55:06" title="everything is easier with a spot of threshold cryptography" />
</psc:chapters>
    <itunes:duration>3409</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Apple’s Memory Integrity Enforcement</itunes:title>
    <title>Apple’s Memory Integrity Enforcement</title>
    <itunes:summary><![CDATA[Apple announced its new suite of memory security improvements from the top of the stack all the way to the bottom, so we dug through what they did and how they did it (performantly).   Watch on YouTube: https://www.youtube.com/watch?v=9FJwOI2PliU  Transcript: https://securitycryptographywhatever.com/2025/10/31/apple-mie  Links:  - https://security.apple.com/blog/memory-integrity-enforcement/ - Secure Page Table Monitor and Trusted Execution Monitor: https://support.apple.com/guide/securi...]]></itunes:summary>
    <description><![CDATA[<p>Apple announced its new suite of memory security improvements from the top of the stack all the way to the bottom, so we dug through what they did and how they did it (performantly). <br/><br/>Watch on YouTube: https://www.youtube.com/watch?v=9FJwOI2PliU<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/10/31/apple-mie<br/><br/>Links:<br/><br/>- https://security.apple.com/blog/memory-integrity-enforcement/<br/>- Secure Page Table Monitor and Trusted Execution Monitor: https://support.apple.com/guide/security/operating-system-integrity-sec8b776536b/1/web/1#secd022396fb<br/>- https://security.apple.com/blog/towards-the-next-generation-of-xnu-memory-safety/<br/>- https://developer.apple.com/documentation/xcode/adopting-type-aware-memory-allocation<br/>- https://security.apple.com/blog/what-if-we-had-sockpuppet-in-ios16/<br/>- https://arxiv.org/pdf/2510.09272<br/>- https://googleprojectzero.blogspot.com/2023/11/first-handset-with-mte-on-market.html<br/>- https://developer.apple.com/documentation/xcode/adopting-type-aware-memory-allocation<br/>- https://arxiv.org/pdf/2510.09272<br/>- https://spectreattack.com/spectre.pdf<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Apple announced its new suite of memory security improvements from the top of the stack all the way to the bottom, so we dug through what they did and how they did it (performantly). <br/><br/>Watch on YouTube: https://www.youtube.com/watch?v=9FJwOI2PliU<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/10/31/apple-mie<br/><br/>Links:<br/><br/>- https://security.apple.com/blog/memory-integrity-enforcement/<br/>- Secure Page Table Monitor and Trusted Execution Monitor: https://support.apple.com/guide/security/operating-system-integrity-sec8b776536b/1/web/1#secd022396fb<br/>- https://security.apple.com/blog/towards-the-next-generation-of-xnu-memory-safety/<br/>- https://developer.apple.com/documentation/xcode/adopting-type-aware-memory-allocation<br/>- https://security.apple.com/blog/what-if-we-had-sockpuppet-in-ios16/<br/>- https://arxiv.org/pdf/2510.09272<br/>- https://googleprojectzero.blogspot.com/2023/11/first-handset-with-mte-on-market.html<br/>- https://developer.apple.com/documentation/xcode/adopting-type-aware-memory-allocation<br/>- https://arxiv.org/pdf/2510.09272<br/>- https://spectreattack.com/spectre.pdf<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/18109334-apple-s-memory-integrity-enforcement.mp3" length="40881060" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18109334</guid>
    <pubDate>Fri, 31 Oct 2025 01:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18109334/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18109334/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18109334/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/18109334/transcript.vtt" type="text/vtt" />
    <itunes:duration>3405</itunes:duration>
    <itunes:keywords>security,memory,apple,mie,mte,vulns</itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Stop Using Encrypted Email with William Woodruff</itunes:title>
    <title>Stop Using Encrypted Email with William Woodruff</title>
    <itunes:summary><![CDATA[There was a bug in an OpenPGP library which finally gave us an excuse to tear encrypted email via PGP to shreds. Our special guest William Woodruff joined us to help explain the vuln and indulge our gnashing of teeth on why email was never meant to be encrypted and how other modern tools do the job much, much better.  Watch on YouTube: https://www.youtube.com/watch?v=IoL3LfIozJo  Transcript: https://securitycryptographywhatever.com/2025/08/22/stop-using-encrypted-email-with-william-woodruff  ...]]></itunes:summary>
    <description><![CDATA[<p>There was a bug in an OpenPGP library which finally gave us an excuse to tear encrypted email via PGP to shreds. Our special guest William Woodruff joined us to help explain the vuln and indulge our gnashing of teeth on why email was never meant to be encrypted and how other modern tools do the job much, much better.<br/><br/>Watch on YouTube: https://www.youtube.com/watch?v=IoL3LfIozJo<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/08/22/stop-using-encrypted-email-with-william-woodruff<br/><br/>Links:<br/><br/>- William Woodruff: https://yossarian.net/<br/>- https://www.latacora.com/blog/2020/02/19/stop-using-encrypted/<br/>- https://www.rfc-editor.org/rfc/rfc4880<br/>- https://codeanlabs.com/blog/research/cve-2025-47934-spoofing-openpgp-js-signatures/<br/>- https://www.mailpile.is/blog/2014-10-07_Some_Thoughts_on_GnuPG.html<br/>- https://www.rfc-editor.org/rfc/rfc9580.html<br/>- https://www.tumblr.com/accidentallyquadratic<br/>- https://www.w3.org/TR/xmldsig-core/<br/>- https://support.yubico.com/hc/en-us/articles/360013790259-Using-Your-YubiKey-with-OpenPGP<br/>- https://www.rfc-editor.org/rfc/rfc9580.html#name-signature-packet-type-id-2<br/>- https://www.rfc-editor.org/rfc/rfc9580.html#name-key-derivation-function<br/>- https://en.wikipedia.org/wiki/S/MIME<br/>- https://delta.chat<br/>- https://signal.org/blog/the-ecosystem-is-moving/<br/>- https://phakeobj.netlify.app/posts/gigacage/<br/>- https://x.com/dakami<br/><br/></p><p>-----BEGIN PGP MESSAGE-----<br/>U2FsdGVkX1/OF+EynrukxZnSAXwgksTGSIkQ6s4X9Ns7JgQ2ZymeQAp8uD09MtkJ<br/>ce5HOKcjhUkZOMbJl3I5iOcPgSxCGG8KccNXcY6msdAD3pdlmR5cWJpn6+qGwqvo<br/>KCsj+DYwFW6tltLBXP/cdnh9z8ktRXqfwQW+uhB5Zcaw28pzmNz/rA0cb0cLGiaX<br/>uxp9A0iWhwf2gFpUSiIJyXGLJAc8eeI1LXfISXi7IkowDMp4x+iDbOlrR0d6zCkp<br/>IKpNGReokcWhUrlGVONiVUrApZS2fvxQoHgaIvwLl5FM1WdrbQIV41DB+rgtZJhE<br/>NSgMkhQ0y1bBAOM25ykRjC/UUS/q0ddXz1ThGi6vRIp4/8vkqOsEXHv5M1oT9FQT<br/>UGK3zyffq0FqGBFj6kwVZ0X0JQFmtydZKhSYEPE9s4mcfvxKNQsySK7wlxMerKrf<br/>f9ZxOR7rHjE3IfqtoizX8EH+MYy2lRCoCKeLbZd0G1LcVhBhRpoXfqL2IboAWqT+<br/>U8R2eyts7qiNuWQUtmCzKNmaJMS+1M+pVN5ZXAdSqK2OJVJZgO8Ie7q4HVZeAd3G<br/>HzP7owf+VerCguOYN41cxGle1QpeFi0xcYHNna1bgbodFZ8eGDOq5yCuvmQa04Xy<br/>J4vRv7xcp/v16CniL1rN6KhnzdW2gLky8depnYyhm8NvdMFETA6K6eIYm1roD+C2<br/>wwOOKRxUpTI54ov+HYDDU+HUmpFykSesHQJ75o9m0w7V2kR/+E46olFMhHo8JWnL<br/>NsGd5QlD/fyedMXHAjimXuFk/YFnwa1lh4XwSwYm+c8ZnIfrS6oEEdUSwXMCwwVT<br/>7/tMw+ab0YRsx19hBLS41oxMz+DCah+/KDMEHv0I+VxaCH8ZfaKD4tRhduSvcWkn<br/>Nat3Xp8/MAmO5xN1U8s1dFvrlnt+yqDz7Wn0kVDiax2dTJVgftetqOkoSVvGdMex<br/>9K0ILUUMEpHYBISIaAc7NjoG4BieSeK7wuzBXdhHutVZVKp2ty+mAd8xPlrmemsX<br/>lzBhV/kcmF4rcG4eqoWcKpZQY8ZUDufwhIcNqIZEA+wQoKbmBQCR/NradwUrCAIs<br/>AQFMVhSYmr7ffA6Ty0twSWeVMDQmxdW+6gKA3EiTAJkFXPpdkhBUzuZHC7Eeph7D<br/>F0Ks8Vu/wzOhNsd2s2wYYF6Dl3xctcOj7eMw8VS1HtExszulM57TnqTDaLGPcX6o<br/>m8NORwMEtQrCbJd/fdmoNPN/cXzLPHQj3qVZ0F50iNec6zSnmBLIRX4SAYOqzN/2<br/>icvr98Caa1oX3pUlm9W2Hcz30SXJDxOf+mqH6zL4QTAMs3/K9OkaO9nmyPelwoCw<br/>VI1q/PsMpqQhGikdM5hrzg6IcEOg5zpLB6N+wqkcGyXFzI2gSQTWYOv4thrIxPY5<br/>G9yNi4dhU+2+KJCa6aoPyAlyc41Yd3ARTeahHEjtdj6PcueRPQdVm+qWCRp09bp3<br/>oic7ljzMVrPRgdbRrzFyEAIhN9Fi4QZ08/yCLEt/BPG+N8j0cZixoj54SKi07uSO<br/>WRDrzGvgSegGCCIFKjAsq9ay0sBm61XLcZqdtj57NpNzd/y/yFYvjEQLyyn8VnFA<br/>RwOaM3zjrufNC+kYVkHCYzfvu+JopScZjMiuBXI9v8OTOXlj+Ai97bnftwmpQ263<br/>5vyearRHCNATFNa96Sxd1cLjV+ECUlD4hAZQPyel8groXsyjKaMxoOkaZjG/5MDQ<br/>8KPtes32kjTmneyLSzrUaAD0F4l/iltBXzDNiT6BHD7HJmERbdkoab7+DC1hxxC1<br/>VuOHOX+G/U5NUNjxAercuFOY6kgAH5HM+woGjLUsoc5LESqyPdddeg==<br/>-----END PGP MESSAGE-----</p><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>There was a bug in an OpenPGP library which finally gave us an excuse to tear encrypted email via PGP to shreds. Our special guest William Woodruff joined us to help explain the vuln and indulge our gnashing of teeth on why email was never meant to be encrypted and how other modern tools do the job much, much better.<br/><br/>Watch on YouTube: https://www.youtube.com/watch?v=IoL3LfIozJo<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/08/22/stop-using-encrypted-email-with-william-woodruff<br/><br/>Links:<br/><br/>- William Woodruff: https://yossarian.net/<br/>- https://www.latacora.com/blog/2020/02/19/stop-using-encrypted/<br/>- https://www.rfc-editor.org/rfc/rfc4880<br/>- https://codeanlabs.com/blog/research/cve-2025-47934-spoofing-openpgp-js-signatures/<br/>- https://www.mailpile.is/blog/2014-10-07_Some_Thoughts_on_GnuPG.html<br/>- https://www.rfc-editor.org/rfc/rfc9580.html<br/>- https://www.tumblr.com/accidentallyquadratic<br/>- https://www.w3.org/TR/xmldsig-core/<br/>- https://support.yubico.com/hc/en-us/articles/360013790259-Using-Your-YubiKey-with-OpenPGP<br/>- https://www.rfc-editor.org/rfc/rfc9580.html#name-signature-packet-type-id-2<br/>- https://www.rfc-editor.org/rfc/rfc9580.html#name-key-derivation-function<br/>- https://en.wikipedia.org/wiki/S/MIME<br/>- https://delta.chat<br/>- https://signal.org/blog/the-ecosystem-is-moving/<br/>- https://phakeobj.netlify.app/posts/gigacage/<br/>- https://x.com/dakami<br/><br/></p><p>-----BEGIN PGP MESSAGE-----<br/>U2FsdGVkX1/OF+EynrukxZnSAXwgksTGSIkQ6s4X9Ns7JgQ2ZymeQAp8uD09MtkJ<br/>ce5HOKcjhUkZOMbJl3I5iOcPgSxCGG8KccNXcY6msdAD3pdlmR5cWJpn6+qGwqvo<br/>KCsj+DYwFW6tltLBXP/cdnh9z8ktRXqfwQW+uhB5Zcaw28pzmNz/rA0cb0cLGiaX<br/>uxp9A0iWhwf2gFpUSiIJyXGLJAc8eeI1LXfISXi7IkowDMp4x+iDbOlrR0d6zCkp<br/>IKpNGReokcWhUrlGVONiVUrApZS2fvxQoHgaIvwLl5FM1WdrbQIV41DB+rgtZJhE<br/>NSgMkhQ0y1bBAOM25ykRjC/UUS/q0ddXz1ThGi6vRIp4/8vkqOsEXHv5M1oT9FQT<br/>UGK3zyffq0FqGBFj6kwVZ0X0JQFmtydZKhSYEPE9s4mcfvxKNQsySK7wlxMerKrf<br/>f9ZxOR7rHjE3IfqtoizX8EH+MYy2lRCoCKeLbZd0G1LcVhBhRpoXfqL2IboAWqT+<br/>U8R2eyts7qiNuWQUtmCzKNmaJMS+1M+pVN5ZXAdSqK2OJVJZgO8Ie7q4HVZeAd3G<br/>HzP7owf+VerCguOYN41cxGle1QpeFi0xcYHNna1bgbodFZ8eGDOq5yCuvmQa04Xy<br/>J4vRv7xcp/v16CniL1rN6KhnzdW2gLky8depnYyhm8NvdMFETA6K6eIYm1roD+C2<br/>wwOOKRxUpTI54ov+HYDDU+HUmpFykSesHQJ75o9m0w7V2kR/+E46olFMhHo8JWnL<br/>NsGd5QlD/fyedMXHAjimXuFk/YFnwa1lh4XwSwYm+c8ZnIfrS6oEEdUSwXMCwwVT<br/>7/tMw+ab0YRsx19hBLS41oxMz+DCah+/KDMEHv0I+VxaCH8ZfaKD4tRhduSvcWkn<br/>Nat3Xp8/MAmO5xN1U8s1dFvrlnt+yqDz7Wn0kVDiax2dTJVgftetqOkoSVvGdMex<br/>9K0ILUUMEpHYBISIaAc7NjoG4BieSeK7wuzBXdhHutVZVKp2ty+mAd8xPlrmemsX<br/>lzBhV/kcmF4rcG4eqoWcKpZQY8ZUDufwhIcNqIZEA+wQoKbmBQCR/NradwUrCAIs<br/>AQFMVhSYmr7ffA6Ty0twSWeVMDQmxdW+6gKA3EiTAJkFXPpdkhBUzuZHC7Eeph7D<br/>F0Ks8Vu/wzOhNsd2s2wYYF6Dl3xctcOj7eMw8VS1HtExszulM57TnqTDaLGPcX6o<br/>m8NORwMEtQrCbJd/fdmoNPN/cXzLPHQj3qVZ0F50iNec6zSnmBLIRX4SAYOqzN/2<br/>icvr98Caa1oX3pUlm9W2Hcz30SXJDxOf+mqH6zL4QTAMs3/K9OkaO9nmyPelwoCw<br/>VI1q/PsMpqQhGikdM5hrzg6IcEOg5zpLB6N+wqkcGyXFzI2gSQTWYOv4thrIxPY5<br/>G9yNi4dhU+2+KJCa6aoPyAlyc41Yd3ARTeahHEjtdj6PcueRPQdVm+qWCRp09bp3<br/>oic7ljzMVrPRgdbRrzFyEAIhN9Fi4QZ08/yCLEt/BPG+N8j0cZixoj54SKi07uSO<br/>WRDrzGvgSegGCCIFKjAsq9ay0sBm61XLcZqdtj57NpNzd/y/yFYvjEQLyyn8VnFA<br/>RwOaM3zjrufNC+kYVkHCYzfvu+JopScZjMiuBXI9v8OTOXlj+Ai97bnftwmpQ263<br/>5vyearRHCNATFNa96Sxd1cLjV+ECUlD4hAZQPyel8groXsyjKaMxoOkaZjG/5MDQ<br/>8KPtes32kjTmneyLSzrUaAD0F4l/iltBXzDNiT6BHD7HJmERbdkoab7+DC1hxxC1<br/>VuOHOX+G/U5NUNjxAercuFOY6kgAH5HM+woGjLUsoc5LESqyPdddeg==<br/>-----END PGP MESSAGE-----</p><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/17684968-stop-using-encrypted-email-with-william-woodruff.mp3" length="51228916" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2025/08/22/stop-using-encrypted-email-with-william-woodruff</link>
    <itunes:author>Security Cryptography Whatever</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17684968</guid>
    <pubDate>Fri, 22 Aug 2025 22:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17684968/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17684968/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17684968/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17684968/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/17684968/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="intro" />
  <psc:chapter start="0:48" title="openpgp.js vuln" />
  <psc:chapter start="1:39" title="pgp message formats" />
  <psc:chapter start="3:30" title="pgp key servers" />
  <psc:chapter start="4:14" title="parsing vulns" />
  <psc:chapter start="13:30" title="pgp for encrypted email" />
  <psc:chapter start="28:22" title="fcking metadata" />
  <psc:chapter start="38:14" title="m-m-m-metadata" />
  <psc:chapter start="38:40" title="SMTP m-m-m-metadata" />
  <psc:chapter start="39:22" title="dkim, spam" />
  <psc:chapter start="41:53" title="federation" />
  <psc:chapter start="44:30" title="how big is ur email archive" />
  <psc:chapter start="52:06" title="forward secrecy" />
  <psc:chapter start="1:01:12" title="what you should actually use" />
  <psc:chapter start="1:10:17" title="final opinions" />
</psc:chapters>
    <itunes:duration>4267</itunes:duration>
    <itunes:keywords>security,cryptography,software,formats,pgp,openpgp,gpg,email,signal</itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Alex Gaynor</itunes:title>
    <title>Alex Gaynor</title>
    <itunes:summary><![CDATA[We chat with friend of the pod and special guest Alex Gaynor, former deputy chief technologist at the FTC and all around good Security Person™. Join for nerdery about WebAuthn, stay for accidentally melting down GitHub APIs around November 2020!  Watch on YouTube: https://www.youtube.com/watch?v=gBoGvyvsSi4 Transcript: https://securitycryptographywhatever.com/2025/08/16/alex-gaynor Links: - https://knowyourmeme.com/memes/no-take-only-throw - https://alexgaynor.net/2025/jan/13/challenges-...]]></itunes:summary>
    <description><![CDATA[<p>We chat with friend of the pod and special guest Alex Gaynor, former deputy chief technologist at the FTC and all around good Security Person™. Join for nerdery about WebAuthn, stay for accidentally melting down GitHub APIs around November 2020! </p><p>Watch on YouTube: https://www.youtube.com/watch?v=gBoGvyvsSi4</p><p>Transcript: https://securitycryptographywhatever.com/2025/08/16/alex-gaynor</p><p>Links:</p><p>- https://knowyourmeme.com/memes/no-take-only-throw<br/>- https://alexgaynor.net/2025/jan/13/challenges-funding-open-source/<br/>- https://alexgaynor.net/2025/apr/08/putting-a-price-tag-on-open-source/<br/>- https://dadrian.io/blog/posts/corporate-support-xz/<br/>- https://alex.github.io/nyt-2020-election-scraper/battleground-state-changes.html<br/>- https://github.com/alex/nyt-2020-election-scraper<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We chat with friend of the pod and special guest Alex Gaynor, former deputy chief technologist at the FTC and all around good Security Person™. Join for nerdery about WebAuthn, stay for accidentally melting down GitHub APIs around November 2020! </p><p>Watch on YouTube: https://www.youtube.com/watch?v=gBoGvyvsSi4</p><p>Transcript: https://securitycryptographywhatever.com/2025/08/16/alex-gaynor</p><p>Links:</p><p>- https://knowyourmeme.com/memes/no-take-only-throw<br/>- https://alexgaynor.net/2025/jan/13/challenges-funding-open-source/<br/>- https://alexgaynor.net/2025/apr/08/putting-a-price-tag-on-open-source/<br/>- https://dadrian.io/blog/posts/corporate-support-xz/<br/>- https://alex.github.io/nyt-2020-election-scraper/battleground-state-changes.html<br/>- https://github.com/alex/nyt-2020-election-scraper<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/17680054-alex-gaynor.mp3" length="61476154" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2025/08/16/alex-gaynor</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17680054</guid>
    <pubDate>Sat, 16 Aug 2025 14:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17680054/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17680054/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17680054/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17680054/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/17680054/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:00" title="Alex Gaynor at the FTC" />
  <psc:chapter start="1:56" title="US Digital Service and Healthcare.gov" />
  <psc:chapter start="6:16" title="FTC&#39;s Role in Technology and Consumer Protection" />
  <psc:chapter start="7:52" title="&#39;Favorite&#39; FTC Cases" />
  <psc:chapter start="31:55" title="Open Source" />
  <psc:chapter start="40:23" title="Python Cryptography, Rust" />
  <psc:chapter start="43:37" title="Managing Conflicting Needs in OpenSSL" />
  <psc:chapter start="44:17" title="Upstreaming Rust to OpenSSL" />
  <psc:chapter start="45:29" title="Design Decisions and Compatibility Challenges" />
  <psc:chapter start="46:16" title="Rust Crates and Reusability" />
  <psc:chapter start="48:26" title="Labor of Love and Ideology in Open Source" />
  <psc:chapter start="49:05" title="User Frustration and Platform Support" />
  <psc:chapter start="50:55" title="CI Infra and GitHub Actions" />
  <psc:chapter start="56:07" title="Funding Open Source" />
  <psc:chapter start="1:06:01" title="SSO Tax" />
  <psc:chapter start="1:18:33" title="The Alex News Network and 2020 Election" />
  <psc:chapter start="1:24:34" title="👋" />
</psc:chapters>
    <itunes:duration>5121</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Vegas, Baby!</itunes:title>
    <title>Vegas, Baby!</title>
    <itunes:summary><![CDATA[We’re throwing a party in Vegas! Someone called it SCWPodCon last year, and the name stuck. It’s sponsored by Teleport, the infrastructure identity company. Get SSO for SSH! If Thomas was here, I’m sure he’d tell you that Fly.io uses Teleport internally. Oh also there's some thing called Black..pill? Black Pool? Something like that happening in Vegas, with crypto talks, so we chatted about them a bit, plus some other stuff  SCWPodCon 2025: https://securitycryptographywhatever.com/events/black...]]></itunes:summary>
    <description><![CDATA[<p>We’re throwing a party in Vegas! Someone called it SCWPodCon last year, and the name stuck. It’s sponsored by Teleport, the infrastructure identity company. Get SSO for SSH! If Thomas was here, I’m sure he’d tell you that Fly.io uses Teleport internally. Oh also there&apos;s some thing called Black..pill? Black Pool? Something like that happening in Vegas, with crypto talks, so we chatted about them a bit, plus some other stuff<br/><br/>SCWPodCon 2025: https://securitycryptographywhatever.com/events/blackhat</p><p>Transcript: https://securitycryptographywhatever.com/2025/07/29/vegas-baby/</p><p>Links:<br/><br/>- Fault Injection attacks on PQCS signatures: https://www.blackhat.com/us-25/briefings/schedule/index.html#bypassing-pqc-signature-verification-with-fault-injection-dilithium-xmss-sphincs-46362<br/>- Another attack on TETRA: https://www.blackhat.com/us-25/briefings/schedule/index.html#2-cops-2-broadcasting-tetra-end-to-end-under-scrutiny-46143<br/>- Attacks on SCADA / ICS protocols (OPC UA): https://www.blackhat.com/us-25/briefings/schedule/index.html#no-vpn-needed-cryptographic-attacks-against-the-opc-ua-protocol-44760<br/>- Attacks on Nostr:  https://www.blackhat.com/us-25/briefings/schedule/index.html#not-sealed-practical-attacks-on-nostr-a-decentralized-censorship-resistant-protocol-45726<br/>- https://signal.org/blog/the-ecosystem-is-moving/<br/>- https://en.wikipedia.org/wiki/Nostr<br/>- https://eurosp2025.ieee-security.org/program.html<br/>- https://cispa.de/en/research/publications/84648-attacking-and-fixing-the-android-protected-confirmation-protocol<br/>- https://hal.science/hal-05038009v2/file/main.pdf<br/>- 8-bit, abacus, and a dog: https://eprint.iacr.org/2025/1237.pdf<br/>- https://www.youtube.com/watch?v=Dlsa9EBKDGI<br/>- https://www.quantamagazine.org/computer-scientists-figure-out-how-to-prove-lies-20250709/<br/>- https://eprint.iacr.org/2025/118</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We’re throwing a party in Vegas! Someone called it SCWPodCon last year, and the name stuck. It’s sponsored by Teleport, the infrastructure identity company. Get SSO for SSH! If Thomas was here, I’m sure he’d tell you that Fly.io uses Teleport internally. Oh also there&apos;s some thing called Black..pill? Black Pool? Something like that happening in Vegas, with crypto talks, so we chatted about them a bit, plus some other stuff<br/><br/>SCWPodCon 2025: https://securitycryptographywhatever.com/events/blackhat</p><p>Transcript: https://securitycryptographywhatever.com/2025/07/29/vegas-baby/</p><p>Links:<br/><br/>- Fault Injection attacks on PQCS signatures: https://www.blackhat.com/us-25/briefings/schedule/index.html#bypassing-pqc-signature-verification-with-fault-injection-dilithium-xmss-sphincs-46362<br/>- Another attack on TETRA: https://www.blackhat.com/us-25/briefings/schedule/index.html#2-cops-2-broadcasting-tetra-end-to-end-under-scrutiny-46143<br/>- Attacks on SCADA / ICS protocols (OPC UA): https://www.blackhat.com/us-25/briefings/schedule/index.html#no-vpn-needed-cryptographic-attacks-against-the-opc-ua-protocol-44760<br/>- Attacks on Nostr:  https://www.blackhat.com/us-25/briefings/schedule/index.html#not-sealed-practical-attacks-on-nostr-a-decentralized-censorship-resistant-protocol-45726<br/>- https://signal.org/blog/the-ecosystem-is-moving/<br/>- https://en.wikipedia.org/wiki/Nostr<br/>- https://eurosp2025.ieee-security.org/program.html<br/>- https://cispa.de/en/research/publications/84648-attacking-and-fixing-the-android-protected-confirmation-protocol<br/>- https://hal.science/hal-05038009v2/file/main.pdf<br/>- 8-bit, abacus, and a dog: https://eprint.iacr.org/2025/1237.pdf<br/>- https://www.youtube.com/watch?v=Dlsa9EBKDGI<br/>- https://www.quantamagazine.org/computer-scientists-figure-out-how-to-prove-lies-20250709/<br/>- https://eprint.iacr.org/2025/118</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/17580887-vegas-baby.mp3" length="43893471" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2025/07/29/vegas-baby/</link>
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17580887</guid>
    <pubDate>Tue, 29 Jul 2025 08:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17580887/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17580887/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17580887/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/17580887/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/17580887/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="0:30" title="SCWPodCon" />
  <psc:chapter start="0:48" title="Teleport" />
  <psc:chapter start="2:50" title="SSH Certificates and X.509" />
  <psc:chapter start="5:45" title="Deirdre&#39;s Jerb" />
  <psc:chapter start="6:33" title="Black Hat Crypto Highlights" />
  <psc:chapter start="8:11" title="Hollywood Crypto Vulnerabilities" />
  <psc:chapter start="9:30" title="Fault Injection Attacks on Post-Quantum Signatures" />
  <psc:chapter start="14:25" title="Tetra Encryption Protocol" />
  <psc:chapter start="19:21" title="Federated Protocols and Security" />
  <psc:chapter start="26:10" title="Matrix Vulnerabilities" />
  <psc:chapter start="26:38" title="Noster" />
  <psc:chapter start="27:43" title="End-to-End Encryption Challenges" />
  <psc:chapter start="31:07" title="Quantum Factoring with a Dog" />
  <psc:chapter start="33:11" title="Quantum Computing Progress" />
  <psc:chapter start="49:13" title="Fiat Shamir, Proving False Statements" />
  <psc:chapter start="1:00:06" title="Come to our party" />
</psc:chapters>
    <itunes:duration>3656</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>E2EE Storage Done Right with Matilda Backendal Jonas Hofmann and Kien Tuong Truong</itunes:title>
    <title>E2EE Storage Done Right with Matilda Backendal Jonas Hofmann and Kien Tuong Truong</title>
    <itunes:summary><![CDATA[It seems like everyone that tries to deploy end-to-end encrypted cloud storage seems to mess it up, often in new and creative ways. Our special guests Matilda Backendal, Jonas Hofmann, and Kien Tuong Truong give us a tour through the breakage and discuss a new formal model of how to actually build a secure E2EE storage system.   Watch on YouTube: https://youtu.be/sizLiK_byCw  Transcript: https://securitycryptographywhatever.com/2025/05/19/e2ee-storage/  Links: - https://brokencloudstorag...]]></itunes:summary>
    <description><![CDATA[<p>It seems like everyone that tries to deploy end-to-end encrypted cloud<br/>storage seems to mess it up, often in new and creative ways. Our special<br/>guests Matilda Backendal, Jonas Hofmann, and Kien Tuong Truong give us a tour through the breakage and discuss a new formal model of how to actually build a secure E2EE storage system.<br/><br/></p><p>Watch on YouTube: https://youtu.be/sizLiK_byCw</p><p><br/>Transcript: https://securitycryptographywhatever.com/2025/05/19/e2ee-storage/<br/><br/>Links:</p><p>- https://brokencloudstorage.info</p><p>- https://eprint.iacr.org/2024/1616.pdf</p><p>- https://www.sync.com</p><p>- https://www.pcloud.com</p><p>- https://icedrive.net</p><p>- https://seafile.com</p><p>- https://tresorit.com</p><p>- https://eprint.iacr.org/2024/989.pdf</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>It seems like everyone that tries to deploy end-to-end encrypted cloud<br/>storage seems to mess it up, often in new and creative ways. Our special<br/>guests Matilda Backendal, Jonas Hofmann, and Kien Tuong Truong give us a tour through the breakage and discuss a new formal model of how to actually build a secure E2EE storage system.<br/><br/></p><p>Watch on YouTube: https://youtu.be/sizLiK_byCw</p><p><br/>Transcript: https://securitycryptographywhatever.com/2025/05/19/e2ee-storage/<br/><br/>Links:</p><p>- https://brokencloudstorage.info</p><p>- https://eprint.iacr.org/2024/1616.pdf</p><p>- https://www.sync.com</p><p>- https://www.pcloud.com</p><p>- https://icedrive.net</p><p>- https://seafile.com</p><p>- https://tresorit.com</p><p>- https://eprint.iacr.org/2024/989.pdf</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/16604757-e2ee-storage-done-right-with-matilda-backendal-jonas-hofmann-and-kien-tuong-truong.mp3" length="44969228" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2025/05/19/e2ee-storage/</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16604757</guid>
    <pubDate>Mon, 19 May 2025 18:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16604757/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16604757/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16604757/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16604757/transcript.vtt" type="text/vtt" />
    <itunes:duration>3745</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Picking Quantum Resistant Algorithms</itunes:title>
    <title>Picking Quantum Resistant Algorithms</title>
    <itunes:summary><![CDATA[Migrating the US government to quantum-resistant cryptography is hard, luckily the gamer presidents are on it. This episode is extremely not safe for work, nor does it reflect the political opinions of, well, anybody.     "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian) ]]></itunes:summary>
    <description><![CDATA[<p>Migrating the US government to quantum-resistant cryptography is hard, luckily the gamer presidents are on it. This episode is extremely not safe for work, nor does it reflect the political opinions of, well, anybody.<br/><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Migrating the US government to quantum-resistant cryptography is hard, luckily the gamer presidents are on it. This episode is extremely not safe for work, nor does it reflect the political opinions of, well, anybody.<br/><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/16846782-picking-quantum-resistant-algorithms.mp3" length="10780045" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16846782</guid>
    <pubDate>Sun, 23 Mar 2025 20:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16846782/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16846782/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16846782/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16846782/transcript.vtt" type="text/vtt" />
    <itunes:duration>896</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Apple Pulls Advanced Data Protection in the UK with Matt Green and Joe Hall</itunes:title>
    <title>Apple Pulls Advanced Data Protection in the UK with Matt Green and Joe Hall</title>
    <itunes:summary><![CDATA[Apple has pulled the availability of their opt-in iCloud end-to-end encryption feature, called Advanced Data Protection, in the UK. This doesn't only affect UK Apple users, however.   To help us make sense of this surprising move from the fruit company, we got Matt Green, Associate Professor at Johns Hopkins, and Joe Hall, Distinguished Technologist at the Internet Society, on the horn.  Recorded Saturday February 22nd, 2025. Transcript: https://securitycryptographywhatever.com/2025...]]></itunes:summary>
