Security Cryptography Whatever - podcast cover

Security Cryptography Whatever

Deirdre Connolly, Thomas Ptacek, David Adriansecuritycryptographywhatever.com
Some cryptography & security people talk about security, cryptography, and whatever else is happening.

Episodes

SOC2 with Sarah Harvey

We have Sarah Harvey ( @worldwise001 on Twitter) to talk about SOC2, what it means, how to get it, and if it's important or not. The discussion centers around two blog posts written by Thomas: SOC2 Starting Seven: https://latacora.micro.blog/2020/03/12/the-soc-starting.html SOC2 at Fly: https://fly.io/blog/soc2-the-screenshots-will-continue-until-security-improves/ Transcript : https://securitycryptographywhatever.com/2022/10/16/SOC2-with-Sarah-Harvey/ Links: Tailscale recent post on gettin...

Oct 16, 20221 hr 2 minSeason 2Ep. 5

Nate Lawson II

This episode got delayed because David got COVID. Anyway, here's Nate Lawson: The Two Towers. Steven Chu: https://en.wikipedia.org/wiki/Steven_Chu CFB: https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_feedback_(CFB) CCFB: https://link.springer.com/chapter/10.1007/11502760_19 XXTEA: https://en.wikipedia.org/wiki/XXTEA CHERI: https://cseweb.ucsd.edu/~dstefan/cse227-spring20/papers/watson:cheri.pdf Transcript : https://securitycryptographywhatever.com/2022/09/29/nate-lawson-...

Sep 29, 20221 hr 23 minSeason 2Ep. 4

Nate Lawson: Part 1

We bring on Nate Lawson of Root Labs to talk about a little bit of everything, starting with cryptography in the 1990s. Transcript : https://securitycryptographywhatever.com/2022/09/09/nate-lawson-part-1/ References IBM S/390: https://ieeexplore.ieee.org/document/5389176 SSLv2 Spec: https://www-archive.mozilla.org/projects/security/pki/nss/ssl/draft02.html Xbox 360 HMAC: https://beta.ivc.no/wiki/index.php/Xbox_360_Timing_Attack Google Keyczar HMAC bug (reported by Nate): https://rdist.root.org/2...

Sep 09, 20221 hr 20 minSeason 2Ep. 3

Hot Cryptanalytic Summer with Steven Galbraith

Are the isogenies kaput?! There's a new attack that breaks all the known parameter sets for SIDH/SIKE, so Steven Galbraith helps explain where the hell this came from, and where isogeny crypto goes from here. Transcript: https://securitycryptographywhatever.com/2022/08/11/hot-cryptanalytic-summer-with-steven-galbraith/ Merch : https://merch.scwpodcast.com Links: https://eprint.iacr.org/2022/975.pdf https://eprint.iacr.org/2022/1026.pdf https://ellipticnews.wordpress.com/2022/07/31/breaking-...

Aug 11, 202253 minSeason 2Ep. 2

Passkeys with Adam Langley

Adam Langley (Google) comes on the podcast to talk about the evolution of WebAuthN and Passkeys! David's audio was a little finicky in this one. Believe us, it sounded worse before we edited it. Also, we occasionally accidentally refer to U2F as UTF. That's because we just really love strings. Transcript : https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/ Links : GoogleIO Presentation WWDC Presentation W3C WebAuthN Adam's blog on passkeys and CABLE Ca...

Aug 11, 20221 hr 3 minSeason 2Ep. 1

Hertzbleed

Side channels! Frequency scaling! Key encapsulation, oh my! We're talking about the new Hertzbleed paper, but also cryptography conferences, 'passkeys', and end-to-end encrypting yer twitter.com DMs. Transcript : https://securitycryptographywhatever.com/2022/06/17/hertzbleed/ Links: Hertzbleed Attack | ellipticnews (wordpress.com) https://www.hertzbleed.com/hertzbleed.pdf https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3920031 Merch : https://merch.scwpodcast.com "Securit...

Jun 18, 202259 min

OMB Zero Trust Memo with Eric Mill

The US government released a memo about moving to a zero-trust network architecture. What does this mean? We have one of the authors, Eric Mill , on to explain it to us. As always, your @SCWPod hosts are Deirdre Connolly ( @durumcrustulum ), Thomas Ptacek ( @tqbf ), and David Adrian ( @davidcadrian ). Transcript: https://securitycryptographywhatever.com/2022/06/10/omb-zero-trust-memo-with-eric-mill/ Links: OMB Memo Executive order on cybersecurity PIV card Derived PIV BeyondCorp HSTS Preloading ...

