Matteo

42 posts

Matteo

Matteo

@winterdeaf

\hyphenation{cryp-to-gra-phy} Enarghephobic (afraid of unencrypted stuff) PhD student at @ETH. Constantly retiring from CTFs @flagbot_eth @0rganizers

Katılım Aralık 2020
219 Takip Edilen158 Takipçiler
Sabitlenmiş Tweet
Matteo
Matteo@winterdeaf·
Much broken crypto, one common thread: bespoke, ill-designed cryptographic protocols. Matrix, Mega, Threema, Telegram: secure primitives are not enough in complex applications. The new mantra shall be "don't roll your own protocol".
kennyog@kennyog

We (@winterdeaf @kientuong114 and I) took a deep dive on Threema, a Swiss-made secure messaging app. We found 6 new cryptographic vulnerabilities. Full paper at breakingthe3ma.app; mini-thread follows. #threema

English
3
25
65
22.8K
Matteo retweetledi
Miro Haller
Miro Haller@miro_haller·
The 2nd Cryptographic Applications Workshop (#CAW) will be at Eurocrypt 2025! #CAW focuses on the construction and analysis of cryptography built for practice, bridging the gap between research and real-world applications. Our call of talks is open: caw.cryptanalysis.fun
English
1
7
16
3.7K
Matteo
Matteo@winterdeaf·
Much broken crypto, one common thread: bespoke, ill-designed cryptographic protocols. Matrix, Mega, Threema, Telegram: secure primitives are not enough in complex applications. The new mantra shall be "don't roll your own protocol".
kennyog@kennyog

We (@winterdeaf @kientuong114 and I) took a deep dive on Threema, a Swiss-made secure messaging app. We found 6 new cryptographic vulnerabilities. Full paper at breakingthe3ma.app; mini-thread follows. #threema

English
3
25
65
22.8K
Kien Tuong Truong
Kien Tuong Truong@kientuong114·
@_klewi Is there anywhere where we can read about the technical implementation?
English
1
0
0
164
Matteo retweetledi
Miro Haller
Miro Haller@miro_haller·
#WAC6 talks: Matteo Scarlata @winterdeaf will present "why Threema failed in practice" lessons learned from 7 cryptographic attacks against a secure messenger. The paper with @kientuong114 @kennyog will be presented at USENIX '23. Full workshop program: cryptanalysis.fun
English
1
2
9
721
Matteo retweetledi
Luca db
Luca db@cyan_pencil·
I would like to thank the chairs for letting us use heart emojis in the paper title. I think this is a very important step forward for academia and research. Can't wait to use "👀" for related work and "🤨" for limitations on the next one
Mathias Payer@gannimo

Are you working with stubborn aarch64 code? Check out @cyan_pencil's upcoming @USENIXSecurity #SEC23 paper on efficiently rewriting ARM binaries. Insight: using heuristics for optimization on a safe baseline is key! nebelwelt.net/files/23SEC3.p… Comments welcome!

English
0
5
63
6.7K
Matteo retweetledi
Daniel Paleka
Daniel Paleka@dpaleka·
No one sees ChatGPT for the first time and thinks "just some n-gram correlations" or "no real knowledge inside". Those unintuitive beliefs trickle down from some experts, who should know better than to teach their controversial theories as established fact: 🧵 (1/12)
English
19
117
851
219.5K
Matteo retweetledi
kennyog
kennyog@kennyog·
@tqbf The team here is always happy to supply fresh stunt crypto attacks for your enjoyment. 😁 @kientuong114 @winterdeaf
English
1
1
4
643
Matteo retweetledi
Kien Tuong Truong
Kien Tuong Truong@kientuong114·
In early 2022 I started working with Kenny and Matteo on analyzing Threema, the messenger used by 🇨🇭govt, army and 🇩🇪 chancellor. Happy to say that the disclosure period is over and results are out! Fun vulnerabilities included :) Check out our website: breakingthe3ma.app
kennyog@kennyog

We (@winterdeaf @kientuong114 and I) took a deep dive on Threema, a Swiss-made secure messaging app. We found 6 new cryptographic vulnerabilities. Full paper at breakingthe3ma.app; mini-thread follows. #threema

English
3
33
148
42.8K
Matteo
Matteo@winterdeaf·
@cronokirby You are of course right -- it is not a matter of credentials. But when I get out of my academic bubble, I'm always surprised by how scarcely diffused provable security and formal methods are!
English
0
0
2
42
Lúcás Meier
Lúcás Meier@cronokirby·
@winterdeaf I doesn't matter what credentials your team does or doesn't have, it matters what analysis you apply the protocol you have
English
1
0
3
68
Matteo retweetledi
organizers
organizers@0rganizers·
record score on ctftime since they introduced the new rating formula in 2017 🥳
organizers tweet media
English
7
13
118
20.3K
Matteo
Matteo@winterdeaf·
@aurelsec Try with `{permission is not denied}`!
English
0
0
1
0