    <description><![CDATA[<p>Apple has pulled the availability of their opt-in iCloud end-to-end encryption feature, called Advanced Data Protection, in the UK. This doesn&apos;t only affect UK Apple users, however. <br/><br/>To help us make sense of this surprising move from the fruit company, we got Matt Green, Associate Professor at Johns Hopkins, and Joe Hall, Distinguished Technologist at the Internet Society, on the horn. </p><p>Recorded Saturday February 22nd, 2025.</p><p>Transcript: https://securitycryptographywhatever.com/2025/02/24/apple-pulls-adp-in-uk/<br/><br/>Watch episode on YouTube: <a href='https://youtu.be/LAn_yOGUkR0'>https://youtu.be/LAn_yOGUkR0</a></p><p>Links:</p><p>- https://www.lawfaremedia.org/article/apples-cloud-key-vault-and-secure-law-enforcement-access<br/>- https://www.androidcentral.com/how-googles-backup-encryption-works-good-bad-and-ugly<br/>- https://gdpr.eu/right-to-be-forgotten/<br/>- https://www.legislation.gov.uk/id/ukpga/2024/9<br/>- https://www.nytimes.com/2021/05/17/technology/apple-china-censorship-data.html<br/>- https://en.wikipedia.org/wiki/Salt_Typhoon<br/>- Salt Typhoon: https://www.cisa.gov/news-events/news/strengthening-americas-resilience-against-prc-cyber-threats<br/>- https://www.bloomberg.com/news/articles/2025-02-21/apple-removes-end-to-end-encryption-feature-from-uk-after-backdoor-order<br/>- https://support.apple.com/en-us/102651<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Apple has pulled the availability of their opt-in iCloud end-to-end encryption feature, called Advanced Data Protection, in the UK. This doesn&apos;t only affect UK Apple users, however. <br/><br/>To help us make sense of this surprising move from the fruit company, we got Matt Green, Associate Professor at Johns Hopkins, and Joe Hall, Distinguished Technologist at the Internet Society, on the horn. </p><p>Recorded Saturday February 22nd, 2025.</p><p>Transcript: https://securitycryptographywhatever.com/2025/02/24/apple-pulls-adp-in-uk/<br/><br/>Watch episode on YouTube: <a href='https://youtu.be/LAn_yOGUkR0'>https://youtu.be/LAn_yOGUkR0</a></p><p>Links:</p><p>- https://www.lawfaremedia.org/article/apples-cloud-key-vault-and-secure-law-enforcement-access<br/>- https://www.androidcentral.com/how-googles-backup-encryption-works-good-bad-and-ugly<br/>- https://gdpr.eu/right-to-be-forgotten/<br/>- https://www.legislation.gov.uk/id/ukpga/2024/9<br/>- https://www.nytimes.com/2021/05/17/technology/apple-china-censorship-data.html<br/>- https://en.wikipedia.org/wiki/Salt_Typhoon<br/>- Salt Typhoon: https://www.cisa.gov/news-events/news/strengthening-americas-resilience-against-prc-cyber-threats<br/>- https://www.bloomberg.com/news/articles/2025-02-21/apple-removes-end-to-end-encryption-feature-from-uk-after-backdoor-order<br/>- https://support.apple.com/en-us/102651<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/16686782-apple-pulls-advanced-data-protection-in-the-uk-with-matt-green-and-joe-hall.mp3" length="34946691" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16686782</guid>
    <pubDate>Mon, 24 Feb 2025 21:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16686782/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16686782/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16686782/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16686782/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/16686782/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Introduction to Security and Cryptography" />
  <psc:chapter start="5:00" title="Guests Introduction: Meet Matt Green &amp; Joe Hall" />
  <psc:chapter start="15:00" title="What is Advanced Data Protection (ADP)?" />
  <psc:chapter start="25:00" title="The Snoopers Charter Explained" />
  <psc:chapter start="40:00" title="UK&#39;s Control Over Global Data Privacy" />
  <psc:chapter start="55:00" title="Comparing US National Security Orders and UK Powers" />
  <psc:chapter start="1:15:00" title="Apple’s Dilemma: Disabling ADP in the UK" />
  <psc:chapter start="1:30:00" title="User Experience and Security: Balancing Act" />
  <psc:chapter start="1:50:00" title="Future of Encryption: Trends and Predictions" />
</psc:chapters>
    <itunes:duration>2910</itunes:duration>
    <itunes:keywords>apple,e2ee,icloud,encryption,uk,snooper&#39;s charter,adp,advanced data protection,security,cryptography,surveillance,cloud,backup</itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cryptanalyzing LLMs with Nicholas Carlini</itunes:title>
    <title>Cryptanalyzing LLMs with Nicholas Carlini</title>
    <itunes:summary><![CDATA['Let us model our large language model as a hash function—'   Sold.  Our special guest Nicholas Carlini joins us to discuss differential cryptanalysis on LLMs and other attacks, just as the ones that made OpenAI turn off some features, hehehehe.  Watch episode on YouTube: https://youtu.be/vZ64xPI2Rc0  Transcript: https://securitycryptographywhatever.com/2025/01/28/cryptanalyzing-llms-with-nicholas-carlini/  Links:  - https://nicholas.carlini.com - “Stealing Part of a Production Language ...]]></itunes:summary>
    <description><![CDATA[<p>&apos;Let us model our large language model as a hash function—&apos; <br/><br/>Sold.<br/><br/>Our special guest Nicholas Carlini joins us to discuss differential cryptanalysis on LLMs and other attacks, just as the ones that made OpenAI turn off some features, hehehehe.<br/><br/>Watch episode on YouTube: https://youtu.be/vZ64xPI2Rc0<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/01/28/cryptanalyzing-llms-with-nicholas-carlini/<br/><br/>Links:<br/><br/>- https://nicholas.carlini.com<br/>- “Stealing Part of a Production Language Model”: https://arxiv.org/pdf/2403.06634<br/>- ‘Why I attack&quot;’: https://nicholas.carlini.com/writing/2024/why-i-attack.html<br/>- “Cryptanalytic Extraction of Neural Network Models”, CRYPTO 2020: https://arxiv.org/abs/2003.04884<br/>- “Stochastic Parrots”: https://dl.acm.org/doi/10.1145/3442188.3445922<br/>- https://help.openai.com/en/articles/5247780-using-logit-bias-to-alter-token-probability-with-the-openai-api<br/>- https://community.openai.com/t/temperature-top-p-and-top-k-for-chatbot-responses/295542<br/>- https://opensource.org/license/mit<br/>- https://github.com/madler/zlib<br/>- https://ai.meta.com/blog/yann-lecun-ai-model-i-jepa/<br/>- https://nicholas.carlini.com/writing/2024/how-i-use-ai.html<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>&apos;Let us model our large language model as a hash function—&apos; <br/><br/>Sold.<br/><br/>Our special guest Nicholas Carlini joins us to discuss differential cryptanalysis on LLMs and other attacks, just as the ones that made OpenAI turn off some features, hehehehe.<br/><br/>Watch episode on YouTube: https://youtu.be/vZ64xPI2Rc0<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/01/28/cryptanalyzing-llms-with-nicholas-carlini/<br/><br/>Links:<br/><br/>- https://nicholas.carlini.com<br/>- “Stealing Part of a Production Language Model”: https://arxiv.org/pdf/2403.06634<br/>- ‘Why I attack&quot;’: https://nicholas.carlini.com/writing/2024/why-i-attack.html<br/>- “Cryptanalytic Extraction of Neural Network Models”, CRYPTO 2020: https://arxiv.org/abs/2003.04884<br/>- “Stochastic Parrots”: https://dl.acm.org/doi/10.1145/3442188.3445922<br/>- https://help.openai.com/en/articles/5247780-using-logit-bias-to-alter-token-probability-with-the-openai-api<br/>- https://community.openai.com/t/temperature-top-p-and-top-k-for-chatbot-responses/295542<br/>- https://opensource.org/license/mit<br/>- https://github.com/madler/zlib<br/>- https://ai.meta.com/blog/yann-lecun-ai-model-i-jepa/<br/>- https://nicholas.carlini.com/writing/2024/how-i-use-ai.html<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/16516727-cryptanalyzing-llms-with-nicholas-carlini.mp3" length="58133477" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16516727</guid>
    <pubDate>Tue, 28 Jan 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16516727/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16516727/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16516727/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16516727/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/16516727/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Mathematical Attacks on AI Security" />
  <psc:chapter start="12:07" title="AI Model Extraction and Security" />
  <psc:chapter start="16:11" title="Model Extraction Security Mechanism Analysis" />
  <psc:chapter start="29:18" title="Model Extraction Attack Methodology Discussion" />
  <psc:chapter start="39:00" title="Training Data Extraction Attack Methodology" />
  <psc:chapter start="50:59" title="Data Poisoning Attacks and Defenses" />
  <psc:chapter start="59:24" title="AI Security Defense Challenges and Strategies" />
  <psc:chapter start="1:06:20" title="Exploring AI Model Capabilities" />
  <psc:chapter start="1:15:21" title="Challenges in AI Model Security" />
</psc:chapters>
    <itunes:duration>4842</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Biden’s Cyber-Everything Bagel with Carole House</itunes:title>
    <title>Biden’s Cyber-Everything Bagel with Carole House</title>
    <itunes:summary><![CDATA[Just a few days before turning off the lights, the Biden administration dropped a huge cybersecurity executive order including a lot of good stuff, that hopefully [cross your fingers, knock wood, spin around three times and spit] will last into future administrations. We snagged some time with Carole House, outgoing Special Advisor and Acting Senior Director for Cybersecurity and Critical Infrastructure Policy, National Security Council in the Biden-Harris White House, to give us a brain dump...]]></itunes:summary>
    <description><![CDATA[<p>Just a few days before turning off the lights, the Biden administration dropped a huge cybersecurity executive order including a lot of good stuff, that hopefully [cross your fingers, knock wood, spin around three times and spit] will last into future administrations. We snagged some time with Carole House, outgoing Special Advisor and Acting Senior Director for Cybersecurity and Critical Infrastructure Policy, National Security Council in the Biden-Harris White House, to give us a brain dump.<br/><br/>And now due to popular demand, with video of our actual human¹ faces! https://youtu.be/Pqw0W2crQiM<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/01/20/bidens-cyber-everything-bagel-carole-house/<br/><br/>Links:<br/>- https://www.federalregister.gov/d/2025-01470<br/>- https://www.wired.com/story/biden-executive-order-cybersecurity-ai-and-more/<br/>- 2022 EO: https://archive.ph/hvzWd<br/>- 2023 EO: https://www.whitehouse.gov/wp-content/uploads/2023/06/M-23-16-Update-to-M-22-18-Enhancing-Software-Security-1.pdf<br/>- 2021 EO: https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity<br/>- NIST SSDF: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218.pdf<br/>- https://www.federalregister.gov/documents/2015/04/02/2015-07788/blocking-the-property-of-certain-persons-engaging-in-significant-malicious-cyber-enabled-activities<br/>- IEEPA: https://www.govinfo.gov/content/pkg/USCODE-2023-title50/pdf/USCODE-2023-title50-chap35-sec1701.pdf<br/><br/>¹ Actual human faces not guaranteed in all cases</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Just a few days before turning off the lights, the Biden administration dropped a huge cybersecurity executive order including a lot of good stuff, that hopefully [cross your fingers, knock wood, spin around three times and spit] will last into future administrations. We snagged some time with Carole House, outgoing Special Advisor and Acting Senior Director for Cybersecurity and Critical Infrastructure Policy, National Security Council in the Biden-Harris White House, to give us a brain dump.<br/><br/>And now due to popular demand, with video of our actual human¹ faces! https://youtu.be/Pqw0W2crQiM<br/><br/>Transcript: https://securitycryptographywhatever.com/2025/01/20/bidens-cyber-everything-bagel-carole-house/<br/><br/>Links:<br/>- https://www.federalregister.gov/d/2025-01470<br/>- https://www.wired.com/story/biden-executive-order-cybersecurity-ai-and-more/<br/>- 2022 EO: https://archive.ph/hvzWd<br/>- 2023 EO: https://www.whitehouse.gov/wp-content/uploads/2023/06/M-23-16-Update-to-M-22-18-Enhancing-Software-Security-1.pdf<br/>- 2021 EO: https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity<br/>- NIST SSDF: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218.pdf<br/>- https://www.federalregister.gov/documents/2015/04/02/2015-07788/blocking-the-property-of-certain-persons-engaging-in-significant-malicious-cyber-enabled-activities<br/>- IEEPA: https://www.govinfo.gov/content/pkg/USCODE-2023-title50/pdf/USCODE-2023-title50-chap35-sec1701.pdf<br/><br/>¹ Actual human faces not guaranteed in all cases</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/16471596-biden-s-cyber-everything-bagel-with-carole-house.mp3" length="41235929" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16471596</guid>
    <pubDate>Mon, 20 Jan 2025 19:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16471596/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16471596/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16471596/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16471596/transcript.vtt" type="text/vtt" />
    <itunes:duration>3434</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Quantum Willow with John Schanck and Samuel Jacques</itunes:title>
    <title>Quantum Willow with John Schanck and Samuel Jacques</title>
    <itunes:summary><![CDATA[THE QUANTUM COMPUTERS ARE COMING...right? We got Samuel Jacques and John Schanck at short notice to answer that question plus a bunch of other about error correcting codes, logical qubits, T-gates, and more about Google's new quantum computer Willow.  Transcript: https://securitycryptographywhatever.com/2024/12/18/quantum-willow  Links:  - https://blog.google/technology/research/google-willow-quantum-chip/  - https://research.google/blog/making-quantum-error-correction-work/ - https://bl...]]></itunes:summary>
    <description><![CDATA[<p>THE QUANTUM COMPUTERS ARE COMING...right? We got Samuel Jacques and John Schanck at short notice to answer that question plus a bunch of other about error correcting codes, logical qubits, T-gates, and more about Google&apos;s new quantum computer Willow.<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/12/18/quantum-willow<br/><br/>Links:<br/><br/>- https://blog.google/technology/research/google-willow-quantum-chip/ <br/>- https://research.google/blog/making-quantum-error-correction-work/<br/>- https://blog.google/technology/google-deepmind/alphaqubit-quantum-error-correction/  <br/>- https://www.nature.com/articles/s41586-024-08449-y<br/>- Sam’s ‘Landscape of Quantum Computing’ chart: https://sam-jaques.appspot.com/quantum\_landscape\_2024  <br/>- The above, originally published in 2021: https://sam-jaques.appspot.com/quantum\_landscape<br/>- https://sam-jaques.appspot.com<br/>- https://jmschanck.info/</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>THE QUANTUM COMPUTERS ARE COMING...right? We got Samuel Jacques and John Schanck at short notice to answer that question plus a bunch of other about error correcting codes, logical qubits, T-gates, and more about Google&apos;s new quantum computer Willow.<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/12/18/quantum-willow<br/><br/>Links:<br/><br/>- https://blog.google/technology/research/google-willow-quantum-chip/ <br/>- https://research.google/blog/making-quantum-error-correction-work/<br/>- https://blog.google/technology/google-deepmind/alphaqubit-quantum-error-correction/  <br/>- https://www.nature.com/articles/s41586-024-08449-y<br/>- Sam’s ‘Landscape of Quantum Computing’ chart: https://sam-jaques.appspot.com/quantum\_landscape\_2024  <br/>- The above, originally published in 2021: https://sam-jaques.appspot.com/quantum\_landscape<br/>- https://sam-jaques.appspot.com<br/>- https://jmschanck.info/</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/16290647-quantum-willow-with-john-schanck-and-samuel-jacques.mp3" length="38622038" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16290647</guid>
    <pubDate>Wed, 18 Dec 2024 17:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16290647/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16290647/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16290647/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16290647/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/16290647/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Quantum Willow with John Schanck and Samuel Jacques" />
  <psc:chapter start="0:12" title="Advancements in Quantum Error Correction" />
  <psc:chapter start="14:54" title="Classical Decoders in Quantum Computing" />
  <psc:chapter start="28:17" title="Advancements in Quantum Gate Error Correction" />
  <psc:chapter start="36:55" title="Resource States in Quantum Computation" />
  <psc:chapter start="43:05" title="Future Prospects in Quantum Computing" />
</psc:chapters>
    <itunes:duration>3216</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Dual_EC_DRBG with Justin Schuh and Matthew Green</itunes:title>
    <title>Dual_EC_DRBG with Justin Schuh and Matthew Green</title>
    <itunes:summary><![CDATA[Nothing we have ever recorded on SCW has brought so much joy to David. However, at several points during the episode, we may have witnessed Matthew Green's soul leave his body.  Our esteemed guests Justin Schuh and Matt Green joined us to debate whether `Dual_EC_DRBG` was intentionally backdoored by the NSA or 'just' a major fuckup.  Transcript: https://securitycryptographywhatever.com/2024/12/07/dual-ec-drbg  Links:  - Dicky George at InfiltrateCon 2014, 'Life at Both Ends of the Barrel - An...]]></itunes:summary>
    <description><![CDATA[<p>Nothing we have ever recorded on SCW has brought so much joy to<br/>David. However, at several points during the episode, we may have witnessed Matthew Green&apos;s soul leave his body.<br/><br/>Our esteemed guests Justin Schuh and Matt Green joined us to debate whether `Dual_EC_DRBG` was intentionally backdoored by the NSA or &apos;just&apos; a major fuckup.<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/12/07/dual-ec-drbg<br/><br/>Links:<br/><br/>- Dicky George at InfiltrateCon 2014, &apos;Life at Both Ends of the Barrel - An NSA Targeting Retrospective&apos;: [https://youtu.be/qq-LCyRp6bU?si=MyTBKomkIVaxSy1Q](https://youtu.be/qq-LCyRp6bU?si=MyTBKomkIVaxSy1Q)<br/>- Dicky George: [https://www.nsa.gov/Press-Room/Digital-Media-Center/Biographies/Biography-View-Page/Article/3330261/richard-dickie-george/](https://www.nsa.gov/Press-Room/Digital-Media-Center/Biographies/Biography-View-Page/Article/3330261/richard-dickie-george/)<br/>- NYTimes on Sigint Enabling Project: [https://archive.nytimes.com/www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-campaign-against-encryption.html](https://archive.nytimes.com/www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-campaign-against-encryption.html)<br/>- On the Practical Exploitability of Dual EC<br/>in TLS Implementations: [https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-checkoway.pdf](https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-checkoway.pdf)<br/>- Wired - Researchers Solve Juniper Backdoor Mystery; Signs Point to NSA [https://www.wired.com/2015/12/researchers-solve-the-juniper-mystery-and-they-say-its-partially-the-nsas-fault/](https://www.wired.com/2015/12/researchers-solve-the-juniper-mystery-and-they-say-its-partially-the-nsas-fault/)<br/>- ProPublica - Revealed: The NSA&apos;s Secret Campaign to Crack, Undermine Internet Security [https://www.propublica.org/article/the-nsas-secret-campaign-to-crack-undermine-internet-encryption](https://www.propublica.org/article/the-nsas-secret-campaign-to-crack-undermine-internet-encryption)<br/>- DDoSecrets - Sigint Enabling Project: [https://data.ddosecrets.com/Snowden%20archive/sigint-enabling-project.pdf](https://data.ddosecrets.com/Snowden%20archive/sigint-enabling-project.pdf)<br/>- IAD: [https://www.iad.gov/](https://www.iad.gov/)<br/>- Ars Technica - “Unauthorized code” in Juniper firewalls decrypts encrypted VPN traffic: [https://web.archive.org/web/20151222023311/http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/](https://web.archive.org/web/20151222023311/http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/)<br/>- 2015 IMPORTANT JUNIPER SECURITY ANNOUNCEMENT: [https://web.archive.org/web/20151221171526/http://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554](https://web.archive.org/web/20151221171526/http://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554)<br/>- Extended Random Values for TLS: [https://datatracker.ietf.org/doc/html/draft-rescorla-tls-extended-random-00](https://datatracker.ietf.org/doc/html/draft-rescorla-tls-extended-random-00)<br/>- The Art of Software Security Assessment: [https://www.amazon.com/Art-Software-Security-Assessment-Vulnerabilities/dp/0321444426](https://www.amazon.com/Art-Software-Security-Assessment-Vulnerabilities/dp/0321444426)</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Nothing we have ever recorded on SCW has brought so much joy to<br/>David. However, at several points during the episode, we may have witnessed Matthew Green&apos;s soul leave his body.<br/><br/>Our esteemed guests Justin Schuh and Matt Green joined us to debate whether `Dual_EC_DRBG` was intentionally backdoored by the NSA or &apos;just&apos; a major fuckup.<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/12/07/dual-ec-drbg<br/><br/>Links:<br/><br/>- Dicky George at InfiltrateCon 2014, &apos;Life at Both Ends of the Barrel - An NSA Targeting Retrospective&apos;: [https://youtu.be/qq-LCyRp6bU?si=MyTBKomkIVaxSy1Q](https://youtu.be/qq-LCyRp6bU?si=MyTBKomkIVaxSy1Q)<br/>- Dicky George: [https://www.nsa.gov/Press-Room/Digital-Media-Center/Biographies/Biography-View-Page/Article/3330261/richard-dickie-george/](https://www.nsa.gov/Press-Room/Digital-Media-Center/Biographies/Biography-View-Page/Article/3330261/richard-dickie-george/)<br/>- NYTimes on Sigint Enabling Project: [https://archive.nytimes.com/www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-campaign-against-encryption.html](https://archive.nytimes.com/www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-campaign-against-encryption.html)<br/>- On the Practical Exploitability of Dual EC<br/>in TLS Implementations: [https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-checkoway.pdf](https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-checkoway.pdf)<br/>- Wired - Researchers Solve Juniper Backdoor Mystery; Signs Point to NSA [https://www.wired.com/2015/12/researchers-solve-the-juniper-mystery-and-they-say-its-partially-the-nsas-fault/](https://www.wired.com/2015/12/researchers-solve-the-juniper-mystery-and-they-say-its-partially-the-nsas-fault/)<br/>- ProPublica - Revealed: The NSA&apos;s Secret Campaign to Crack, Undermine Internet Security [https://www.propublica.org/article/the-nsas-secret-campaign-to-crack-undermine-internet-encryption](https://www.propublica.org/article/the-nsas-secret-campaign-to-crack-undermine-internet-encryption)<br/>- DDoSecrets - Sigint Enabling Project: [https://data.ddosecrets.com/Snowden%20archive/sigint-enabling-project.pdf](https://data.ddosecrets.com/Snowden%20archive/sigint-enabling-project.pdf)<br/>- IAD: [https://www.iad.gov/](https://www.iad.gov/)<br/>- Ars Technica - “Unauthorized code” in Juniper firewalls decrypts encrypted VPN traffic: [https://web.archive.org/web/20151222023311/http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/](https://web.archive.org/web/20151222023311/http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/)<br/>- 2015 IMPORTANT JUNIPER SECURITY ANNOUNCEMENT: [https://web.archive.org/web/20151221171526/http://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554](https://web.archive.org/web/20151221171526/http://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554)<br/>- Extended Random Values for TLS: [https://datatracker.ietf.org/doc/html/draft-rescorla-tls-extended-random-00](https://datatracker.ietf.org/doc/html/draft-rescorla-tls-extended-random-00)<br/>- The Art of Software Security Assessment: [https://www.amazon.com/Art-Software-Security-Assessment-Vulnerabilities/dp/0321444426](https://www.amazon.com/Art-Software-Security-Assessment-Vulnerabilities/dp/0321444426)</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/16236432-dual_ec_drbg-with-justin-schuh-and-matthew-green.mp3" length="48809028" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16236432</guid>
    <pubDate>Sat, 07 Dec 2024 15:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16236432/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16236432/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16236432/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/16236432/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/16236432/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Dual_EC_DRBG with Justin Schuh and Matthew Green" />
  <psc:chapter start="0:12" title="Debate on Dual EC Backdoor" />
  <psc:chapter start="10:08" title="NSA&#39;s Dual EC Backdoor Controversy" />
  <psc:chapter start="16:43" title="Technical Director Explains NSA&#39;s Randomness Method" />
  <psc:chapter start="20:30" title="NSA&#39;s Dual EC Backdoor Dilemma" />
  <psc:chapter start="31:47" title="Debate on Intentional Crime vs Negligence" />
  <psc:chapter start="44:06" title="Discussion on NetScreen Firewall Vulnerability" />
  <psc:chapter start="50:17" title="NSA&#39;s Dual EC Backdoor Debate" />
  <psc:chapter start="1:02:16" title="Cryptographers Debate NSA&#39;s Dual EC Backdoor" />
  <psc:chapter start="1:06:20" title="Debate on Backdoor Intent and Capability" />
</psc:chapters>
    <itunes:duration>4065</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>A Little Bit of Rust Goes a Long Way with Android&#39;s Jeff Vander Stoep</itunes:title>
    <title>A Little Bit of Rust Goes a Long Way with Android&#39;s Jeff Vander Stoep</title>
    <itunes:summary><![CDATA[You may not be rewriting the world in Rust, but if you follow the findings of the Android team and our guest Jeff Vander Stoep, you'll drive down your memory-unsafety vulnerabilities more than 2X below the industry average over time! 🎉  Transcript: https://securitycryptographywhatever.com/2024/10/15/a-little-bit-of-rust-goes-a-long-way/  Links: - https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html - “Safe Coding”: https://dl.acm.org/doi/10.1145/36516...]]></itunes:summary>
    <description><![CDATA[<p>You may not be rewriting the world in Rust, but if you follow the findings of the Android team and our guest Jeff Vander Stoep, you&apos;ll drive down your memory-unsafety vulnerabilities more than 2X below the industry average over time! 🎉<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/10/15/a-little-bit-of-rust-goes-a-long-way/<br/><br/>Links:<br/>- https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html<br/>- “Safe Coding”: https://dl.acm.org/doi/10.1145/3651621<br/>- “effectiveness of security design”: https://docs.google.com/presentation/d/16LZ6T-tcjgp3T8_N3m0pa5kNA1DwIsuMcQYDhpMU7uU/edit#slide=id.g3e7cac054a_0_89<br/>- https://security.googleblog.com/2024/02/improving-interoperability-between-rust-and-c.html<br/>- https://github.com/google/crubit<br/>- https://github.com/google/autocxx<br/>- https://en.wikipedia.org/wiki/Stagefright_(bug)<br/>- https://security.googleblog.com/2021/04/rust-in-android-platform.html<br/>- https://chromium.googlesource.com/chromium/src/+/master/docs/security/rule-of-2.md<br/>- https://www.usenix.org/conference/usenixsecurity22/presentation/alexopoulos<br/>-https://kb.meinbergglobal.com/kb/time_sync/ntp/ntp_vulnerabilities_reported_2023-04<br/>- https://blog.isosceles.com/the-legacy-of-stagefright/<br/>- https://research.google/pubs/secure-by-design-googles-perspective-on-memory-safety/<br/>- https://www.youtube.com/watch?v=QrrH2lcl9ew<br/>- https://source.android.com/docs/setup/build/rust/building-rust-modules/overview<br/>- https://github.com/rust-lang/rust-bindgen<br/>- https://security.googleblog.com/2021/06/rustc-interop-in-android-platform.html</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>You may not be rewriting the world in Rust, but if you follow the findings of the Android team and our guest Jeff Vander Stoep, you&apos;ll drive down your memory-unsafety vulnerabilities more than 2X below the industry average over time! 🎉<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/10/15/a-little-bit-of-rust-goes-a-long-way/<br/><br/>Links:<br/>- https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html<br/>- “Safe Coding”: https://dl.acm.org/doi/10.1145/3651621<br/>- “effectiveness of security design”: https://docs.google.com/presentation/d/16LZ6T-tcjgp3T8_N3m0pa5kNA1DwIsuMcQYDhpMU7uU/edit#slide=id.g3e7cac054a_0_89<br/>- https://security.googleblog.com/2024/02/improving-interoperability-between-rust-and-c.html<br/>- https://github.com/google/crubit<br/>- https://github.com/google/autocxx<br/>- https://en.wikipedia.org/wiki/Stagefright_(bug)<br/>- https://security.googleblog.com/2021/04/rust-in-android-platform.html<br/>- https://chromium.googlesource.com/chromium/src/+/master/docs/security/rule-of-2.md<br/>- https://www.usenix.org/conference/usenixsecurity22/presentation/alexopoulos<br/>-https://kb.meinbergglobal.com/kb/time_sync/ntp/ntp_vulnerabilities_reported_2023-04<br/>- https://blog.isosceles.com/the-legacy-of-stagefright/<br/>- https://research.google/pubs/secure-by-design-googles-perspective-on-memory-safety/<br/>- https://www.youtube.com/watch?v=QrrH2lcl9ew<br/>- https://source.android.com/docs/setup/build/rust/building-rust-modules/overview<br/>- https://github.com/rust-lang/rust-bindgen<br/>- https://security.googleblog.com/2021/06/rustc-interop-in-android-platform.html</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/15925001-a-little-bit-of-rust-goes-a-long-way-with-android-s-jeff-vander-stoep.mp3" length="53242286" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15925001</guid>