Jun 11, 20221 hr 1 min

Tink with Sophie Schmieg

We talk about Tink with Sophie Schmieg, cryptographer and algebraic geometer at Google. Transcript: https://securitycryptographywhatever.com/2022/05/28/tink-with-sophie-schmieg/ Links: Sophie: https://twitter.com/SchmiegSophie Tink: https://github.com/google/tink RWC talk: https://youtube.com/watch?t=1028&v=CiH6iqjWpt8 Where to store keys: https://twitter.com/SchmiegSophie/status/1413502566797778948 EAX mode: https://en.wikipedia.org/wiki/EAX_mode AES-GCM-SIV: https://en.wikipedia.org/wiki/A...

May 28, 20221 hr 7 min

Cancellable Crypto Takes and Real World Crypto

Live from Amsterdam, it's cancellable crypto hot takes! A fun little meme, plus a preview of the Real World Crypto program! Transcript : https://securitycryptographywhatever.com/2022/04/12/cancellable-crypto-takes-and-real-world-crypto/ Links: Tony's twete: https://twitter.com/bascule/status/1512539700220805124 Real World Crypto 2022: https://rwc.iacr.org/2022 Merch! https://merch.scwpodcast.com Find us at: https://twitter.com/scwpod https://twitter.com/durumcrustulum https://twitter.c...

Apr 13, 20221 hr 11 min

Lattices and Michigan Football with Chris Peikert

We're back! With an episode on lattice-based cryptography, with Professor Chris Peikert of the University of Michigan, David's alma mater. When we recorded this, Michigan football had just beaten Ohio for the first time in a bajillion years, so you get a nerdy coda on college football this time! Transcript: https://securitycryptographywhatever.com/2022/03/12/lattices-and-michigan-football-with-chris-peikert/ Slides: https://web.eecs.umich.edu/~cpeikert/pubs/slides-qcrypt.pdf Links: He ...

Mar 13, 20221 hr 10 min

Biscuits with Geoffroy Couprie

We've trashed JWTs, discussed PASETO, Macaroons, and now, Biscuits! Actually, multiple iterations of Biscuits! Pairings and gamma signatures and Datalog, oh my! 🍪 Transcript: https://securitycryptographywhatever.com/2022/01/29/biscuits-with-geoffroy-couprie/ Links: Biscuits V2 : https://www.biscuitsec.org Experiments iterating on Biscuits: https://github.com/biscuit-auth/biscuit/tree/master/experimentations Apache Pulsar: https://pulsar.apache.org Spec: https://github.com/biscuit-auth/bisc...

Jan 29, 202259 min

Tailscale with Avery Pennarun and Brad Fitzpatrick

“Can I Tailscale my Chromecast?” You love Tailscale, I love Tailscale, we loved talking to Avery Pennarun and Brad Fitzpatrick from Tailscale about, I dunno, Go generics. Oh, and TAILSCALE! And DNS. And WASM. Transcript: https://securitycryptographywhatever.com/2022/01/15/tailscale-with-avery-pennarun-brad-fitzpatrick/ People: Avery Pennarun (@apenwarr) Brad Fitzpatrick (@bradfitz) Deirdre Connolly (@durumcrustulum) Thomas Ptacek (@tqbf) David Adrian (@davidcadrian) @SCWPod Links: DERP server: h...

Jan 15, 20221 hr 18 min

The feeling's mutual: mTLS with Colm MacCárthaigh

We recorded this months ago, and now it's finally up! Colm MacCárthaigh joined us to chat about all things TLS, S2N , MTLS, SSH, fuzzing, formal verification, implementing state machines, and of course, DNSSEC. Transcript: https://securitycryptographywhatever.com/2021/12/29/the-feeling-s-mutual-mtls-with-colm-maccarthaigh/ Find us at: https://twitter.com/scwpod https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian "Security Cryptography Whatever&q...

Dec 29, 20211 hr 11 min

Holiday Call-in Spectacular!

Happy New Year! Feliz Navidad! Merry Yule! Happy Hannukah! Pour one out for the log4j incident responders! We did a call-in episode on Twitter Spaces and recorded it, so that's why the audio sounds different. We talked about BLOCKCHAIN/Web3 (blech), testing, post-quantum crypto, client certificates, ssh client certificates, threshold cryptography, U2F/WebAuthn, car fob attacks, geese, and more! Transcript: https://securitycryptographywhatever.com/2021/12/21/holiday-call-in-spectacular/ Find...

Dec 22, 20211 hr 22 min

WireGuard with Jason Donenfeld

Hey, a new episode! We had a fantastic conversation with Jason Donenfeld, creator of our favorite modern VPN protocol: WireGuard! We touched on kernel hacking, formal verification, post-quantum cryptography, developing with disassemblers, and more! Transcript: https://securitycryptographywhatever.com/2021/12/05/wireguard-with-jason-donenfeld/ Links: WireGuard: https://www.wireguard.com Tamarin : https://tamarin-prover.github.io IDApro : https://hex-rays.com/ida-pro NIST PQC : https://csrc.nist.g...

