Congratulations to our researcher @AlexBakas@twitter.com for having his paper on Function Hiding accepted as a poster at the 21st International Conference on Cryptology and Network Security ( 2022).

The demand for design experts is high. Study at @TampereUni@twitter.com to become one, and you will definitely be needed in the industry. Read about the SoC education offered in Tampere and its relation to the real-life SoC development.

In which a blogger finds the private key used to sign Hyundai car software updates … by googling it. They used a key pair from a popular tutorial. 😂😂😂

IBM's got talent (aye, aye)

The Pirates of the CSIDH salute ye, @KhanhCrypto@twitter.com, Maxime (and extras Sebastian, @BootleJonathan@twitter.com, Patrick, Vadim, @gregor_seiler@twitter.com)


It is 2022, and your computer now runs at 3 MHz.

“Do you mean 3 GHz?”

Nope! A malicious hyperthread can make shared libraries run up to ~1000x slower, resulting in a huge SNR boost for side-channel attacks.

[HyperDegrade, by @acaldaya@twitter.com]

I’m a sucker for vuln research like this. The team found a cool bug (the APIC fails to zero out the full 16 bytes of a buffer used to satisfy a 4-byte read, and so leaks cached data in the unused 12 bytes). But what’s cool is how they did it.

Today we disclose ÆPIC Leak: Architecturally Leaking Uninitialized Data from the Microarchitecture 🔥
It is the *first* architectural CPU bug able to leak sensitive data from the cache hierarchy: like an uninitialized read but in the CPU itself.


New blog post "NSA, NIST, and post-quantum cryptography: Announcing my second lawsuit against the U.S. government." blog.cr.yp.to/20220805-nsa.htm Case filed in federal court today by @LoevyAndLoevy@twitter.com.

Google has open-sourced a new tool called Paranoid that can be used to check for well-known weaknesses in cryptographic artifacts such as public keys, digital signatures, and general pseudorandom numbers


I share with you the released version of sibc!
Thanks to the contributors for the speedups on the library.
You can play with a faster csidh (in python)

PS. We added some links and comments concerning Castryck-Decru's attack!

2022 submission deadline is 22 Aug (AoE)!
27th Nordic Conference on Secure IT Systems,
30 Nov—2 Dec, Reykjavik University, Iceland.

NIST's latest report (1) says NIST is confident in the security of Kyber; (2) says Kyber-512 >= AES-128; (3) says Kyber-768 >= AES-192. But attack advances keep reducing lattice security levels! It will be completely unsurprising if the next round of attacks falsifies #2 and #3.

Kyber is the new PQC KEM! If you wonder how it works, but are a bit afraid of lattices, Ruben Gonzalez and I have you covered: just watch our video at CCC, in which we explain all you need to know: media.ccc.de/v/rc3-2021-cwtv-2

Of all the ways to organize an industrial society that humans have tried so far, the Nordic social democracy is the least bad. Not perfect and in dire need of improvement, but still least bad.

Here's where Finland for instance shines: a thread.

New resource page available on timing attacks, including recommendations for action to take regarding overclocking attacks such as : timing.attacks.cr.yp.to Don't wait for the next public overclocking attack; take proactive steps to defend your data against compromise.

Today we are in Tampere and online for the third regular meeting! Thanks @NISEC_TAU@twitter.com for hosting us!

Happy to be in Tampere with our partners in @SPIRSProject@twitter.com . Thanks to @NISEC_TAU@twitter.com for hosting us!

