Marcus Brinkmann's Avatar

Marcus Brinkmann

@lambdafu

I'm a tempura shrimp and you can't catch me! | 🐒 Terrapin Attack | πŸ¦™ ALPACA Attack | 🦝 Raccoon Attack | 😈 DEMONS Attack | @lambdafu@mastodon.social

63
Followers
69
Following
49
Posts
23.01.2025
Joined
Posts Following

Latest posts by Marcus Brinkmann @lambdafu

Why?

08.03.2026 12:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
βš“ T8044 gpg-agent stack buffer overflow in pkdecrypt using KEM

On the plus side, LLMs don’t hold their noses at hard to read code like GnuPG (I remember your students complaining about it). dev.gnupg.org/T8044

16.02.2026 15:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I am not familiar with verified code. Is it common to have admit, lax and delayed proof statements? Great write up, thanks!

13.02.2026 09:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I gave our students two screenshots, one with a valid PGP signature and one with a signature by the attacker (also valid) where the signer had a different eTLD and a spoofed From: address. They complained it was too hard to spot .org instead of .de. We need sender validation for signed PGP emails!

11.02.2026 06:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I’m sorry you had a bad exp. It absolutely can be, but at least for me that’s rare. I prefer β€žcoordinated vuln. disclosureβ€œ because it doesn’t imply other ways are irresponsible. Anyway I would hate to be boxed in one form of disclosure. Interests of stakeholders can be aligned, why not use that?

10.02.2026 07:28 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

My experience: It's surprisingly usable. First result was within 5 minutes, fine tuning was done after two hours. Another two hours for adding convenience features, and a final hour for testing and cutting a release.

08.02.2026 00:58 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Main features: Filter by topics, keywords (from title and abstracts), text, or preference. Sort by number, title, score, preference. Show all abstracts or just one, show topics. Navigate and rank by keyboard. Undo and redo. Everything is stored in local storage (just reload the CSV and it's there).

08.02.2026 00:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
A screenshot of a web page that shows a list of papers that can be filtered and searched, to enter review preferences for a HotCRP conference.

A screenshot of a web page that shows a list of papers that can be filtered and searched, to enter review preferences for a HotCRP conference.

I vibe-coded hotcrp bidding helper with Claude. It's a single index.html (+2 JS libs from CDN). Preferences can be im- and exported via CSV. Topics/Keyword scores can be taken from your own publications (just drop in PDFs and run a script). Image shows fake data. Enjoy! github.com/lambdafu/hot...

08.02.2026 00:51 πŸ‘ 1 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

When the AI wars come, we will wish the browser war back.

30.01.2026 00:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Call for papers

Now's your chance to participate in growing academic cryptography participation in the Middle East and North Africa region: the Africacrypt call for papers is out!

Submit your paper and come join us this July in beautiful Hammamet, Tunisia: www.africacrypt2026.tn/call-for-pap...

29.01.2026 11:33 πŸ‘ 7 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0

Anything in particular? I wouldn’t even know where to look for news and stories on that industry.

25.01.2026 09:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

The decent thing would be to delete the inbox every afternoon before heading home. Then everybody has a fighting chance.

13.01.2026 16:12 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Over the past few months, I have left my comfort zone and begun working on Agentic AI systems. For that, I am now trying to fill several roles, so if that sounds like something you'd like to work on with me, please get in touch.

12.01.2026 08:22 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Submissions are now open for the SPIQE Workshop! Submit your work until 12th of March AoE! βš›οΈ spiqe.cool

06.01.2026 15:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

At the gpg.fail talk and omg #39c3

You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message.

Won’t even blame PGP here. C is unsafe at any speed.

gpg has not fixed it yet.

27.12.2025 16:31 πŸ‘ 437 πŸ” 110 πŸ’¬ 4 πŸ“Œ 21

What are good alternatives?

27.12.2025 12:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

We are just waiting for our AI token quota to reset.

10.12.2025 08:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

At least they now know we didn’t withdraw our submission.

10.12.2025 08:16 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

The university library MΓΌnster has a clear opinion on this matter. upload.wikimedia.org/wikipedia/co...

05.12.2025 09:28 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I strongly believe that AI will have a lasting impression on human to human communication. Expectations will be presented as prompts rather than as opportunities. The response to non-compliance will be reinforcement rather than reflection. And success will be judged by how well the recipient obeyed.

05.12.2025 09:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
SPIQE

Announcing SPIQE 2026: 2nd Workshop on Secure Protocol Implementations in the Quantum Era, bringing together researchers and implementers to securely deploy PQC!

πŸ“ Co-located with Euro S&P in Lisbon, Portugal, July 6-10, 2026
spiqe.cool
#SPIQE2026 #EuroSP #PostQuantumCrypto

03.12.2025 14:32 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Das erinnert mich sehr an die Arbeiten von Andy Goldsworthy!

10.11.2025 07:42 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

When I met Hermann HΓ€rtig at Eurosys 2006 I talked to him about the relevance of formal verification in OS design and he just smiled and asked me if I can show that a user space program can’t escape to ring 0 (kernel mode) on the CPU. 😲

06.11.2025 20:54 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Counterpoint: imagine an alternative world where the NSA truly believes that QC is possible within two or three decades. Could we observe the difference from the outside? And if no, which world is more likely?

23.10.2025 06:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I haven’t been in Paris for a long time. But I have been in Barcelona and although it is smelly and really crowded, I had no involuntary body contact there at all. People seemed to in general have more awareness of what is going on around them. Japan is wonderful, and a great inspiration!

19.10.2025 13:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Inside the train: People blocking free seats, playing loud music, talking loudly, drinking beer, coffee in a puddle on the ground. I’m used to it (I’ve grown up here), but it’s just flat out awful. I think the trains would be better with a more open seat layout and strict, enforced no food/drinks).

19.10.2025 13:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

And because trains share platforms, there are no markings to tell you where the train goes and where you can stand and wait. People rush to the doors and block the people trying to get out - it’s really annoying.

19.10.2025 12:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

By far the biggest problem is the trains, though. It’s nice that we have such a dense public transport system, but they all share the same rails, which causes congestion with famous delays. And if you miss one train, you have to switch platforms with all your stuff. Platforms can also change sudden.

19.10.2025 12:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Let’s not talk about the dirty ground. The Germans in my area are in general pretty badly behaved (shoving, running, letting your wheeled suitcase run ahead of you without holding it, taking loudly etc.) and there is just not enough workers around to keep things clean and people in check.

19.10.2025 12:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

It’s also insane that renting a little trolley for your bags costs 2.50 EUR. And of course you can’t go to the train station with it, so it is pretty useless anyway.

19.10.2025 12:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0