CS Prof. Security and applied cryptography. Some highlights: Zerocash (zcash, et al. ), Zexe (Aleo, Aztec, etc ), zk-creds/zk-promises(...)

Washington DC/ UMD
The effect of AI on growing security /crypto conferences: "I have published more papers in top tier security and crypto venues then all 5 of my r1 co-reviewers for usenix COMBINED"--junior collaborator of mine. IMHO, at best , we will get boring nitpick free papers out of this.
3
8
1,651
In a few months we will have: "Muse: Hey girl, I know you still think about him, want to see where he's been?" And guides like we got with Venmo:
Anthropic marketing: We built a god only we can control and gave it a “wet lab” Muse marketing: Heyy girl I know you have dozens of unpaid parking tickets. Let’s get that cleaned up
5
1,213
" A zero-knowledge proof can tell a counterparty 'Yes, this person meets your requirement' without that counterparty knowing your name, income, or address" 2026: SEC Commissioner @HesterPeirce suggests it. 2016: reviewer number 2 complains its unrealistic in a paper. sec.gov/newsroom/speeches-st…
7
25
147
7,833
Note, actually getting a zk proof for regulatory compliance is a bit more complicated than proving static eligibility requirements. For many regulatory requirements, you are going to need a means to detect fake data and stolen or shared accounts.
2
20
915
She thought she had nothing to hide, flock and the police thought otherwise.
NEW: Florida woman gives emotional testimony about being placed in solitary confinement for more than 3 days after a Flock camera falsely connected her vehicle to a deadly crash: "Correctional officers told me I had to stay there because of the severity of my charges... The cell door was shut and it was not open for approximately 86 hours." “I was terrified. I was facing the possibility of spending the rest of my life in prison for a crash I knew that I had not been involved in." "At my lowest point, I didn't want to be alive.” Lindsey Isaacs spent nearly 2 weeks in maximum-security jail before the charges were dropped.
2
9
2,205
Meanwhile the only phishing I get on LinkedIn is someone trying to get me into a data science master's. Which might actually be more financially damaging.....
Join me to see the short story of how I was offered a "Strategic advisory role" for the BlackRock executive commitee. 👇
4
1,260
If someone finds a side channel on this, is it a vampire attack?
ethereum wallet that requires blood first transaction on mainnet full 20m video of the prototype and my late night ai psychosis:
1
18
1,485
My 2018 talk "Satoshi Has No Clothes: Failures in On-Chain Privacy" is still a decent summary of bad privacy designs for blockchains. slideslive.com/38911785/sato… New since then: FHE shielded pools. They make some sense for dark pools, but the global decryption key FHE requires, even if split over n servers, makes them a bad fit for pure payments. Monero went from 10 to 15 decoys and plans to move to full-chain membership proofs (FCMP++) at some point. Oh, and Zcash proving went from 2 seconds on desktop to <400ms on an iPhone.
8
14
105
4,180
1
10
65
2,321
Privacy isn't dead. AI didn't kill it. AI killed "I have nothing to hide." It's never too late to start hiding new things. You might want to criticize your government someday. Or book a vacation at the everyday price, not the one made just for you and your recent promotion.
It's only dead if you give up I'm not giving up on privacy. I'm doubling down. firefly.social/post/x/210138…
1
9
62
3,523
What happens to Crypto/Eurocrypt when a proof of security becomes easy? Everyone's first instinct with AI papers is to raise standards, reject misformatted or technically incorrect papers. But it won't work forever. How do you define taste if those (poor) proxies are gone?
Eurocrypt 2027 received 1059 submissions, up 56% from last year (680). I'm not even sure what "review preferences" are supposed to mean with over 1000 submissions -- "I have familiarity with the subject matter of these, um, 300 papers..?"
1
1
25
4,094
Are STARKs zk yet? In theory zk by blinding is easy. In practice, implementations didn't do it, leading a few of my colleagues to wonder about feasibility. Claude tells me: "StarkWare has Shieldnet, a private payment pool, proven with Stwo. But I can't find the documentation for the zk part — no blinding parameters published, and their Lean verification work targets soundness."
8
37
3,899
On device and in-cloud trusted hardware is not perfectly secure or private. For some uses its great, for others catastrophic. For civil-society applications like Apple's Reference Image, we need to keep this in mind. Calling it Private Cloud Compute hides the distinction.
