Tag Archive

cryptography

10 posts found

Merkle-Damgard State Leakage: Exploiting Secret Concatenation in API Auth

How Merkle-Damgard hash constructions leak internal state vectors and why secret concatenation fails API authentication.

Europol Quantum Warning: Hardening Crypto Wallet Signatures Before Harvest-Now Attacks

Europol flagged crypto wallets as the primary risk for harvest-now-decrypt-later quantum attacks. Here is a technical breakdown of how to evaluate signature exp…

Paying for AI Without Revealing Who You Are: Zero-Knowledge Inference Tokens Explained

Zero-knowledge proofs decouple payment identity from LLM inference requests. Here is how the cryptographic architecture works and what security risks exist at t…

Proving zkVM Circuit Soundness: Lessons from zkWasm and Coq

A USENIX study showed 90% of zero-knowledge circuit vulnerabilities break soundness. Here is how formal verification in Coq caught a flawed call frame design th…

Hardware Security Modules Don’t Make Signing Interfaces Safe

Keeping a private key inside an HSM is not enough. UC San Diego and INRIA researchers forged RSA signatures without extracting the key — by treating the device …

X25519MLKEM768 vs X25519: Evaluating Hybrid Post-Quantum Key Encapsulation

A technical comparison of X25519 and hybrid X25519MLKEM768 in TLS 1.3, evaluating handshake wire overhead, CPU cycles, cryptanalytic resilience, and edge middle…

Voltage Glitching and Side-Channel Leakage in Embedded Cryptographic Silicon

Hardware security modules and cold storage wallets isolate private keys inside microcontroller flash memory. When attackers obtain physical access, precision vo…

Noise Handshakes for NAT Traversal: Rathole Multiplexing Architecture

An architectural look at how user-space Noise Protocol tunnels avoid TCP-over-TCP breakdown and solve CGNAT ingress bottlenecks.

How to Replace Static Authorized Keys with OpenSSH Cryptographic Certificates

Replace static authorized_keys with an OpenSSH Certificate Authority to issue time-limited certificates, eliminate known_hosts prompts, and enforce instant revo…

Why Entropy Failures Haunt Self-Hosted Cryptography

A practical analysis of entropy exhaustion, kernel RNG validation on Linux nodes, and defensive key generation patterns.

Press Cmd K to search برای جستجوی سایت از Cmd+K استفاده کنید