    <pubDate>Tue, 15 Oct 2024 15:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15925001/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15925001/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15925001/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15925001/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/15925001/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="A Little Bit of Rust Goes a Long Way with Android&#39;s Jeff Vander Stoep" />
  <psc:chapter start="0:12" title="Security and Memory Safety in Android" />
  <psc:chapter start="10:14" title="Evaluating Memory Safety and Security Boundaries" />
  <psc:chapter start="17:04" title="Scaling Memory-Safe Code for Security" />
  <psc:chapter start="23:33" title="Assessing Memory Safety for Future Code" />
  <psc:chapter start="28:43" title="Memory Safety and Security Progress" />
  <psc:chapter start="35:37" title="Analyzing Memory Safety Issue Trends" />
  <psc:chapter start="45:39" title="Transitioning to Memory-Safe Code" />
  <psc:chapter start="1:00:22" title="Practical Approach to Memory Safety" />
</psc:chapters>
    <itunes:duration>4435</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Campaign Security with [REDACTED]</itunes:title>
    <title>Campaign Security with [REDACTED]</title>
    <itunes:summary><![CDATA[With the 2024 United States Presidential Election right around the corner, we talk to an unnamed guest who has worked on cybersecurity for political campaigns in the United States since 2004. We recorded this in late August, 2024.  Transcript: https://securitycryptographywhatever.com/2024/10/13/campaign-security/  Links:  - Active Measures by Thomas Rind: https://us.macmillan.com/books/9780374287269/activemeasures - Aurora: https://en.wikipedia.org/wiki/Operation\_Aurora - Google APP announce...]]></itunes:summary>
    <description><![CDATA[<p>With the 2024 United States Presidential Election right around the corner, we talk to an unnamed guest who has worked on cybersecurity for political campaigns in the United States since 2004. We recorded this in late August, 2024.<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/10/13/campaign-security/<br/><br/>Links:<br/><br/>- Active Measures by Thomas Rind: <a href='https://us.macmillan.com/books/9780374287269/activemeasures'>https://us.macmillan.com/books/9780374287269/activemeasures</a><br/>- Aurora: <a href='https://en.wikipedia.org/wiki/Operation\_Aurora'>https://en.wikipedia.org/wiki/Operation\_Aurora</a><br/>- Google APP announcement, October 2017: <a href='https://www.wired.com/story/google-advanced-protection-locks-down-accounts/'>https://www.wired.com/story/google-advanced-protection-locks-down-accounts/</a><br/>- XXD: <a href='https://linux.die.net/man/1/xxd'>https://linux.die.net/man/1/xxd</a><br/>- Adobe Reader October 2016 Security Update: <a href='https://helpx.adobe.com/security/products/acrobat/apsb16-33.html'>https://helpx.adobe.com/security/products/acrobat/apsb16-33.html</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>With the 2024 United States Presidential Election right around the corner, we talk to an unnamed guest who has worked on cybersecurity for political campaigns in the United States since 2004. We recorded this in late August, 2024.<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/10/13/campaign-security/<br/><br/>Links:<br/><br/>- Active Measures by Thomas Rind: <a href='https://us.macmillan.com/books/9780374287269/activemeasures'>https://us.macmillan.com/books/9780374287269/activemeasures</a><br/>- Aurora: <a href='https://en.wikipedia.org/wiki/Operation\_Aurora'>https://en.wikipedia.org/wiki/Operation\_Aurora</a><br/>- Google APP announcement, October 2017: <a href='https://www.wired.com/story/google-advanced-protection-locks-down-accounts/'>https://www.wired.com/story/google-advanced-protection-locks-down-accounts/</a><br/>- XXD: <a href='https://linux.die.net/man/1/xxd'>https://linux.die.net/man/1/xxd</a><br/>- Adobe Reader October 2016 Security Update: <a href='https://helpx.adobe.com/security/products/acrobat/apsb16-33.html'>https://helpx.adobe.com/security/products/acrobat/apsb16-33.html</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/15917924-campaign-security-with-redacted.mp3" length="60247418" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15917924</guid>
    <pubDate>Sun, 13 Oct 2024 16:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15917924/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15917924/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15917924/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15917924/transcript.vtt" type="text/vtt" />
    <itunes:duration>5019</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Telegram with Matthew Green</itunes:title>
    <title>Telegram with Matthew Green</title>
    <itunes:summary><![CDATA[We finally have an excuse to tear down Telegram! Their CEO got arrested by the French, apparently not because the cryptography in Telegram is bad, but special guest Matt Green joined us to talk about how the cryptography is bad anyway, and you probably shouldn't use Telegram as a secure messenger of any kind!   Transcript: https://securitycryptographywhatever.com/2024/09/06/telegram  Links:  - https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-ap...]]></itunes:summary>
    <description><![CDATA[<p>We finally have an excuse to tear down Telegram! Their CEO got arrested by the French, apparently not because the cryptography in Telegram is bad, but special guest Matt Green joined us to talk about how the cryptography is bad anyway, and you probably shouldn&apos;t use Telegram as a secure messenger of any kind!<br/><br/><br/>Transcript: https://securitycryptographywhatever.com/2024/09/06/telegram<br/><br/>Links:<br/><br/>- https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-app/<br/>- Lavabit / Ladar Levinson: https://en.wikipedia.org/wiki/Lavabit<br/>- Pavel Durov indictment statement from French authorities: https://www.tribunal-de-paris.justice.fr/sites/default/files/2024-08/2024-08-28%20-%20CP%20TELEGRAM%20mise%20en%20examen.pdf<br/>- MTProto 2.0 protocol spec: https://core.telegram.org/api/end-to-end<br/>- https://words.filippo.io/dispatches/telegram-ecdh/<br/>- MTProto 1.0 (old no longer used): - https://web.archive.org/web/20131220000537/https://core.telegram.org/api/end-to-end#key-generation<br/>- OTR: https://otr.cypherpunks.ca/otr-wpes.pdf<br/>- AES and sha2 used in ‘Infinite Garble Extension’ mode: https://eprint.iacr.org/2015/1177.pdf<br/>- Four Attacks and a Proof for Telegram: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;arnumber=9833666<br/>- History of Telegram e2ee chats availability: https://en.wikipedia.org/wiki/Telegram_(software)#Architecture<br/>- https://securitycryptographywhatever.com/2023/01/27/threema/<br/>- https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/<br/>- https://en.wikipedia.org/wiki/Matrix_(protocol), introduced in September 2014</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We finally have an excuse to tear down Telegram! Their CEO got arrested by the French, apparently not because the cryptography in Telegram is bad, but special guest Matt Green joined us to talk about how the cryptography is bad anyway, and you probably shouldn&apos;t use Telegram as a secure messenger of any kind!<br/><br/><br/>Transcript: https://securitycryptographywhatever.com/2024/09/06/telegram<br/><br/>Links:<br/><br/>- https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-app/<br/>- Lavabit / Ladar Levinson: https://en.wikipedia.org/wiki/Lavabit<br/>- Pavel Durov indictment statement from French authorities: https://www.tribunal-de-paris.justice.fr/sites/default/files/2024-08/2024-08-28%20-%20CP%20TELEGRAM%20mise%20en%20examen.pdf<br/>- MTProto 2.0 protocol spec: https://core.telegram.org/api/end-to-end<br/>- https://words.filippo.io/dispatches/telegram-ecdh/<br/>- MTProto 1.0 (old no longer used): - https://web.archive.org/web/20131220000537/https://core.telegram.org/api/end-to-end#key-generation<br/>- OTR: https://otr.cypherpunks.ca/otr-wpes.pdf<br/>- AES and sha2 used in ‘Infinite Garble Extension’ mode: https://eprint.iacr.org/2015/1177.pdf<br/>- Four Attacks and a Proof for Telegram: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;arnumber=9833666<br/>- History of Telegram e2ee chats availability: https://en.wikipedia.org/wiki/Telegram_(software)#Architecture<br/>- https://securitycryptographywhatever.com/2023/01/27/threema/<br/>- https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/<br/>- https://en.wikipedia.org/wiki/Matrix_(protocol), introduced in September 2014</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/15702370-telegram-with-matthew-green.mp3" length="46157481" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15702370</guid>
    <pubDate>Fri, 06 Sep 2024 23:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15702370/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15702370/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15702370/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15702370/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/15702370/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Telegram with Matthew Green" />
  <psc:chapter start="0:12" title="Cryptocurrency and the French Legal System" />
  <psc:chapter start="9:42" title="Telegram&#39;s Finite Field Crypto Parameters" />
  <psc:chapter start="16:22" title="Cryptographic Protocol Vulnerabilities and Concerns" />
  <psc:chapter start="27:35" title="Messaging Protocol Security Concerns" />
  <psc:chapter start="31:49" title="Modern Messaging Protocol Security Evaluation" />
  <psc:chapter start="35:42" title="Inadequacies of IGE Encryption Mode" />
  <psc:chapter start="45:29" title="Encrypted Messaging Protocol Vulnerabilities" />
  <psc:chapter start="59:08" title="Cross-Border Legal System Comparison" />
</psc:chapters>
    <itunes:duration>3844</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Summertime Sadness</itunes:title>
    <title>Summertime Sadness</title>
    <itunes:summary><![CDATA[Are you going to be in Vegas during BlackHat / DEF CON? We're hosting a mixer, sponsored by Observa! We have limited capacity, so please only register if you can actually come. Location details are in the confirmation email. Tickets will be released in batches, so if you get waitlisted, there's a good chance you still get in. Looking forward to seeing you in Vegas!  Ticket Link: https://www.eventbrite.com/e/scwpod-vegas-2024-tickets-946939099337  We talk about CrowdStrike in this episode, but...]]></itunes:summary>
    <description><![CDATA[<p>Are you going to be in Vegas during BlackHat / DEF CON? We&apos;re hosting a mixer, sponsored by <a href='https://observa.com'>Observa</a>! We have limited capacity, so please only register if you can actually come. Location details are in the confirmation email. Tickets will be released in batches, so if you get waitlisted, there&apos;s a good chance you still get in. Looking forward to seeing you in Vegas!<br/><br/>Ticket Link: <a href='https://www.eventbrite.com/e/scwpod-vegas-2024-tickets-946939099337'>https://www.eventbrite.com/e/scwpod-vegas-2024-tickets-946939099337</a><br/><br/>We talk about CrowdStrike in this episode, but we know we made some mistakes:</p><ul><li>The sys files may be code in addition to data.</li><li>The bug might be bigger than &quot;just&quot; a null pointer exception.</li></ul><p>Luckily, none of that is actually relevant to the main issues we discuss.</p><p>Show page: https://securitycryptographywhatever.com/2024/07/24/summertime-sadness/<br/><br/>Other Links:</p><ul><li><a href='https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization'>https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization</a></li><li><a href='https://dadrian.io/blog/posts/pqc-signatures-2024/'>https://dadrian.io/blog/posts/pqc-signatures-2024/</a></li><li><a href='https://dadrian.io/blog/posts/cto/'>https://dadrian.io/blog/posts/cto/</a></li><li><a href='https://www.blackhat.com/us-24/briefings/schedule/'>https://www.blackhat.com/us-24/briefings/schedule/</a></li><li><a href='https://terrapin-attack.com/'>https://terrapin-attack.com/</a></li><li><a href='https://www.youtube.com/watch?v=-AqayGm0_pw'>https://www.youtube.com/watch?v=-AqayGm0_pw</a></li></ul><p>More like ClownStrike, amirite?</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Are you going to be in Vegas during BlackHat / DEF CON? We&apos;re hosting a mixer, sponsored by <a href='https://observa.com'>Observa</a>! We have limited capacity, so please only register if you can actually come. Location details are in the confirmation email. Tickets will be released in batches, so if you get waitlisted, there&apos;s a good chance you still get in. Looking forward to seeing you in Vegas!<br/><br/>Ticket Link: <a href='https://www.eventbrite.com/e/scwpod-vegas-2024-tickets-946939099337'>https://www.eventbrite.com/e/scwpod-vegas-2024-tickets-946939099337</a><br/><br/>We talk about CrowdStrike in this episode, but we know we made some mistakes:</p><ul><li>The sys files may be code in addition to data.</li><li>The bug might be bigger than &quot;just&quot; a null pointer exception.</li></ul><p>Luckily, none of that is actually relevant to the main issues we discuss.</p><p>Show page: https://securitycryptographywhatever.com/2024/07/24/summertime-sadness/<br/><br/>Other Links:</p><ul><li><a href='https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization'>https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization</a></li><li><a href='https://dadrian.io/blog/posts/pqc-signatures-2024/'>https://dadrian.io/blog/posts/pqc-signatures-2024/</a></li><li><a href='https://dadrian.io/blog/posts/cto/'>https://dadrian.io/blog/posts/cto/</a></li><li><a href='https://www.blackhat.com/us-24/briefings/schedule/'>https://www.blackhat.com/us-24/briefings/schedule/</a></li><li><a href='https://terrapin-attack.com/'>https://terrapin-attack.com/</a></li><li><a href='https://www.youtube.com/watch?v=-AqayGm0_pw'>https://www.youtube.com/watch?v=-AqayGm0_pw</a></li></ul><p>More like ClownStrike, amirite?</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/15471031-summertime-sadness.mp3" length="41381828" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2024/07/24/summertime-sadness/</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15471031</guid>
    <pubDate>Wed, 24 Jul 2024 21:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15471031/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15471031/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15471031/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15471031/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/15471031/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Vegas Party" />
  <psc:chapter start="2:55" title="Crowdstrike" />
  <psc:chapter start="28:00" title="NIST Standards" />
  <psc:chapter start="38:00" title="BlackHat" />
</psc:chapters>
    <itunes:duration>3446</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Zero Day Markets with Mark Dowd</itunes:title>
    <title>Zero Day Markets with Mark Dowd</title>
    <itunes:summary><![CDATA[We have Mark Dowd on, founder of Aziumuth Security and one of the authors of The Art of Software Security Assessment, to talk about the market for zero day vulnerabilities, and how mitigations affect monetizing offensive security work.  Transcript: https://securitycryptographywhatever.com/2024/06/24/mdowd/  Links: https://www.azimuthsecurity.com/https://www.vigilantlabs.com/https://github.com/mdowd79/presentations/blob/main/bluehat2023-mdowd-final.pdfhttps://i.blackhat.com/USA21/Wednesday-Han...]]></itunes:summary>
    <description><![CDATA[<p>We have Mark Dowd on, founder of Aziumuth Security and one of the authors of The Art of Software Security Assessment, to talk about the market for zero day vulnerabilities, and how mitigations affect monetizing offensive security work.<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/06/24/mdowd/<br/><br/>Links:</p><ul><li><a href='https://www.azimuthsecurity.com/'>https://www.azimuthsecurity.com/</a></li><li><a href='https://www.vigilantlabs.com/'>https://www.vigilantlabs.com/</a></li><li><a href='https://github.com/mdowd79/presentations/blob/main/bluehat2023-mdowd-final.pdf'>https://github.com/mdowd79/presentations/blob/main/bluehat2023-mdowd-final.pdf</a></li><li><a href='https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Hack-Different-Pwning-IOS-14-With-Generation-Z-Bug-wp.pdf'>https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Hack-Different-Pwning-IOS-14-With-Generation-Z-Bug-wp.pdf</a></li><li><a href='https://i.blackhat.com/USA-19/Wednesday/us-19-Shwartz-Selling-0-Days-To-Governments-And-Offensive-Security-Companies.pdf'>https://i.blackhat.com/USA-19/Wednesday/us-19-Shwartz-Selling-0-Days-To-Governments-And-Offensive-Security-Companies.pdf</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We have Mark Dowd on, founder of Aziumuth Security and one of the authors of The Art of Software Security Assessment, to talk about the market for zero day vulnerabilities, and how mitigations affect monetizing offensive security work.<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/06/24/mdowd/<br/><br/>Links:</p><ul><li><a href='https://www.azimuthsecurity.com/'>https://www.azimuthsecurity.com/</a></li><li><a href='https://www.vigilantlabs.com/'>https://www.vigilantlabs.com/</a></li><li><a href='https://github.com/mdowd79/presentations/blob/main/bluehat2023-mdowd-final.pdf'>https://github.com/mdowd79/presentations/blob/main/bluehat2023-mdowd-final.pdf</a></li><li><a href='https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Hack-Different-Pwning-IOS-14-With-Generation-Z-Bug-wp.pdf'>https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Hack-Different-Pwning-IOS-14-With-Generation-Z-Bug-wp.pdf</a></li><li><a href='https://i.blackhat.com/USA-19/Wednesday/us-19-Shwartz-Selling-0-Days-To-Governments-And-Offensive-Security-Companies.pdf'>https://i.blackhat.com/USA-19/Wednesday/us-19-Shwartz-Selling-0-Days-To-Governments-And-Offensive-Security-Companies.pdf</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/15301528-zero-day-markets-with-mark-dowd.mp3" length="61814226" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2024/06/24/mdowd/</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15301528</guid>
    <pubDate>Mon, 24 Jun 2024 08:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15301528/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15301528/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15301528/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15301528/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/15301528/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Mark Dowd" />
  <psc:chapter start="1:03:20" title="After Dark" />
</psc:chapters>
    <itunes:duration>5149</itunes:duration>
    <itunes:keywords>vulnerability,security,zero day,hacking,markets,intelligence,mdowd</itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>ekr</itunes:title>
    <title>ekr</title>
    <itunes:summary><![CDATA[iykyk  Transcript: https://securitycryptographywhatever.com/2024/05/25/ekr/  Links: - https://hovav.net/ucsd/dist/draft-shacham-tls-fasttrack-00.txt - https://crypto.stanford.edu/~dabo/pubs/papers/fasttrack.pdf - https://datatracker.ietf.org/doc/html/rfc8446 - SoK: SCT Auditing in Certificate Transparency: https://arxiv.org/pdf/2203.01661 - A hard look at Certificate Transparency, Part I: Transparency Systems: https://educatedguesswork.org/posts/transparency-part-1/ - A hard look at Certifica...]]></itunes:summary>
    <description><![CDATA[<p>iykyk<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/05/25/ekr/<br/><br/>Links:<br/>- https://hovav.net/ucsd/dist/draft-shacham-tls-fasttrack-00.txt<br/>- https://crypto.stanford.edu/~dabo/pubs/papers/fasttrack.pdf<br/>- https://datatracker.ietf.org/doc/html/rfc8446<br/>- SoK: SCT Auditing in Certificate Transparency: https://arxiv.org/pdf/2203.01661<br/>- A hard look at Certificate Transparency, Part I: Transparency Systems: https://educatedguesswork.org/posts/transparency-part-1/<br/>- A hard look at Certificate Transparency: CT in Reality: https://educatedguesswork.org/posts/transparency-part-2/<br/>- E2EE on the web: is the web really that bad? https://emilymstark.com/2024/02/09/e2ee-on-the-web-is-the-web-really-that-bad.html<br/>- Launching Default End-to-End Encryption on Messenger: https://about.fb.com/news/2023/12/default-end-to-end-encryption-on-messenger/<br/>- ekr&apos;s newsletter: https://educatedguesswork.org<br/>- Over 25 years of ekr RFCs: https://www.rfc-editor.org/search/rfc_search_detail.php?sortkey=Date&amp;sorting=DESC&amp;page=All&amp;author=rescorla&amp;pubstatus[]=Any&amp;pub_date_type=any<br/><br/>Subscribe to his newsletter at <a href='https://educatedguesswork.org/'>https://educatedguesswork.org/</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>iykyk<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/05/25/ekr/<br/><br/>Links:<br/>- https://hovav.net/ucsd/dist/draft-shacham-tls-fasttrack-00.txt<br/>- https://crypto.stanford.edu/~dabo/pubs/papers/fasttrack.pdf<br/>- https://datatracker.ietf.org/doc/html/rfc8446<br/>- SoK: SCT Auditing in Certificate Transparency: https://arxiv.org/pdf/2203.01661<br/>- A hard look at Certificate Transparency, Part I: Transparency Systems: https://educatedguesswork.org/posts/transparency-part-1/<br/>- A hard look at Certificate Transparency: CT in Reality: https://educatedguesswork.org/posts/transparency-part-2/<br/>- E2EE on the web: is the web really that bad? https://emilymstark.com/2024/02/09/e2ee-on-the-web-is-the-web-really-that-bad.html<br/>- Launching Default End-to-End Encryption on Messenger: https://about.fb.com/news/2023/12/default-end-to-end-encryption-on-messenger/<br/>- ekr&apos;s newsletter: https://educatedguesswork.org<br/>- Over 25 years of ekr RFCs: https://www.rfc-editor.org/search/rfc_search_detail.php?sortkey=Date&amp;sorting=DESC&amp;page=All&amp;author=rescorla&amp;pubstatus[]=Any&amp;pub_date_type=any<br/><br/>Subscribe to his newsletter at <a href='https://educatedguesswork.org/'>https://educatedguesswork.org/</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/15130093-ekr.mp3" length="77974526" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-15130093</guid>
    <pubDate>Fri, 24 May 2024 11:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15130093/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15130093/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15130093/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/15130093/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/15130093/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="ekr" />
  <psc:chapter start="0:12" title="History of Internet Security Protocols" />
  <psc:chapter start="5:52" title="Evolution of TLS Protocol Version" />
  <psc:chapter start="15:23" title="Evolution of TLS and Security" />
  <psc:chapter start="25:35" title="Certificate Transparency Design and Implementation" />
  <psc:chapter start="36:28" title="Advancements in Private Information Retrieval" />
  <psc:chapter start="40:30" title="Complexities of Certificate Transparency Implementation" />
  <psc:chapter start="48:06" title="Design Constraints in Digital Signatures" />
  <psc:chapter start="58:02" title="Challenges in Internet Security and DNS" />
  <psc:chapter start="1:09:48" title="Post-Quantum Cryptography and Adoption Trends" />
  <psc:chapter start="1:23:14" title="Binary Transparency and Security Models" />
  <psc:chapter start="1:35:29" title="Security Measures for Web Applications" />
</psc:chapters>
    <itunes:duration>6496</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>STIR/SHAKEN with Paul Grubbs and Josh Brown</itunes:title>
    <title>STIR/SHAKEN with Paul Grubbs and Josh Brown</title>
    <itunes:summary><![CDATA[Josh Brown and Paul Grubbs join us to describe how those damned spam calls work, and how STIR/SHAKEN is supposed to try to stop them, but have other privacy and security implications as well.   Transcript: https://securitycryptographywhatever.com/2024/04/30/stir-shaken/  Links:  - https://iacr.org/submit/files/slides/2024/rwc/rwc2024/98/slides.pdf - https://www.youtube.com/watch?v=3trxXF0-fRU - Paul Grubbs: https://web.eecs.umich.edu/~paulgrub/  "Security Cryptography Whatever" is h...]]></itunes:summary>
    <description><![CDATA[<p>Josh Brown and Paul Grubbs join us to describe how those damned spam calls work, and how STIR/SHAKEN is supposed to try to stop them, but have other privacy and security implications as well. <br/><br/>Transcript: https://securitycryptographywhatever.com/2024/04/30/stir-shaken/<br/><br/>Links: <br/>- https://iacr.org/submit/files/slides/2024/rwc/rwc2024/98/slides.pdf<br/>- https://www.youtube.com/watch?v=3trxXF0-fRU<br/>- Paul Grubbs: https://web.eecs.umich.edu/~paulgrub/</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Josh Brown and Paul Grubbs join us to describe how those damned spam calls work, and how STIR/SHAKEN is supposed to try to stop them, but have other privacy and security implications as well. <br/><br/>Transcript: https://securitycryptographywhatever.com/2024/04/30/stir-shaken/<br/><br/>Links: <br/>- https://iacr.org/submit/files/slides/2024/rwc/rwc2024/98/slides.pdf<br/>- https://www.youtube.com/watch?v=3trxXF0-fRU<br/>- Paul Grubbs: https://web.eecs.umich.edu/~paulgrub/</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/14984222-stir-shaken-with-paul-grubbs-and-josh-brown.mp3" length="44508713" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-14984222</guid>
    <pubDate>Tue, 30 Apr 2024 12:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14984222/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14984222/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14984222/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14984222/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/14984222/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="STIR/SHAKEN with Paul Grubbs and Josh Brown" />
  <psc:chapter start="0:12" title="Combatting Robocall Scams With Stir-Shaken" />
  <psc:chapter start="6:10" title="Telephone Network Protocols and Security" />
  <psc:chapter start="20:48" title="Phone Call Authentication and Deniability" />
  <psc:chapter start="31:38" title="Protocol Issues in Telephone Networks" />
  <psc:chapter start="38:26" title="Telecom Privacy Risks in Metadata Sharing" />
  <psc:chapter start="48:41" title="Challenges and Solutions in PKI" />
  <psc:chapter start="53:01" title="Certificate Transparency and Security Improvements" />
</psc:chapters>
    <itunes:duration>3707</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cryptography Tier List</itunes:title>
    <title>Cryptography Tier List</title>
    <itunes:summary><![CDATA[(NSFW) Three AI-generated guests rank cryptography things into a tier list. Play along at home and make your own tier list: https://tiermaker.com/create/cryptography-15683166  This episode is definitely not safe for work and definitely a parody. Do not base your decision in the 2024 election off of this podcast episode. No campaigns have endorsed this podcast.  "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian) ]]></itunes:summary>
    <description><![CDATA[<p>(NSFW) Three AI-generated guests rank cryptography things into a tier list. Play along at home and make your own tier list: https://tiermaker.com/create/cryptography-15683166<br/><br/>This episode is definitely not safe for work and definitely a parody. Do not base your decision in the 2024 election off of this podcast episode. No campaigns have endorsed this podcast.</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>(NSFW) Three AI-generated guests rank cryptography things into a tier list. Play along at home and make your own tier list: https://tiermaker.com/create/cryptography-15683166<br/><br/>This episode is definitely not safe for work and definitely a parody. Do not base your decision in the 2024 election off of this podcast episode. No campaigns have endorsed this podcast.</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/14749105-cryptography-tier-list.mp3" length="14046265" type="audio/mpeg" />
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14749105</guid>
    <pubDate>Sat, 23 Mar 2024 02:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14749105/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14749105/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14749105/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14749105/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/14749105/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Cryptography Tier List" />
  <psc:chapter start="0:04" title="Modern Cryptography Tier List Discussion" />
  <psc:chapter start="11:24" title="Ranking Cryptographic Concepts and Algorithms" />
</psc:chapters>
    <itunes:duration>1168</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>bonus</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Post-Quantum iMessage with Douglas Stebila</itunes:title>
    <title>Post-Quantum iMessage with Douglas Stebila</title>
    <itunes:summary><![CDATA[Apple iMessage is getting a big upgrade! Not only are they rolling out ratcheting, but they’re going post-quantum, AND they’re doing post-quantum ratcheting! Douglas Stebila joined us to talk about his security analysis of the new PQ3 protocol update and not indulge our wild Apple speculations:  Transcript: https://securitycryptographywhatever.com/2024/03/03/post-quantum-imessage-with-douglas-stebila/  Links: - https://security.apple.com/blog/imessage-pq3/ - Security analysis of the iMessage ...]]></itunes:summary>