Replying to @secparam
It's super Orwellian to read professions adopting corporate marketing adjectives as if they're statements of fact: "trusted" hardware, "Private" Cloud Compute, "trusted" man-in-the-middle. The world has lost its senses on the underlying threat model.
2
1
12
1,649
Apple Reference Image is a good example of where you need nuance. When PCC breaks, Apple sees unedited images, which could expose journalists or sources. And they retain identity info for revocation. We need to be clear about those risks. And then there's the treacherous computing angle nitter.net/TimSweeneyEpic/status/…
Replying to @timsoret
I hate that Apple is legitimizing Adobe's failed "content authenticity" DRM and surveillance initiative. Sounds nice until governments demand identifying information be added, and demand all images without the DRM be treated as suspect, and use it to further censor social media.
3
497
Ian Miers retweeted
“Who’s a good boy?!” Hackers just dumped the contents of a Flock camera. They found: 🔴Software explicitly detecting people, not just plates 🔴1.6 million images logged in 21 days 🔴Key to decrypt files stored on the device itself. Finds directly contradict Flock, which claims someone with physical access can't access images. Making it worse,@GainSec warned about the physical access issue more than a year ago & Flock downplayed it. And yeah, the Flock camera logged “Who’s a good boy?!” about every 2 minutes, all while plagued with errors, crashes & reboots. By @dmehro & @josephfcox wired.com/story/hackers-floc…
195
7,588
24,971
879,886
Apple's new "Reference Image" design suggests something Apple won't say out loud: they don't actually trust the iPhone's Secure Enclave that much. They're probably right, and that has implications both for other proposals to stop deepfakes and for privacy-preserving identity, if it ever gets beyond stopping kids from looking at porn. Reference Image is a mode in the iPhone camera where Apple's servers sign a photo as genuine. The phone sends the raw data, signed by its trusted hardware, to Apple's Private Cloud Compute (PCC) servers, which process it, apply edits, and sign the result. It hides who took the photo, though Apple appears to keep identifying data so it can revoke photos from hacked phones. But why involve Apple's servers at all? It costs money and adds risk for Apple, like demands to deanonymize journalists, so they really have to get Private Compute Right. Maybe Apple couldn't get the image pipeline running inside the Secure Enclave. I doubt it. They could have, or could have with some work. But iPhones get jailbroken, and keys can be extracted from the Secure Enclave. If your threat model includes nation states making deepfakes, assume they'll do it. So I think Apple is using PCC as a trusted man-in-the-middle: it sees everything, so it can try to block exploited devices, and adapt as they see what attackers do. The other thing that relies on secure hardware is privacy-preserving credentials. Google's zk-id proposal uses hardware device binding to prevent credential sharing, and you might want to verify biometrics at enrollment too. But if we start using this for privacy-preserving KYC in banking and cryptocurrency, or for proof of personhood and deepfake prevention on social media, attackers will try to steal credentials or buy and borrow legit accounts. Device binding is meant to stop this. Apple's design suggests they think it can't.
13
16
137
10,546
Remember, if you say "threshold cryptography" 2 out of 3 times, it will keep the North Korean hackers away. Never mind that bridge they just hacked by stealing the keys for multiple distinct signing parties.
3
4
29
1,943
Of course, there are cases where you have no choice: signature keys for transactions have to live somewhere Then there are cases like key or identity escrow, where your claiming threshold cryptography mitigates very obvious downsides.
271
Kyc is, effectively, an identity escrow system. If you have zero knowledge who you customer is and a legal obligation to know, it doesn't work.
If I had a nickel for every time CT says ZK-KYC without meeting any of the baseline product requirements for a regulated fintech or financial institution
11
7
51
8,734
And as Mike Mosier points out, KYC isn't a single thing.
“KYC” isn't a defined reg term. It's people combining parts of CIP, CDD, EDD, OFAC & recordkeeping rules w/ different req’s. Some allow reliance, non-documentary verification, or risk-based procedures that don't inherently require full clear-text PII, let alone direct escrow.
1
428
Ian Miers retweeted
“KYC” isn't a defined reg term. It's people combining parts of CIP, CDD, EDD, OFAC & recordkeeping rules w/ different req’s. Some allow reliance, non-documentary verification, or risk-based procedures that don't inherently require full clear-text PII, let alone direct escrow.
2
5
29
2,011