







This is a quick post I wanted to write about a hobby project I spent a weekend on. It has little to do with real cryptography, and mostly doesn’t expose a particularly exciting vulnerability.…
Encrypted Spaces — Research preview
An architecture for collaborative applications where data is encrypted and operations are cryptographically verifiable.

Let’s talk about AI and end-to-end encryption
Recently I came across a fantastic new paper by a group of NYU and Cornell researchers entitled “How to think about end-to-end encryption and AI.” I’m extremely grateful to see th…

Web-based cryptography is always snake oil
Nowadays, there is an epidemic of web applications purporting to offer “end-to-end” encryption. Examples might range from a file upload service, which allows you to upload and share files of arbitrary size and promises “end-to-end encryption”; or a web-based password safe service which claims that it can't see your passwords because they're encrypted; or a web-based cryptocurrency wallet.

OKCupid Co-Founder Max Krohn Believes People Are Ready to Love Encryption
Encryption has always been good, the problem is that it’s never been easy.

A Post-Quantum Future for Let's Encrypt
Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (“MTCs”), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. This post is about these plans and why we believe MTCs are worth pursuing as a key to a post-quantum future. An increasingly urgent problem For much of the last several years, the conversation about post-quantum cryptography has been a conversation about encryption. The reasoning was straightforward: an attacker who records encrypted traffic today might be able to decrypt it years from now once quantum computers can break the underlying math. Authentication, the part of TLS that indicates a server is who it says it is, has been a less urgent problem. A quantum computer needs to forge a signature in real time, not retroactively, so threats to authentication hinge on the existence of a cryptographically relevant quantum computer (CRQC).

Architecture
Overview of Ente's end-to-end encrypted architecture—learn how your data is encrypted on-device, securely shared, and safely stored using cryptography.

encryption rant
Robustly-secured data that can surprisingly vanish at a moments notice.

Web Crypto’s SubtleCrypto: A Masterclass in Developer Hostility and How It Strangles the Modern Web
Not Subtle, Just Sabotage — An API Against the Web
Noble cryptography
Paul Miller. I make projects which help developers to build awesome things

Cryptopedia — Oakland Public Library
Cryptopedia — Demcak, Andrew — Cryptopedia by Andrew Demcak speaks directly to the secret sides of our beings, to our shadow-selves. It is the oldest story we have, and it wants to be told. This collection comes from a place where children go missing, where monsters roam freely, and urban myths transform into realities.
Privacy, human rights, and Tornado Cash
I am more worried about privacy than crypto crime.

My first impressions of web3
Despite considering myself a cryptographer, I have not found myself particularly drawn to “crypto.” I don’t think I’ve ever actually said the words “get off my lawn,” but I’m much more likely to click on Pepperidge Farm Remembers flavored memes about how “crypto” used to mean “cryptography” than ...
The crypto dream
Arvind Narayanan just gave a fascinating talk at Princeton’s Center for Information Technology Policy entitled ‘What Happened to the Crypto Dream?’. That link is to the video, whi…

Meeting where AI eyes can't follow
I applied to the Community Privacy Residency, and the past projects reminded me of a cryptographic exploration I come back to every once in a while, just for...