    <description><![CDATA[<p>Apple iMessage is getting a big upgrade! Not only are they rolling out ratcheting, but they’re going post-quantum, AND they’re doing post-quantum ratcheting! Douglas Stebila joined us to talk about his security analysis of the new PQ3 protocol update and not indulge our wild Apple speculations:<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/03/03/post-quantum-imessage-with-douglas-stebila/<br/><br/>Links:<br/>- https://security.apple.com/blog/imessage-pq3/<br/>- Security analysis of the iMessage PQ3 protocol<br/>https://security.apple.com/assets/files/A_Formal_Analysis_of_the_iMessage_PQ3_Messaging_Protocol_Basin_et_al.pdf<br/>- Ratcheting design: https://eprint.iacr.org/2024/220.pdf<br/>- When Messages are Keys: Is HMAC a dual-PRF?: https://eprint.iacr.org/2023/861.pdf<br/>- Real World Deniability in Messaging: https://eprint.iacr.org/2023/403.pdf<br/>- Padmé: https://www.petsymposium.org/2019/files/papers/issue4/popets-2019-0056.pdf<br/>- Max Headroom: https://www.youtube.com/watch?v=cYdpOjletnc<br/>- Extended Canetti-Krawczyk model: https://iacr.org/archive/eurocrypt2001/20450451.pdf<br/>- Douglas Stebila: https://www.douglas.stebila.ca/<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Apple iMessage is getting a big upgrade! Not only are they rolling out ratcheting, but they’re going post-quantum, AND they’re doing post-quantum ratcheting! Douglas Stebila joined us to talk about his security analysis of the new PQ3 protocol update and not indulge our wild Apple speculations:<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/03/03/post-quantum-imessage-with-douglas-stebila/<br/><br/>Links:<br/>- https://security.apple.com/blog/imessage-pq3/<br/>- Security analysis of the iMessage PQ3 protocol<br/>https://security.apple.com/assets/files/A_Formal_Analysis_of_the_iMessage_PQ3_Messaging_Protocol_Basin_et_al.pdf<br/>- Ratcheting design: https://eprint.iacr.org/2024/220.pdf<br/>- When Messages are Keys: Is HMAC a dual-PRF?: https://eprint.iacr.org/2023/861.pdf<br/>- Real World Deniability in Messaging: https://eprint.iacr.org/2023/403.pdf<br/>- Padmé: https://www.petsymposium.org/2019/files/papers/issue4/popets-2019-0056.pdf<br/>- Max Headroom: https://www.youtube.com/watch?v=cYdpOjletnc<br/>- Extended Canetti-Krawczyk model: https://iacr.org/archive/eurocrypt2001/20450451.pdf<br/>- Douglas Stebila: https://www.douglas.stebila.ca/<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/14619578-post-quantum-imessage-with-douglas-stebila.mp3" length="40032015" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-14619578</guid>
    <pubDate>Sun, 03 Mar 2024 16:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14619578/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14619578/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14619578/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14619578/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/14619578/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Post-Quantum iMessage with Douglas Stebila" />
  <psc:chapter start="0:12" title="Apple&#39;s Post-Quantum iMessage Security Analysis" />
  <psc:chapter start="17:08" title="Hybrid Key Agreement Protocols and Security" />
  <psc:chapter start="27:47" title="Cryptographic Deniability in Messaging" />
  <psc:chapter start="39:36" title="Messaging Security Protocol Updates" />
</psc:chapters>
    <itunes:duration>3334</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>High-assurance Post-Quantum Crypto with Franziskus Kiefer and Karthik Bhargavan</itunes:title>
    <title>High-assurance Post-Quantum Crypto with Franziskus Kiefer and Karthik Bhargavan</title>
    <itunes:summary><![CDATA[We welcome Franziskus and Karthik from Cryspen to discuss their new high-assurance implementation of ML-KEM (the final form of Kyber), discussing how formal methods can both help provide correctness guarantees, security assurances, and performance wins for your crypto code!  Transcript: https://securitycryptographywhatever.com/2024/01/29/high-assurance-kyber/  Links:  - https://cryspen.com/post/ml-kem-implementation/ - https://github.com/cryspen/libcrux/ - https://github.com/formosa-crypto/li...]]></itunes:summary>
    <description><![CDATA[<p>We welcome Franziskus and Karthik from Cryspen to discuss their new high-assurance implementation of ML-KEM (the final form of Kyber), discussing how formal methods can both help provide correctness guarantees, security assurances, and performance wins for your crypto code!<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/01/29/high-assurance-kyber/<br/><br/>Links:<br/><br/>- https://cryspen.com/post/ml-kem-implementation/<br/>- https://github.com/cryspen/libcrux/<br/>- https://github.com/formosa-crypto/libjade<br/>- https://cryspen.com/post/pqxdh/<br/>- https://eprint.iacr.org/2023/1933.pdf<br/>- Franziskus Kiefer: https://franziskuskiefer.de/<br/>- Karthik Bhargavan: https://bhargavan.info/</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We welcome Franziskus and Karthik from Cryspen to discuss their new high-assurance implementation of ML-KEM (the final form of Kyber), discussing how formal methods can both help provide correctness guarantees, security assurances, and performance wins for your crypto code!<br/><br/>Transcript: https://securitycryptographywhatever.com/2024/01/29/high-assurance-kyber/<br/><br/>Links:<br/><br/>- https://cryspen.com/post/ml-kem-implementation/<br/>- https://github.com/cryspen/libcrux/<br/>- https://github.com/formosa-crypto/libjade<br/>- https://cryspen.com/post/pqxdh/<br/>- https://eprint.iacr.org/2023/1933.pdf<br/>- Franziskus Kiefer: https://franziskuskiefer.de/<br/>- Karthik Bhargavan: https://bhargavan.info/</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/14401626-high-assurance-post-quantum-crypto-with-franziskus-kiefer-and-karthik-bhargavan.mp3" length="40500626" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-14401626</guid>
    <pubDate>Mon, 29 Jan 2024 18:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14401626/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14401626/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14401626/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14401626/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/14401626/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="High-assurance Post-Quantum Crypto with Franziskus Kiefer and Karthik Bhargavan" />
  <psc:chapter start="0:12" title="ML-KEM Implementation in Rust" />
  <psc:chapter start="11:55" title="High-assurance Software Development" />
  <psc:chapter start="19:07" title="Understanding Secret Independence and Crypto Proofs" />
  <psc:chapter start="30:45" title="Vulnerabilities in ML-KEM Encryption Process" />
  <psc:chapter start="43:02" title="Protocol Design" />
  <psc:chapter start="49:17" title="Transitioning to Rust and Post-Quantum Cryptography" />
</psc:chapters>
    <itunes:duration>3373</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Encrypting Facebook Messenger with Jon Millican and Timothy Buck</itunes:title>
    <title>Encrypting Facebook Messenger with Jon Millican and Timothy Buck</title>
    <itunes:summary><![CDATA[Facebook Messenger has finally been end-to-end encrypted, a couple of years after Mark Zuckerberg announced it! Plus Instagram DMs are trialing ephemeral E2EE DMs too! We invited on Jon Millican and Timothy Buck from Meta to discuss this major cross-platform endeavor, and how David Bowie fits into their personal Labyrinth.  Transcript: https://securitycryptographywhatever.com/2023/12/28/e2ee-fb-messenger/  Links:  - https://www.facebook.com/notes/2420600258234172 - https://eprint.iacr.org/202...]]></itunes:summary>
    <description><![CDATA[<p>Facebook Messenger has finally been end-to-end encrypted, a couple of years after Mark Zuckerberg announced it! Plus Instagram DMs are trialing ephemeral E2EE DMs too! We invited on Jon Millican and Timothy Buck from Meta to discuss this major cross-platform endeavor, and how David Bowie fits into their personal Labyrinth.<br/><br/>Transcript: https://securitycryptographywhatever.com/2023/12/28/e2ee-fb-messenger/<br/><br/>Links:<br/><br/>- https://www.facebook.com/notes/2420600258234172<br/>- https://eprint.iacr.org/2022/1044.pdf<br/>- https://engineering.fb.com/2023/12/06/security/building-end-to-end-security-for-messenger/<br/>- https://www.theverge.com/2023/12/6/23991501/facebook-messenger-default-end-to-end-encryption-meta<br/>- https://www.threads.net/@jonmillican/post/C0kQPAyoFpr<br/>- https://engineering.fb.com/wp-content/uploads/2023/12/MessengerEnd-to-EndEncryptionOverview_12-6-2023.pdf<br/>- https://engineering.fb.com/wp-content/uploads/2023/12/TheLabyrinthEncryptedMessageStorageProtocol_12-6-2023.pdf<br/>- https://engineering.fb.com/2022/03/10/security/code-verify/<br/>- https://chrome.google.com/webstore/detail/code-verify/llohflklppcaghdpehpbklhlfebooeog</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Facebook Messenger has finally been end-to-end encrypted, a couple of years after Mark Zuckerberg announced it! Plus Instagram DMs are trialing ephemeral E2EE DMs too! We invited on Jon Millican and Timothy Buck from Meta to discuss this major cross-platform endeavor, and how David Bowie fits into their personal Labyrinth.<br/><br/>Transcript: https://securitycryptographywhatever.com/2023/12/28/e2ee-fb-messenger/<br/><br/>Links:<br/><br/>- https://www.facebook.com/notes/2420600258234172<br/>- https://eprint.iacr.org/2022/1044.pdf<br/>- https://engineering.fb.com/2023/12/06/security/building-end-to-end-security-for-messenger/<br/>- https://www.theverge.com/2023/12/6/23991501/facebook-messenger-default-end-to-end-encryption-meta<br/>- https://www.threads.net/@jonmillican/post/C0kQPAyoFpr<br/>- https://engineering.fb.com/wp-content/uploads/2023/12/MessengerEnd-to-EndEncryptionOverview_12-6-2023.pdf<br/>- https://engineering.fb.com/wp-content/uploads/2023/12/TheLabyrinthEncryptedMessageStorageProtocol_12-6-2023.pdf<br/>- https://engineering.fb.com/2022/03/10/security/code-verify/<br/>- https://chrome.google.com/webstore/detail/code-verify/llohflklppcaghdpehpbklhlfebooeog</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/14197135-encrypting-facebook-messenger-with-jon-millican-and-timothy-buck.mp3" length="42930845" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-14197135</guid>
    <pubDate>Thu, 28 Dec 2023 17:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14197135/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14197135/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14197135/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/14197135/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/14197135/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Encrypting Facebook Messenger with Jon Millican and Timothy Buck" />
  <psc:chapter start="0:12" title="Facebook Messenger and Instagram DMs" />
  <psc:chapter start="12:51" title="Labyrinth and Cryptographic User Experience" />
  <psc:chapter start="20:34" title="Understanding Cryptographic Labels and ORF" />
  <psc:chapter start="33:10" title="Emerging Trends in Encryption Design" />
  <psc:chapter start="44:41" title="Code Verify Extension and Instagram DMs" />
  <psc:chapter start="50:56" title="Discussion on Post-Quantum Security and Encryption" />
</psc:chapters>
    <itunes:duration>3575</itunes:duration>
    <itunes:keywords>cryptography, security, messaging, facebook, meta, instagram, dms, labyrinth</itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Attacking Lattice-based Cryptography with Martin Albrecht</itunes:title>
    <title>Attacking Lattice-based Cryptography with Martin Albrecht</title>
    <itunes:summary><![CDATA[Returning champion Martin Albrecht joins us to help explain how we measure the security of lattice-based cryptosystems like Kyber and Dilithium against attackers. QRAM, BKZ, LLL, oh my!  Transcript: https://securitycryptographywhatever.com/2023/11/13/lattice-attacks/  Links:  - https://pq-crystals.org/kyber/index.shtml - https://pq-crystals.org/dilithium/index.shtml - https://eprint.iacr.org/2019/930.pdf - https://en.wikipedia.org/wiki/Short_integer_solution_problem - Frodo: https://eprint.ia...]]></itunes:summary>
    <description><![CDATA[<p>Returning champion Martin Albrecht joins us to help explain how we measure the security of lattice-based cryptosystems like Kyber and Dilithium against attackers. QRAM, BKZ, LLL, oh my!<br/><br/>Transcript: https://securitycryptographywhatever.com/2023/11/13/lattice-attacks/<br/><br/>Links:<br/><br/>- https://pq-crystals.org/kyber/index.shtml<br/>- https://pq-crystals.org/dilithium/index.shtml<br/>- https://eprint.iacr.org/2019/930.pdf<br/>- https://en.wikipedia.org/wiki/Short_integer_solution_problem<br/>- Frodo: https://eprint.iacr.org/2016/659<br/>- https://csrc.nist.gov/CSRC/media/Events/third-pqc-standardization-conference/documents/accepted-papers/ribeiro-saber-pq-key-pqc2021.pdf<br/>- https://en.wikipedia.org/wiki/Hermite_normal_form<br/>- https://en.wikipedia.org/wiki/Wagner%E2%80%93Fischer_algorithm<br/>- https://www.math.auckland.ac.nz/~sgal018/crypto-book/ch18.pdf<br/>- https://eprint.iacr.org/2019/1161<br/>- QRAM: https://arxiv.org/abs/2305.10310<br/>- https://en.wikipedia.org/wiki/Lenstra%E2%80%93Lenstra%E2%80%93Lov%C3%A1sz_lattice_basis_reduction_algorithm<br/>- MATZOV improved dual lattice attack: https://zenodo.org/records/6412487<br/>- https://eprint.iacr.org/2008/504.pdf<br/>- https://eprint.iacr.org/2023/302.pdf</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Returning champion Martin Albrecht joins us to help explain how we measure the security of lattice-based cryptosystems like Kyber and Dilithium against attackers. QRAM, BKZ, LLL, oh my!<br/><br/>Transcript: https://securitycryptographywhatever.com/2023/11/13/lattice-attacks/<br/><br/>Links:<br/><br/>- https://pq-crystals.org/kyber/index.shtml<br/>- https://pq-crystals.org/dilithium/index.shtml<br/>- https://eprint.iacr.org/2019/930.pdf<br/>- https://en.wikipedia.org/wiki/Short_integer_solution_problem<br/>- Frodo: https://eprint.iacr.org/2016/659<br/>- https://csrc.nist.gov/CSRC/media/Events/third-pqc-standardization-conference/documents/accepted-papers/ribeiro-saber-pq-key-pqc2021.pdf<br/>- https://en.wikipedia.org/wiki/Hermite_normal_form<br/>- https://en.wikipedia.org/wiki/Wagner%E2%80%93Fischer_algorithm<br/>- https://www.math.auckland.ac.nz/~sgal018/crypto-book/ch18.pdf<br/>- https://eprint.iacr.org/2019/1161<br/>- QRAM: https://arxiv.org/abs/2305.10310<br/>- https://en.wikipedia.org/wiki/Lenstra%E2%80%93Lenstra%E2%80%93Lov%C3%A1sz_lattice_basis_reduction_algorithm<br/>- MATZOV improved dual lattice attack: https://zenodo.org/records/6412487<br/>- https://eprint.iacr.org/2008/504.pdf<br/>- https://eprint.iacr.org/2023/302.pdf</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/13962690-attacking-lattice-based-cryptography-with-martin-albrecht.mp3" length="41302821" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-13962690</guid>
    <pubDate>Mon, 13 Nov 2023 12:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13962690/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13962690/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13962690/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13962690/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/13962690/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Attacking Lattice-based Cryptography with Martin Albrecht" />
  <psc:chapter start="0:12" title="Analyzing the Security of Post-Quantum Cryptography" />
  <psc:chapter start="13:13" title="Finding Short Vectors in Lattices" />
  <psc:chapter start="19:11" title="Quantum Speedup in Cryptography" />
  <psc:chapter start="28:13" title="Understanding and Applying BKZ Algorithm" />
  <psc:chapter start="37:38" title="Lattice-Based Cryptanalysis and Improvements" />
  <psc:chapter start="46:57" title="RAM and Storage in Classical Attacks" />
  <psc:chapter start="52:49" title="Discussion on AES Quantum Computing Costs" />
</psc:chapters>
    <itunes:duration>3440</itunes:duration>
    <itunes:keywords>cryptography, security, post-quantum, lattices, attacks, sieves, LLL</itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Signal&#39;s Post-Quantum PQXDH, Same-Origin Policy, E2EE in the Browser Revisted</itunes:title>
    <title>Signal&#39;s Post-Quantum PQXDH, Same-Origin Policy, E2EE in the Browser Revisted</title>
    <itunes:summary><![CDATA[We're back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.  Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc  Links:  - https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/ - https://...]]></itunes:summary>
    <description><![CDATA[<p>We&apos;re back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.<br/><br/>Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc<br/><br/>Links:<br/><br/>- https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/<br/>- https://github.com/superfly/macaroon<br/>- https://cryspen.com/post/pqxdh/<br/>- https://eprint.iacr.org/2023/1390.pdf</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We&apos;re back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.<br/><br/>Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc<br/><br/>Links:<br/><br/>- https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/<br/>- https://github.com/superfly/macaroon<br/>- https://cryspen.com/post/pqxdh/<br/>- https://eprint.iacr.org/2023/1390.pdf</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/13924833-signal-s-post-quantum-pqxdh-same-origin-policy-e2ee-in-the-browser-revisted.mp3" length="56963594" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-13924833</guid>
    <pubDate>Tue, 07 Nov 2023 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13924833/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13924833/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13924833/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13924833/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/13924833/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Issues With Encrypted Jabber Communications" />
  <psc:chapter start="13:53" title="App and Web Security Challenges" />
  <psc:chapter start="22:26" title="Benefits and Limitations of Web Encryption" />
  <psc:chapter start="29:54" title="Benefits and Challenges of Browser-Based Cryptography" />
  <psc:chapter start="35:09" title="Web App Security and Distribution Models" />
  <psc:chapter start="48:36" title="Web Security and Signal Key Exchange" />
  <psc:chapter start="53:49" title="X3DH Protocol and Signal&#39;s Key Exchange" />
  <psc:chapter start="1:08:11" title="Camry Encapsulation Attack and Secure Encryption" />
</psc:chapters>
    <itunes:duration>4745</itunes:duration>
    <itunes:keywords>cryptography, security, signal, post-quantum, hybrid, protocols, same-origin, e2ee, browsers</itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>&#39;Jerry Solinas deserves a raise&#39; with Steve Weis</itunes:title>
    <title>&#39;Jerry Solinas deserves a raise&#39; with Steve Weis</title>
    <itunes:summary><![CDATA[We explore how the NIST curve parameter seeds were generated, as best we can, with returning champion Steve Weis!  “At the point where we find an intelligible English string that generates the NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore.”  Transcript: https://securitycryptographywhatever.com/2023/10/12/the-nist-curves  Links:  - Steve’s post: https://saweis.net/posts/nist-curve-seed-origins.html - ANSI X9.62 ECDSA: https://safecurves.cr.y...]]></itunes:summary>
    <description><![CDATA[<p>We explore how the NIST curve parameter seeds were generated, as best we can, with returning champion Steve Weis!<br/><br/>“At the point where we find an intelligible English string that generates the<br/>NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore.”<br/><br/>Transcript: https://securitycryptographywhatever.com/2023/10/12/the-nist-curves<br/><br/>Links:<br/><br/>- Steve’s post: https://saweis.net/posts/nist-curve-seed-origins.html<br/>- ANSI X9.62 ECDSA: https://safecurves.cr.yp.to/grouper.ieee.org/groups/1363/private/x9-62-09-20-98.pdf / FIPS 186-2 https://csrc.nist.gov/files/pubs/fips/186-2/final/docs/fips186-2.pdf<br/>- “A RIDDLE WRAPPED IN AN ENIGMA”: https://eprint.iacr.org/2015/1018.pdf<br/>- https://arstechnica.com/information-technology/2015/01/nsa-official-support-of-backdoored-dual_ec_drbg-was-regrettable/<br/>- https://www.muckrock.com/foi/united-states-of-america-10/origin-of-fips-186-4-elliptic-curves-over-prime-field-seed-parameters-national-institute-of-standards-and-technology-78756/<br/>- https://www.muckrock.com/foi/united-states-of-america-10/origin-of-fips-186-4-elliptic-curves-over-prime-field-seed-parameters-national-security-agency-78755/<br/>- Filippo’s bounty: https://words.filippo.io/dispatches/seeds-bounty/<br/>- Recommendations for Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters - NIST 800-186 with Curve25519 and friends<br/>- RFC 8422: Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS) Versions 1.2 and Earlier<br/>- https://www.rfc-editor.org/rfc/rfc4492#section-6<br/>- https://blog.cryptographyengineering.com/2017/12/19/the-strange-story-of-extended-random/<br/>- https://en.wikipedia.org/wiki/Bullrun_(decryption_program)<br/>- https://en.wikipedia.org/wiki/BSAFE<br/>- https://sockpuppet.org/blog/2015/08/04/is-extended-random-malicious/</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We explore how the NIST curve parameter seeds were generated, as best we can, with returning champion Steve Weis!<br/><br/>“At the point where we find an intelligible English string that generates the<br/>NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore.”<br/><br/>Transcript: https://securitycryptographywhatever.com/2023/10/12/the-nist-curves<br/><br/>Links:<br/><br/>- Steve’s post: https://saweis.net/posts/nist-curve-seed-origins.html<br/>- ANSI X9.62 ECDSA: https://safecurves.cr.yp.to/grouper.ieee.org/groups/1363/private/x9-62-09-20-98.pdf / FIPS 186-2 https://csrc.nist.gov/files/pubs/fips/186-2/final/docs/fips186-2.pdf<br/>- “A RIDDLE WRAPPED IN AN ENIGMA”: https://eprint.iacr.org/2015/1018.pdf<br/>- https://arstechnica.com/information-technology/2015/01/nsa-official-support-of-backdoored-dual_ec_drbg-was-regrettable/<br/>- https://www.muckrock.com/foi/united-states-of-america-10/origin-of-fips-186-4-elliptic-curves-over-prime-field-seed-parameters-national-institute-of-standards-and-technology-78756/<br/>- https://www.muckrock.com/foi/united-states-of-america-10/origin-of-fips-186-4-elliptic-curves-over-prime-field-seed-parameters-national-security-agency-78755/<br/>- Filippo’s bounty: https://words.filippo.io/dispatches/seeds-bounty/<br/>- Recommendations for Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters - NIST 800-186 with Curve25519 and friends<br/>- RFC 8422: Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS) Versions 1.2 and Earlier<br/>- https://www.rfc-editor.org/rfc/rfc4492#section-6<br/>- https://blog.cryptographyengineering.com/2017/12/19/the-strange-story-of-extended-random/<br/>- https://en.wikipedia.org/wiki/Bullrun_(decryption_program)<br/>- https://en.wikipedia.org/wiki/BSAFE<br/>- https://sockpuppet.org/blog/2015/08/04/is-extended-random-malicious/</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/13763874-jerry-solinas-deserves-a-raise-with-steve-weis.mp3" length="41435392" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-13763874</guid>
    <pubDate>Wed, 11 Oct 2023 23:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13763874/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13763874/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13763874/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13763874/transcript.vtt" type="text/vtt" />
    <itunes:duration>3451</itunes:duration>
    <itunes:keywords>cryptography, security, nsa, nist, elliptic curves, seeds, hashing, backdoors, dual_ec_drbg</itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cruel Summer: hybrid signatures, Downfall, Zenbleed, 2G downgrades</itunes:title>
    <title>Cruel Summer: hybrid signatures, Downfall, Zenbleed, 2G downgrades</title>
    <itunes:summary><![CDATA[We're back from our summer vacation! We're covering a bunch of stuff we saw and did:  Transcript:  https://securitycryptographywhatever.com/2023/09/13/cruel-summer/  Links: - Zenbleed: https://lock.cmpxchg8b.com/zenbleed.html - Downfall: https://downfall.page - Post-quantum Yubikeys: https://security.googleblog.com/2023/08/toward-quantum-resilient-security-keys.html  "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian ...]]></itunes:summary>
    <description><![CDATA[<p>We&apos;re back from our summer vacation! We&apos;re covering a bunch of stuff we saw and did:<br/><br/>Transcript: <br/>https://securitycryptographywhatever.com/2023/09/13/cruel-summer/<br/><br/>Links:<br/>- Zenbleed: https://lock.cmpxchg8b.com/zenbleed.html<br/>- Downfall: https://downfall.page<br/>- Post-quantum Yubikeys: https://security.googleblog.com/2023/08/toward-quantum-resilient-security-keys.html</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We&apos;re back from our summer vacation! We&apos;re covering a bunch of stuff we saw and did:<br/><br/>Transcript: <br/>https://securitycryptographywhatever.com/2023/09/13/cruel-summer/<br/><br/>Links:<br/>- Zenbleed: https://lock.cmpxchg8b.com/zenbleed.html<br/>- Downfall: https://downfall.page<br/>- Post-quantum Yubikeys: https://security.googleblog.com/2023/08/toward-quantum-resilient-security-keys.html</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/13582805-cruel-summer-hybrid-signatures-downfall-zenbleed-2g-downgrades.mp3" length="42207582" type="audio/mpeg" />
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-13582805</guid>
    <pubDate>Wed, 13 Sep 2023 03:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13582805/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13582805/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13582805/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13582805/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/1822302/13582805/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Cruel Summer: hybrid signatures, Downfall, Zenbleed, 2G downgrades" />
  <psc:chapter start="0:01" title="Microarchitectural Vulnerabilities and Cybersecurity Conferences" />
  <psc:chapter start="7:54" title="Discussion on Vulnerabilities" />
  <psc:chapter start="22:32" title="Crypto Attacks and JWT Vulnerabilities" />
  <psc:chapter start="34:12" title="Encryption and Post-Quantum Security Discussion" />
  <psc:chapter start="45:01" title="Post-Quantum Cryptography and Signature Schemes" />
</psc:chapters>
    <itunes:duration>3515</itunes:duration>
    <itunes:keywords>cryptography, hybrid signatures, 2G, downfall, zenbleed, downgrades</itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why do we think anything is secure, with Steve Weis</itunes:title>
    <title>Why do we think anything is secure, with Steve Weis</title>
    <itunes:summary><![CDATA[What does P vs NP have to do with cryptography? Why do people love and laugh about the random oracle model? What's an oracle? What do you mean factoring and discrete log don't have proofs of hardness? How does any of this cryptography stuff work, anyway? We trapped Steve Weis into answering our many questions.  Transcript:  https://securitycryptographywhatever.com/2023/06/29/why-do-we-think-anything-is-secure-with-steve-weis/  Links: - The Random Oracle Methodology, Revisited: https://ep...]]></itunes:summary>
    <description><![CDATA[<p>What does P vs NP have to do with cryptography? Why do people love and laugh about the random oracle model? What&apos;s an oracle? What do you mean factoring and discrete log don&apos;t have proofs of hardness? How does any of this cryptography stuff work, anyway? We trapped Steve Weis into answering our many questions.<br/><br/>Transcript: <br/>https://securitycryptographywhatever.com/2023/06/29/why-do-we-think-anything-is-secure-with-steve-weis/<br/><br/>Links:<br/>- The Random Oracle Methodology, Revisited: https://eprint.iacr.org/1998/011.pdf<br/>- Factoring integers with CADO-NFS: https://www.ens-lyon.fr/LIP/AriC/wp-content/uploads/2015/03/JDetrey-tutorial.pdf<br/>- On One-way Functions from NP-Complete Problems: https://eprint.iacr.org/2021/513.pdf<br/>- Seny Kamara&apos;s lecture notes on provable security: https://cs.brown.edu/~seny/2950-v/2-provablesecurity.pdf<br/>- How To Simulate It – A Tutorial on the Simulation Proof Technique: https://eprint.iacr.org/2016/046.pdf<br/>- A Survey of Leakage-Resilient Cryptography: https://eprint.iacr.org/2019/302<br/>- A Decade of Lattice Cryptography: https://eprint.iacr.org/2015/939.pdf</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>What does P vs NP have to do with cryptography? Why do people love and laugh about the random oracle model? What&apos;s an oracle? What do you mean factoring and discrete log don&apos;t have proofs of hardness? How does any of this cryptography stuff work, anyway? We trapped Steve Weis into answering our many questions.<br/><br/>Transcript: <br/>https://securitycryptographywhatever.com/2023/06/29/why-do-we-think-anything-is-secure-with-steve-weis/<br/><br/>Links:<br/>- The Random Oracle Methodology, Revisited: https://eprint.iacr.org/1998/011.pdf<br/>- Factoring integers with CADO-NFS: https://www.ens-lyon.fr/LIP/AriC/wp-content/uploads/2015/03/JDetrey-tutorial.pdf<br/>- On One-way Functions from NP-Complete Problems: https://eprint.iacr.org/2021/513.pdf<br/>- Seny Kamara&apos;s lecture notes on provable security: https://cs.brown.edu/~seny/2950-v/2-provablesecurity.pdf<br/>- How To Simulate It – A Tutorial on the Simulation Proof Technique: https://eprint.iacr.org/2016/046.pdf<br/>- A Survey of Leakage-Resilient Cryptography: https://eprint.iacr.org/2019/302<br/>- A Decade of Lattice Cryptography: https://eprint.iacr.org/2015/939.pdf</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/13130340-why-do-we-think-anything-is-secure-with-steve-weis.mp3" length="33350653" type="audio/mpeg" />
