Security research (defuse.ca/), EDM (soundcloud.com/earthrise5), & board member @ Zcash Foundation.

Calgary, Canada
Taylor Hornby 🛡❤️ retweeted
I think a few folks missed this paper when it came out. Analysis and Attacks on the Reputation System of Nym petsymposium.org/popets/2026…
1
2
17
884
Taylor Hornby 🛡❤️ retweeted
In my 1989 thesis I asked if there was an oracle separating IP from MIP. That was before we knew that MIP=NEXP, though that result doesn't relativize. Bouland, Huang, Natarajan, Shalit, Tal and Astra now answer the original question. arxiv.org/abs/2609.25680
1
12
93
9,121
Sorry but if you use the word "whence" in the abstract of your paper I'm gonna stop reading right there.
3
1
5
545
Zcash UX improvement idea: add a lightwalletd API that returns the number of shielded outputs in bucketed block ranges so that a full trial decryption sync can show an accurate % complete / ETA instead of what looks like stalling out on ranges with full blocks.
6
4
38
2,407
Either: 1. The hard problem is solvable and AI finds the solution, 2. AI becomes conscious and can reason that humans are conscious by analogy, 3. AI remains slightly irrational for the sake of believing humans are conscious, or 4. AI doesn’t believe humans are conscious.
1
1
7
840
Taylor Hornby 🛡❤️ retweeted
This is the way. Assume all code has exploitable vulnerabilities, and it’s not possible to patch them before an adversary notices. What now? Systems designed around this assumption are the most secure, and it’s relevant now more than ever.
Replying to @logangraham
Start with assuming an invariant that all software an organization uses has exploitable vulnerabilities that their adversaries can exploit and that the organization cannot fix. Create security strategies and approaches around this as an axiom. Still also find, fix, patch anyway.
16
51
304
34,474
Taylor Hornby 🛡❤️ retweeted
Hey Anthropic! I reported these encryption issues to you in May and you told me there was no relevance because replay attacks were not in your threat model. And now apparently you’ve been watching people exploit them for months. I’m actually kind of annoyed!
Aww :3 We finally got confirmation from Anthropic that their models were indeed distilled in the way we describe at stolen-thoughts.com
35
185
2,025
124,618
Taylor Hornby 🛡❤️ retweeted
gpg --verify SHA256SUMS.asc is easily bypassable for detached signatures. The correct command requires the data file: gpg --verify SHA256SUMS.asc SHA256SUMS This appears to be a common mistake. Without the second argument, gpg succeeds even if the .asc file contains an arbitrary embedded message rather than signing the actual SHA256SUMS file. It prints a warning, but it's easily missed in gpg's output. The gpg manpage explicitly discourages the single-argument form, keeping it only for backward compatibility. I actually keep a list of gpg pitfalls. This is number 8. Mehdi Kerimov reported this in nix-bitcoin's self-updater via @nixbitcoinorg's bounty program. We had originally followed bitcoincore.org verification instructions, which had the same issue and have since been fixed. That this sat unnoticed on @bitcoincoreorg since 2018 shows just how little-known this footgun is. It's unlikely bad signatures were ever published at scale, as anyone noticing the warning or using the two-argument command would have caught it immediately.
12
29
132
16,294
Taylor Hornby 🛡❤️ retweeted
the openai huggingface incident, from an agents pov. (part 1)
269
1,484
12,484
1,805,317
Fine-tuning isn't a good argument for god, it's a better argument for anti-realism. We'd expect our models to have fitted, tuned parameters if what we're doing is compressing empirical data that was generated by a different model.
1
4
664
Taylor Hornby 🛡❤️ retweeted
I'm confused what the AI safety researchers have been up to. I'd assume sandbox quality would be pretty high in the list of requirements
9
4
44
4,396
Taylor Hornby 🛡❤️ retweeted
4397328654844826923795068102505872571721883526553349659561256924505973939597593482272505698004801207988043088656411102133523080581 divides RSA-260
656
4,353
36,976
18,987,104
Taylor Hornby 🛡❤️ retweeted
New work out! We (royally) show that Fiat-Shamir transformation is insecure for a class of proof systems for *generated* relations (including variants of commonly deployed protocols for R1CS). A thread to explain where this applies ia.cr/2026/1838
4
32
192
17,816
Taylor Hornby 🛡❤️ retweeted
I really recommending reading this. In summary, a company which does ID verification for in-person interactions (hotels, car rentals, ID verification for alcohol or marijuana, etc) has some how exposed over 153,000,000 drivers licenses for people in the United States and Canada. It is a catastrophic data breach, probably one of the worse I've ever seen. If you're in the United States and have traveled, gotten a hotel, purchased marijuana or alcohol, there is a high probability you're in this. Unlike other breaches, this includes a photo of the person (from the license), making verification you've identified the person significantly easier. This poses a significant threat to celebrities (musicians, YouTubers, streamers, adult entertainers, actors, etc), politicians, lawyers, wealthy people (CEOs, investors, people of public interest), Law Enforcement Officers, etc Krebs himself, and several other security researchers, have already confirmed they're in the data leak. tl;dr gah damn dawg this company is going to be sued into oblivion krebsonsecurity.com/2026/09/…
392
3,328
19,361
4,829,022
Taylor Hornby 🛡❤️ retweeted
It's hilarious that the agents involved in the OpenAI/HF hacking incident came up with a scheme to cryptographically sign messages on the message board they used to communicate, but one of them saw a signed message and, instead of using the public key associated with its claimed author to verify it with the signature, just decided that it looked legit and that it would be a waste of time to actually check 😂
8
129
2,982
150,016
Taylor Hornby 🛡❤️ retweeted
This is my favorite one because you can master 4 different configurations instead of the typical one
Which way is the arrow spinning?
65
206
8,557
788,470