CS Prof. Security and applied cryptography. Some highlights: Zerocash (zcash, et al. ), Zexe (Aleo, Aztec, etc ), zk-creds/zk-promises(...)

Washington DC/ UMD
Signal rolled out "Automatic Key Verification," which sounds like gibberish to cryptographers. Turns out, it's key transparency. So what's key transparency? It's a phone book that makes sure you can't secretly be tricked into talking to the wrong person. When Bob talks to Jenny, he needs to know her public key. If he gets the wrong one it's like calling the wrong number. Even if everything is secure, he's talking to the wrong person. The problem is, if the app on Bob's phone just asks for Jenny's key, Signal's servers could lie. Far more problematically, they could be forced to lie by an outside attacker, or hacked. The UK, in particular, seem positively chuffed to try and break encrypted chats this way. Instead of calling Jenny, you'll get some blokes in Cheltenham. Of course, the Brits miss that hackers in Russia or Iran might do the same to calls to Downing Street. Key transparency builds a shared phone book mapping users' names/phone numbers to their public keys. The logic being someone, like say Jenny, will notice if her key is wrong, so we just need to make sure everyone has the same consistent phone book. That book is too big for everyone to have a copy, so Signal keeps it on their server, but then builds a clever way for everyone to make sure they are getting answers from the same unaltered phone book (technically it's a log, not a book). This is done with a Merkle tree and auditors (in Signal's case, currently Cloudflare and Trail of Bits).
4
4
51
4,143
I wonder if the pope, for a split second, contemplated bringing back indulgences, just for AI. After all, if there's a 1% chance it has a soul, surely someone will pay ....
NEW: According to a bombshell report in the New York Times, Anthropic co-founder Chris Olah threatened to walk out of Pope Leo XIV’s AI encyclical launch in May because the pope rejected the idea that machines can be conscious. Olah’s team then privately lobbied the pope’s advisers “to take the possibility of model consciousness seriously.” Pope Leo XIV held firm. For months, Anthropic has wined and dined theologians and religious scholars under nondisclosure agreements, hoping they would bless the idea that Claude has moral standing. thelettersfromleo.com/p/nyt-…
1
3
872
Ian Miers retweeted
NEW: A Federal judge just ruled that a warrantless Flock/ALPR search violated a woman's 4th Amendment rights! "Why is it the government's business where everyone goes all the time?" "Freedom from persistent, dragnet-style surveillance while in public is not a foreign concept in our society, and it is a reasonable expectation that society already accepts" Judge Sara Hill (N.D. Oklahoma) notes other courts, including in Oklahoma, ruled the other way on Flock searches. She argues that a decision from 1983 shouldn't govern 2026 networks of what she calls "indiscriminate mass surveillance." "This Court is now faced with technology that appears to be approaching the dragnet type law enforcement practice Mr. Knotts warned of." Setting up for an interesting fight in circuit court if the government appeals. Story by @jason_koebler 404media.co/federal-judge-ru… Ruling: storage.courtlistener.com/re…
17
351
1,003
26,296
The AI sandbox vs. alignment debate for security kinda misses reality. Existing sandboxes are laughably bad, especially for training. But we should also expect good sandboxes to both get broken AND be necessarily porous to be useful. Which means you end up with an arms race of sandboxes, monitoring, and trying to be clever.
I’ve been reading the sandboxing arguments between infosec people and AI alignment folks, and I tried to summarize and referee them a bit in this post. blog.cryptographyengineering…
3
2
19
2,268
Why does adding private payments to Bitcoin seemingly require witness encryption, the cryptographic equivalent of a jetpack? Why is that awesome, impressive, and a bad idea? And how do you make a cryptocurrency like Bitcoin or Zcash private in the first place? To answer that, we need to cover 1) why Bitcoin is public, 2) how you fix that, 3) the socio-political complications using that solution in Bitcoin, and 4) the cryptographic jetpack workaround.
12
22
115
7,315
Bottom line. Shielded Bitcoin is an impresive idea, in the academic sense. But it's impressive in the same way two surgeons talking about a surgery might be impressed by how involved it was. You don't want to be that patient, no matter how impressive and good the surgeon is. And this is fine for research; it's good people are working on this, it's good work. But if you're in Bitcoin, maybe change your zeitgeist so you don't need open heart surgery while suspended over a valcano by a 3D printed jetpack. Its probably safer.
2
3
22
435
Again, I want to emphasize, the socio-political constraints in Bitcoin are not invented by the authors of Shielded Bitcoin, and they are what lead to the complex design and its downsides. It looks like it’s the best you can do under the circumstances if you want to keep Bitcoin as is. It’s impressive in that sense. I'd say it’s the idea I would have come up with too given these (absurd) constraints, but the truth is I'd have given up and found some folks to make their own blockchain.
2
15
1,084