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-13130340</guid>
    <pubDate>Thu, 29 Jun 2023 03:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13130340/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13130340/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13130340/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/13130340/transcript.vtt" type="text/vtt" />
    <itunes:duration>2777</itunes:duration>
    <itunes:keywords>cryptography, security games, security model, complexity classes, random oracle</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>15</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Elon&#39;s Encrypted DMs with Matthew Garrett</itunes:title>
    <title>Elon&#39;s Encrypted DMs with Matthew Garrett</title>
    <itunes:summary><![CDATA[Are Twitter’s new encrypted DMs unreadable even if you put a gun to Elon’s head? We invited Matthew Garrett on to do a deep decompiled dive into what kind of cryptography actually shipped.  Transcript:  https://securitycryptographywhatever.com/2023/05/29/elons-encrypted-dms-with-matthew-garrett/  Links: https://mjg59.dreamwidth.org/66791.html https://help.twitter.com/en/using-twitter/encrypted-direct-messages https://www.techdirt.com/2023/05/11/twitter-launches-not-actually-encrypted-enc...]]></itunes:summary>
    <description><![CDATA[<p>Are Twitter’s new encrypted DMs unreadable even if you put a gun to Elon’s head? We invited Matthew Garrett on to do a deep decompiled dive into what kind of cryptography actually shipped.<br/><br/>Transcript: <br/>https://securitycryptographywhatever.com/2023/05/29/elons-encrypted-dms-with-matthew-garrett/<br/><br/>Links:<br/>https://mjg59.dreamwidth.org/66791.html<br/>https://help.twitter.com/en/using-twitter/encrypted-direct-messages<br/>https://www.techdirt.com/2023/05/11/twitter-launches-not-actually-encrypted-encrypted-dms/<br/>BrokenKDF2BytesGenerator: https://github.com/bcgit/bc-java/blob/master/prov/src/main/java/org/bouncycastle/jce/provider/BrokenKDF2BytesGenerator.java#L70<br/>Analysis from sweis: https://twitter.com/sweis/status/1657082478727933954?s=20<br/>https://signal.org/docs/specifications/x3dh/<br/>https://signal.org/docs/specifications/doubleratchet/<br/>https://support.signal.org/hc/en-us/articles/360007059752-Backup-and-Restore-Messages<br/>Trail of Bits has not audited nor signed a contract yet, per Platformer: https://www.platformer.news/p/why-you-cant-trust-twitters-encrypted</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Are Twitter’s new encrypted DMs unreadable even if you put a gun to Elon’s head? We invited Matthew Garrett on to do a deep decompiled dive into what kind of cryptography actually shipped.<br/><br/>Transcript: <br/>https://securitycryptographywhatever.com/2023/05/29/elons-encrypted-dms-with-matthew-garrett/<br/><br/>Links:<br/>https://mjg59.dreamwidth.org/66791.html<br/>https://help.twitter.com/en/using-twitter/encrypted-direct-messages<br/>https://www.techdirt.com/2023/05/11/twitter-launches-not-actually-encrypted-encrypted-dms/<br/>BrokenKDF2BytesGenerator: https://github.com/bcgit/bc-java/blob/master/prov/src/main/java/org/bouncycastle/jce/provider/BrokenKDF2BytesGenerator.java#L70<br/>Analysis from sweis: https://twitter.com/sweis/status/1657082478727933954?s=20<br/>https://signal.org/docs/specifications/x3dh/<br/>https://signal.org/docs/specifications/doubleratchet/<br/>https://support.signal.org/hc/en-us/articles/360007059752-Backup-and-Restore-Messages<br/>Trail of Bits has not audited nor signed a contract yet, per Platformer: https://www.platformer.news/p/why-you-cant-trust-twitters-encrypted</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/12939879-elon-s-encrypted-dms-with-matthew-garrett.mp3" length="37805122" type="audio/mpeg" />
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-12939879</guid>
    <pubDate>Mon, 29 May 2023 13:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12939879/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12939879/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12939879/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12939879/transcript.vtt" type="text/vtt" />
    <itunes:duration>3148</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>WhatsApp Key Transparency with Jasleen Malvai and Kevin Lewi</itunes:title>
    <title>WhatsApp Key Transparency with Jasleen Malvai and Kevin Lewi</title>
    <itunes:summary><![CDATA[WhatsApp has announced they’re rolling out key transparency! Doing this at WhatsApp-scale (aka billions and biiillions of keys) is a significant task, so we talked to Jasleen Malvai and Kevin Lewi about how it works.  Transcript:  https://securitycryptographywhatever.com/2023/05/06/whatsapp-key-transparency  Links:  https://engineering.fb.com/2023/04/13/security/whatsapp-key-transparency/ https://github.com/facebook/akd Parkeet: https://eprint.iacr.org/2023/081.pdf CONIKS: https://e...]]></itunes:summary>
    <description><![CDATA[<p>WhatsApp has announced they’re rolling out key transparency! Doing this at WhatsApp-scale (aka billions and biiillions of keys) is a significant task, so we talked to Jasleen Malvai and Kevin Lewi about how it works.<br/><br/>Transcript: <br/>https://securitycryptographywhatever.com/2023/05/06/whatsapp-key-transparency<br/><br/>Links: <br/>https://engineering.fb.com/2023/04/13/security/whatsapp-key-transparency/<br/>https://github.com/facebook/akd<br/>Parkeet: https://eprint.iacr.org/2023/081.pdf<br/>CONIKS: https://eprint.iacr.org/2014/1004.pdf<br/>SEEMless: https://eprint.iacr.org/2018/607.pdf<br/>WhatsApp Security Whitepaper: https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf<br/>Keybase key transparency: https://book.keybase.io/docs/server</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>WhatsApp has announced they’re rolling out key transparency! Doing this at WhatsApp-scale (aka billions and biiillions of keys) is a significant task, so we talked to Jasleen Malvai and Kevin Lewi about how it works.<br/><br/>Transcript: <br/>https://securitycryptographywhatever.com/2023/05/06/whatsapp-key-transparency<br/><br/>Links: <br/>https://engineering.fb.com/2023/04/13/security/whatsapp-key-transparency/<br/>https://github.com/facebook/akd<br/>Parkeet: https://eprint.iacr.org/2023/081.pdf<br/>CONIKS: https://eprint.iacr.org/2014/1004.pdf<br/>SEEMless: https://eprint.iacr.org/2018/607.pdf<br/>WhatsApp Security Whitepaper: https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf<br/>Keybase key transparency: https://book.keybase.io/docs/server</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/12795197-whatsapp-key-transparency-with-jasleen-malvai-and-kevin-lewi.mp3" length="40137661" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-12795197</guid>
    <pubDate>Sat, 06 May 2023 03:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12795197/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12795197/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12795197/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12795197/transcript.vtt" type="text/vtt" />
    <itunes:duration>3343</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>13</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Messaging Layer Security (MLS) with Raphael Robert</itunes:title>
    <title>Messaging Layer Security (MLS) with Raphael Robert</title>
    <itunes:summary><![CDATA[Messaging Layer Security (MLS) 1.0 is (basically) here! We invited Raphael Robert, coauthor of the MLS specification to explain it to us and answer our annoying questions (read: why does this exist?)  Transcript: https://securitycryptographywhatever.com/2023/04/22/mls/  Links: - https://messaginglayersecurity.rocks/ - https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html - https://messaginglayersecurity.rocks/mls-architecture/draft-ietf-mls-architecture.html - https:/...]]></itunes:summary>
    <description><![CDATA[<p>Messaging Layer Security (MLS) 1.0 is (basically) here! We invited Raphael<br/>Robert, coauthor of the MLS specification to explain it to us and answer our annoying questions (read: why does this exist?)<br/><br/>Transcript:<br/>https://securitycryptographywhatever.com/2023/04/22/mls/<br/><br/>Links:<br/>- https://messaginglayersecurity.rocks/<br/>- https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html<br/>- https://messaginglayersecurity.rocks/mls-architecture/draft-ietf-mls-architecture.html<br/>- https://github.com/openmls/openmls<br/>- https://eprint.iacr.org/2022/1533.pdf<br/>- https://eprint.iacr.org/2020/1327.pdf<br/>- https://eprint.iacr.org/2022/559.pdf<br/>- https://signal.org/docs/<br/>- https://en.wikipedia.org/wiki/Key_encapsulation_mechanism<br/>- https://twitter.com/beurdouche/status/1220617962182389760<br/>- https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html#mls-ciphersuites<br/>- https://www.ietf.org/archive/id/draft-ietf-mls-federation-02.html<br/>- https://datatracker.ietf.org/wg/mimi/documents/<br/>- https://competition-policy.ec.europa.eu/dma/dma-workshops/interoperability-workshop_en<br/>- Yes in the protocol document this is 1.0: https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html#section-6</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Messaging Layer Security (MLS) 1.0 is (basically) here! We invited Raphael<br/>Robert, coauthor of the MLS specification to explain it to us and answer our annoying questions (read: why does this exist?)<br/><br/>Transcript:<br/>https://securitycryptographywhatever.com/2023/04/22/mls/<br/><br/>Links:<br/>- https://messaginglayersecurity.rocks/<br/>- https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html<br/>- https://messaginglayersecurity.rocks/mls-architecture/draft-ietf-mls-architecture.html<br/>- https://github.com/openmls/openmls<br/>- https://eprint.iacr.org/2022/1533.pdf<br/>- https://eprint.iacr.org/2020/1327.pdf<br/>- https://eprint.iacr.org/2022/559.pdf<br/>- https://signal.org/docs/<br/>- https://en.wikipedia.org/wiki/Key_encapsulation_mechanism<br/>- https://twitter.com/beurdouche/status/1220617962182389760<br/>- https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html#mls-ciphersuites<br/>- https://www.ietf.org/archive/id/draft-ietf-mls-federation-02.html<br/>- https://datatracker.ietf.org/wg/mimi/documents/<br/>- https://competition-policy.ec.europa.eu/dma/dma-workshops/interoperability-workshop_en<br/>- Yes in the protocol document this is 1.0: https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html#section-6</p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/12703019-messaging-layer-security-mls-with-raphael-robert.mp3" length="39646434" type="audio/mpeg" />
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-12703019</guid>
    <pubDate>Sat, 22 Apr 2023 17:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12703019/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12703019/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12703019/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12703019/transcript.vtt" type="text/vtt" />
    <itunes:duration>3302</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Real World: Crypto (2023)</itunes:title>
    <title>Real World: Crypto (2023)</title>
    <itunes:summary><![CDATA[Real World Cryptography 2023 is happening any moment now in Tokyo. Also, some phone basebands are broken.  Links https://rwc.iacr.org/2023/https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html Transcript: https://securitycryptographywhatever.com/2023/03/24/rwc-2023/    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian) ]]></itunes:summary>
    <description><![CDATA[<p>Real World Cryptography 2023 is happening any moment now in Tokyo. Also, some phone basebands are broken.<br/><br/><b>Links</b></p><ul><li>https://rwc.iacr.org/2023/</li><li>https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html</li></ul><p><br/><b>Transcript: </b>https://securitycryptographywhatever.com/2023/03/24/rwc-2023/<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Real World Cryptography 2023 is happening any moment now in Tokyo. Also, some phone basebands are broken.<br/><br/><b>Links</b></p><ul><li>https://rwc.iacr.org/2023/</li><li>https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html</li></ul><p><br/><b>Transcript: </b>https://securitycryptographywhatever.com/2023/03/24/rwc-2023/<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/12511539-real-world-crypto-2023.mp3" length="39522200" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2023/03/24/rwc-2023/</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12511539</guid>
    <pubDate>Fri, 24 Mar 2023 22:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12511539/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12511539/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12511539/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12511539/transcript.vtt" type="text/vtt" />
    <itunes:duration>3291</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Threema with Kenny Paterson, Matteo Scarlata and Kien Tuong Truong </itunes:title>
    <title>Threema with Kenny Paterson, Matteo Scarlata and Kien Tuong Truong </title>
    <itunes:summary><![CDATA[Another day, another ostensibly secure messenger that quails under the gaze of some intrepid cryptographers. This time, it's Threema, and the gaze belongs to Kenny Paterson, Matteo Scarlata, and Kien Tuong Truong from ETH Zurich. Get ready for some stunt cryptography, like 2 Fast 2 Furious stunts.  Transcript:  https://securitycryptographywhatever.com/2023/01/27/threema/  Links: https://breakingthe3ma.app/ https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf https://thre...]]></itunes:summary>
    <description><![CDATA[<p>Another day, another ostensibly secure messenger that quails under the gaze of some intrepid cryptographers. This time, it&apos;s Threema, and the gaze belongs to Kenny Paterson, Matteo Scarlata, and Kien Tuong Truong from ETH Zurich. Get ready for some stunt cryptography, like 2 Fast 2 Furious stunts.<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2023/01/27/threema/'>https://securitycryptographywhatever.com/2023/01/27/threema/<br/></a><br/>Links:<br/><a href='https://breakingthe3ma.app/'>https://breakingthe3ma.app/<br/></a><a href='https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf'>https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf<br/></a><a href='https://threema.ch/en/blog/posts/ibex'>https://threema.ch/en/blog/posts/ibex</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Another day, another ostensibly secure messenger that quails under the gaze of some intrepid cryptographers. This time, it&apos;s Threema, and the gaze belongs to Kenny Paterson, Matteo Scarlata, and Kien Tuong Truong from ETH Zurich. Get ready for some stunt cryptography, like 2 Fast 2 Furious stunts.<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2023/01/27/threema/'>https://securitycryptographywhatever.com/2023/01/27/threema/<br/></a><br/>Links:<br/><a href='https://breakingthe3ma.app/'>https://breakingthe3ma.app/<br/></a><a href='https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf'>https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf<br/></a><a href='https://threema.ch/en/blog/posts/ibex'>https://threema.ch/en/blog/posts/ibex</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/12129035-threema-with-kenny-paterson-matteo-scarlata-and-kien-tuong-truong.mp3" length="46043673" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2023/01/27/threema</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12129035</guid>
    <pubDate>Fri, 27 Jan 2023 01:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12129035/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12129035/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12129035/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/12129035/transcript.vtt" type="text/vtt" />
    <itunes:duration>3835</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Has RSA been destroyed by a quantum computer???</itunes:title>
    <title>Has RSA been destroyed by a quantum computer???</title>
    <itunes:summary><![CDATA[There's a paper that claims one can factor a RSA-2048 modulus with the help of a 372-qubit quantum computer. Are we all gonna die?  Also some musings about Bruce Schneier.  Errata: Schneier's honorary PhD is from the University of Westminster, not UW.  Transcript: https://securitycryptographywhatever.com/2023/01/06/has-rsa-been-destroyed-by-a-quantum-computer/  Links:  https://arxiv.org/pdf/2212.12372.pdf https://eprint.iacr.org/2021/232.pdf https://github.com/lducas/SchnorrGate https://sweis...]]></itunes:summary>
    <description><![CDATA[<p>There&apos;s a paper that claims one can factor a RSA-2048 modulus with the help of a 372-qubit quantum computer. Are we all gonna die?<br/><br/>Also some musings about Bruce Schneier.<br/><br/>Errata:<br/>Schneier&apos;s honorary PhD is from the University of Westminster, not UW.</p><p><br/>Transcript:<br/><a href='https://securitycryptographywhatever.com/2023/01/06/has-rsa-been-destroyed-by-a-quantum-computer/'>https://securitycryptographywhatever.com/2023/01/06/has-rsa-been-destroyed-by-a-quantum-computer/</a><br/><br/>Links:<br/><br/>https://arxiv.org/pdf/2212.12372.pdf<br/>https://eprint.iacr.org/2021/232.pdf<br/>https://github.com/lducas/SchnorrGate<br/>https://sweis.medium.com/did-schnorr-destroy-rsa-show-me-the-factors-dcb1bb980ab0<br/>https://www.schneier.com/blog/archives/2023/01/breaking-rsa-with-a-quantum-computer.html<br/>https://scottaaronson.blog/?p=6957<br/><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>There&apos;s a paper that claims one can factor a RSA-2048 modulus with the help of a 372-qubit quantum computer. Are we all gonna die?<br/><br/>Also some musings about Bruce Schneier.<br/><br/>Errata:<br/>Schneier&apos;s honorary PhD is from the University of Westminster, not UW.</p><p><br/>Transcript:<br/><a href='https://securitycryptographywhatever.com/2023/01/06/has-rsa-been-destroyed-by-a-quantum-computer/'>https://securitycryptographywhatever.com/2023/01/06/has-rsa-been-destroyed-by-a-quantum-computer/</a><br/><br/>Links:<br/><br/>https://arxiv.org/pdf/2212.12372.pdf<br/>https://eprint.iacr.org/2021/232.pdf<br/>https://github.com/lducas/SchnorrGate<br/>https://sweis.medium.com/did-schnorr-destroy-rsa-show-me-the-factors-dcb1bb980ab0<br/>https://www.schneier.com/blog/archives/2023/01/breaking-rsa-with-a-quantum-computer.html<br/>https://scottaaronson.blog/?p=6957<br/><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11996492-has-rsa-been-destroyed-by-a-quantum-computer.mp3" length="29738597" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2023/01/06/has-rsa-been-destroyed-by-a-quantum-computer/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-11996492</guid>
    <pubDate>Fri, 06 Jan 2023 23:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11996492/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11996492/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11996492/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11996492/transcript.vtt" type="text/vtt" />
    <itunes:duration>2476</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>End of Year Wrap Up</itunes:title>
    <title>End of Year Wrap Up</title>
    <itunes:summary><![CDATA[David and Deirdre gab about some stuff we didn't get to or just recently happened, like Tailscale's new Tailnet Lock, the Okta breach, what the fuck CISOs are for anyway, Rust in Android and Chrome, passkeys support, and of course, SBF.  Transcript: https://securitycryptographywhatever.com/2023/01/04/end-of-year-wrap-up/  Links: https://tailscale.com/blog/tailnet-lock/ https://security.googleblog.com/2022/12/memory-safe-languages-in-android-13.html https://groups.google.com/a/chromium.org/g/c...]]></itunes:summary>
    <description><![CDATA[<p>David and Deirdre gab about some stuff we didn&apos;t get to or just recently happened, like Tailscale&apos;s new Tailnet Lock, the Okta breach, what the fuck CISOs are for anyway, Rust in Android and Chrome, passkeys support, and of course, SBF.<br/><br/><b>Transcript:</b><br/><a href='https://securitycryptographywhatever.com/2023/01/04/end-of-year-wrap-up/'>https://securitycryptographywhatever.com/2023/01/04/end-of-year-wrap-up/</a><br/><br/><b>Links:</b><br/>https://tailscale.com/blog/tailnet-lock/<br/>https://security.googleblog.com/2022/12/memory-safe-languages-in-android-13.html<br/>https://groups.google.com/a/chromium.org/g/chromium-dev/c/0z-6VJ9ZpVU<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>David and Deirdre gab about some stuff we didn&apos;t get to or just recently happened, like Tailscale&apos;s new Tailnet Lock, the Okta breach, what the fuck CISOs are for anyway, Rust in Android and Chrome, passkeys support, and of course, SBF.<br/><br/><b>Transcript:</b><br/><a href='https://securitycryptographywhatever.com/2023/01/04/end-of-year-wrap-up/'>https://securitycryptographywhatever.com/2023/01/04/end-of-year-wrap-up/</a><br/><br/><b>Links:</b><br/>https://tailscale.com/blog/tailnet-lock/<br/>https://security.googleblog.com/2022/12/memory-safe-languages-in-android-13.html<br/>https://groups.google.com/a/chromium.org/g/chromium-dev/c/0z-6VJ9ZpVU<br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11982412-end-of-year-wrap-up.mp3" length="42829963" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2023/01/04/end-of-year-wrap-up/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-11982412</guid>
    <pubDate>Wed, 04 Jan 2023 21:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11982412/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11982412/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11982412/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11982412/transcript.vtt" type="text/vtt" />
    <itunes:duration>3567</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Software Safety and Twitter with Kevin Riggle</itunes:title>
    <title>Software Safety and Twitter with Kevin Riggle</title>
    <itunes:summary><![CDATA[We talk to Kevin Riggle (@kevinriggle) about complexity and safety. We also talk about the Twitter acquisition. While recording, we discovered a new failure mode where Kevin couldn't hear Thomas, but David and Deirdre could, so there's not much Thomas this episode. If you ever need to get Thomas to voluntarily stop talking, simply mute him to half the audience!  https://twitter.com/kevinriggle  Transcript:  https://securitycryptographywhatever.com/2022/11/24/software-safety-and-twitter-with-k...]]></itunes:summary>
    <description><![CDATA[<p>We talk to Kevin Riggle (<a href='https://twitter.com/kevinriggle'>@kevinriggle</a>) about complexity and safety. We also talk about the Twitter acquisition. While recording, we discovered a new failure mode where Kevin couldn&apos;t hear Thomas, but David and Deirdre could, so there&apos;s not much Thomas this episode. If you ever need to get Thomas to voluntarily stop talking, simply mute him to half the audience!<br/><br/><a href='https://twitter.com/kevinriggle'>https://twitter.com/kevinriggle<br/></a><br/><b>Transcript: <br/></b><a href='https://securitycryptographywhatever.com/2022/11/24/software-safety-and-twitter-with-kevin-riggle/'>https://securitycryptographywhatever.com/2022/11/24/software-safety-and-twitter-with-kevin-riggle/<br/></a><br/><b>Errata</b></p><ul><li>It was the Mars Climate Orbiter that crashed due to a units mismatch</li><li>David confused the Dreamliner with the 737 Max</li></ul><p><b>Links</b></p><ul><li><a href='https://free-dissociation.com/blog/posts/2018/08/why-is-it-so-hard-to-build-safe-software/'>https://free-dissociation.com/blog/posts/2018/08/why-is-it-so-hard-to-build-safe-software/</a></li><li><a href='https://complexsystems.group/'>https://complexsystems.group/</a></li><li><a href='https://how.complexsystems.fail/'>https://how.complexsystems.fail/</a></li><li><a href='https://noncombatant.org/2016/06/20/get-into-security-engineering/'>https://noncombatant.org/2016/06/20/get-into-security-engineering/</a></li><li><a href='https://blog.nelhage.com/2010/03/security-doesnt-respect-abstraction/'>https://blog.nelhage.com/2010/03/security-doesnt-respect-abstraction/</a></li><li><a href='http://sunnyday.mit.edu/safer-world.pdf'>http://sunnyday.mit.edu/safer-world.pdf</a></li><li><a href='https://www.adaptivecapacitylabs.com/john-allspaw/'>https://www.adaptivecapacitylabs.com/john-allspaw/</a></li><li><a href='https://www.etsy.com/codeascraft/blameless-postmortems'>https://www.etsy.com/codeascraft/blameless-postmortems</a></li><li><a href='https://increment.com/security/approachable-threat-modeling/'>https://increment.com/security/approachable-threat-modeling/</a></li><li><a href='https://www.nytimes.com/2022/11/17/arts/music/taylor-swift-tickets-ticketmaster.html'>https://www.nytimes.com/2022/11/17/arts/music/taylor-swift-tickets-ticketmaster.html</a></li><li><a href='https://www.hillelwayne.com/post/are-we-really-engineers/'>https://www.hillelwayne.com/post/are-we-really-engineers/</a></li><li><a href='https://www.hillelwayne.com/post/we-are-not-special/'>https://www.hillelwayne.com/post/we-are-not-special/</a></li><li><a href='https://www.hillelwayne.com/post/what-we-can-learn/'>https://www.hillelwayne.com/post/what-we-can-learn/</a></li><li><a href='https://lotr.fandom.com/wiki/Denethor_II'>https://lotr.fandom.com/wiki/Denethor_II</a></li><li><a href='https://twitter.com/sarahjeong/status/1587597972136546304'>https://twitter.com/sarahjeong/status/1587597972136546304</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We talk to Kevin Riggle (<a href='https://twitter.com/kevinriggle'>@kevinriggle</a>) about complexity and safety. We also talk about the Twitter acquisition. While recording, we discovered a new failure mode where Kevin couldn&apos;t hear Thomas, but David and Deirdre could, so there&apos;s not much Thomas this episode. If you ever need to get Thomas to voluntarily stop talking, simply mute him to half the audience!<br/><br/><a href='https://twitter.com/kevinriggle'>https://twitter.com/kevinriggle<br/></a><br/><b>Transcript: <br/></b><a href='https://securitycryptographywhatever.com/2022/11/24/software-safety-and-twitter-with-kevin-riggle/'>https://securitycryptographywhatever.com/2022/11/24/software-safety-and-twitter-with-kevin-riggle/<br/></a><br/><b>Errata</b></p><ul><li>It was the Mars Climate Orbiter that crashed due to a units mismatch</li><li>David confused the Dreamliner with the 737 Max</li></ul><p><b>Links</b></p><ul><li><a href='https://free-dissociation.com/blog/posts/2018/08/why-is-it-so-hard-to-build-safe-software/'>https://free-dissociation.com/blog/posts/2018/08/why-is-it-so-hard-to-build-safe-software/</a></li><li><a href='https://complexsystems.group/'>https://complexsystems.group/</a></li><li><a href='https://how.complexsystems.fail/'>https://how.complexsystems.fail/</a></li><li><a href='https://noncombatant.org/2016/06/20/get-into-security-engineering/'>https://noncombatant.org/2016/06/20/get-into-security-engineering/</a></li><li><a href='https://blog.nelhage.com/2010/03/security-doesnt-respect-abstraction/'>https://blog.nelhage.com/2010/03/security-doesnt-respect-abstraction/</a></li><li><a href='http://sunnyday.mit.edu/safer-world.pdf'>http://sunnyday.mit.edu/safer-world.pdf</a></li><li><a href='https://www.adaptivecapacitylabs.com/john-allspaw/'>https://www.adaptivecapacitylabs.com/john-allspaw/</a></li><li><a href='https://www.etsy.com/codeascraft/blameless-postmortems'>https://www.etsy.com/codeascraft/blameless-postmortems</a></li><li><a href='https://increment.com/security/approachable-threat-modeling/'>https://increment.com/security/approachable-threat-modeling/</a></li><li><a href='https://www.nytimes.com/2022/11/17/arts/music/taylor-swift-tickets-ticketmaster.html'>https://www.nytimes.com/2022/11/17/arts/music/taylor-swift-tickets-ticketmaster.html</a></li><li><a href='https://www.hillelwayne.com/post/are-we-really-engineers/'>https://www.hillelwayne.com/post/are-we-really-engineers/</a></li><li><a href='https://www.hillelwayne.com/post/we-are-not-special/'>https://www.hillelwayne.com/post/we-are-not-special/</a></li><li><a href='https://www.hillelwayne.com/post/what-we-can-learn/'>https://www.hillelwayne.com/post/what-we-can-learn/</a></li><li><a href='https://lotr.fandom.com/wiki/Denethor_II'>https://lotr.fandom.com/wiki/Denethor_II</a></li><li><a href='https://twitter.com/sarahjeong/status/1587597972136546304'>https://twitter.com/sarahjeong/status/1587597972136546304</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11753287-software-safety-and-twitter-with-kevin-riggle.mp3" length="42217741" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/11/24/software-safety-and-twitter-with-kevin-riggle/</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11753287</guid>
    <pubDate>Thu, 24 Nov 2022 03:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11753287/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11753287/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11753287/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11753287/transcript.vtt" type="text/vtt" />
    <itunes:duration>3516</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Matrix with Martin Albrecht and Dan Jones</itunes:title>
    <title>Matrix with Martin Albrecht and Dan Jones</title>
    <itunes:summary><![CDATA[No not the movie: the secure group messaging protocol! Or rather all the bugs and vulns that a team of researchers found when trying to formalize said protocol. Martin Albrecht and Dan Jones joined us to walk us through "Practically-exploitable Cryptographic Vulnerabilities in Matrix".  Transcript: https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/  Links:  https://nebuchadnezzar-megolm.github.io/static/paper.pdfhttps://nebuchadnezzar-megolm.github...]]></itunes:summary>
