Deno promises to be secure by default. A study by CISPA researcher Abdullah Alhamdan shows that while Deno has a smaller attack surface than Node.js, it is not automatically secure. Shadow permissions and URL-based imports can introduce supply-chain risks. Learn more: cispa.de/en/deno
Sabotage as a service. Iran is recruiting spies and potential saboteurs through Telegram, and Russia is doing the same. Both services pay ordinary people for specific tasks, because maintaining classical agent networks is too expensive and too easy to dismantle. inews.co.uk/news/iran-hi...
Especially since they can make it come from a contact you trust already in a thread that already exists
@kientuong114.bsky.social Just occurred to me: the message injection vulnerability is really a premium malware injection method by an APT actor
Me, secretly hoping that someone will notice that my caps lock posts have layered meanings and references (try googling this one for example)
People reading this post: this guy is weird and tweets in broken English and caps lock
Translation: Iβve left #realworldcrypto a few hours early to enjoy the sunny weather in Taipei and to recharge a bit, but am still available in Taipei the next couple of days in case anyone would like to reach out.
NOW I WILL SLEEP FOR THE OTHER 100 YEARS.
Iβll be at the coffee area in around 20mins with your box! Which color will you get!??????!!?!??!?
Also please show me ID before I can give you the box (for safety reasons)
Yes obviously, this is a very dangerous and serious product!
Rahoe Night Market! I got one for you!
Buying myself a souvenir of today. Which color will I get???
Very humbled by the reaction to my talk! Tried to talk to as many people as I could today afterwards, but my social battery is now minus 700% so I really need a break. I will be available tomorrow if anyone wants to chat more! #realworldcrypto
This is the session that reminds us: cryptography is not just math. It's policy, ethics, power, and access. When proofs aren't enough, context matters. And building crypto education in Lebanon proves cryptographic infrastructure can be an act of resilience.
The room gets philosophical. Cryptography & Society chaired by Nick Sullivan ( @nicksullivan.org ): what is crypto hiding from itself? Security vs. interoperability? CRA policy? Proofs that aren't enough? And Nadim Kobeissi on teaching crypto in post-crisis Lebanon. #realworldcrypto
The talk by @simonecolombo.bsky.social, @malb.bsky.social and @bedow.bsky.social at #realworldcrypto is super important and exceptional! Everyone should review this talk: iacr.org/submit/files...
I can never thank you enough for the years of laughs, witty commentary and thoughtful questions your comics have given me and my friends!
A BEAUTY IS JOYING IN MY HEART!
Spoke to seven trillion people today
Abstract. Signal is a secure messaging app offering end-to-end security for pairwise and group communications. It has tens of millions of users, and has heavily influenced the design of other secure messaging apps (including WhatsApp). Signal has been heavily analysed and, as a result, is rightly regarded as setting the βgold standardβ for messaging apps by the scientific community. We present two practical attacks that break the integrity properties of Signal in its advertised threat model. Each attack arises from different features of Signal that are poorly documented and have eluded formal security analyses. The first attack, affecting Android and Desktop, arises from Signalβs introduction of identities based on usernames (instead of phone numbers) in early 2022. We show that the protocol for resolving identities based on usernames and on phone numbers introduced a vulnerability that allows a malicious server to inject arbitrary messages into one-to-one conversations under specific circumstances. The injection causes a user-visible alert about a change of safety numbers, but if the users compare their safety numbers, they will be correct. The second attack is even more severe. It arises from Signalβs Sealed Sender (SSS) feature, designed to allow sender identities to be hidden. We show that a combination of two errors in the SSS implementation in Android allows a malicious server to inject arbitrary messages into both one-to-one and group conversations. The errors relate to missing key checks and the loss of context when cryptographic processing is distributed across multiple software components. The attack is undetectable by users and can be mounted at any time, without any preconditions. As far as we can tell, the vulnerability has been present since the introduction of SSS in 2018. We disclosed both attacks to Signal. The vulnerabilities were promptly acknowledged and patched: the first vulnerability was fixed two days after disclosure, while the second one was patched after eight days. Beyond presenting these devastating attacks on Signalβs end-to-end security guarantees, we discuss more broadly what can be learned about the challenges of deploying new security features in complex software projects.
Image showing part 2 of abstract.
Signal Lost (Integrity): The Signal App is More than the Sum of its Protocols (Kien Tuong Truong, Noemi Terzo, Kenneth G. Paterson) ia.cr/2026/484
Just finished presenting this work at Real World Crypto in Taipei :)
TL;DR: We found 2 attacks on Signal (Android, Desktop) where a malicious server can inject messages in conversations.
Super fun project! Thanks a bunch to Noemi Terzo, @kennyog.bsky.social, and @cryptojedi.bsky.social
Incredible that thirteen years later, the core problem affecting my original secure messaging project, Cryptocat, is being seriously considered!
Cryptocat was essentially the poster child for this precise weakness of the web.
Watching remotely? You can follow Real World Crypto 2026 on YouTube livestreams (also available via the website):
Day 1 (Mar 9): youtube.com/live/QQhyxFj...
Day 2 (Mar 10): youtube.com/live/00zvMSW...
Day 3 (Mar 11): youtube.com/live/v_AFtbW...
π΄π±π§ 83 children among almost 400 people killed in one week of conflict between Israel and Hezbollah, says Lebanon's health minister.