Dec 05, 20211 hr 21 min

PAKEs, oPRFs, algebra with George Tankersley

A conversation that started with PAKEs (password-authenticated key exchanges) and touched on some cool math things: PRFs, finite fields, elliptic curve groups, anonymity protocols, hashing to curve groups, prime order groups, and more. With special guest, George Tankersley! Transcript: https://securitycryptographywhatever.com/2021/10/26/pakes-oprfs-algebra-with-george-tankersley/ Links: SRP deprecation: https://blog.cryptographyengineering.com/should-you-use-srp OPAQUE: https://www.ietf.org/id/d...

Oct 26, 20211 hr 15 min

"Patch, Damnit!"

A lot of fixes got pushed in the past week! Please apply your updates! Apple, Chrome, Matrix, Azure, and more nonsense. Transcript: https://securitycryptographywhatever.com/2021/09/20/patch-damnit/ Find us at: https://twitter.com/scwpod https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian Links! The accuvant story in MIT Technology Review All the Apple platforms patched FORCEDENTRY no-click 0-day Chrome patched some 0-days that were being exploited in the ...

Sep 20, 20211 hr 15 min

How to be a Certificate Authority with Ryan Sleevi

Not the hero the internet deserves, but the one we need: it's Ryan Sleevi! We get into the weeds on becoming a certificate authority, auditing said authorities, DNSSEC, DANE, taking over country code top level domains, Luxembourg, X.509, ASN.1, CBOR, more JSON (!), ACME, Let's Encrypt, and more, on this extra lorge episode with the web PKI's Batman. Transcript: https://securitycryptographywhatever.com/2021/09/06/how-to-be-a-certificate-authority-with-ryan-sleevi/ Find us at: https...

Sep 06, 20212 hr 34 min

Apple's CSAM Detection with Matthew Green

We're talking about Apple's new proposed client-side CSAM detection system . We weren't sure if we were going to cover this, and then we realized that not all of us have been paying super close attention to what the hell this thing is, and have a lot of questions about it. So we're talking about it, with our special guest Professor Matthew Green. We cover how Apple's system works, what it does (and doesn't), where we have unanswered questions, and where some of the ...

Aug 28, 202153 min

Platform Security Part Deux with Justin Schuh

We did not run out of things to talk about: Chrome vs. Safari vs. Firefox. Rust vs. C++. Bug bounties vs. exploit development. The Peace Corps vs. The Marine Corps. Transcript: https://securitycryptographywhatever.com/2021/08/21/platform-security-part-deux-with-justin-schuh/ Find us at: https://twitter.com/scwpod https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), ...

Aug 21, 20211 hr 20 min

What do we do about JWT? with Jonathan Rudenberg

🔥JWT🔥 We talk about all sorts of tokens: JWT, PASETO, Protobuf Tokens, Macaroons, and Biscuits. With the great Jonathan Rudenberg! After we recorded this, Thomas went deep on tokens even beyond what we talked about here: https://fly.io/blog/api-tokens-a-tedious-survey/ Transcript: https://securitycryptographywhatever.com/2021/08/12/what-do-we-do-about-jwt-with-jonathan-rudenberg/ Find us at: https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian https://tw...

Aug 12, 20211 hr 15 min

The Great "Roll Your Own Crypto" Debate with Filippo Valsorda

Special guest Filippo Valsorda joins us to debate with Thomas on whether one should or should not "roll your own crypto", and how to produce better cryptography in general. After we recorded this, David went even deeper on 'rolling your own crypto' in a blog post here: https://dadrian.io/blog/posts/roll-your-own-crypto/ Transcript: https://securitycryptographywhatever.com/2021/07/31/the-great-roll-your-own-crypto-debate-with-filippo-valsorda/ Links: https://peter.website/meow...

Jul 31, 20211 hr 1 min

NSO group, Pegasus, Zero-Days, i(OS|Message) security

Deirdre, Thomas and David talk about NSO group, Pegasus, whether iOS a burning trash fire, the zero-day market, and whether rewriting all of iOS in Swift is a viable strategy for reducing all these vulns. Transcript: https://securitycryptographywhatever.com/2021/07/26/nso-group-pegasus-zero-days-i-os-message-security/ Find us at: https://twitter.com/durumcrustulum https://twitter.com/tqbf https://twitter.com/davidcadrian "Security Cryptography Whatever" is hosted by Deirdre Connolly (@...

Jul 26, 20211 hr