    <description><![CDATA[<p>No not the movie: the secure group messaging protocol! Or rather all the bugs and vulns that a team of researchers found when trying to formalize said protocol. Martin Albrecht and Dan Jones joined us to walk us through &quot;Practically-exploitable Cryptographic<br/>Vulnerabilities in Matrix&quot;.<br/><br/><b>Transcript</b>:<br/><a href='https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/'>https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/</a><br/><br/><b>Links:</b> </p><ul><li>https://nebuchadnezzar-megolm.github.io/static/paper.pdf</li><li>https://nebuchadnezzar-megolm.github.io</li><li>Signal Private Group system: https://eprint.iacr.org/2019/1416.pdf</li><li>https://signal.org/blog/signal-private-group-system/</li><li>https://spec.matrix.org/latest/</li><li>WhatsApp Security Whitepaper: https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf</li><li>https://www.usenix.org/conference/usenixsecurity21/presentation/albrecht FS, PCS etc</li><li>Other clients: https://nvd.nist.gov/vuln/detail/CVE-2022-39252 https://nvd.nist.gov/vuln/detail/CVE-2022-39254 https://nvd.nist.gov/vuln/detail/CVE-2022-39264 </li><li>https://dadrian.io/blog/posts/roll-your-own-crypto/</li><li>https://podcasts.apple.com/us/podcast/the-great-roll-your-own-crypto-debate-feat-filippo-valsorda/id1578405214?i=1000530617719 </li><li>WhatsApp End-to-End Encrypted Backups: https://blog.whatsapp.com/end-to-end-encrypted-backups-on-whatsapp</li><li>Roll your own and Telegram: https://mtpsym.github.io/ </li></ul><p><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>No not the movie: the secure group messaging protocol! Or rather all the bugs and vulns that a team of researchers found when trying to formalize said protocol. Martin Albrecht and Dan Jones joined us to walk us through &quot;Practically-exploitable Cryptographic<br/>Vulnerabilities in Matrix&quot;.<br/><br/><b>Transcript</b>:<br/><a href='https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/'>https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/</a><br/><br/><b>Links:</b> </p><ul><li>https://nebuchadnezzar-megolm.github.io/static/paper.pdf</li><li>https://nebuchadnezzar-megolm.github.io</li><li>Signal Private Group system: https://eprint.iacr.org/2019/1416.pdf</li><li>https://signal.org/blog/signal-private-group-system/</li><li>https://spec.matrix.org/latest/</li><li>WhatsApp Security Whitepaper: https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf</li><li>https://www.usenix.org/conference/usenixsecurity21/presentation/albrecht FS, PCS etc</li><li>Other clients: https://nvd.nist.gov/vuln/detail/CVE-2022-39252 https://nvd.nist.gov/vuln/detail/CVE-2022-39254 https://nvd.nist.gov/vuln/detail/CVE-2022-39264 </li><li>https://dadrian.io/blog/posts/roll-your-own-crypto/</li><li>https://podcasts.apple.com/us/podcast/the-great-roll-your-own-crypto-debate-feat-filippo-valsorda/id1578405214?i=1000530617719 </li><li>WhatsApp End-to-End Encrypted Backups: https://blog.whatsapp.com/end-to-end-encrypted-backups-on-whatsapp</li><li>Roll your own and Telegram: https://mtpsym.github.io/ </li></ul><p><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11614796-matrix-with-martin-albrecht-and-dan-jones.mp3" length="47835800" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-11614796</guid>
    <pubDate>Wed, 02 Nov 2022 01:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11614796/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11614796/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11614796/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11614796/transcript.vtt" type="text/vtt" />
    <itunes:duration>3984</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>SOC2 with Sarah Harvey</itunes:title>
    <title>SOC2 with Sarah Harvey</title>
    <itunes:summary><![CDATA[We have Sarah Harvey (@worldwise001 on Twitter) to talk about SOC2, what it means, how to get it, and if it's important or not. The discussion centers around two blog posts written by Thomas: SOC2 Starting Seven: https://latacora.micro.blog/2020/03/12/the-soc-starting.htmlSOC2 at Fly: https://fly.io/blog/soc2-the-screenshots-will-continue-until-security-improves/Transcript: https://securitycryptographywhatever.com/2022/10/16/SOC2-with-Sarah-Harvey/  Links: Tailscale recent post on getting SOC...]]></itunes:summary>
    <description><![CDATA[<p>We have Sarah Harvey (<a href='https://twitter.com/worldwise001'>@worldwise001</a> on Twitter) to talk about SOC2, what it means, how to get it, and if it&apos;s important or not. The discussion centers around two blog posts written by Thomas:</p><ul><li>SOC2 Starting Seven: https://latacora.micro.blog/2020/03/12/the-soc-starting.html</li><li>SOC2 at Fly: https://fly.io/blog/soc2-the-screenshots-will-continue-until-security-improves/</li></ul><p><b>Transcript</b>:<br/><a href='https://securitycryptographywhatever.com/2022/10/16/SOC2-with-Sarah-Harvey/'>https://securitycryptographywhatever.com/2022/10/16/SOC2-with-Sarah-Harvey/</a><br/><br/><b>Links:</b></p><ul><li>Tailscale recent post on getting SOC2’d: <a href='https://tailscale.com/blog/soc2-type2/'>https://tailscale.com/blog/soc2-type2/</a></li><li>SSO Tax: <a href='https://sso.tax/'>https://sso.tax</a></li><li>David’s previous job: <a href='https://getnametag.com/'>https://getnametag.com</a></li><li>David&apos;s other startup: <a href='https://censys.io/'>https://censys.io</a></li><li>Thomas works at <a href='https://fly.io/'>https://fly.io</a></li></ul><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We have Sarah Harvey (<a href='https://twitter.com/worldwise001'>@worldwise001</a> on Twitter) to talk about SOC2, what it means, how to get it, and if it&apos;s important or not. The discussion centers around two blog posts written by Thomas:</p><ul><li>SOC2 Starting Seven: https://latacora.micro.blog/2020/03/12/the-soc-starting.html</li><li>SOC2 at Fly: https://fly.io/blog/soc2-the-screenshots-will-continue-until-security-improves/</li></ul><p><b>Transcript</b>:<br/><a href='https://securitycryptographywhatever.com/2022/10/16/SOC2-with-Sarah-Harvey/'>https://securitycryptographywhatever.com/2022/10/16/SOC2-with-Sarah-Harvey/</a><br/><br/><b>Links:</b></p><ul><li>Tailscale recent post on getting SOC2’d: <a href='https://tailscale.com/blog/soc2-type2/'>https://tailscale.com/blog/soc2-type2/</a></li><li>SSO Tax: <a href='https://sso.tax/'>https://sso.tax</a></li><li>David’s previous job: <a href='https://getnametag.com/'>https://getnametag.com</a></li><li>David&apos;s other startup: <a href='https://censys.io/'>https://censys.io</a></li><li>Thomas works at <a href='https://fly.io/'>https://fly.io</a></li></ul><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11510254-soc2-with-sarah-harvey.mp3" length="44390107" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/10/16/SOC2-with-Sarah-Harvey/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-11510254</guid>
    <pubDate>Sun, 16 Oct 2022 17:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11510254/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11510254/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11510254/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11510254/transcript.vtt" type="text/vtt" />
    <itunes:duration>3697</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Nate Lawson II</itunes:title>
    <title>Nate Lawson II</title>
    <itunes:summary><![CDATA[This episode got delayed because David got COVID. Anyway, here's Nate Lawson: The Two Towers. Steven Chu: https://en.wikipedia.org/wiki/Steven_ChuCFB: https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_feedback_(CFB)CCFB: https://link.springer.com/chapter/10.1007/11502760_19XXTEA: https://en.wikipedia.org/wiki/XXTEACHERI: https://cseweb.ucsd.edu/~dstefan/cse227-spring20/papers/watson:cheri.pdf Transcript: https://securitycryptographywhatever.com/2022/09/29/nate-lawson-ii/  Er...]]></itunes:summary>
    <description><![CDATA[<p>This episode got delayed because David got COVID. Anyway, here&apos;s Nate Lawson: The Two Towers.</p><ul><li>Steven Chu: <a href='https://en.wikipedia.org/wiki/Steven_Chu'>https://en.wikipedia.org/wiki/Steven_Chu</a></li><li>CFB: <a href='https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_feedback_(CFB)'>https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_feedback_(CFB)</a></li><li>CCFB: <a href='https://link.springer.com/chapter/10.1007/11502760_19'>https://link.springer.com/chapter/10.1007/11502760_19</a></li><li>XXTEA: <a href='https://en.wikipedia.org/wiki/XXTEA'>https://en.wikipedia.org/wiki/XXTEA</a></li><li>CHERI: <a href='https://cseweb.ucsd.edu/~dstefan/cse227-spring20/papers/watson:cheri.pdf'>https://cseweb.ucsd.edu/~dstefan/cse227-spring20/papers/watson:cheri.pdf</a></li></ul><p><br/><b>Transcript</b>:<br/><a href='https://securitycryptographywhatever.com/2022/09/29/nate-lawson-ii/'>https://securitycryptographywhatever.com/2022/09/29/nate-lawson-ii/</a><br/><br/><b>Errata</b>:</p><ul><li>Pedram Amini did in fact do Pai Mei</li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>This episode got delayed because David got COVID. Anyway, here&apos;s Nate Lawson: The Two Towers.</p><ul><li>Steven Chu: <a href='https://en.wikipedia.org/wiki/Steven_Chu'>https://en.wikipedia.org/wiki/Steven_Chu</a></li><li>CFB: <a href='https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_feedback_(CFB)'>https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_feedback_(CFB)</a></li><li>CCFB: <a href='https://link.springer.com/chapter/10.1007/11502760_19'>https://link.springer.com/chapter/10.1007/11502760_19</a></li><li>XXTEA: <a href='https://en.wikipedia.org/wiki/XXTEA'>https://en.wikipedia.org/wiki/XXTEA</a></li><li>CHERI: <a href='https://cseweb.ucsd.edu/~dstefan/cse227-spring20/papers/watson:cheri.pdf'>https://cseweb.ucsd.edu/~dstefan/cse227-spring20/papers/watson:cheri.pdf</a></li></ul><p><br/><b>Transcript</b>:<br/><a href='https://securitycryptographywhatever.com/2022/09/29/nate-lawson-ii/'>https://securitycryptographywhatever.com/2022/09/29/nate-lawson-ii/</a><br/><br/><b>Errata</b>:</p><ul><li>Pedram Amini did in fact do Pai Mei</li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11410130-nate-lawson-ii.mp3" length="60011524" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/09/29/nate-lawson-ii/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-11410130</guid>
    <pubDate>Thu, 29 Sep 2022 17:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11410130/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11410130/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11410130/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11410130/transcript.vtt" type="text/vtt" />
    <itunes:duration>4999</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Nate Lawson: Part 1</itunes:title>
    <title>Nate Lawson: Part 1</title>
    <itunes:summary><![CDATA[We bring on Nate Lawson of Root Labs to talk about a little bit of everything, starting with cryptography in the 1990s.  Transcript: https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/  References IBM S/390: https://ieeexplore.ieee.org/document/5389176SSLv2 Spec: https://www-archive.mozilla.org/projects/security/pki/nss/ssl/draft02.htmlXbox 360 HMAC: https://beta.ivc.no/wiki/index.php/Xbox_360_Timing_AttackGoogle Keyczar HMAC bug (reported by Nate): https://rdist.root.org/...]]></itunes:summary>
    <description><![CDATA[<p>We bring on Nate Lawson of Root Labs to talk about a little bit of everything, starting with cryptography in the 1990s.<br/><br/><b>Transcript</b>:<br/><a href='https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/'>https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/</a><br/><br/><b>References</b></p><ul><li>IBM S/390: https://ieeexplore.ieee.org/document/5389176</li><li>SSLv2 Spec: https://www-archive.mozilla.org/projects/security/pki/nss/ssl/draft02.html</li><li>Xbox 360 HMAC: https://beta.ivc.no/wiki/index.php/Xbox_360_Timing_Attack</li><li>Google Keyczar HMAC bug (reported by Nate): https://rdist.root.org/2009/05/28/timing-attack-in-google-keyczar-library/</li></ul><p><b>Errata</b></p><ul><li>HMAC actually published in 1996, not 1997</li><li>&quot;That was one of the first, I think hardware applications of DPA was, was, um, satellite TV cards.&quot; Not true, they first were able to break Mondex, a MasterCard smart card</li></ul><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We bring on Nate Lawson of Root Labs to talk about a little bit of everything, starting with cryptography in the 1990s.<br/><br/><b>Transcript</b>:<br/><a href='https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/'>https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/</a><br/><br/><b>References</b></p><ul><li>IBM S/390: https://ieeexplore.ieee.org/document/5389176</li><li>SSLv2 Spec: https://www-archive.mozilla.org/projects/security/pki/nss/ssl/draft02.html</li><li>Xbox 360 HMAC: https://beta.ivc.no/wiki/index.php/Xbox_360_Timing_Attack</li><li>Google Keyczar HMAC bug (reported by Nate): https://rdist.root.org/2009/05/28/timing-attack-in-google-keyczar-library/</li></ul><p><b>Errata</b></p><ul><li>HMAC actually published in 1996, not 1997</li><li>&quot;That was one of the first, I think hardware applications of DPA was, was, um, satellite TV cards.&quot; Not true, they first were able to break Mondex, a MasterCard smart card</li></ul><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11291490-nate-lawson-part-1.mp3" length="57754241" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-11291490</guid>
    <pubDate>Fri, 09 Sep 2022 16:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11291490/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11291490/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11291490/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11291490/transcript.vtt" type="text/vtt" />
    <itunes:duration>4811</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Hot Cryptanalytic Summer with Steven Galbraith</itunes:title>
    <title>Hot Cryptanalytic Summer with Steven Galbraith</title>
    <itunes:summary><![CDATA[Are the isogenies kaput?! There's a new attack that breaks all the known parameter sets for SIDH/SIKE, so Steven Galbraith helps explain where the hell this came from, and where isogeny crypto goes from here.  Transcript:  https://securitycryptographywhatever.com/2022/08/11/hot-cryptanalytic-summer-with-steven-galbraith/  Merch: https://merch.scwpodcast.com  Links: https://eprint.iacr.org/2022/975.pdfhttps://eprint.iacr.org/2022/1026.pdfhttps://ellipticnews.wordpress.com/2022/07/31/breaking-s...]]></itunes:summary>
    <description><![CDATA[<p>Are the isogenies kaput?! There&apos;s a new attack that breaks all the known parameter sets for SIDH/SIKE, so Steven Galbraith helps explain where the hell this came from, and where isogeny crypto goes from here.<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2022/08/11/hot-cryptanalytic-summer-with-steven-galbraith/'>https://securitycryptographywhatever.com/2022/08/11/hot-cryptanalytic-summer-with-steven-galbraith/</a><br/><br/><b>Merch</b>: <a href='https://merch.scwpodcast.com/'>https://merch.scwpodcast.com</a><br/><br/><b>Links:</b></p><ul><li><a href='https://eprint.iacr.org/2022/975.pdf'>https://eprint.iacr.org/2022/975.pdf</a></li><li><a href='https://eprint.iacr.org/2022/1026.pdf'>https://eprint.iacr.org/2022/1026.pdf</a></li><li><a href='https://ellipticnews.wordpress.com/2022/07/31/breaking-supersingular-isogeny-diffie-hellman-sidh/'>https://ellipticnews.wordpress.com/2022/07/31/breaking-supersingular-isogeny-diffie-hellman-sidh/</a></li><li>GPST active adaptive attack against SIDH: <a href='https://eprint.iacr.org/2016/859.pdf'>https://eprint.iacr.org/2016/859.pdf</a></li><li>Failing to hash into supersingular isogeny graphs: <a href='https://eprint.iacr.org/2022/975.pdf'>https://eprint.iacr.org/2022/518.pdf</a></li><li><a href='https://eprint.iacr.org/2022/975.pdf'>https://research.nccgroup.com/2022/08/08/implementing-the-castryck-decru-sidh-key-recovery-attack-in-sagemath/</a></li><li>Kuperberg attack via Peikert: <a href='https://eprint.iacr.org/2019/725'>https://eprint.iacr.org/2019/725</a>.pdf</li><li>SQISign: <a href='https://eprint.iacr.org/2020/1240.pdf'>https://eprint.iacr.org/2020/1240.pdf</a></li><li>(Post recording)  Breaking SIDH in polynomial time:<br/><a href='https://eprint.iacr.org/2022/975.pdf'>https://eprint.iacr.org/2022/1038.pdf</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Are the isogenies kaput?! There&apos;s a new attack that breaks all the known parameter sets for SIDH/SIKE, so Steven Galbraith helps explain where the hell this came from, and where isogeny crypto goes from here.<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2022/08/11/hot-cryptanalytic-summer-with-steven-galbraith/'>https://securitycryptographywhatever.com/2022/08/11/hot-cryptanalytic-summer-with-steven-galbraith/</a><br/><br/><b>Merch</b>: <a href='https://merch.scwpodcast.com/'>https://merch.scwpodcast.com</a><br/><br/><b>Links:</b></p><ul><li><a href='https://eprint.iacr.org/2022/975.pdf'>https://eprint.iacr.org/2022/975.pdf</a></li><li><a href='https://eprint.iacr.org/2022/1026.pdf'>https://eprint.iacr.org/2022/1026.pdf</a></li><li><a href='https://ellipticnews.wordpress.com/2022/07/31/breaking-supersingular-isogeny-diffie-hellman-sidh/'>https://ellipticnews.wordpress.com/2022/07/31/breaking-supersingular-isogeny-diffie-hellman-sidh/</a></li><li>GPST active adaptive attack against SIDH: <a href='https://eprint.iacr.org/2016/859.pdf'>https://eprint.iacr.org/2016/859.pdf</a></li><li>Failing to hash into supersingular isogeny graphs: <a href='https://eprint.iacr.org/2022/975.pdf'>https://eprint.iacr.org/2022/518.pdf</a></li><li><a href='https://eprint.iacr.org/2022/975.pdf'>https://research.nccgroup.com/2022/08/08/implementing-the-castryck-decru-sidh-key-recovery-attack-in-sagemath/</a></li><li>Kuperberg attack via Peikert: <a href='https://eprint.iacr.org/2019/725'>https://eprint.iacr.org/2019/725</a>.pdf</li><li>SQISign: <a href='https://eprint.iacr.org/2020/1240.pdf'>https://eprint.iacr.org/2020/1240.pdf</a></li><li>(Post recording)  Breaking SIDH in polynomial time:<br/><a href='https://eprint.iacr.org/2022/975.pdf'>https://eprint.iacr.org/2022/1038.pdf</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11123170-hot-cryptanalytic-summer-with-steven-galbraith.mp3" length="37883480" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/08/11/hot-cryptanalytic-summer-with-steven-galbraith/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-11123170</guid>
    <pubDate>Thu, 11 Aug 2022 14:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11123170/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11123170/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11123170/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11123170/transcript.vtt" type="text/vtt" />
    <itunes:duration>3155</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Passkeys with Adam Langley</itunes:title>
    <title>Passkeys with Adam Langley</title>
    <itunes:summary><![CDATA[Adam Langley (Google) comes on the podcast to talk about the evolution of WebAuthN and Passkeys!  David's audio was a little finicky in this one. Believe us, it sounded worse before we edited it. Also, we occasionally accidentally refer to U2F as UTF. That's because we just really love strings.  Transcript:  https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/  Links: GoogleIO PresentationWWDC PresentationW3C WebAuthNAdam's blog on passkeys and CABLECable / Hybrid P...]]></itunes:summary>
    <description><![CDATA[<p>Adam Langley (Google) comes on the podcast to talk about the evolution of WebAuthN and Passkeys!<br/><br/>David&apos;s audio was a little finicky in this one. Believe us, it sounded worse before we edited it. Also, we occasionally accidentally refer to U2F as UTF. That&apos;s because we just really love strings.<br/><br/><b>Transcript</b>: <br/><a href='https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/'>https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/</a><br/><br/><b>Links</b>:</p><ul><li><a href='https://www.youtube.com/watch?v=xghjqgj4peA&amp;t=540s'>GoogleIO Presentation</a></li><li><a href='https://developer.apple.com/videos/play/wwdc2022/10092/'>WWDC Presentation</a></li><li><a href='https://w3c.github.io/webauthn/'>W3C WebAuthN</a></li><li>Adam&apos;s blog on <a href='https://www.imperialviolet.org/2022/07/04/passkeys.html'>passkeys</a> and <a href='https://www.imperialviolet.org/2021/10/20/cablev2.html'>CABLE</a></li><li><a href='https://github.com/w3c/webauthn/pull/1755'>Cable / Hybrid PR</a></li><li><a href='https://fidoalliance.org/specs/fido-v2.0-ps-20190130/fido-client-to-authenticator-protocol-v2.0-ps-20190130.html'>CTAP spec </a>from FIDO</li><li>Noise <a href='https://noiseexplorer.com/patterns/NKpsk0/'>NKPSK</a></li><li><a href='https://tailscale.com/blog/how-tailscale-works/'>DERP</a></li></ul><p><br/><b>Don&apos;t forget about merch!</b> <a href='https://merch.securitycryptographywhatever.com/'>https://merch.securitycryptographywhatever.com/</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Adam Langley (Google) comes on the podcast to talk about the evolution of WebAuthN and Passkeys!<br/><br/>David&apos;s audio was a little finicky in this one. Believe us, it sounded worse before we edited it. Also, we occasionally accidentally refer to U2F as UTF. That&apos;s because we just really love strings.<br/><br/><b>Transcript</b>: <br/><a href='https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/'>https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/</a><br/><br/><b>Links</b>:</p><ul><li><a href='https://www.youtube.com/watch?v=xghjqgj4peA&amp;t=540s'>GoogleIO Presentation</a></li><li><a href='https://developer.apple.com/videos/play/wwdc2022/10092/'>WWDC Presentation</a></li><li><a href='https://w3c.github.io/webauthn/'>W3C WebAuthN</a></li><li>Adam&apos;s blog on <a href='https://www.imperialviolet.org/2022/07/04/passkeys.html'>passkeys</a> and <a href='https://www.imperialviolet.org/2021/10/20/cablev2.html'>CABLE</a></li><li><a href='https://github.com/w3c/webauthn/pull/1755'>Cable / Hybrid PR</a></li><li><a href='https://fidoalliance.org/specs/fido-v2.0-ps-20190130/fido-client-to-authenticator-protocol-v2.0-ps-20190130.html'>CTAP spec </a>from FIDO</li><li>Noise <a href='https://noiseexplorer.com/patterns/NKpsk0/'>NKPSK</a></li><li><a href='https://tailscale.com/blog/how-tailscale-works/'>DERP</a></li></ul><p><br/><b>Don&apos;t forget about merch!</b> <a href='https://merch.securitycryptographywhatever.com/'>https://merch.securitycryptographywhatever.com/</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/11122508-passkeys-with-adam-langley.mp3" length="45395758" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/</link>
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11122508</guid>
    <pubDate>Thu, 11 Aug 2022 12:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11122508/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11122508/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11122508/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/11122508/transcript.vtt" type="text/vtt" />
    <itunes:duration>3781</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Hertzbleed</itunes:title>
    <title>Hertzbleed</title>
    <itunes:summary><![CDATA[Side channels! Frequency scaling! Key encapsulation, oh my! We're talking about the new Hertzbleed paper, but also cryptography conferences, 'passkeys', and end-to-end encrypting yer twitter.com DMs.  Transcript:  https://securitycryptographywhatever.com/2022/06/17/hertzbleed/   Links: Hertzbleed Attack | ellipticnews (wordpress.com)https://www.hertzbleed.com/hertzbleed.pdfhttps://papers.ssrn.com/sol3/papers.cfm?abstract_id=3920031Merch: https://merch.scwpodcast.com  "Security Cryptograp...]]></itunes:summary>
    <description><![CDATA[<p>Side channels! Frequency scaling! Key encapsulation, oh my! We&apos;re talking about the new Hertzbleed paper, but also cryptography conferences, &apos;passkeys&apos;, and end-to-end encrypting yer twitter.com DMs.<br/><br/><b>Transcript</b>: <br/><a href='https://securitycryptographywhatever.com/2022/06/17/hertzbleed/'>https://securitycryptographywhatever.com/2022/06/17/hertzbleed/</a><br/><br/><b> Links:</b></p><ul><li><a href='https://ellipticnews.wordpress.com/2022/06/14/hertzbleed-attack/'><b>Hertzbleed Attack | ellipticnews (wordpress.com)</b></a></li><li><a href='https://www.hertzbleed.com/hertzbleed.pdf'><b>https://www.hertzbleed.com/hertzbleed.pdf</b></a></li><li><a href='https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3920031'><b>https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3920031</b></a></li></ul><p><b>Merch</b>: <a href='https://merch.scwpodcast.com/'>https://merch.scwpodcast.com</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Side channels! Frequency scaling! Key encapsulation, oh my! We&apos;re talking about the new Hertzbleed paper, but also cryptography conferences, &apos;passkeys&apos;, and end-to-end encrypting yer twitter.com DMs.<br/><br/><b>Transcript</b>: <br/><a href='https://securitycryptographywhatever.com/2022/06/17/hertzbleed/'>https://securitycryptographywhatever.com/2022/06/17/hertzbleed/</a><br/><br/><b> Links:</b></p><ul><li><a href='https://ellipticnews.wordpress.com/2022/06/14/hertzbleed-attack/'><b>Hertzbleed Attack | ellipticnews (wordpress.com)</b></a></li><li><a href='https://www.hertzbleed.com/hertzbleed.pdf'><b>https://www.hertzbleed.com/hertzbleed.pdf</b></a></li><li><a href='https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3920031'><b>https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3920031</b></a></li></ul><p><b>Merch</b>: <a href='https://merch.scwpodcast.com/'>https://merch.scwpodcast.com</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/10812724-hertzbleed.mp3" length="42256933" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/06/17/hertzbleed/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-10812724</guid>
    <pubDate>Fri, 17 Jun 2022 22:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10812724/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10812724/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10812724/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10812724/transcript.vtt" type="text/vtt" />
    <itunes:duration>3519</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>OMB Zero Trust Memo with Eric Mill</itunes:title>
    <title>OMB Zero Trust Memo with Eric Mill</title>
    <itunes:summary><![CDATA[The US government released a memo about moving to a zero-trust network architecture. What does this mean? We have one of the authors, Eric Mill, on to explain it to us.  As always, your @SCWPod hosts are Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian).  Transcript:  https://securitycryptographywhatever.com/2022/06/10/omb-zero-trust-memo-with-eric-mill/  Links: OMB MemoExecutive order on cybersecurity PIV card Derived PIVBeyondCorpHSTS Prel...]]></itunes:summary>
    <description><![CDATA[<p>The US government <a href='https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf'>released a memo</a> about moving to a zero-trust network architecture. What does this mean? We have one of the authors, <a href='https://konklone.com/'>Eric Mill</a>, on to explain it to us.<br/><br/>As always, your <a href='https://twitter.com/scwpod'>@SCWPod</a> hosts are Deirdre Connolly (<a href='https://twitter.com/durumcrustulum'>@durumcrustulum</a>), Thomas Ptacek (<a href='https://twitter.com/tqbf'>@tqbf</a>), and David Adrian (<a href='https://twitter.com/davidcadrian'>@davidcadrian</a>).<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2022/06/10/omb-zero-trust-memo-with-eric-mill/'>https://securitycryptographywhatever.com/2022/06/10/omb-zero-trust-memo-with-eric-mill/</a><br/><br/><b>Links:</b></p><ul><li><a href='https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf'>OMB Memo</a></li><li><a href='https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity'>Executive order on cybersecurity</a> </li><li><a href='https://www.oit.va.gov/programs/piv/index.cfm'>PIV card</a> <ul><li><a href='https://csrc.nist.gov/publications/detail/sp/800-157/final'>Derived PIV</a></li></ul></li><li><a href='https://cloud.google.com/beyondcorp'>BeyondCorp</a></li><li><a href='https://hstspreload.org/'>HSTS Preloading</a><ul><li><a href='https://home.dotgov.gov/management/preloading/'>.gov preloading</a> </li></ul></li><li><a href='https://jhalderm.com/pub/papers/mail-imc15.pdf'>Neither Rain, Nor Snow, Nor MITM</a></li><li><a href='https://www.whitehouse.gov/wp-content/uploads/2021/10/M-22-01.pdf'>EDR memo</a></li><li><a href='https://join.tts.gsa.gov/'>Technology Transformation Services (TTS)</a></li><li><a href='https://isitchristmas.com/'>Is it Christmas?</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>The US government <a href='https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf'>released a memo</a> about moving to a zero-trust network architecture. What does this mean? We have one of the authors, <a href='https://konklone.com/'>Eric Mill</a>, on to explain it to us.<br/><br/>As always, your <a href='https://twitter.com/scwpod'>@SCWPod</a> hosts are Deirdre Connolly (<a href='https://twitter.com/durumcrustulum'>@durumcrustulum</a>), Thomas Ptacek (<a href='https://twitter.com/tqbf'>@tqbf</a>), and David Adrian (<a href='https://twitter.com/davidcadrian'>@davidcadrian</a>).<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2022/06/10/omb-zero-trust-memo-with-eric-mill/'>https://securitycryptographywhatever.com/2022/06/10/omb-zero-trust-memo-with-eric-mill/</a><br/><br/><b>Links:</b></p><ul><li><a href='https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf'>OMB Memo</a></li><li><a href='https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity'>Executive order on cybersecurity</a> </li><li><a href='https://www.oit.va.gov/programs/piv/index.cfm'>PIV card</a> <ul><li><a href='https://csrc.nist.gov/publications/detail/sp/800-157/final'>Derived PIV</a></li></ul></li><li><a href='https://cloud.google.com/beyondcorp'>BeyondCorp</a></li><li><a href='https://hstspreload.org/'>HSTS Preloading</a><ul><li><a href='https://home.dotgov.gov/management/preloading/'>.gov preloading</a> </li></ul></li><li><a href='https://jhalderm.com/pub/papers/mail-imc15.pdf'>Neither Rain, Nor Snow, Nor MITM</a></li><li><a href='https://www.whitehouse.gov/wp-content/uploads/2021/10/M-22-01.pdf'>EDR memo</a></li><li><a href='https://join.tts.gsa.gov/'>Technology Transformation Services (TTS)</a></li><li><a href='https://isitchristmas.com/'>Is it Christmas?</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/10767220-omb-zero-trust-memo-with-eric-mill.mp3" length="43620284" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/06/10/omb-zero-trust-memo-with-eric-mill/</link>
