Remote
Sophie Schmieg
@sophieschmieg@infosec.exchange
Leading cryptography (ISE Crypto) at Google.
Opinions my own.
Content usually badly explained mathematics
4856 Followers
283 Following
50 Posts
Joined November 14, 2022
profession:
cryptography engineer
hobby:
Kerbal Space Program
hobby:
Lego
hobby:
Factory Sim Games
Out of context work quote: "we should find these machines, take their CPUs, and mount them on a stick as a warning to the others"
Open post
In order to go viral on Mastodon, your post should include at least one cat and some criticism of AI. So here is Binah disliking large language models.
736
54
321
1
Open post
If you told me ten years ago that one day I would get into online fights with economic Nobel price laureates, and that I would be the one looking sane in the exchange, I would have laughed out loud.
171
15
53
0
Open post
I see, when NIST considers 6 bit a rounding error offset by memory cost, they basically claim that 2⁴⁰ + 2⁴⁰ = 2⁸⁰, but when someone reduces the attack cost of Classic McEliece to substantially below 2¹²⁸, memory suddenly is very important and means that the work should be dismissed.
17
1
3
0
Open post
Replying to
Most recent context:
https://github.com/golang/go/issues/80573
But generally, middle boxes that try to parse ClientHello while not following the corresponding RFCs and then dying are a constant scourge on the internet. Leave the ClientHello alone, it's not for you, if it was for you, you wouldn't be a middle box, but a server.
13
1
4
0
Open post
Replying to
Maybe we can define a PQC signature that kills the very concept of a middle box itself. Like on a platonic ideal level.
12
1
3
0
Open post
Has anyone written a "things developers misunderstand about probabilities" guide?
23
1
20
0
Open post
Okay, now I need a version of this with all the PQC algorithms.
https://youtube.com/shorts/7m5zila7gnY?is=FuX-_vXeqEWe4tMl
13
1
1
0
Open post
Boosted by @hypebot@goingdark.social
I think I might need to check some luggage, my bag doesn't want to close.
223
6
84
0
Open post
Replying to on mastodon.social
1
1
0
0
Open post
The Deutsches Museum Thermometer has an out of bounds exception
50
0
34
0
Open post
Boosted by @hypebot@goingdark.social
@saraislet@infosec.exchange : Look at that girl's tattoo
Me: sorry, missed it
@saraislet@infosec.exchange : Look at those boots!
Me: sorry, missed it
@saraislet@infosec.exchange : Look at…
Me: we're at a train station. Just assume that I'm distracted by trains.
40
0
15
0
Open post
Replying to
@paul_ipv6@infosec.exchange especially given the horrendous amount of overtly political 6-3 decisions that came out of this Supreme Court. He's literally angry about these justices doing the bare minimum to uphold their oath.
2
1
0
0
Open post
Me: I don't think we have lounge access. I mean you can ask, but they're going to be incredibly rude about it so I'm not going to
@saraislet@infosec.exchange *asks*
@saraislet@infosec.exchange is politely told no
Me: 🤔
Me: …
Me: oh! We're in Canada! That was rude for Canada! I was confused there for a bit.
21
3
1
0
Open post
Replying to
@alwayscurious@infosec.exchange @mei@donotsta.re one important thing to know about mathematics is that there are two layers to every problem: how to find the solution and how to formalize the solution. Finding the solution usually involves steps that are omitted when writing up the solution as a formal proof, but are just as important to develop. Oftentimes, the formal write-up ends up being the inverse of what you actually did to find the solution in the first place: you start out exploring your problem and noting necessary and sufficient conditions for it. Then you start looking at those conditions and try to find necessary and sufficient conditions for these etc.
But when writing up the proof, you start with your collection of lemmas, and only move to prove the main theorem once you have all your preconditions sorted out.
Reduction proofs follow a similar pattern: when actually doing the research, you don't start with "assuming I have an attack on my problem, how does this attack my building blocks", but you start with "what properties do I need and what building blocks provide those", and only when you have a construction that actually works you move to write it up as a formal reduction proof, following the breadcrumbs you got when constructing your protocol/primitive.
