CS Prof. Security and applied cryptography. Some highlights: Zerocash (zcash, et al. ), Zexe (Aleo, Aztec, etc ), zk-creds/zk-promises(...)

Washington DC/ UMD
Based in United States
Filter
Exclude
Time range
-
Minimum likes
Replying to @bcrypt
Man, I had forgotten about that. The tail end of the "surely we can just add encryption to existing protocols" era.
2
169
Signal rolled out "Automatic Key Verification," which sounds like gibberish to cryptographers. Turns out, it's key transparency. So what's key transparency? It's a phone book that makes sure you can't secretly be tricked into talking to the wrong person. When Bob talks to Jenny, he needs to know her public key. If he gets the wrong one it's like calling the wrong number. Even if everything is secure, he's talking to the wrong person. The problem is, if the app on Bob's phone just asks for Jenny's key, Signal's servers could lie. Far more problematically, they could be forced to lie by an outside attacker, or hacked. The UK, in particular, seem positively chuffed to try and break encrypted chats this way. Instead of calling Jenny, you'll get some blokes in Cheltenham. Of course, the Brits miss that hackers in Russia or Iran might do the same to calls to Downing Street. Key transparency builds a shared phone book mapping users' names/phone numbers to their public keys. The logic being someone, like say Jenny, will notice if her key is wrong, so we just need to make sure everyone has the same consistent phone book. That book is too big for everyone to have a copy, so Signal keeps it on their server, but then builds a clever way for everyone to make sure they are getting answers from the same unaltered phone book (technically it's a log, not a book). This is done with a Merkle tree and auditors (in Signal's case, currently Cloudflare and Trail of Bits).
4
6
57
4,600
Yes, so? There's certainly a possibility a single LLM is somehow conscious. I would imagine most sane people have not spent enough time interacting with one to be sure. Probably they are looking at the totality of AI results and going "huh, maybe." Hence the question about swarms.
1
53
Replying to @matthew_d_green
Are you sure HAl is what we got? Most of the impressive results are from multiple agents interacting. Possibly agent swarms.
1
108
I wonder if the pope, for a split second, contemplated bringing back indulgences, just for AI. After all, if there's a 1% chance it has a soul, surely someone will pay ....
NEW: According to a bombshell report in the New York Times, Anthropic co-founder Chris Olah threatened to walk out of Pope Leo XIV’s AI encyclical launch in May because the pope rejected the idea that machines can be conscious. Olah’s team then privately lobbied the pope’s advisers “to take the possibility of model consciousness seriously.” Pope Leo XIV held firm. For months, Anthropic has wined and dined theologians and religious scholars under nondisclosure agreements, hoping they would bless the idea that Claude has moral standing. thelettersfromleo.com/p/nyt-…
1
3
888
Replying to @colludingnode
So you've forgiven them for the old EWR terminal A?
1
2
70
Replying to @colludingnode
Is exaggeratedly hating New Jersey transplant behavior?
2
5
193
Replying to @matthew_d_green
What happens if it’s the metaphorical equivalent of ants but more of them? Where there's some emergent intelligence in an army of agents, but any given one is not. It seems there's a huge spectrum of what alien intelligence would look like and it’s probably not HAL.
1
4
437
Ian Miers retweeted
NEW: A Federal judge just ruled that a warrantless Flock/ALPR search violated a woman's 4th Amendment rights! "Why is it the government's business where everyone goes all the time?" "Freedom from persistent, dragnet-style surveillance while in public is not a foreign concept in our society, and it is a reasonable expectation that society already accepts" Judge Sara Hill (N.D. Oklahoma) notes other courts, including in Oklahoma, ruled the other way on Flock searches. She argues that a decision from 1983 shouldn't govern 2026 networks of what she calls "indiscriminate mass surveillance." "This Court is now faced with technology that appears to be approaching the dragnet type law enforcement practice Mr. Knotts warned of." Setting up for an interesting fight in circuit court if the government appeals. Story by @jason_koebler 404media.co/federal-judge-ru… Ruling: storage.courtlistener.com/re…
17
353
1,008
26,593
Something is a little surprising with the papers results. We'd expert diversion to be large amounts by corrupt insiders, which seems unlikely to show up as a spike in transaction volume a month later. And apparently they don't have geolocation data for transactions, they used web traffic by country as a proxy.
3
235
I can see the politics point, but thats a terrible privacy trade off you'll either end up with a bunch of fragmented pools, no fungibility and little privacy , or one mega pool that gets hacked.
1
2
61
Im not sure I follow. Even if we ignore denomination, if the anonymity set is shared, so is the blast radius of the bank gets hacked or rugs everyone.
1
1
34
Replying to @nemothenoone
Technically you only need multiplication by a constant. But yes seems hard
24
Fidmint is chuamian e-cash with a distributed set of banks that issue blindly signed tokens? So for privacy, you want one unified anonymity set. But if you have a unified anonymity set, then any bank can rug everyone. How does this tradeoff work?
1
2
253
To be clear, here I mean a committee for generating ECDSA deposit addresses where the private key is witness encrypted. Lets assume we have the WE setup done, that should be one time.
113
Replying to @handanKAlper
Yes, that was basically what I was getting at. Except, if you have an ongoing committee that has to regularly generate fresh addresses, in practice, you have a problem, because it will be mostly the same people each time and the compromise model is an ongoing attack where they get rooted, not a snapshot. That said, I had not thought about doing it Powers of Tau style when I wrote this. That occurred to me this morning; then you don't necessarily need a fixed committee, since you just take the shares from everyone who submitted and its one shot participation. No need to find reliable parties who stay online. Stil, ideally, you want this process to be rare. x.lingyaoai.com/secparam/status/210564…
Replying to @nemothenoone
I think you mean that the other way, as long as 1 of n is honest, the system is secure. I left the treshold vauge because there might be some security/availably tradeoffs there. Unless you can make the entire thing one shot participation, Powers of Tao style. That might be possible. You'd end up with a powers of tao style ECDSA key and a separate witnes encryptions for each input share.
1
172
Replying to @nemothenoone
It requires a lot of witness ciphertexts, one per share/participant. Maybe thats fine, especially if withdraws are rare. You could try to reconstruct the private key inside witness encryption to compress it. You'd need multiplicatively homomorphic witness encryption.
1
40
Replying to @nemothenoone
I think you mean that the other way, as long as 1 of n is honest, the system is secure. I left the treshold vauge because there might be some security/availably tradeoffs there. Unless you can make the entire thing one shot participation, Powers of Tao style. That might be possible. You'd end up with a powers of tao style ECDSA key and a separate witnes encryptions for each input share.
1
213
Replying to @nemothenoone
Looking forward to it.
1
19
Replying to @zkchesterton
ShieldedCSV doesn't specify how to do shield/unshielded from native Bitcoin last I looked. There's a hope Bitvm works, but unclear on that. Alpen I don't know, but looks like it also doesn't specify bridging.
56