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10767220</guid>
    <pubDate>Fri, 10 Jun 2022 21:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10767220/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10767220/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10767220/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10767220/transcript.vtt" type="text/vtt" />
    <itunes:duration>3633</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Tink with Sophie Schmieg</itunes:title>
    <title>Tink with Sophie Schmieg</title>
    <itunes:summary><![CDATA[We talk about Tink with Sophie Schmieg, cryptographer and algebraic geometer at Google.  Transcript:  https://securitycryptographywhatever.com/2022/05/28/tink-with-sophie-schmieg/  Links: Sophie: https://twitter.com/SchmiegSophieTink: https://github.com/google/tinkRWC talk: https://youtube.com/watch?t=1028&amp;v=CiH6iqjWpt8Where to store keys: https://twitter.com/SchmiegSophie/status/1413502566797778948EAX mode: https://en.wikipedia.org/wiki/EAX_modeAES-GCM-SIV: https://en.wikipedia.org/wiki/...]]></itunes:summary>
    <description><![CDATA[<p>We talk about Tink with Sophie Schmieg, cryptographer and algebraic geometer at Google.<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2022/05/28/tink-with-sophie-schmieg/'>https://securitycryptographywhatever.com/2022/05/28/tink-with-sophie-schmieg/<br/></a><br/><b>Links:</b></p><ul><li>Sophie: <a href='https://twitter.com/SchmiegSophie'>https://twitter.com/SchmiegSophie</a></li><li>Tink: <a href='https://github.com/google/tink'>https://github.com/google/tink</a></li><li>RWC talk: <a href='https://youtube.com/watch?t=1028&amp;v=CiH6iqjWpt8'>https://youtube.com/watch?t=1028&amp;v=CiH6iqjWpt8</a></li><li>Where to store keys: <a href='https://twitter.com/SchmiegSophie/status/1413502566797778948'>https://twitter.com/SchmiegSophie/status/1413502566797778948</a></li><li>EAX mode: <a href='https://en.wikipedia.org/wiki/EAX_mode'>https://en.wikipedia.org/wiki/EAX_mode</a></li><li>AES-GCM-SIV: <a href='https://en.wikipedia.org/wiki/AES-GCM-SIV'>https://en.wikipedia.org/wiki/AES-GCM-SIV</a></li><li>Deterministic AEADs: <a href='https://github.com/google/tink/blob/master/docs/PRIMITIVES.md#deterministic-authenticated-encryption-with-associated-data'>https://github.com/google/tink/blob/master/docs/PRIMITIVES.md#deterministic-authenticated-encryption-with-associated-data</a></li><li>Thai Duong: <a href='https://twitter.com/XorNinja'>https://twitter.com/XorNinja</a></li><li>AWS-SDK Vuln: <a href='https://twitter.com/XorNinja/status/1310587707605659649'>https://twitter.com/XorNinja/status/1310587707605659649</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We talk about Tink with Sophie Schmieg, cryptographer and algebraic geometer at Google.<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2022/05/28/tink-with-sophie-schmieg/'>https://securitycryptographywhatever.com/2022/05/28/tink-with-sophie-schmieg/<br/></a><br/><b>Links:</b></p><ul><li>Sophie: <a href='https://twitter.com/SchmiegSophie'>https://twitter.com/SchmiegSophie</a></li><li>Tink: <a href='https://github.com/google/tink'>https://github.com/google/tink</a></li><li>RWC talk: <a href='https://youtube.com/watch?t=1028&amp;v=CiH6iqjWpt8'>https://youtube.com/watch?t=1028&amp;v=CiH6iqjWpt8</a></li><li>Where to store keys: <a href='https://twitter.com/SchmiegSophie/status/1413502566797778948'>https://twitter.com/SchmiegSophie/status/1413502566797778948</a></li><li>EAX mode: <a href='https://en.wikipedia.org/wiki/EAX_mode'>https://en.wikipedia.org/wiki/EAX_mode</a></li><li>AES-GCM-SIV: <a href='https://en.wikipedia.org/wiki/AES-GCM-SIV'>https://en.wikipedia.org/wiki/AES-GCM-SIV</a></li><li>Deterministic AEADs: <a href='https://github.com/google/tink/blob/master/docs/PRIMITIVES.md#deterministic-authenticated-encryption-with-associated-data'>https://github.com/google/tink/blob/master/docs/PRIMITIVES.md#deterministic-authenticated-encryption-with-associated-data</a></li><li>Thai Duong: <a href='https://twitter.com/XorNinja'>https://twitter.com/XorNinja</a></li><li>AWS-SDK Vuln: <a href='https://twitter.com/XorNinja/status/1310587707605659649'>https://twitter.com/XorNinja/status/1310587707605659649</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/10697566-tink-with-sophie-schmieg.mp3" length="48294378" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/05/28/tink-with-sophie-schmieg/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-10697566</guid>
    <pubDate>Sat, 28 May 2022 17:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10697566/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10697566/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10697566/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10697566/transcript.vtt" type="text/vtt" />
    <itunes:duration>4022</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cancellable Crypto Takes and Real World Crypto </itunes:title>
    <title>Cancellable Crypto Takes and Real World Crypto </title>
    <itunes:summary><![CDATA[Live from Amsterdam, it's cancellable crypto hot takes! A fun little meme, plus a preview of the Real World Crypto program!  Transcript:  https://securitycryptographywhatever.com/2022/04/12/cancellable-crypto-takes-and-real-world-crypto/  Links:  Tony's twete: https://twitter.com/bascule/status/1512539700220805124 Real World Crypto 2022: https://rwc.iacr.org/2022 Merch! https://merch.scwpodcast.com  Find us at: https://twitter.com/scwpod https://twitter.com/durumcrustulum https://twitter.com/...]]></itunes:summary>
    <description><![CDATA[<p>Live from Amsterdam, it&apos;s cancellable crypto hot takes! A fun little meme, plus a preview of the Real World Crypto program!<br/><br/><b>Transcript</b>: <br/><a href='https://securitycryptographywhatever.com/2022/04/12/cancellable-crypto-takes-and-real-world-crypto/'>https://securitycryptographywhatever.com/2022/04/12/cancellable-crypto-takes-and-real-world-crypto/</a><br/><br/><b>Links:</b><br/><br/>Tony&apos;s twete: <a href='https://twitter.com/bascule/status/1512539700220805124'>https://twitter.com/bascule/status/1512539700220805124</a><br/>Real World Crypto 2022: <a href='https://rwc.iacr.org/2022'>https://rwc.iacr.org/2022</a><br/>Merch! <a href='https://merch.scwpodcast.com'>https://merch.scwpodcast.com</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Live from Amsterdam, it&apos;s cancellable crypto hot takes! A fun little meme, plus a preview of the Real World Crypto program!<br/><br/><b>Transcript</b>: <br/><a href='https://securitycryptographywhatever.com/2022/04/12/cancellable-crypto-takes-and-real-world-crypto/'>https://securitycryptographywhatever.com/2022/04/12/cancellable-crypto-takes-and-real-world-crypto/</a><br/><br/><b>Links:</b><br/><br/>Tony&apos;s twete: <a href='https://twitter.com/bascule/status/1512539700220805124'>https://twitter.com/bascule/status/1512539700220805124</a><br/>Real World Crypto 2022: <a href='https://rwc.iacr.org/2022'>https://rwc.iacr.org/2022</a><br/>Merch! <a href='https://merch.scwpodcast.com'>https://merch.scwpodcast.com</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/10428127-cancellable-crypto-takes-and-real-world-crypto.mp3" length="51191506" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/04/12/cancellable-crypto-takes-and-real-world-crypto/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-10428127</guid>
    <pubDate>Tue, 12 Apr 2022 20:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10428127/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10428127/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10428127/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10428127/transcript.vtt" type="text/vtt" />
    <itunes:duration>4264</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Lattices and Michigan Football with Chris Peikert</itunes:title>
    <title>Lattices and Michigan Football with Chris Peikert</title>
    <itunes:summary><![CDATA[We're back! With an episode on lattice-based cryptography, with Professor Chris Peikert of the University of Michigan, David's alma mater. When we recorded this, Michigan football had just beaten Ohio for the first time in a bajillion years, so you get a nerdy coda on college football this time!  Transcript:  https://securitycryptographywhatever.com/2022/03/12/lattices-and-michigan-football-with-chris-peikert/  Slides: https://web.eecs.umich.edu/~cpeikert/pubs/slides-qcrypt.pdf  Links:  He Gi...]]></itunes:summary>
    <description><![CDATA[<p>We&apos;re back! With an episode on lattice-based cryptography, with Professor Chris Peikert of the University of Michigan, David&apos;s alma mater. When we recorded this, Michigan football had just beaten Ohio for the first time in a bajillion years, so you get a nerdy coda on college football this time!<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2022/03/12/lattices-and-michigan-football-with-chris-peikert/'>https://securitycryptographywhatever.com/2022/03/12/lattices-and-michigan-football-with-chris-peikert/<br/></a><br/><b>Slides:</b> <a href='https://web.eecs.umich.edu/~cpeikert/pubs/slides-qcrypt.pdf'>https://web.eecs.umich.edu/~cpeikert/pubs/slides-qcrypt.pdf</a><br/><br/><b>Links:</b><br/><br/>He Gives C-Sieves on the CSIDH:<b> </b><a href='https://eprint.iacr.org/2019/725'>https://eprint.iacr.org/2019/725</a><br/>Lattice-based Cryptography: <a href='https://cims.nyu.edu/~regev/papers/pqc.pdf'>https://cims.nyu.edu/~regev/papers/pqc.pdf</a><br/>NIST PQC Competition: <a href='https://csrc.nist.gov/Projects/post-quantum-cryptography'>https://csrc.nist.gov/Projects/post-quantum-cryptography</a><br/> The 2nd Bar Ilan Winter School on Cryptography Lattice- Based Cryptography and Applications: <a href='https://www.youtube.com/playlist?list=PL8Vt-7cSFnw2OmpCmPLLwSx0-Yqb2ptqO'>https://www.youtube.com/playlist?list=PL8Vt-7cSFnw2OmpCmPLLwSx0-Yqb2ptqO</a><br/>A Decade of Lattice Cryptography: <a href='https://eprint.iacr.org/2015/939.pdf'>https://eprint.iacr.org/2015/939.pdf</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We&apos;re back! With an episode on lattice-based cryptography, with Professor Chris Peikert of the University of Michigan, David&apos;s alma mater. When we recorded this, Michigan football had just beaten Ohio for the first time in a bajillion years, so you get a nerdy coda on college football this time!<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2022/03/12/lattices-and-michigan-football-with-chris-peikert/'>https://securitycryptographywhatever.com/2022/03/12/lattices-and-michigan-football-with-chris-peikert/<br/></a><br/><b>Slides:</b> <a href='https://web.eecs.umich.edu/~cpeikert/pubs/slides-qcrypt.pdf'>https://web.eecs.umich.edu/~cpeikert/pubs/slides-qcrypt.pdf</a><br/><br/><b>Links:</b><br/><br/>He Gives C-Sieves on the CSIDH:<b> </b><a href='https://eprint.iacr.org/2019/725'>https://eprint.iacr.org/2019/725</a><br/>Lattice-based Cryptography: <a href='https://cims.nyu.edu/~regev/papers/pqc.pdf'>https://cims.nyu.edu/~regev/papers/pqc.pdf</a><br/>NIST PQC Competition: <a href='https://csrc.nist.gov/Projects/post-quantum-cryptography'>https://csrc.nist.gov/Projects/post-quantum-cryptography</a><br/> The 2nd Bar Ilan Winter School on Cryptography Lattice- Based Cryptography and Applications: <a href='https://www.youtube.com/playlist?list=PL8Vt-7cSFnw2OmpCmPLLwSx0-Yqb2ptqO'>https://www.youtube.com/playlist?list=PL8Vt-7cSFnw2OmpCmPLLwSx0-Yqb2ptqO</a><br/>A Decade of Lattice Cryptography: <a href='https://eprint.iacr.org/2015/939.pdf'>https://eprint.iacr.org/2015/939.pdf</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/10238739-lattices-and-michigan-football-with-chris-peikert.mp3" length="50443578" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/03/12/lattices-and-michigan-football-with-chris-peikert/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-10238739</guid>
    <pubDate>Sat, 12 Mar 2022 22:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10238739/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10238739/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10238739/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/10238739/transcript.vtt" type="text/vtt" />
    <itunes:duration>4201</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Biscuits with Geoffroy Couprie</itunes:title>
    <title>Biscuits with Geoffroy Couprie</title>
    <itunes:summary><![CDATA[We've trashed JWTs, discussed PASETO, Macaroons, and now, Biscuits! Actually, multiple iterations of Biscuits! Pairings and gamma signatures and Datalog, oh my! 🍪   Transcript: https://securitycryptographywhatever.com/2022/01/29/biscuits-with-geoffroy-couprie/  Links:  Biscuits V2: https://www.biscuitsec.org  Experiments iterating on  Biscuits: https://github.com/biscuit-auth/biscuit/tree/master/experimentations  Apache Pulsar: https://pulsar.apache.org  Spec: https://github.com/biscuit-...]]></itunes:summary>
    <description><![CDATA[<p>We&apos;ve trashed JWTs, discussed PASETO, Macaroons, and now, Biscuits! Actually, multiple iterations of Biscuits! Pairings and gamma signatures and Datalog, oh my! 🍪 <br/><br/><b>Transcript:</b><br/><a href='https://securitycryptographywhatever.com/2022/01/29/biscuits-with-geoffroy-couprie/'>https://securitycryptographywhatever.com/2022/01/29/biscuits-with-geoffroy-couprie/</a><br/><br/><b>Links:</b><br/><br/><b>Biscuits V2</b>: <a href='https://www.biscuitsec.org/'><b>https://www.biscuitsec.org</b></a><br/><br/><b>Experiments iterating on  Biscuits: </b><a href='https://github.com/biscuit-auth/biscuit/tree/master/experimentations'><b>https://github.com/biscuit-auth/biscuit/tree/master/experimentations</b></a><b><br/><br/>Apache Pulsar: </b><a href='https://pulsar.apache.org/'><b>https://pulsar.apache.org</b></a><b><br/><br/>Spec: </b><a href='https://github.com/biscuit-auth/biscuit/blob/master/SPECIFICATIONS.md'><b>https://github.com/biscuit-auth/biscuit/blob/master/SPECIFICATIONS.md</b></a><b><br/></b><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We&apos;ve trashed JWTs, discussed PASETO, Macaroons, and now, Biscuits! Actually, multiple iterations of Biscuits! Pairings and gamma signatures and Datalog, oh my! 🍪 <br/><br/><b>Transcript:</b><br/><a href='https://securitycryptographywhatever.com/2022/01/29/biscuits-with-geoffroy-couprie/'>https://securitycryptographywhatever.com/2022/01/29/biscuits-with-geoffroy-couprie/</a><br/><br/><b>Links:</b><br/><br/><b>Biscuits V2</b>: <a href='https://www.biscuitsec.org/'><b>https://www.biscuitsec.org</b></a><br/><br/><b>Experiments iterating on  Biscuits: </b><a href='https://github.com/biscuit-auth/biscuit/tree/master/experimentations'><b>https://github.com/biscuit-auth/biscuit/tree/master/experimentations</b></a><b><br/><br/>Apache Pulsar: </b><a href='https://pulsar.apache.org/'><b>https://pulsar.apache.org</b></a><b><br/><br/>Spec: </b><a href='https://github.com/biscuit-auth/biscuit/blob/master/SPECIFICATIONS.md'><b>https://github.com/biscuit-auth/biscuit/blob/master/SPECIFICATIONS.md</b></a><b><br/></b><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9973086-biscuits-with-geoffroy-couprie.mp3" length="42447876" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/01/29/biscuits-with-geoffroy-couprie/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9973086</guid>
    <pubDate>Sat, 29 Jan 2022 01:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9973086/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9973086/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9973086/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9973086/transcript.vtt" type="text/vtt" />
    <itunes:duration>3535</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Tailscale with Avery Pennarun and Brad Fitzpatrick</itunes:title>
    <title>Tailscale with Avery Pennarun and Brad Fitzpatrick</title>
    <itunes:summary><![CDATA[“Can I Tailscale my Chromecast?”   You love Tailscale, I love Tailscale, we loved talking to Avery Pennarun and Brad Fitzpatrick from Tailscale about, I dunno, Go generics. Oh, and TAILSCALE! And DNS. And WASM.  Transcript: https://securitycryptographywhatever.com/2022/01/15/tailscale-with-avery-pennarun-brad-fitzpatrick/  People: Avery Pennarun (@apenwarr)Brad Fitzpatrick (@bradfitz)Deirdre Connolly (@durumcrustulum)Thomas Ptacek (@tqbf)David Adrian (@davidcadrian)@SCWPodLinks: DERP server: ...]]></itunes:summary>
    <description><![CDATA[<p>“Can I Tailscale my Chromecast?” <br/><br/>You love Tailscale, I love Tailscale, we loved talking to Avery Pennarun and Brad Fitzpatrick from Tailscale about, I dunno, Go generics. Oh, and TAILSCALE! And DNS. And WASM.<br/><br/><b>Transcript:</b><br/><a href='https://securitycryptographywhatever.com/2022/01/15/tailscale-with-avery-pennarun-brad-fitzpatrick/'>https://securitycryptographywhatever.com/2022/01/15/tailscale-with-avery-pennarun-brad-fitzpatrick/</a><br/><br/>People:</p><ul><li>Avery Pennarun (@apenwarr)</li><li>Brad Fitzpatrick (@bradfitz)</li><li>Deirdre Connolly (@durumcrustulum)</li><li>Thomas Ptacek (@tqbf)</li><li>David Adrian (@davidcadrian)</li><li>@SCWPod</li></ul><p><b>Links:</b></p><ul><li>DERP server: <a href='https://github.com/tailscale/tailscale/tree/main/derp'>https://github.com/tailscale/tailscale/tree/main/derp</a></li><li><a href='https://xtermjs.org/'>https://xtermjs.org/</a></li><li>The Tail at Scale : <a href='https://research.google/pubs/pub40801/'>https://research.google/pubs/pub40801/</a></li><li>Raft: <a href='https://raft.github.io/'>https://raft.github.io/</a></li><li>Litestream: <a href='https://litestream.io/'>https://litestream.io/</a></li><li>MagicDNS: <a href='https://tailscale.com/kb/1081/magicdns/'>https://tailscale.com/kb/1081/magicdns/</a></li><li>Netstack: <a href='https://github.com/google/netstack'>https://github.com/google/netstack</a></li></ul><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>“Can I Tailscale my Chromecast?” <br/><br/>You love Tailscale, I love Tailscale, we loved talking to Avery Pennarun and Brad Fitzpatrick from Tailscale about, I dunno, Go generics. Oh, and TAILSCALE! And DNS. And WASM.<br/><br/><b>Transcript:</b><br/><a href='https://securitycryptographywhatever.com/2022/01/15/tailscale-with-avery-pennarun-brad-fitzpatrick/'>https://securitycryptographywhatever.com/2022/01/15/tailscale-with-avery-pennarun-brad-fitzpatrick/</a><br/><br/>People:</p><ul><li>Avery Pennarun (@apenwarr)</li><li>Brad Fitzpatrick (@bradfitz)</li><li>Deirdre Connolly (@durumcrustulum)</li><li>Thomas Ptacek (@tqbf)</li><li>David Adrian (@davidcadrian)</li><li>@SCWPod</li></ul><p><b>Links:</b></p><ul><li>DERP server: <a href='https://github.com/tailscale/tailscale/tree/main/derp'>https://github.com/tailscale/tailscale/tree/main/derp</a></li><li><a href='https://xtermjs.org/'>https://xtermjs.org/</a></li><li>The Tail at Scale : <a href='https://research.google/pubs/pub40801/'>https://research.google/pubs/pub40801/</a></li><li>Raft: <a href='https://raft.github.io/'>https://raft.github.io/</a></li><li>Litestream: <a href='https://litestream.io/'>https://litestream.io/</a></li><li>MagicDNS: <a href='https://tailscale.com/kb/1081/magicdns/'>https://tailscale.com/kb/1081/magicdns/</a></li><li>Netstack: <a href='https://github.com/google/netstack'>https://github.com/google/netstack</a></li></ul><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9890092-tailscale-with-avery-pennarun-and-brad-fitzpatrick.mp3" length="56456573" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2022/01/15/tailscale-with-avery-pennarun-brad-fitzpatrick/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9890092</guid>
    <pubDate>Sat, 15 Jan 2022 04:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9890092/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9890092/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9890092/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9890092/transcript.vtt" type="text/vtt" />
    <itunes:duration>4702</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>The feeling&#39;s mutual: mTLS with Colm MacCárthaigh</itunes:title>
    <title>The feeling&#39;s mutual: mTLS with Colm MacCárthaigh</title>
    <itunes:summary><![CDATA[We recorded this months ago, and now it's finally up!   Colm MacCárthaigh joined us to chat about all things TLS, S2N, MTLS, SSH, fuzzing, formal verification, implementing state machines, and of course, DNSSEC.  Transcript:  https://securitycryptographywhatever.com/2021/12/29/the-feeling-s-mutual-mtls-with-colm-maccarthaigh/  Find us at: https://twitter.com/scwpod https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian     "Security Cryptography What...]]></itunes:summary>
    <description><![CDATA[<p>We recorded this months ago, and now it&apos;s finally up!<br/> <br/>Colm MacCárthaigh joined us to chat about all things TLS, <a href='https://github.com/aws/s2n-tls'>S2N</a>, MTLS, SSH, fuzzing, formal verification, implementing state machines, and of course, DNSSEC.<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2021/12/29/the-feeling-s-mutual-mtls-with-colm-maccarthaigh/'>https://securitycryptographywhatever.com/2021/12/29/the-feeling-s-mutual-mtls-with-colm-maccarthaigh/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We recorded this months ago, and now it&apos;s finally up!<br/> <br/>Colm MacCárthaigh joined us to chat about all things TLS, <a href='https://github.com/aws/s2n-tls'>S2N</a>, MTLS, SSH, fuzzing, formal verification, implementing state machines, and of course, DNSSEC.<br/><br/><b>Transcript:</b> <br/><a href='https://securitycryptographywhatever.com/2021/12/29/the-feeling-s-mutual-mtls-with-colm-maccarthaigh/'>https://securitycryptographywhatever.com/2021/12/29/the-feeling-s-mutual-mtls-with-colm-maccarthaigh/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9801340-the-feeling-s-mutual-mtls-with-colm-maccarthaigh.mp3" length="50797190" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/12/29/the-feeling-s-mutual-mtls-with-colm-maccarthaigh/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9801340</guid>
    <pubDate>Wed, 29 Dec 2021 01:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9801340/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9801340/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9801340/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9801340/transcript.vtt" type="text/vtt" />
    <itunes:duration>4231</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Holiday Call-in Spectacular!</itunes:title>
    <title>Holiday Call-in Spectacular!</title>
    <itunes:summary><![CDATA[Happy New Year! Feliz Navidad! Merry Yule! Happy Hannukah! Pour one out for the log4j incident responders!  We did a call-in episode on Twitter Spaces and recorded it, so that's why the audio sounds different. We talked about BLOCKCHAIN/Web3 (blech), testing, post-quantum crypto, client certificates, ssh client certificates, threshold cryptography, U2F/WebAuthn, car fob attacks, geese, and more!  Transcript:  https://securitycryptographywhatever.com/2021/12/21/holiday-call-in-spectacular/  Fi...]]></itunes:summary>
    <description><![CDATA[<p>Happy New Year! Feliz Navidad! Merry Yule! Happy Hannukah! Pour one out for the log4j incident responders!<br/><br/>We did a call-in episode on Twitter Spaces and recorded it, so that&apos;s why the audio sounds different. We talked about BLOCKCHAIN/Web3 (blech), testing, post-quantum crypto, client certificates, ssh client certificates, threshold cryptography, U2F/WebAuthn, car fob attacks, geese, and more!<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/12/21/holiday-call-in-spectacular/'>https://securitycryptographywhatever.com/2021/12/21/holiday-call-in-spectacular/<br/></a><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/> </p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Happy New Year! Feliz Navidad! Merry Yule! Happy Hannukah! Pour one out for the log4j incident responders!<br/><br/>We did a call-in episode on Twitter Spaces and recorded it, so that&apos;s why the audio sounds different. We talked about BLOCKCHAIN/Web3 (blech), testing, post-quantum crypto, client certificates, ssh client certificates, threshold cryptography, U2F/WebAuthn, car fob attacks, geese, and more!<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/12/21/holiday-call-in-spectacular/'>https://securitycryptographywhatever.com/2021/12/21/holiday-call-in-spectacular/<br/></a><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/> </p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9767820-holiday-call-in-spectacular.mp3" length="59171550" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/12/21/holiday-call-in-spectacular/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9767820</guid>
    <pubDate>Tue, 21 Dec 2021 21:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9767820/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9767820/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9767820/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9767820/transcript.vtt" type="text/vtt" />
    <itunes:duration>4929</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>WireGuard with Jason Donenfeld</itunes:title>
    <title>WireGuard with Jason Donenfeld</title>
    <itunes:summary><![CDATA[Hey, a new episode! We had a fantastic conversation with Jason Donenfeld, creator of our favorite modern VPN protocol: WireGuard! We touched on kernel hacking, formal verification, post-quantum cryptography, developing with disassemblers, and more!  Transcript:  https://securitycryptographywhatever.com/2021/12/05/wireguard-with-jason-donenfeld/  Links:  WireGuard: https://www.wireguard.comTamarin: https://tamarin-prover.github.ioIDApro: https://hex-rays.com/ida-proNIST PQC: https://csrc....]]></itunes:summary>
    <description><![CDATA[<p>Hey, a new episode! We had a fantastic conversation with Jason Donenfeld, creator of our favorite modern VPN protocol: WireGuard! We touched on kernel hacking, formal verification, post-quantum cryptography, developing with disassemblers, and more!<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/12/05/wireguard-with-jason-donenfeld/'>https://securitycryptographywhatever.com/2021/12/05/wireguard-with-jason-donenfeld/</a><br/><br/>Links: </p><ul><li><b>WireGuard: </b><a href='https://blog.cryptographyengineering.com/should-you-use-srp'>https://www.wireguard.com</a></li><li><b>Tamarin</b>: <a href='https://tamarin-prover.github.io'>https://tamarin-prover.github.io</a></li><li><b>IDApro</b>: <a href='https://hex-rays.com/ida-pro'>https://hex-rays.com/ida-pro</a></li><li><b>NIST PQC</b>: <a href='https://csrc.nist.gov/projects/post-quantum-cryptography/round-3-submissions'>https://csrc.nist.gov/projects/post-quantum-cryptography/round-3-submissions</a></li><li><b>WireGuard Patreon</b>: <a href='https://www.patreon.com/zx2c4'>https://www.patreon.com/zx2c4</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Hey, a new episode! We had a fantastic conversation with Jason Donenfeld, creator of our favorite modern VPN protocol: WireGuard! We touched on kernel hacking, formal verification, post-quantum cryptography, developing with disassemblers, and more!<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/12/05/wireguard-with-jason-donenfeld/'>https://securitycryptographywhatever.com/2021/12/05/wireguard-with-jason-donenfeld/</a><br/><br/>Links: </p><ul><li><b>WireGuard: </b><a href='https://blog.cryptographyengineering.com/should-you-use-srp'>https://www.wireguard.com</a></li><li><b>Tamarin</b>: <a href='https://tamarin-prover.github.io'>https://tamarin-prover.github.io</a></li><li><b>IDApro</b>: <a href='https://hex-rays.com/ida-pro'>https://hex-rays.com/ida-pro</a></li><li><b>NIST PQC</b>: <a href='https://csrc.nist.gov/projects/post-quantum-cryptography/round-3-submissions'>https://csrc.nist.gov/projects/post-quantum-cryptography/round-3-submissions</a></li><li><b>WireGuard Patreon</b>: <a href='https://www.patreon.com/zx2c4'>https://www.patreon.com/zx2c4</a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9667632-wireguard-with-jason-donenfeld.mp3" length="58418191" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/12/05/wireguard-with-jason-donenfeld/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9667632</guid>
    <pubDate>Sun, 05 Dec 2021 17:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9667632/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9667632/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9667632/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9667632/transcript.vtt" type="text/vtt" />
    <itunes:duration>4866</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>PAKEs, oPRFs, algebra with George Tankersley</itunes:title>