The formal step is still very important, especially for primitives, as it ensures that nothing slipped through. In protocols you can use things like universal composability instead of reduction at times, making the proof look more natural.
1
1
1
0
Open post
Replying to
@alwayscurious@infosec.exchange @mei@donotsta.re these proof types serve slightly different purposes: reduction proofs are very useful when constructing cryptographic primitives. I.e. you want to show that AES-CTR is IND-CPA secure as long as AES is a secure PRP.
The direct proofs you mentioned are usually used to prove protocols secure, using the properties that the primitives are shown to have to construct an interaction that is secure, as long as the components are secure.
They usually could also be written as reduction proofs (assume the protocol is broken by attacker A. Since we verified the certificate, this means the certificate has a valid signature without the adversary having access to the private key, we can construct an EUF-CMA attacker A' that calls A, simulating the protocol to it using its oracle that will now win its attack game). It's just that for a protocol analysis this type of reduction proof is usually overkill and doesn't convey information, so it's merely implied and left to the reader.
1
1
0
0
Open post
Open post
Replying to
@paul_ipv6@infosec.exchange that does sound more accurate, yes. MitM as a service.
1
0
0
0
Open post
Things will get real fun when all these new TLS WG members realize that it is not, in fact, a vote.
https://datatracker.ietf.org/doc/html/rfc7282#page-16
16
7
1
0
Open post
I had this one sitting in my draft queue before I went on vacation, and forgot to hit publish. I hope nobody starved.
So please enjoy my rant on hybrid signatures.
https://keymaterial.net/2026/06/18/on-hybrid-signatures/
19
4
10
1
Open post
I feel like "For all Mankind" is more and more just the prequel for the Expanse
15
6
2
0
Open post
Lol. LMFAO, even.
Men literally count the number of times a woman uses the word "literally" in order to avoid going to ther^H^H^H looking at the content of a blog post.
https://mailarchive.ietf.org/arch/msg/tls/0KXcI7-afJC1hlDFs-Hy87BkRY8/
12
2
4
0
Open post
Replying to
@kouett@soc.kouett.net.eu.org @lina@vt.social honestly, it's too bad for that. I can whip you up a way of generating "keys" that would be impossible to cryptanalyse, just the fact that you used my server to generate them is enough. Why let your adversaries exploit the same weaknesses you are exploiting when you don't have to? This smells of incompetence, not intent.
15
0
0
0
Open post
Christianity is only valid modulo two
7
1
1
0
Open post
Replying to
@prism@infosec.exchange @neurovagrant@masto.deoan.org the algorithm was @catsalad@infosec.exchange all along!
12
0
2
0
Open post
I don't get why anybody is listening to Jacob Applebaum. My cat has about the same expertise in cryptography, and has never been credibly accused of sexual abuse. She's also a lot cuter.
2
4
0
0
Open post
Me: what's up with all these goose memes?
…
…
Me: Goose was not valued!
2
0
1
0
Open post
I now get pestered by more djb minions on here being all like BuT WhAt If YoUr BaNk UsEd PuRe ML-KEM?!!)?!?
Well, if my bank servers support this cipher exactly nothing happens. My client will still not offer it, so it will not be negotiated. And if it were to be negotiated then… also nothing would happen and my data would stay secure.
1
2
0
0
Open post
Help me settle this important issue with my wife, @saraislet@infosec.exchange
How many presidents had sex at least once in the Oval Office after becoming president?
2
3
4
0
Open post
The three energy levels of the cat atom, before excitement.
0
1
0
0
Open post
I hate coming of airplane Wi-Fi to the news that there has been a terror attack on the pride parade in Berlin
0
0
0
0
Open post
LEAN was used to prove the Collatz conjecture. The proof exploited several vulnerabilities in the proving engine, and is not actually valid, which is par for the course for the Collatz conjecture, known exploit of the human mind.
0
1
0
0
Open post
Don't make Wittgenstein cry, please.
https://mailarchive.ietf.org/arch/msg/tls/vPt6gIgWBHlvDcIN6lvHg8CPLJE/
0
1
0
0
Open post
My wife: "the car went 4 miles per kWh"
Me: "don't you mean 1.7 mm/J?
0
1
0
1
Open post
On the HAWK break: setting aside the LLM part of the narrative, this fits very well into my priors. I only had started looking at HAWK fairly recently and have not devoted much time to it, but when then I was not really convinced by the security argument. My main concern is that HAWK's public key is a global property, while any other module lattice based scheme only ever reveals local properties (Local/Global with respect to the number field order). Global properties contain much more usable information, so being able to reduce the problem to a smaller lattice is not too unexpected. I do not expect similar results to apply for MLWE or NTRU based schemes. Even though HAWK is a lattice algorithm, it's one that is much more deeply intertwined with the module structure, which gives it an Achilles heel.
The fact that this was done with heavy LLM assistance on the other hand is quite surprising. It's unclear how much of this is marketing hype, and there is no surpassing human capabilities there yet (except maybe in time spent), so I don't see a revolution in cryptanalysis per se, but certainly interesting new tools for researchers.
0
0
0
0
Open post
Imagine misquoting German phrases in public, to a German.
Like what the hell is even happening here?!?
https://mailarchive.ietf.org/arch/msg/tls/ZHXO2T39xNb8Fg-QDqK5sjF7kww/
0
0
0
0
Open post
Going to hotel bar, asking for dinner
Host: dinner?!? Not football?!?
Me: yes dinner. Food, for eating, please.
Ah Vienna, never change.
0
1
0
0
Open post
Why do 3mg of US melatonin absolutely knock me out to the point of being tired in the morning, while 3mg of European melanin, with the same jetleg time and direction barely keep me asleep until midnight.
Both products claim to only contain 3mg of melatonin and pill filler, but the European variant is in a capsule and the US variant is not.
0
1
0
0
Open post
TLS session in half an hour. Can I have some pictures of cute kittens, to offset the cosmic balance?
0
0
0
0
Open post
Ah, I see the pure ML-KEM LC has been resolved to the positive by the chairs while I was in the air.
Brace for impact
0
1
0
0
Open post
Imagine falsely thinking something is an online poll, try to manipulate the outcome by getting your followers to "vote", still losing the "poll" by a decent margin, even though no organized counter campaign exists and overwhelmingly losing when the actual rules are applied as written, and calling foul play.
That's essentially the non-technical version of the non-story of pure ML-KEM in TLS at IETF.
(The technical story is that the stakes couldn't be lower with the details in my now 8 months old blog post)
Now let's hope journalists manage to do some source work before writing articles on how the IETF has been undermined by intelligence agencies trying to backdoor everything
0
0
0
0
Open post
How to interpret a base64 encoded ML-DSA signature: first kilobyte: the exhausting part
Second to last bytes: AAAAAAAAAAAA the eternal scream after being done with the exhausting part
The last few bytes: the death rattle
0
1
0
0
Open post
*Opens the TLS WG inbox after three weeks OOO*
*Closes the TLS WG inbox*
0
0
0
0
Open post
Newspaper: trump threatens tariffs due to Canadian wildfire smoke
My jetlagged brain: I'm pretty sure the Canadians aren't charging for the smoke to begin with
0
1
0
0
Open post
The fact that three Supreme Court Justices were willing to throw it jus solis shows you how "conservative" they are.
0
0
0
0
Open post
Replying to
@andrewg@mastodon.ie @unrequitedlove@mastodon.social @letoams@defcon.social he does love to produce lots of text.
He also loves to throw only vaguely related papers at people that usually don't support what he says they do, but it takes you half an hour to figure out, because now you have to read a paper.
0
0
0
0
Open post
Technician: so usually this end is supposed to be cool and that end is supposed to be warm, but in your case it's the other way around
Me: so we have heatpump?
Technician *laughs*: no you have a broken AC
0
0
0
0