    <title>PAKEs, oPRFs, algebra with George Tankersley</title>
    <itunes:summary><![CDATA[A conversation that started with PAKEs (password-authenticated key exchanges) and touched on some cool math things: PRFs, finite fields, elliptic curve groups, anonymity protocols, hashing to curve groups, prime order groups, and more.   With special guest, George Tankersley!  Transcript:  https://securitycryptographywhatever.com/2021/10/26/pakes-oprfs-algebra-with-george-tankersley/  Links:  SRP deprecation: https://blog.cryptographyengineering.com/should-you-use-srpOPAQUE: https://www....]]></itunes:summary>
    <description><![CDATA[<p>A conversation that started with PAKEs (password-authenticated key exchanges) and touched on some cool math things: PRFs, finite fields, elliptic curve groups, anonymity protocols, hashing to curve groups, prime order groups, and more. <br/><br/>With special guest, George Tankersley!<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/10/26/pakes-oprfs-algebra-with-george-tankersley/'>https://securitycryptographywhatever.com/2021/10/26/pakes-oprfs-algebra-with-george-tankersley/</a><br/><br/>Links: </p><ul><li><b>SRP deprecation: </b><a href='https://blog.cryptographyengineering.com/should-you-use-srp'>https://blog.cryptographyengineering.com/should-you-use-srp</a></li><li><b>OPAQUE: </b><a href='https://www.ietf.org/id/draft-irtf-cfrg-opaque-06.html'>https://www.ietf.org/id/draft-irtf-cfrg-opaque-06.html</a></li><li><b>obfs: </b><a href='https://github.com/shadowsocks/simple-obfs'><b>https://github.com/shadowsocks/simple-obfs</b></a></li><li><b>Elligator: </b><a href='https://elligator.cr.yp.to/'><b>https://elligator.cr.yp.to</b></a></li><li><b>Hash to Curve: </b><a href='https://www.ietf.org/archive/id/draft-irtf-cfrg-hash-to-curve-12.html'><b>https://www.ietf.org/archive/id/draft-irtf-cfrg-hash-to-curve-12.html</b></a></li><li><b>Magic Wormhole: </b><a href='https://github.com/magic-wormhole/magic-wormhole'><b>https://github.com/magic-wormhole/magic-wormhole</b></a></li><li><b>Biscuits: </b><a href='https://github.com/CleverCloud/biscuit'><b>https://github.com/CleverCloud/biscuit</b></a></li><li><b>Ristretto: </b><a href='https://ristretto.group/'><b>https://ristretto.group</b></a></li><li><b>Monero signature bug: </b><a href='https://www.getmonero.org/ru/2017/05/17/disclosure-of-a-major-bug-in-cryptonote-based-currencies.html'><b>https://www.getmonero.org/ru/2017/05/17/disclosure-of-a-major-bug-in-cryptonote-based-currencies.html</b></a></li><li><b>SIDH smooth-order supersingular curves: </b><a href='https://link.springer.com/chapter/10.1007/978-3-662-53018-4_21'><b>https://link.springer.com/chapter/10.1007/978-3-662-53018-4_21</b></a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>A conversation that started with PAKEs (password-authenticated key exchanges) and touched on some cool math things: PRFs, finite fields, elliptic curve groups, anonymity protocols, hashing to curve groups, prime order groups, and more. <br/><br/>With special guest, George Tankersley!<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/10/26/pakes-oprfs-algebra-with-george-tankersley/'>https://securitycryptographywhatever.com/2021/10/26/pakes-oprfs-algebra-with-george-tankersley/</a><br/><br/>Links: </p><ul><li><b>SRP deprecation: </b><a href='https://blog.cryptographyengineering.com/should-you-use-srp'>https://blog.cryptographyengineering.com/should-you-use-srp</a></li><li><b>OPAQUE: </b><a href='https://www.ietf.org/id/draft-irtf-cfrg-opaque-06.html'>https://www.ietf.org/id/draft-irtf-cfrg-opaque-06.html</a></li><li><b>obfs: </b><a href='https://github.com/shadowsocks/simple-obfs'><b>https://github.com/shadowsocks/simple-obfs</b></a></li><li><b>Elligator: </b><a href='https://elligator.cr.yp.to/'><b>https://elligator.cr.yp.to</b></a></li><li><b>Hash to Curve: </b><a href='https://www.ietf.org/archive/id/draft-irtf-cfrg-hash-to-curve-12.html'><b>https://www.ietf.org/archive/id/draft-irtf-cfrg-hash-to-curve-12.html</b></a></li><li><b>Magic Wormhole: </b><a href='https://github.com/magic-wormhole/magic-wormhole'><b>https://github.com/magic-wormhole/magic-wormhole</b></a></li><li><b>Biscuits: </b><a href='https://github.com/CleverCloud/biscuit'><b>https://github.com/CleverCloud/biscuit</b></a></li><li><b>Ristretto: </b><a href='https://ristretto.group/'><b>https://ristretto.group</b></a></li><li><b>Monero signature bug: </b><a href='https://www.getmonero.org/ru/2017/05/17/disclosure-of-a-major-bug-in-cryptonote-based-currencies.html'><b>https://www.getmonero.org/ru/2017/05/17/disclosure-of-a-major-bug-in-cryptonote-based-currencies.html</b></a></li><li><b>SIDH smooth-order supersingular curves: </b><a href='https://link.springer.com/chapter/10.1007/978-3-662-53018-4_21'><b>https://link.springer.com/chapter/10.1007/978-3-662-53018-4_21</b></a></li></ul><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9439685-pakes-oprfs-algebra-with-george-tankersley.mp3" length="54135297" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/10/26/pakes-oprfs-algebra-with-george-tankersley/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9439685</guid>
    <pubDate>Tue, 26 Oct 2021 19:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9439685/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9439685/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9439685/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9439685/transcript.vtt" type="text/vtt" />
    <itunes:duration>4509</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>&quot;Patch, Damnit!&quot;</itunes:title>
    <title>&quot;Patch, Damnit!&quot;</title>
    <itunes:summary><![CDATA[A lot of fixes got pushed in the past week! Please apply your updates!  Apple, Chrome, Matrix, Azure, and more nonsense.  Transcript: https://securitycryptographywhatever.com/2021/09/20/patch-damnit/  Find us at: https://twitter.com/scwpod https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian  Links! The accuvant story in MIT Technology Review All the Apple platforms patched FORCEDENTRY no-click 0-day Chrome patched some 0-days that were being exploited ...]]></itunes:summary>
    <description><![CDATA[<p>A lot of fixes got pushed in the past week! Please apply your updates! <br/>Apple, Chrome, Matrix, Azure, and more nonsense.<br/><br/>Transcript:<br/><a href='https://securitycryptographywhatever.com/2021/09/20/patch-damnit/'>https://securitycryptographywhatever.com/2021/09/20/patch-damnit/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/>Links!<br/><a href='https://www.technologyreview.com/2021/09/15/1035813/us-sold-iphone-exploit-uae'>The accuvant story in MIT Technology Review</a><br/>All the Apple platforms <a href='https://support.apple.com/en-us/HT212807'>patched</a> <a href='https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild/'>FORCEDENTRY</a> no-click 0-day<br/>Chrome <a href='https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html'>patched some 0-days</a> that were being exploited in the wild<br/>PASETO <a href='https://paragonie.com/blog/2021/09/promoting-misuse-resistance-in-paseto-libraries'>update</a> <br/><br/><a href='https://securitycryptographywhatever.com/2021/09/20/patch-damnit/'><br/></a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>A lot of fixes got pushed in the past week! Please apply your updates! <br/>Apple, Chrome, Matrix, Azure, and more nonsense.<br/><br/>Transcript:<br/><a href='https://securitycryptographywhatever.com/2021/09/20/patch-damnit/'>https://securitycryptographywhatever.com/2021/09/20/patch-damnit/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/>Links!<br/><a href='https://www.technologyreview.com/2021/09/15/1035813/us-sold-iphone-exploit-uae'>The accuvant story in MIT Technology Review</a><br/>All the Apple platforms <a href='https://support.apple.com/en-us/HT212807'>patched</a> <a href='https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild/'>FORCEDENTRY</a> no-click 0-day<br/>Chrome <a href='https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html'>patched some 0-days</a> that were being exploited in the wild<br/>PASETO <a href='https://paragonie.com/blog/2021/09/promoting-misuse-resistance-in-paseto-libraries'>update</a> <br/><br/><a href='https://securitycryptographywhatever.com/2021/09/20/patch-damnit/'><br/></a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9225773-patch-damnit.mp3" length="53974830" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/09/20/patch-damnit/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9225773</guid>
    <pubDate>Mon, 20 Sep 2021 04:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9225773/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9225773/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9225773/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9225773/transcript.vtt" type="text/vtt" />
    <itunes:duration>4496</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How to be a Certificate Authority with Ryan Sleevi</itunes:title>
    <title>How to be a Certificate Authority with Ryan Sleevi</title>
    <itunes:summary><![CDATA[Not the hero the internet deserves, but the one we need: it's Ryan Sleevi!  We get into the weeds on becoming a certificate authority, auditing said authorities, DNSSEC, DANE, taking over country code top level domains, Luxembourg, X.509, ASN.1, CBOR, more JSON (!), ACME, Let's Encrypt, and more, on this extra lorge episode with the web PKI's Batman.   Transcript:  https://securitycryptographywhatever.com/2021/09/06/how-to-be-a-certificate-authority-with-ryan-sleevi/  Find us at: https://twit...]]></itunes:summary>
    <description><![CDATA[<p>Not the hero the internet deserves, but the one we need: it&apos;s Ryan Sleevi!<br/><br/>We get into the weeds on becoming a certificate authority, auditing said authorities, DNSSEC, DANE, taking over country code top level domains, Luxembourg, X.509, ASN.1, CBOR, more JSON (!), ACME, Let&apos;s Encrypt, and more, on this extra lorge episode with the web PKI&apos;s Batman.<br/><br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/09/06/how-to-be-a-certificate-authority-with-ryan-sleevi/'>https://securitycryptographywhatever.com/2021/09/06/how-to-be-a-certificate-authority-with-ryan-sleevi/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Not the hero the internet deserves, but the one we need: it&apos;s Ryan Sleevi!<br/><br/>We get into the weeds on becoming a certificate authority, auditing said authorities, DNSSEC, DANE, taking over country code top level domains, Luxembourg, X.509, ASN.1, CBOR, more JSON (!), ACME, Let&apos;s Encrypt, and more, on this extra lorge episode with the web PKI&apos;s Batman.<br/><br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/09/06/how-to-be-a-certificate-authority-with-ryan-sleevi/'>https://securitycryptographywhatever.com/2021/09/06/how-to-be-a-certificate-authority-with-ryan-sleevi/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9146390-how-to-be-a-certificate-authority-with-ryan-sleevi.mp3" length="67838310" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/09/06/how-to-be-a-certificate-authority-with-ryan-sleevi/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9146390</guid>
    <pubDate>Mon, 06 Sep 2021 04:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9146390/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9146390/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9146390/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9146390/transcript.vtt" type="text/vtt" />
    <itunes:duration>5651</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Apple&#39;s CSAM Detection with Matthew Green</itunes:title>
    <title>Apple&#39;s CSAM Detection with Matthew Green</title>
    <itunes:summary><![CDATA[We're talking about Apple's new proposed client-side CSAM detection system. We weren't sure if we were going to cover this, and then we realized that not all of us have been paying super close attention to what the hell this thing is, and have a lot of questions about it. So we're talking about it, with our special guest Professor Matthew Green.  We cover how Apple's system works, what it does (and doesn't), where we have unanswered questions, and where some of the gaps are.  Transcript:  htt...]]></itunes:summary>
    <description><![CDATA[<p>We&apos;re talking about Apple&apos;s new proposed <a href='https://www.apple.com/child-safety/'>client-side CSAM detection system</a>. We weren&apos;t sure if we were going to cover this, and then we realized that not all of us have been paying super close attention to what the hell this thing is, and have a lot of questions about it. So we&apos;re talking about it, with our special guest Professor Matthew Green.<br/><br/>We cover how Apple&apos;s system works, what it does (and doesn&apos;t), where we have unanswered questions, and where some of the gaps are.<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/08/27/apple-s-csam-detection-with-matthew-green/'>https://securitycryptographywhatever.com/2021/08/27/apple-s-csam-detection-with-matthew-green/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/>Links:<br/><a href='https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf'>https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf</a></p><p><a href='https://www.apple.com/child-safety/pdf/Apple_PSI_System_Security_Protocol_and_Analysis.pdf'>https://www.apple.com/child-safety/pdf/Apple_PSI_System_Security_Protocol_and_Analysis.pdf</a></p><p><a href='https://www.law.cornell.edu/uscode/text/18/2258A'>https://www.law.cornell.edu/uscode/text/18/2258A</a></p><p><a href='https://www.missingkids.org/content/dam/missingkids/gethelp/2020-reports-by-esp.pdf'>https://www.missingkids.org/content/dam/missingkids/gethelp/2020-reports-by-esp.pdf</a></p><p><a href='https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT'>https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT</a></p><p><a href='https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_what_it_does'>https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_what_it_does</a></p><p><a href='https://research.fb.com/blog/2021/02/understanding-the-intentions-of-child-sexual-abuse-material-csam-sharers/'>https://research.fb.com/blog/2021/02/understanding-the-intentions-of-child-sexual-abuse-material-csam-sharers/</a></p><p><a href='https://www.nytimes.com/interactive/2019/11/09/us/internet-child-sex-abuse.html'>https://www.nytimes.com/interactive/2019/11/09/us/internet-child-sex-abuse.html</a></p><p><a href='https://www.apple.com/child-safety/pdf/Expanded_Protections_for_Children_Frequently_Asked_Questions.pdf'>https://www.apple.com/child-safety/pdf/Expanded_Protections_for_Children_Frequently_Asked_Questions.pdf</a></p><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We&apos;re talking about Apple&apos;s new proposed <a href='https://www.apple.com/child-safety/'>client-side CSAM detection system</a>. We weren&apos;t sure if we were going to cover this, and then we realized that not all of us have been paying super close attention to what the hell this thing is, and have a lot of questions about it. So we&apos;re talking about it, with our special guest Professor Matthew Green.<br/><br/>We cover how Apple&apos;s system works, what it does (and doesn&apos;t), where we have unanswered questions, and where some of the gaps are.<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/08/27/apple-s-csam-detection-with-matthew-green/'>https://securitycryptographywhatever.com/2021/08/27/apple-s-csam-detection-with-matthew-green/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/>Links:<br/><a href='https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf'>https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf</a></p><p><a href='https://www.apple.com/child-safety/pdf/Apple_PSI_System_Security_Protocol_and_Analysis.pdf'>https://www.apple.com/child-safety/pdf/Apple_PSI_System_Security_Protocol_and_Analysis.pdf</a></p><p><a href='https://www.law.cornell.edu/uscode/text/18/2258A'>https://www.law.cornell.edu/uscode/text/18/2258A</a></p><p><a href='https://www.missingkids.org/content/dam/missingkids/gethelp/2020-reports-by-esp.pdf'>https://www.missingkids.org/content/dam/missingkids/gethelp/2020-reports-by-esp.pdf</a></p><p><a href='https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT'>https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT</a></p><p><a href='https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_what_it_does'>https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_what_it_does</a></p><p><a href='https://research.fb.com/blog/2021/02/understanding-the-intentions-of-child-sexual-abuse-material-csam-sharers/'>https://research.fb.com/blog/2021/02/understanding-the-intentions-of-child-sexual-abuse-material-csam-sharers/</a></p><p><a href='https://www.nytimes.com/interactive/2019/11/09/us/internet-child-sex-abuse.html'>https://www.nytimes.com/interactive/2019/11/09/us/internet-child-sex-abuse.html</a></p><p><a href='https://www.apple.com/child-safety/pdf/Expanded_Protections_for_Children_Frequently_Asked_Questions.pdf'>https://www.apple.com/child-safety/pdf/Expanded_Protections_for_Children_Frequently_Asked_Questions.pdf</a></p><p><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9099774-apple-s-csam-detection-with-matthew-green.mp3" length="38147465" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/08/27/apple-s-csam-detection-with-matthew-green/</link>
    <itunes:author>Deirdre Connolly, Thomas Ptacek, David Adrian</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9099774</guid>
    <pubDate>Fri, 27 Aug 2021 23:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9099774/transcript" type="text/html" />
    <itunes:duration>3177</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Platform Security Part Deux with Justin Schuh</itunes:title>
    <title>Platform Security Part Deux with Justin Schuh</title>
    <itunes:summary><![CDATA[We did not run out of things to talk about: Chrome vs. Safari vs. Firefox. Rust vs. C++. Bug bounties vs. exploit development. The Peace Corps vs. The Marine Corps.  Transcript:  https://securitycryptographywhatever.com/2021/08/21/platform-security-part-deux-with-justin-schuh/  Find us at: https://twitter.com/scwpod https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian    "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), T...]]></itunes:summary>
    <description><![CDATA[<p>We did not run out of things to talk about: Chrome vs. Safari vs. Firefox. Rust vs. C++. Bug bounties vs. exploit development. The Peace Corps vs. The Marine Corps.<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/08/21/platform-security-part-deux-with-justin-schuh/'>https://securitycryptographywhatever.com/2021/08/21/platform-security-part-deux-with-justin-schuh/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>We did not run out of things to talk about: Chrome vs. Safari vs. Firefox. Rust vs. C++. Bug bounties vs. exploit development. The Peace Corps vs. The Marine Corps.<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/08/21/platform-security-part-deux-with-justin-schuh/'>https://securitycryptographywhatever.com/2021/08/21/platform-security-part-deux-with-justin-schuh/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><br/></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9063230-platform-security-part-deux-with-justin-schuh.mp3" length="57649291" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/08/21/platform-security-part-deux-with-justin-schuh/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9063230</guid>
    <pubDate>Sat, 21 Aug 2021 00:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9063230/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9063230/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9063230/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9063230/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="4324.471" duration="48.0" />
    <itunes:duration>4802</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>What do we do about JWT? with Jonathan Rudenberg</itunes:title>
    <title>What do we do about JWT? with Jonathan Rudenberg</title>
    <itunes:summary><![CDATA[🔥JWT🔥  We talk about all sorts of tokens: JWT, PASETO, Protobuf Tokens, Macaroons, and Biscuits. With the great Jonathan Rudenberg!  After we recorded this, Thomas went deep on tokens even beyond what we talked about here: https://fly.io/blog/api-tokens-a-tedious-survey/  Transcript: https://securitycryptographywhatever.com/2021/08/12/what-do-we-do-about-jwt-with-jonathan-rudenberg/  Find us at: https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian https...]]></itunes:summary>
    <description><![CDATA[<p>🔥JWT🔥<br/><br/>We talk about all sorts of tokens: JWT, PASETO, Protobuf Tokens, Macaroons, and Biscuits. With the great Jonathan Rudenberg!<br/><br/>After we recorded this, Thomas went deep on tokens even beyond what we talked about here: <a href='https://fly.io/blog/api-tokens-a-tedious-survey/'>https://fly.io/blog/api-tokens-a-tedious-survey/</a><br/><br/>Transcript: <a href='https://securitycryptographywhatever.com/2021/08/12/what-do-we-do-about-jwt-with-jonathan-rudenberg/'>https://securitycryptographywhatever.com/2021/08/12/what-do-we-do-about-jwt-with-jonathan-rudenberg/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>🔥JWT🔥<br/><br/>We talk about all sorts of tokens: JWT, PASETO, Protobuf Tokens, Macaroons, and Biscuits. With the great Jonathan Rudenberg!<br/><br/>After we recorded this, Thomas went deep on tokens even beyond what we talked about here: <a href='https://fly.io/blog/api-tokens-a-tedious-survey/'>https://fly.io/blog/api-tokens-a-tedious-survey/</a><br/><br/>Transcript: <a href='https://securitycryptographywhatever.com/2021/08/12/what-do-we-do-about-jwt-with-jonathan-rudenberg/'>https://securitycryptographywhatever.com/2021/08/12/what-do-we-do-about-jwt-with-jonathan-rudenberg/</a><br/><br/>Find us at:<br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf</a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a><br/><a href='https://twitter.com/scwpod'>https://twitter.com/scwpod</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/9020991-what-do-we-do-about-jwt-with-jonathan-rudenberg.mp3" length="53972947" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/08/12/what-do-we-do-about-jwt-with-jonathan-rudenberg/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-9020991</guid>
    <pubDate>Thu, 12 Aug 2021 16:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9020991/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9020991/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9020991/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/9020991/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="0.0" duration="30.0" />
    <itunes:duration>4496</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Great &quot;Roll Your Own Crypto&quot; Debate with Filippo Valsorda</itunes:title>
    <title>The Great &quot;Roll Your Own Crypto&quot; Debate with Filippo Valsorda</title>
    <itunes:summary><![CDATA[Special guest Filippo Valsorda joins us to debate with Thomas on whether one should or should not "roll your own crypto", and how to produce better cryptography in general.  After we recorded this, David went even deeper  on 'rolling your own crypto' in a blog post here: https://dadrian.io/blog/posts/roll-your-own-crypto/  Transcript:  https://securitycryptographywhatever.com/2021/07/31/the-great-roll-your-own-crypto-debate-with-filippo-valsorda/  Links: https://peter.website/meow-hash-c...]]></itunes:summary>
    <description><![CDATA[<p>Special guest <a href='https://twitter.com/filosottile'>Filippo Valsorda</a> joins us to debate with Thomas on whether one should or should not &quot;roll your own crypto&quot;, and how to produce better cryptography in general.<br/><br/>After we recorded this, David went even deeper  on &apos;rolling your own crypto&apos; in a blog post here: <a href='https://dadrian.io/blog/posts/roll-your-own-crypto/'>https://dadrian.io/blog/posts/roll-your-own-crypto/</a><br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/07/31/the-great-roll-your-own-crypto-debate-with-filippo-valsorda/'>https://securitycryptographywhatever.com/2021/07/31/the-great-roll-your-own-crypto-debate-with-filippo-valsorda/</a><br/><br/>Links:<br/><a href='https://peter.website/meow-hash-cryptanalysis'>https://peter.website/meow-hash-cryptanalysis</a><br/><a href='https://arxiv.org/pdf/2107.04940.pdf'>https://arxiv.org/pdf/2107.04940.pdf</a><br/><a href='https://ristretto.group/'>https://ristretto.group</a><br/><a href='https://filippo.io/heartbleed'>https://filippo.io/heartbleed</a><br/><br/>Find us at:<br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf </a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Special guest <a href='https://twitter.com/filosottile'>Filippo Valsorda</a> joins us to debate with Thomas on whether one should or should not &quot;roll your own crypto&quot;, and how to produce better cryptography in general.<br/><br/>After we recorded this, David went even deeper  on &apos;rolling your own crypto&apos; in a blog post here: <a href='https://dadrian.io/blog/posts/roll-your-own-crypto/'>https://dadrian.io/blog/posts/roll-your-own-crypto/</a><br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/07/31/the-great-roll-your-own-crypto-debate-with-filippo-valsorda/'>https://securitycryptographywhatever.com/2021/07/31/the-great-roll-your-own-crypto-debate-with-filippo-valsorda/</a><br/><br/>Links:<br/><a href='https://peter.website/meow-hash-cryptanalysis'>https://peter.website/meow-hash-cryptanalysis</a><br/><a href='https://arxiv.org/pdf/2107.04940.pdf'>https://arxiv.org/pdf/2107.04940.pdf</a><br/><a href='https://ristretto.group/'>https://ristretto.group</a><br/><a href='https://filippo.io/heartbleed'>https://filippo.io/heartbleed</a><br/><br/>Find us at:<br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf </a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/8953842-the-great-roll-your-own-crypto-debate-with-filippo-valsorda.mp3" length="43797424" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/07/31/the-great-roll-your-own-crypto-debate-with-filippo-valsorda/</link>
    <itunes:author>Security, Cryptography, Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-8953842</guid>
    <pubDate>Sat, 31 Jul 2021 18:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/8953842/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/8953842/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/8953842/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/8953842/transcript.vtt" type="text/vtt" />
    <itunes:duration>3648</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>NSO group, Pegasus, Zero-Days, i(OS|Message) security</itunes:title>
    <title>NSO group, Pegasus, Zero-Days, i(OS|Message) security</title>
    <itunes:summary><![CDATA[Deirdre, Thomas and David talk about NSO group, Pegasus,  whether iOS a burning trash fire, the zero-day market, and whether rewriting all of iOS in Swift is a viable strategy for reducing all these vulns.  Transcript:  https://securitycryptographywhatever.com/2021/07/26/nso-group-pegasus-zero-days-i-os-message-security/  Find us at:  https://twitter.com/durumcrustulum https://twitter.com/tqbf  https://twitter.com/davidcadrian  "Security Cryptography Whatever" is hosted by Deirdre Connol...]]></itunes:summary>
    <description><![CDATA[<p>Deirdre, Thomas and David talk about NSO group, Pegasus,  whether iOS a burning trash fire, the zero-day market, and whether rewriting all of iOS in Swift is a viable strategy for reducing all these vulns.<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/07/26/nso-group-pegasus-zero-days-i-os-message-security/'>https://securitycryptographywhatever.com/2021/07/26/nso-group-pegasus-zero-days-i-os-message-security/</a><br/><br/>Find us at:<br/><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf </a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></description>
    <content:encoded><![CDATA[<p>Deirdre, Thomas and David talk about NSO group, Pegasus,  whether iOS a burning trash fire, the zero-day market, and whether rewriting all of iOS in Swift is a viable strategy for reducing all these vulns.<br/><br/>Transcript: <br/><a href='https://securitycryptographywhatever.com/2021/07/26/nso-group-pegasus-zero-days-i-os-message-security/'>https://securitycryptographywhatever.com/2021/07/26/nso-group-pegasus-zero-days-i-os-message-security/</a><br/><br/>Find us at:<br/><br/><a href='https://twitter.com/durumcrustulum'>https://twitter.com/durumcrustulum</a><br/><a href='https://twitter.com/tqbf'>https://twitter.com/tqbf </a><br/><a href='https://twitter.com/davidcadrian'>https://twitter.com/davidcadrian</a></p><p><br/>&quot;Security Cryptography Whatever&quot; is hosted by <a href='https://twitter.com/durumcrustulum'>Deirdre Connolly</a> (@durumcrustulum), <a href='https://twitter.com/tqbf'>Thomas Ptacek</a> (@tqbf), and <a href='https://twitter.com/dadrian'>David Adrian</a> (@dadrian)</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1822302/episodes/8926799-nso-group-pegasus-zero-days-i-os-message-security.mp3" length="42922191" type="audio/mpeg" />
    <link>https://securitycryptographywhatever.com/2021/07/26/nso-group-pegasus-zero-days-i-os-message-security/</link>
    <itunes:author>Security Cryptography Whatever </itunes:author>
    <guid isPermaLink="false">Buzzsprout-8926799</guid>
    <pubDate>Mon, 26 Jul 2021 19:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1822302/8926799/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/8926799/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/8926799/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1822302/8926799/transcript.vtt" type="text/vtt" />
    <itunes:duration>3575</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
